Privacy & guardrails
Keeping sensitive data safe and stopping AI from saying things it shouldn't.
In healthcare, legal and government work, where data goes matters more than which model you use. I design systems where sensitive data is separated by architecture — so a bad prompt can't route around it — with checks on what goes in and what comes out.
- What this covers
- PHI / PII detection, tokenization and re-identification on read
- Two-zone architectures that keep identified data away from hosted models
- Prompt-injection defense, including injection through retrieved content
- Structured output enforcement, audit logging and role-based access
Work in this area
Case study · Legal practices — plaintiff, defense & injuryMedical-Legal Intelligence PlatformHelps attorneys make sense of thousands of pages of medical records — without patient details ever reaching an outside AI service, and with the same answer every time the case is run.Case study · Health plans & payersHealthcare Claims IntelligenceTurns piles of messy claim documents into clean, structured summaries, so physicians spend their time deciding instead of reading.Case study · U.S. government transit authoritySecure Enterprise AI AssistantA private, ChatGPT-style assistant that lets thousands of employees ask questions about internal documents — with every conversation logged and nothing leaving the organisation.
Other areas
Contact
Working on something
like this?
I'm open to AI engineering, architecture and training work. Tell me what you're building and what the constraints are — that's usually enough to start.
Prefer a short form? Send a project brief
- Taking on new projects
- Usually replies within a day