AI compliance for healthtech

When an NHS trust asks if you can prove your AI decisions — what do you say?

Velarc is a compliance layer for AI. It sits between your application and your AI provider, capturing every interaction with the business context auditors actually need.

Request early access

Observability tools track costs and latency. Enterprise governance platforms cost six figures and take months to implement. Nothing exists for healthtech companies that need to demonstrate AI compliance now — before August 2026, before the next procurement conversation, before the first audit.

01 — Integrate
One API call

Point your application at the Velarc proxy endpoint instead of your AI provider directly. Add structured business context as metadata — use case, business object, user. That's the integration. A Spring Boot starter SDK for zero-boilerplate configuration is coming soon.

02 — Capture
Every interaction logged

Who initiated it, what clinical object it touched, what the AI decided. Structured business context, not just prompts and responses.

03 — Prove
Audit-ready on demand

When an auditor or NHS trust asks for your AI audit trail, you have one. Export it, share it, stand behind it.

Complete audit trail

Every AI interaction logged automatically. Audit events are append-only by design — the application layer never modifies or deletes them. Database-level enforcement is on the security roadmap.

Structured business context

Not just prompts and responses — clinical objects, user identity, use case metadata captured with every call.

EU AI Act coverage

Articles 12 and 19 for high-risk AI systems — automatic event logging and minimum six-month retention. Enforceable 2 August 2026.

Compliance reporting

Export what an auditor actually needs — not a developer dashboard. Structured records of AI activity by use case, by user, for any given period. Compliance reporting is on the roadmap.

Provider-neutral

Works with OpenAI and Anthropic. Azure OpenAI — required by many NHS and UK enterprise customers for data residency — is next on the provider roadmap. Additional providers follow.

Healthcare domain support

Built by an engineer with 30 years' experience in regulated industries — healthcare, finance, and energy.

Built for healthtech. Applicable to any regulated industry operating high-risk AI.

Azure OpenAI

Required by NHS and UK enterprise customers who mandate Azure data residency. In active development — next provider on the roadmap.

Spring Boot starter SDK

A single Maven dependency that auto-configures the Velarc proxy client via your existing application.yml. Zero boilerplate. No manual HTTP client wiring required.

Resilient proxy with fallback

If Velarc is ever unreachable, your AI traffic continues directly to your provider — uninterrupted. The SDK captures the interaction locally and reconciles it with your audit trail automatically on recovery.

Encryption at rest

AES-256-GCM application-layer encryption for AI request and response content, with per-tenant key management via external KMS. Infrastructure and schema are already in place.

Scheduled compliance reports

Export what an auditor actually needs — a structured record of AI activity for a given period, by use case, by user. Manual export and scheduled automated delivery are both on the roadmap.

Configurable retention periods

Enforce minimum retention periods per pricing tier — six months on Starter, twelve months on Professional. Designed to meet EU AI Act Article 19 requirements automatically.

Self-hosted deployment

Run Velarc on your own infrastructure for full data residency control. Available at Enterprise tier. Designed for organisations with strict cloud infrastructure requirements.

EU AI Act — enforceable 2 August 2026

Healthcare AI is explicitly classified as high-risk under the EU AI Act. From August 2026, operators must automatically log AI interactions with a minimum six-month retention period. Velarc is built specifically to meet these obligations — not retrofitted from a developer observability tool.

Starter
£399
per month
  • Audit trail and trace logging
  • Up to 3 use cases
  • 6-month retention
  • Manual export
  • Email support
  • Data Processing Agreement included
Request access
Enterprise
Custom
annual contract
  • Everything in Professional
  • Self-hosted deployment
  • Custom retention period
  • Dedicated support + SLA
  • Data Processing Agreement included
Get in touch

Request early access

We're onboarding a small number of healthtech companies ahead of the August 2026 deadline. Get in touch to start the conversation.

Thanks — we'll be in touch within 48 hours.