{% extends "base.html" %} {% block surface %}surface-paper{% endblock %} {% block bstheme %}light{% endblock %} {% block title %}Who builds this — HealthClaw Guardrails{% endblock %} {% block head %} {% endblock %} {% block content %}
So this page says who does, under what rules, and what is not covered. It is deliberately specific about the limits.
HealthClaw Guardrails is built and maintained by Vestel AI LLC, a limited liability company organised in the Commonwealth of Pennsylvania. The maintainer is Eugene Vestel.
{# TODO(eugene): two or three sentences of background — what you worked on before this, and why health data specifically. This is the paragraph a partnerships lead or an investor reads first, and it is the one thing on this page nobody else can write for you. Keep it factual: roles and systems, not adjectives. #}Longer-form writing on the thinking behind the project: Building a New, Empowered Health System and How I Build My Personal OpenClaw.
Most of what makes a guardrail layer trustworthy is process, not code. These are enforced in CI, not stated as intentions.
The security posture page covers what the grade does and does not cover.
Stated plainly, because finding it out on a procurement call wastes your time and mine.
Three ways, depending on what you need. All of them start at support@healthclaw.io.
MIT licensed. Run it locally in ten seconds, point it at your own FHIR server, or install the plugin into Claude Code. If a guardrail is missing for your case, an issue or a pull request is the fastest path.
If you are putting an agent near clinical data and need the permission, redaction, and audit layer to be someone else's problem, this is the layer. Useful when you want FHIR and MCP expertise applied to your surface rather than rebuilt in-house.
Say what you are building and where it touches patient data. A short technical call is usually enough to tell whether this fits.
Read the security posture first. If the gaps listed there are disqualifying for your procurement process, they will be disqualifying in month three as well, and it is better to know now.
Where a pilot does work: a scoped evaluation against synthetic or de-identified data, with the conformance grade as the acceptance criterion, and a written account of what the guardrails did and did not cover.
Clinical and standards advisors review the parts of this that make claims about care. Named here once they have agreed to be.