Tell us which applications call models today.

Internal teams and vendors. We reply within two business days with a draft policy: which callers, which models, which data, under which agreements.

Contact us

A person replies.

About six weeks to the first routes.

Week 1

Inventory

Your applications, teams, and vendors become registry entries. Teams get sandbox keys.

Weeks 2–3

Policy draft

Which callers, which routes, which models, what gets replaced, what each budget is. You review it like any other change.

Weeks 3–4

Deploy

The container goes into your cloud account. The first team requests a real route; one vendor changes its URL.

Week 6 on

First report

From real traffic. Then monthly, and on every policy change.

Timeline illustrative. We're working with a small number of health systems through 2027.

Fitting it in.

Our teams already have API keys from a provider. What changes?

The provider key moves into the gateway. The team gets a Miso key that reaches every provider the system holds an agreement with, on the routes the team is approved for, under a budget. Each call records the agreement that covered it.

We already run a vendor-risk program. What does Miso add?

Your program reviews each vendor and reaches a decision. Miso turns the model-and-data part of that decision into a registry entry and a route, then checks each request against it. The record shows each request matched the decision.

Our EHR vendor says its AI features are covered under our existing BAA.

Probably true for the vendor's own traffic, and the registry holds that agreement as the vendor's entry. The model provider behind the feature also needs to be on your provider registry, with its scope, retention, and region. The console shows whether it is.

We have a GRC platform. Where does this sit?

Your GRC platform holds the policy documents and the evidence people upload. Miso holds the routes that run on traffic and the record of the traffic. The monthly pack and the obligations ledger export into whatever you use.

Will it lower our model spend?

It shows spend by team, route, and vendor from your own records, and a route can select the cheapest approved model. What you negotiate with providers is between you and them.

How it behaves.

Can Miso send PHI to a model without an agreement?

No. A route's candidate models are drawn from the provider registry, and a provider without a BAA on file is outside every route. Selection by cost, latency, or a score you set happens inside that set.

Does PHI leave our network?

Yes, to a model provider, when a route allows it and the provider has a BAA on file. Miso itself runs in your account and decides which approved endpoints may receive which data. Identifiers the route says to replace are replaced before the request goes out.

Is Miso in the request path? What happens when it's down?

Yes. Each request passes through it on the way to a provider. It runs as one container in your account; run two behind your load balancer. If the gateway is unreachable, the caller gets an error and nothing is sent.

Does Miso store prompts?

It stores hashes, identifier types and counts, and the fields in the record. Prompt text is off by default, and the compose file says so.

What happens when a provider changes a model?

Each model is pinned to a version the provider documents as fixed. When a new one is published, the console shows a comparison, old and new on your own samples, both in the record. The privacy officer approves, and the pin moves with a dated, hashed policy change.

How does it handle state law, like Texas HB 149?

As obligations on a route: disclosure, human review, subject identification. Miso returns them to the caller on every response and records the acknowledgment. The ledger shows which obligation on which route satisfies which state overlay, and where there is a gap. Whether a law applies to a route is a determination your counsel makes.

Running it.

Who runs it day to day?

Your infrastructure team operates the deployment in your account. Miso maintains the software, ships releases, and supports the deployment; you apply releases on your schedule. Policy changes go through validation and are dated and hashed, including the ones that come from approved route requests.

How long until a team has a real route?

A sandbox key the first day. A route request with purpose, data class, candidates, and a sentence about the data goes to the privacy officer with the validator's findings attached. Approval puts it live.

What does a vendor have to change?

The base URL, a bearer credential, and a header naming the route. On routes that touch other patients' records, a header naming the patient.

What if we want it hosted?

Miso can run in a Miso-operated account under a BAA with you. Same policy file, same record. Move it into your own account later; callers keep the same endpoint.