CORE · core.golden-i.io

Healthcare doesn't have an operating system. It has thousands.

Every vendor reinvents the same foundation — identity, permissions, consent, audit — privately, incompatibly. That's why nothing trusts anything. CORE is that foundation built once, properly: our first product. We built nine more on top of it. Yours can be next.

Your products
CURISREMITUSPROBISFORMULISVIGILISYOURS
CORE
Foundationidentity · auth · events
Clinicalencounters · orders
Trust & Complianceconsent · anchoring
Revenue & Operationseligibility · billing
One foundation · Every product on itSOC 2 Type II · HIPAA · 42 CFR Part 2
The foundation

One foundation, built once.

A trusted foundation for every healthcare solution — identity, permissions, consent, audit — built once, properly. Every application above inherits its capabilities, whole.

GoldenI mark Powered by GoldenI.
Product applications
everything you run — inherits every capability below, on day one
run on
COREshared services, grouped in four layers
01
Foundation
identity & authpermissionsevent busaudit chain
02
Clinical
patients & encountersorders & medicationsschedulingcare plans
03
Trust & Compliance
consentcredentialingjurisdiction rulesattestation
04
Revenue & Operations
fee scheduleseligibilitybilling rulesclaims & remittance
runs where you choose
Storage & infrastructure
our cloud · in-country · your servers — deployment is your call

Build a service once, in the foundation, and every application inherits the capability — fix it once, everything gets the fix; upgrade it once, everything gets the upgrade.

And it scales the same way: a new service lands in the foundation once, and every application can use the capability the moment it ships. Build what you need without compromising the foundation — which buys six properties no feature list can:

Verifiable

CORE records what happened.

Every action becomes a permanent event; any record replays exactly as it stood at any moment. "What did the clinician see at 2:14 PM?" is a query, not a forensic project.

Safe

No single breach yields a person.

Identity, clinical, and operational data are structurally separated — a breach of any one yields data that is meaningless on its own. How anchoring works →

Real-time

Every answer from live data.

The record is current the moment it's written — queries, dashboards, and decisions run on what happened, not last night's batch.

Research-grade RWE

Ready for the study.

Every record is captured in a form aligned with FDA real-world evidence guidance — the same provenance, immutability, and audit trail a clinical-trial submission demands. Born that way, not reconstructed after.

Born compliant

Compliance your product is born with.

Consent that actually compartments — enforced by architecture, not policy, 42 CFR Part 2 included — plus credentialing, jurisdiction rules, incident reporting, attestation.

Most products spend years defending the seams. On CORE there are no seams to defend.

Sovereign

Globally deployable.

Run in our cloud, in-country to meet data-residency requirements, or on your own servers — the same platform, wherever your data is legally required to live.

Durable

And it lasts. While healthcare is still retiring fax machines, CORE is built on NIST's post-quantum standard — the same one Google shipped in 2025.

Records meant to last decades, protected past the horizon.

The Compute Chain

AI, governed before it answers.

Seven stages. Every one a receipt. The model is the only part you can swap.

01A person asksAuthenticated. Never anonymous.
02Permissions resolveBefore the AI sees anything.
03One channel of five The other doors close.
04Data is scopedOnly what the channel permits.
05The model runsSwappable. Version recorded, every call.
06Response, with receiptLogged as an event.
07A human decidesAI never acts alone.
Seven stages. Seven receipts. One chain.→ tamper-evident audit trail

You're not locked into a model.
You're locked into the governance.

AI changes every month. Each capability runs the model that suits it best — swap it, upgrade it, retire it. The permissions, scopes, and receipts around it never move.

The exact model and version are recorded with every call.

One capability · one governed slot
Summarize a visitmodel A · v3→ model A · v4
Draft a lettermodel B · v2
Classify a requestmodel C · v7
Swap the model. The slot — permissions, scope, receipts — never changes.
Judgment stays humanAI never replaces clinical guidance or decisions — it supports them, giving clinicians better resources.
GovernedThe data scope is enforced before any access occurs.
Not silentEvery input, output, and human decision is an event.
Scales with youNew capabilities inherit the pipeline, permission-scoped from day one.
Platform HelpSystem knowledge only
Medical CompanionYour own record
Clinical AssistantThis encounter only
Operations IntelAggregates only
Revenue CycleCharge events only

Every GoldenI product inherits this pipeline on day one — only the vocabulary changes.

Why it matters

Every one of these steps is captured as a single unbroken record — what was asked, what data the model was allowed to see, which model answered, what it returned, and the licensed human who decided what to do with it. That record is the Compute Chain. When someone asks, a year later, how an AI-assisted decision was made and whether it was made responsibly, the Compute Chain is the answer — the compliance record every organization using AI in care should have, and almost none of them do.

Custody

We secure it. You decide who reads it.

Everything on CORE is encrypted — and where it lives is your call: our cloud, in-country infrastructure, or your own servers. Wherever it runs, the access model doesn't change: your patients, your clinicians, and no one you didn't choose. Not us.

Support access exists only when you open a session. Production changes require approved, tiered requests — including ours. Our operational view is aggregate-only, never clinical.

And the boundary runs in both directions. Clinical data moves to the outside world — labs, HIEs, payers — through one governed gateway: NEXUS. Our own platform utilities, messaging to telephony, connect through a separate brokered gate of their own.

Nothing reaches outside CORE without passing a checkpoint that records it. Not your data. Not even our vendors.

We run the substrate the way you'd demand a power grid be run: maintained by people with access to the machinery, never the contents.

How GoldenI runs itself

One governed path in.
One governed path out.
Your controls in between.

FORGE

The only way code reaches production — and only a human opens it.

Every change passes role-based approval and separation of duties: the author can't approve their own change. Our automated reviewers screen every release first — but they can't approve one. Only a person can. Each step is verified; every action is written to a tamper-evident log.

We built it this way so a broken update can't reach you through one engineer's mistake or one unreviewed line. It's the separation-of-duties discipline regulated industries run on — the reason you can trust what ships. There is no other path in, and no standing access. Including ours.

JUNCTION

The only way services reach out.

Every outside connection — email, messaging, voice, mapping — routes through one brokered, monitored gate, not scattered across the platform. Nothing leaves CORE without passing a checkpoint that records it. Not your data. Not even our vendors.

CONSOLE

And the controls are yours.

Between those two gates sits the console you run yourself — users, roles, configuration, the compartments that wall off your most sensitive records. You hold the keys. We don't. Support reaches your data only through a session you open, and closes when you close it.

In service of your org

Everything else is us, working for you.

Onboarding, support, security, uptime, your numbers, controlled fixes — the operational apps that stand behind your platform. Each runs on aggregate signals, never clinical content. None of them is a way in.

GENESIS

We bring you on

Onboarding and the commercial relationship — contract to go-live, billing, renewals. We stand behind it.

LIGHTHOUSE

We support your people

Support reaches a client's data only through a session the client themselves opens — absent one, the door stays shut.

SENTRY

We protect your environment

Security monitoring with active response: credential-attack detection, impossible-travel logins, session termination, step-up verification.

PULSE

We keep the lights on

Platform health and incident response — live status, alerting, incident timeline. Aggregate health only, never patient data.

COMPASS

We show you how you're doing

Client outcomes and KPIs per account — adoption, clinical, financial, and operational health.

SCALPEL

We fix things, under control

The only tool that can change production data, approval-gated end to end.

SCALPEL · in practice

Here's an example of what that looks like. A patient is registered at a new clinic under her married name. The clinic doesn't know GoldenI already holds her record, under her maiden name, from a prior organization — so a second record is created. The two now need to become one.

That's a routine consolidation: it moves through a single engineer's approval. More complex changes need two and a lead; high-impact changes require the CTO. CORE validates every approved request before it executes. No direct database access exists — not even for us.

Born research-grade

Most healthcare data has to be cleaned into evidence. Ours is born as it.

Real-world evidence usually means retrofitting: normalize, re-verify, pray the provenance survives scrutiny. Data captured on CORE doesn't take that trip — it's recorded in a form aligned with FDA real-world evidence guidance from the first write, provenance intact by construction.

If you're building anything that touches trials, registries, or regulators, ask us what that's worth. We've done the math.

For builders

Don't like our EHR? Build on our foundation anyway.

CORE is open to builders. Run a different EHR on it. Build your own product on it. Bring your country, your specialty, your idea — the hardest problems in healthcare software are already solved beneath you: identity, consent, audit, permissions, AI governance, regulatory plumbing.

Spend your effort where it belongs — on better care, and on what's never been built before. CORE was our first product. We built nine more on top of it — and the next one doesn't have to be ours.

CORE was our first product.
Yours could be next.

We built CORE before we built anything else — then bet nine products on it. Every one inherits everything on this page, on day one. So would yours. And open doesn't mean unguarded: every product on CORE is certified and permission-scoped — including the nine we built.

Questions builders ask

The questions, answered.

Where are the developer docs?

With the SDK. Access is by request while we onboard early builders — the SDK and docs ship under NDA during early access, and production access comes with a certificate. Request SDK access →

What's on the public ledger — and what never is?

Proofs, and nothing else. Cryptographic fingerprints designed to show a record hasn't changed — never the record itself, never PHI, never anything readable. How anchoring works →

Who holds the encryption keys?

That's a deployment decision, not a fixed answer. In our cloud, keys live in managed hardware security modules with zero standing human access. On your own infrastructure, custody can sit with you entirely. In-country deployments keep keys in-jurisdiction. The constant never changes: our standing access is zero.

How do we migrate fifteen years of legacy data?

Coexistence first. The migration machinery is part of the substrate, built for the systems you're running today — and nobody big-bangs onto CORE. Switching to GoldenI →

Who decides when the shared data model changes?

Deliberately, and under governance: changes are versioned, reviewed, and policies only ever tighten down the hierarchy — never loosen. The full model is a conversation worth having.

Can we leave?

Yes. Your record exports whole — it was always yours. We'd rather keep you with architecture than with exit costs.

Is it certified?

Security and compliance documentation is available under NDA as part of diligence. Ask.