We think out loud about clinical compute.
The substrate decisions deserve to be argued in public, by the people building on them and the people building the substrate. These are the positions we take, and the work behind them.
Read. Push back. Email the author.
Five things we will defend in public.
Each position is an architectural claim Forge has consequences for. Each one links to the essays we use to defend it. If you disagree, email an author.
- POS / 01Position
Sovereignty is architectural, not contractual.
Most cloud claims about sovereignty rest on a clause in a DPA. Ours rests on routes that don't exist. If the data path to another jurisdiction was never built, you cannot accidentally cross it. We argue for sovereignty as a property of wiring, enforced by physics, not by a paragraph an auditor reads on page 47.
The work behind it - POS / 02Position
MicroVMs are the only credible compute boundary for clinical workloads.
Containers are fine for retail. They are not survivable for clinical software. A shared kernel is a soft boundary, and a soft boundary is one you defend in an audit room. Hardware-isolated microVMs draw the boundary in silicon. That argument has consequences for performance, density, and economics; we make it anyway.
The work behind it - POS / 03Position
Telemetry is evidence. Same workspace, two readers.
The on-call engineer's incident query and the auditor's compliance query should resolve against the same labels in the same workspace. When they don't, both readers are worse off. We argue that observability and evidence are the same product, deployed once, queried by two audiences.
The work behind it - POS / 04Position
Compliance evidence emerges from the runtime.
BAAs are usually negotiated, then the architecture is asked to live up to the document. We do it the other way around: the BAA describes how the runtime already behaves. Same with HIPAA's technical safeguards, GDPR Article 32, BSI C5, and the EU AI Act's Article 9. The evidence is a property of the platform, not a project run before the auditor arrives.
- POS / 05Position
3verest is the mountain. Bifrost crosses. Forge builds.
We are a portfolio company, not a standalone product. 3verest is the sovereign healthcare cloud. The substrate. Bifrost is the guarded crossing between regulated data and frontier AI. The intelligence layer. Forge is the runtime where clinical software gets built and shipped. The workshop. The shape of the family is the shape of the architecture: substrate, intelligence, workshop. A team building on Forge has a sovereign cloud underneath them and a sovereign AI substrate next to them, by design.
The work behind it
These are positions, not opinions. They have consequences. So do we.
Seven essays. Three lenses.
Written quietly. Read slowly. Each essay carries an author, a length, and a tag so you can find the one you came for.
Architecture & strategy.3 essays
MicroVMs for regulated compute.
Why hardware-isolated microVMs are the only credible compute boundary for clinical workloads.
Sovereignty as an operational property.
Sovereignty isn't a marketing word. It's an architectural attribute. Drawn into the wiring before the first workload boots.
The sovereign compute stack.
What sits beneath Forge. Bare metal, private backbone, runtime, and why each layer matters.
Security & perimeter.1 essay
Compliance & evidence.3 essays
HIPAA technical safeguards, in practice.
What §164.312 actually asks for, and how a sovereign runtime answers each clause as a property rather than a configuration.
EU data sovereignty under BSI C5.
Connectivity inside the perimeter. Meeting BSI C5 controls while keeping data inside the German jurisdiction.
Hosting AI models under the EU AI Act.
Article 6, Article 9, and the substrate problem. What a sovereign runtime needs to provide to make Article-9 risk management defensible.
The briefs we share with the people procuring us.
These are the documents that come out of a signed NDA. They are separate from the public essays for a reason: they include audit detail, control mappings, and timelines that we owe to a real buyer in front of us, not to a search engine.
Request a brief- BRF / 01
HITRUST CSF r2 roadmap.
Certification timeline, scope, and gap-analysis methodology. For procurement and security teams.
NDA - BRF / 02
SOC 2 Type II detail.
Audit period, control coverage, and the underlying 3verest substrate report. Available with a signed NDA.
NDA - BRF / 03
BSI C5 control mapping.
How ForgeMesh, ForgeVault, and IsoCell satisfy each control objective. Sized for German procurement.
NDA - BRF / 04
GDPR Article 28 DPA.
Standard DPA with the sub-processor list, sub-jurisdictions, and the right-to-be-forgotten primitive.
NDA - BRF / 05
AI Act Article 9 risk mapping.
How the runtime supports the risk-management system required for high-risk AI. Source map and evidence flow.
NDA
When clinical software needs AI.
Forge gives clinical software a sovereign runtime to be built on. Bifrost gives that software a sovereign substrate for AI. Together they let a team ship a clinical product with a frontier model under the hood, without the patient record ever leaving the perimeter.
That composition isn't a coincidence. It's the portfolio architecture: substrate, intelligence, workshop. The shape of the family is the shape of the product surface.
- 01ForgeRuntime
Your clinical software runs inside hardware-isolated microVMs. PHI lands in ForgeVault, inside a named jurisdiction.
- 02Inside the perimeterSovereign boundary
ForgeMesh holds the network boundary. East-west traffic is mTLS, egress is default-deny, and the data path to Bifrost lives inside the same jurisdiction.
- 03BifrostIntelligence
A frontier model in the curated catalogue runs against your tenant context. The model sees the record. The model never leaves the sovereign perimeter.
- 04EvidenceAudit
Every inference is traced in ForgeObserve and recorded in ForgeAudit. The AI Act Article 9 risk-management story emerges from the runtime, not from a separate process.
Clinical AI ISV
Build the product on Forge. Inference through Bifrost. Ship a single procurement story to the hospital: one perimeter, one auditable trail.
Imaging platform with AI overlays
DICOM ingestion on Forge. Model inference on Bifrost. The radiologist never sees the boundary because the boundary never moved.
Hospital-owned AI
Hospital builds its own copilots on Forge. Bifrost runs the models inside the hospital's jurisdiction. The clinical record never leaves the institution.
Two products, one perimeter. The bridge holds. The forge holds.
Identifiable humans, reachable by email.
The positions and the essays are written by people, not by a brand. If you read something here and want to argue, you can email the person who wrote it.
Scott Crawford
Strategy. Sovereignty. The family architecture.
scott@3verest.comSheraz Bhatti
Architecture. Compute boundaries. Compliance evidence.
sheraz@3verest.comMore contributors as the runtime grows. Each one named, each one reachable.
Read the substrate decisions.
Five positions and seven essays. About 70 minutes if you do them all in one sitting. Most readers do it in two.
Start with the positionsEmail an author.
If you disagree with a position, write a paragraph and send it. We answer every well-formed argument, usually within a week.
scott@3verest.comRequest a brief.
Procurement, security, and clinical-safety reviewers can request the NDA briefs through the contact channel.
Request a briefRead. Push back. Email the author.
If our positions help you, build on them. If they don't, tell us where we're wrong. Either response moves the work forward.