Hermes RelayHermes RelayRequest a Pilot

Verifiable PHI Redaction

We don't just redact PHI — we give you tamper-evident proof it happened.

Hermes redacts PHI in-flight and never stores it — not even encrypted — then seals a cryptographically signed, hash-chained attestation of what was detected and redacted. Built for MSPs serving HIPAA-covered entities.

Zero-retention · In-flight redaction · Hash-chained attestation receipts

Hermes Relay

Illustrative output — sample audit stream (CFR citations limited to categories Hermes detects)

hermes.audit.stream
14:32:01ZREDACT45CFR§164.514(b)(2)(i)(A)sha256:a3f8...c291
14:32:02ZVERIFY45CFR§164.514(b)(2)(i)(B)sha256:7b21...e4f0
14:32:03ZCHAIN_LINK45CFR§164.514(b)(2)(i)(C)sha256:e09a...8d17
14:32:04ZREDACT45CFR§164.514(b)(2)(i)(D)sha256:4d72...91ab
14:32:06ZSEAL45CFR§164.514(b)(2)(i)(F)sha256:8c54...0e3d
14:32:07ZREDACT45CFR§164.514(b)(2)(i)(G)sha256:b6f1...2a48
14:32:09ZVERIFY45CFR§164.514(b)(2)(i)(A)sha256:1e9d...5b76
14:32:10ZREDACT45CFR§164.514(b)(2)(i)(N)sha256:fa30...c812
14:32:11ZCHAIN_LINK45CFR§164.514(b)(2)(i)(O)sha256:25a7...8e09
14:32:13ZREDACT45CFR§164.514(b)(2)(i)(D)sha256:9b4c...d367
14:32:14ZSEAL45CFR§164.514(b)(2)(i)(F)sha256:6e08...41fc
14:32:16ZVERIFY45CFR§164.514(b)(2)(i)(G)sha256:cd17...a59b
14:32:01ZREDACT45CFR§164.514(b)(2)(i)(A)sha256:a3f8...c291
14:32:02ZVERIFY45CFR§164.514(b)(2)(i)(B)sha256:7b21...e4f0
14:32:03ZCHAIN_LINK45CFR§164.514(b)(2)(i)(C)sha256:e09a...8d17
14:32:04ZREDACT45CFR§164.514(b)(2)(i)(D)sha256:4d72...91ab
14:32:06ZSEAL45CFR§164.514(b)(2)(i)(F)sha256:8c54...0e3d
14:32:07ZREDACT45CFR§164.514(b)(2)(i)(G)sha256:b6f1...2a48
14:32:09ZVERIFY45CFR§164.514(b)(2)(i)(A)sha256:1e9d...5b76
14:32:10ZREDACT45CFR§164.514(b)(2)(i)(N)sha256:fa30...c812
14:32:11ZCHAIN_LINK45CFR§164.514(b)(2)(i)(O)sha256:25a7...8e09
14:32:13ZREDACT45CFR§164.514(b)(2)(i)(D)sha256:9b4c...d367
14:32:14ZSEAL45CFR§164.514(b)(2)(i)(F)sha256:6e08...41fc
14:32:16ZVERIFY45CFR§164.514(b)(2)(i)(G)sha256:cd17...a59b

✓ Illustrative chain — tamper-evident format shown for demo purposes

The Documentation Gap

Every tool detects PHI.
None of them can prove
what they did with it.

When OCR investigates a business associate, they do not ask whether you had a scrubbing tool. They ask you to produce the evidence — exactly what was found, under which regulation, by which method, in an unbroken chain from scan to audit. Cloud-based competitors run ML models that cannot answer that question. Their architecture makes honest attestation impossible.

What carriers ask

Is MFA enforced for privileged access? How many PHI records do you handle? Can you document what was found and how it was handled?

Coalition Application Q4, Q6 — verbatim

What OCR demands

Produce documentation of your de-identification method, the specific identifiers found, and the regulatory basis for each classification decision.

45 CFR §164.514(b) — Safe Harbor standard

What MSPs cannot produce

A per-token, CFR-cited, cryptographically signed record that documents Safe Harbor-aligned de-identification — with core identifier coverage today and full Safe Harbor coverage actively expanding.

OCR Risk Analysis Initiative — 2026

OCR issued seven resolution agreements against business associates in 2025 alone — the highest enforcement total against business associates since 2013. For MSPs serving healthcare clients, the documentation gap is not a hypothetical compliance problem. It is an active enforcement trend.

How Hermes Works

Deterministic. Zero-egress.
Audit-ready by design.

ARCHITECTURE

Zero-egress

Hermes runs entirely inside your environment. PHI never transits external infrastructure — making your attestations technically accurate, not just aspirational.

METHOD

Deterministic

Regex and a fixed-version spaCy model detect 16 of 18 HIPAA Safe Harbor identifier categories — 16 via direct text detection, and 2 (biometric identifiers and full-face photographs) via text reference detection only, with a disclosed limitation that binary content cannot be inspected by a text pipeline — SSN, MRN, fax, payment cards, names, dates, addresses, phone, email, IP, URL, account numbers, health plan beneficiary numbers, and VINs — cited to 45 CFR §164.514(b)(2)(i). Never a hosted LLM: the same input produces the same output, every run.

EVIDENCE

Audit-ready

Each decision is recorded as a per-token, CFR-cited event and sealed into a SHA-256 hash chain. The result is an unbroken, tamper-evident record an OCR investigator can verify byte by byte.

Sample audit chain output

Illustrative output — not live product data. CFR citations shown are sample format; Hermes currently covers 16 of 18 Safe Harbor identifier categories — 16 via direct text detection, P (biometric identifiers) and Q (full face photographs) via text reference detection only.

Every scrubbing decision.
Hash-chained.
Audit-ready.

Illustrative sample of Hermes' attestation chain. Hermes detects and redacts the following categories: person names, dates, organizations, phone numbers, email addresses, URLs, IP addresses, physical addresses/locations, US bank numbers, Social Security numbers, and payment card numbers (Luhn-validated). Each redaction is sealed into a SHA-256 hash-chained, cryptographically signed receipt inside your environment — so you get PHI reduction with verifiable proof, not a black box. This is not a claim of certified HIPAA Safe Harbor de-identification.

input.payload
Patient: Sarah Mitchell, DOB 03/14/1978, SSN 412-55-8901
Phone: (555) 000-0000
Diagnosis: Type 2 Diabetes, ICD-10 E11.9
Referring physician requested AI-assisted prior auth summary.

⚠ PHI detected — payload blocked from AI pipeline

output.scrubbed
Patient: [PATIENT_NAME_A], DOB [DATE_C], SSN [SSN_J]
Phone: [PHONE_REDACTED]
Diagnosis: Type 2 Diabetes, ICD-10 E11.9
Referring physician requested AI-assisted prior auth summary.

✓ Core identifiers redacted — name, DOB, SSN, phone numbers (illustrative sample)

hermes.audit.chain — payload_id: hx_20260628_001
5 blocks
blocktimeeventfieldcfr citation
#00000114:32:01ZREDACTPATIENT_NAME45CFR§164.514(b)(2)(i)(A)prev: 0000000000000000hash: sha256:a3f8b291c7e402d1f95a6b3c8e1d4f72a0b5c9e3d6f8a2b4c7e0d3f6a9b2c5e8
#00000214:32:02ZREDACTDATE_OF_BIRTH45CFR§164.514(b)(2)(i)(C)prev: sha256:a3f8b291c7e402d1hash: sha256:7b21e4f0d8c395a2b6f1e8d4c7a0b3e6f9c2d5a8b1e4f7a0c3d6e9b2c5f8a1d4
#00000314:32:03ZREDACTSSN45CFR§164.514(b)(2)(i)(G)prev: sha256:7b21e4f0d8c395a2hash: sha256:e09a8d17f3b4c6e1a2d5f8b0c3e6a9d2f5b8c1e4a7d0f3b6c9e2a5d8f1b4c7e0
#00000414:32:04ZCHAIN_LINKBLOCK_SEAL45CFR§164.312(b)prev: sha256:e09a8d17f3b4c6e1hash: sha256:4d7291ab8c3e6f0a1b4d7e0c3f6a9b2e5d8f1a4c7e0b3d6f9a2c5e8b1d4f7a0c3
#00000514:32:07ZSEALPAYLOAD_SEAL45CFR§164.312(b)prev: sha256:4d7291ab8c3e6f0ahash: sha256:b6f12a48e3c7d0f5a8b2e5d9c1f4a7b0e3d6f9c2a5e8b1d4f7a0c3e6b9d2f5a8b1

✓ Chain integrity verified — each block hash includes the previous block hash. Tamper-evident since block #000001.

Hash-chained attestation records are generated inside your environment for every payload Hermes processes. PHI is redacted in-flight and never stored.

Request a Pilot

Technical architecture

What runs. Where it runs.
What it touches.

Hermes deploys as a single Python service inside the customer environment. No external classifier. No data in transit. The scrubbing pipeline is fully deterministic — the same input produces the same output, every run, with a cryptographic record to prove it.

Deployment specification
Deployment targetCustomer environment — Docker, bare metal, or VM
External network callsNone during scrubbing. Zero-egress by design.
Detection methodRegex + fixed-version spaCy NER + Microsoft Presidio
PHI categories covered18 of 18 Safe Harbor categories — 16 direct text detection, 2 (biometric, full-face photo) via reference detection with disclosed binary content limitation
Audit record formatCOSE_Sign1 asymmetric-signed, RFC 8785 canonical, Merkle-anchored receipts — independently verifiable
CFR citation per tokenYes — 45 CFR §164.514(b)(2)(i) subcategory attached
LLM dependencyNone. Deterministic pipeline only.
SigningEd25519 / ES256 asymmetric signatures — customer-controlled keys, three-tier key hierarchy
API surfaceREST — /v1/scrub, /v1/review, /v1/status, /v1/workspaces
Language / runtimePython 3.12 — uvicorn ASGI

→ Full technical documentation and API reference available to pilot partners upon request.

Structural differentiation

Four things competitors
cannot replicate without
rebuilding from scratch.

01

Cryptographically Signed Attestation

We don't just redact PHI — we give you tamper-evident proof it happened.

Every scrubbing pass emits a signed receipt linked into a hash chain. verify_chain checks signature integrity, previous-hash links, and sequential positions — so an investigator can confirm the record was not forged or truncated after the fact.

02

Zero-Retention, In-Flight Redaction

PHI is redacted in-flight and never stored — not even encrypted.

Detection and redaction run inside your environment. There is no PHI datastore to breach, subpoena, or clean up when an engagement ends. Attestation receipts record only the categories detected and redacted — never the PHI itself.

03

Built for MSPs and SMB Healthcare

The customers who need this most are the ones no competitor serves.

Nightfall costs $20,000-$60,000 per year and requires enterprise procurement, a security team, and a multi-month sales cycle. The 10-person billing company in Knoxville, the regional clinic, the MSP managing 15 HIPAA-covered clients -- none of them will ever see a Nightfall contract. Hermes is priced, packaged, and deployed for exactly those customers. Self-hostable. Operational in a week. No enterprise contract, no security team required.

04

Applicability-Aware Attestation Chain

A receipt is not authoritative evidence unless the chain says it still is.

Hermes tracks whether every receipt in the chain is currently authoritative or has been superseded by a later override. A verifier presented with an old receipt cannot treat it as standalone evidence without traversing to the current chain head — closing the gap between historical validity and current applicability that no competing tool addresses.

-> No other tool in this space produces cryptographically signed, hash-chained records of every PHI redaction decision — tamper-evident proof your AI pipeline handled patient data correctly.

Who built this

Compliance background first.
Engineering second.
That order matters.

Andrew Rogers, Founder & Engineer at Hermes Relay
Andrew RogersFounder & Engineer

Before writing a line of Hermes, I spent years in manufacturing and construction trades, then moved into systems engineering — building self-directed expertise in HIPAA, DSCSA, 21 CFR Part 11, ALCOA+, and GAMP 5 through hands-on pharmaceutical supply chain compliance work, not a classroom.

That order — regulatory depth before the code — is why Hermes is built the way it is. The CFR citations attached to every scrubbing decision aren't decorative. They come from actually having sat with the standard long enough to know which subsection applies to which identifier, in the same way a compliance officer would.

Hermes is built and operated by one person. When you request a pilot, the person who architected the attestation chain is the person on the call.

Vendor-agnostic architecture

Hermes is not a replacement
for your stack. It is the layer
your stack cannot provide.

No DLP platform -- Purview, Netskope, Nightfall -- can produce a zero-egress, deterministic, CFR-cited audit record on its own. Hermes fills that gap and exports the evidence as a generic JSON webhook, ready for anything that accepts one today, with platform-specific connectors as ongoing work.

Generic Webhook Export

Any HTTP JSON webhook receiver

Every scrubbing decision fires a structured JSON event to a URL you configure, with an optional auth header for token-based intake. This is a real, tested capability today -- not a mockup.

-> POST + configurable auth header
Splunk (HTTP Event Collector)

Splunk Cloud - Splunk Enterprise

Point the webhook at your HEC endpoint and set the auth header to your HEC token. Every scrub call lands as a structured event -- CFR citation, field type, hash chain ID, timestamp -- with no custom parser required.

-> HEC-compatible JSON POST
SIEM / DLP -- Broader Landscape

Datadog - CrowdStrike - Azure Sentinel - Purview - Netskope - Zscaler

Platforms that accept a generic webhook or HTTP intake can consume Hermes' event stream today. Platforms requiring signed requests -- Sentinel's Data Collector API, for example -- are not yet supported; that is roadmap work, not a shipped connector.

-> Compatible where webhook intake exists
AI Pipelines

OpenAI - Azure OpenAI - Anthropic - Any LLM endpoint

Call /v1/scrub before your LLM request in your own pipeline code. Core identifiers are scrubbed and the audit record is sealed before payload content reaches the model. Today this is a direct API call you wire in, not an automatic transparent proxy.

-> Direct API call, ahead of your LLM request
How it works

One generic JSON event exporter. Any destination.

Hermes emits a structured event for every scrubbing decision: field type, CFR citation, hash chain ID, payload ID, and timestamp. That event is platform-agnostic JSON over a configurable webhook, with an optional auth header for token-based intake like Splunk's HTTP Event Collector. Platforms requiring signed requests are on the roadmap, not yet shipped.

The enforcement context

The documentation gap has a
dollar figure attached to it.

7

OCR resolution agreements against business associates in 2025 alone

HHS Office for Civil Rights — 2025 Enforcement Report

$7.42M

Average cost of a healthcare data breach — the costliest industry for the 15th consecutive year

IBM Cost of a Data Breach Report 2025

18

Safe Harbor identifier categories OCR expects documented per incident

45 CFR §164.514(b)(2) — HIPAA Safe Harbor Standard

Before you ask

The questions a careful
evaluator asks first.

What happens if Hermes misses a PHI identifier -- a false negative?

No automated PHI redaction system achieves perfect recall, and Hermes does not claim certified Safe Harbor de-identification or blanket HIPAA compliance. Hermes currently detects 18 of 18 HIPAA Safe Harbor identifier categories — 16 via direct detection in text, and 2 (biometric identifiers and full-face photographs) via reference and metadata detection with a disclosed limitation: actual biometric templates and image pixel content cannot be inspected by a text-only pipeline: person names, dates, organizations, phone numbers, fax numbers, email addresses, URLs, IP addresses, physical addresses/locations, Social Security numbers, medical record numbers, health plan beneficiary numbers, account numbers, vehicle identifiers (VINs), and payment card numbers (Luhn-validated). Treat Hermes as a strong first layer for PHI reduction, not a substitute for your risk assessment or human review on high-stakes payloads. The cryptographically signed attestation receipt records exactly which categories were flagged and redacted for a given transaction — tamper-evident proof of what happened, not a vague compliance claim.

What is a hash-chained attestation receipt and why does it matter?

Every time Hermes processes a payload, it emits a signed receipt recording which PHI categories were detected and redacted, a timestamp, and a hash of the previous receipt. These receipts are linked into a chain — so an auditor, OCR investigator, or your client can verify that the record was not altered, forged, or truncated after the fact. It is tamper-evident proof that redaction happened, not a log you wrote yourself after the fact.

Why not just use an enterprise LLM contract with a BAA already in place?

An enterprise BAA with OpenAI, Anthropic, or Microsoft covers how that vendor handles PHI once it reaches them -- it does not produce a record proving what PHI was in the payload in the first place, or that it was identified and handled correctly before transmission. Hermes runs before that call, inside your environment, and produces the CFR-cited evidence trail a BAA alone does not generate. The two are complementary, not competing.

Do you have SOC 2 or a cyber insurance policy today?

Not yet. Hermes is a solo-founder, pre-revenue project moving through pilot engagements now. SOC 2 Type II requires 6-12 months of sustained evidence collection and an independent audit, and is on the roadmap once there is a customer base to audit against. If your organization's vendor risk process requires either as a hard gate today, say so early -- it may mean waiting for a later stage of the product rather than the current pilot.

What's the incident response process if something goes wrong?

Because Hermes runs entirely inside your environment with zero external calls during scrubbing, an incident involving Hermes itself has a narrower blast radius than a cloud-classifier failure would -- there is no third-party breach surface to notify about. That said, a formal, documented incident response plan matched to your organization's specific deployment is part of the pilot onboarding conversation, not something we hand you generically off a template.

Is Hermes a replacement for our compliance officer or MSP's judgment?

No. Hermes produces evidence -- a cryptographically verifiable record of what PHI was detected, under which regulation, and what happened to it. It does not replace the judgment calls a compliance officer or MSP makes about risk tolerance, client communication, or regulatory strategy. Think of it as the evidence layer underneath those decisions, not a substitute for making them.

What happens to data if we stop using Hermes?

PHI is redacted in-flight and never stored, not even encrypted — so there is no PHI store to delete when a pilot or contract ends. Hash-chained attestation receipts (which contain metadata about what was detected, not the PHI itself) remain in your environment and are yours to keep, export, or discard.

Pricing

No enterprise contract.
No security team required.

Hermes is built for the MSP managing 15 HIPAA-covered clients and the 10-person billing company — not the Fortune 500 with a six-month procurement cycle.

PILOT

$2,00030 days

Full production deployment in your environment. No shared infrastructure.

  • →Zero-egress deployment in your environment
  • →Hash-chained audit trail from day one
  • →SSN, PAN, name, date, phone detection
  • →API key + integration support
  • →Direct access to the engineer who built it

PRODUCTION

$500/ month

After pilot. Month-to-month. No enterprise contract required.

  • →Everything in Pilot, ongoing
  • →Expanding identifier coverage
  • →CFR citation updates as regulations change
  • →Priority support via direct channel

Starts after pilot

→ Pilot pricing is fixed for current design partners. Production pricing locks at pilot rate for the first 12 months.

→ Business Associate Agreement (BAA) available upon request. Required for HIPAA-covered deployments.

Know your exposure before your insurer asks

PHI AI Readiness Assessment

A written gap analysis of your current AI tooling against the 45 CFR §164.514(b) Safe Harbor standard — with remediation priorities and an attestation readiness score your insurer or auditor can read. Delivered in five business days. The $750 fee applies in full toward the pilot if you proceed.

  • →Gap analysis against 45 CFR §164.514(b) Safe Harbor — all 18 identifier categories
  • →Remediation priorities ranked by enforcement exposure, not theoretical risk
  • →Attestation readiness score formatted for cyber insurers and OCR auditors
  • →Written report delivered within five business days of intake
  • →$750 fee credited in full toward the pilot program if you proceed

The process: you complete a 15-minute intake questionnaire covering your current AI tooling, PHI workflows, and existing controls. Andrew reviews it against the Safe Harbor standard and delivers a written report. No calls required unless you want one.

$750flat fee
5-day turnaround · credited toward pilot

One pilot.
Your environment.
Your audit chain.

Hermes is currently accepting design partners for remote pilots. 30-day engagement, your infrastructure, full hash-chained audit evidence record from day one.

Zero-egress architecture · Data never leaves your environment · SHA-256 independently verifiable · Safe Harbor-aligned — building toward 45 CFR §164.514(b) · BAA available upon request