TrustLayer by NHID-Clinical
Operational trust infrastructure for healthcare AI agents.
TrustLayer runs the same deterministic controls as the open framework — and adds the production operations that running agents at scale actually requires.
What it is
The framework, operationalized
The open framework answers a question about a single call: was the agent disclosed, authorized, in scope, and audited? That answer is deterministic and anyone can compute it.
Running hundreds of agents across vendors and business units raises a different set of questions. Which agents exist, and who owns them? Which ones changed last week? Can we produce evidence for an auditor without a two-week fire drill? Who approved this agent’s scope, and when does it expire?
TrustLayer answers those. It provides monitoring, evidence, identity management, authorization, and reporting on top of the same control logic — not a different, proprietary standard.
Platform modules
Five modules
Each addresses a distinct operational problem. They compose, but none of them requires the others to be useful.
Agent Registry
Source of truth for AI agent identity — who the agent is, who owns it, what it may do, and when that authority expires.
Agent Registry → MODULE 02Trust Gateway
Runtime enforcement. Identity verification, authorization, disclosure check, scope enforcement, and an audit event — before the healthcare system is reached.
Trust Gateway → MODULE 03Evidence Center
Audit-ready evidence generation: compliance reports, evidence packages, event history, and governance exports.
Evidence Center → MODULE 04Continuous Conformance
Static tests become operational monitoring. When an agent changes, the controls re-run and a regression surfaces before it reaches a call.
Continuous Conformance → MODULE 05Enterprise Workflow
SSO, role-based access control, approval workflows, integrations, and SIEM export — the operational surface a security team expects.
Enterprise Workflow →Open core vs platform
What is open, and what is operated
The left column is free forever under CC BY 4.0. The right column is what you would otherwise build and run yourself.
| Capability | Open framework | TrustLayer |
|---|---|---|
| Specification | ✓ CC BY 4.0, always free | ✓ Same specification |
| Control logic | ✓ Open reference engine | ✓ The same deterministic controls |
| Conformance tests | ✓ Run them yourself | ✓ Hosted and scheduled |
| Simulator | ✓ Open, no account | ✓ Plus evaluation against your own agents |
| Documentation | ✓ Public | ✓ Public |
| Reference implementation | ✓ Fork it, vendor it, replace it | ✓ Managed and operated |
| Community | ✓ Issues, discussions, PRs | ✓ Same community |
| Continuous monitoring | — Run it yourself | ✓ Hosted, on every agent change |
| Dashboards | — | ✓ Fleet-wide operational view |
| Agent registry | — Passport format only | ✓ Managed identity lifecycle |
| Evidence center | — Evidence pack template | ✓ Generated audit-ready packages |
| Enterprise integrations | — | ✓ SSO, RBAC, SIEM, approvals |
Two ways in
Start free with the open framework, or talk to us about running agents at scale.
TrustLayer by NHID-Clinical is in active development. It is not an accredited standard, a certification, or a regulatory compliance guarantee. The open framework it enforces remains free under CC BY 4.0 and is never gated behind a plan.