Open Framework · v1.3 · CC BY 4.0
The open framework
Specification, control catalog, reference implementation, conformance tests, and regulatory mapping for AI agent identity, authorization, disclosure, and audit evidence in healthcare voice workflows.
What the framework contains
Seven components, all open
Each is independently usable. You can adopt the controls without the reference implementation, run the conformance suite against your own engine, or read the regulatory mapping on its own.
Specification
The v1.3 normative document: the problem, the behaviors, the sequence of interaction, scope boundaries, and known gaps.
Read the specification → 02Control catalog
IDG-01, PDX-01, DBC-01, EIT-01, and ATR-01 — what each control checks, what a pass looks like, and where to try it.
Browse the controls → 03NHID-Auth
The v2 cryptographic authorization layer: Ed25519 agent passports, provider-signed delegation, and offline verification.
Read about NHID-Auth → 04Reference implementation
A pure-Python policy engine with no runtime dependencies, TypeScript middleware, voice-platform adapters, and a PowerShell module.
See the implementation → 05Conformance test suite
Machine-readable, deterministic pass/fail tests. Same inputs, same verdict — every time, for anyone who runs them.
Run the tests → 06Technical stack
The five-layer trust stack, from carrier authentication through behavioral disclosure to audit and observability.
See the stack → 07Regulatory alignment
How the controls map to NIST AI RMF, the EU AI Act, ISO/IEC 42001, CMS-0057-F, HIPAA documentation, and state AI laws.
Read the mapping → +Simulator
The open simulator demonstrates NHID-Clinical controls against realistic call scenarios — no setup, no account.
Open the simulator →How the framework relates to the platform
The framework is the standard. TrustLayer is optional infrastructure.
The specification, control catalog, conformance tests, reference implementation, and simulator remain open under CC BY 4.0. You can implement all of it yourself and never talk to us.
TrustLayer runs the same deterministic controls as production infrastructure — monitoring, evidence generation, agent identity management, authorization, and reporting for organizations operating AI agents at scale. It operationalizes the framework. It does not replace it, and it never becomes a prerequisite for using it.
Start with the framework
Read it, run it, and tell us where it breaks.
NHID-Clinical is a voluntary open framework — not an accredited standard, certification, or regulatory requirement. Everything on this page is published under CC BY 4.0.