Control and evidence layer for AI in regulated organisations

Suvard is your AI's black box.

Everything your AI does through Suvard, you can see and prove afterwards. On your own network, without data leaving the building.

Help set the norm for AI evidence in Denmark →
Video: AI-generated illustration

One question

If a regulator, a client, or a relative asked you tomorrow to demonstrate how your staff used AI in a specific case, could you?

Today the answer is usually no. Your systems know who logged in. They rarely know what the AI delivered and what the human did with it, and never in a format others can verify. You cannot assign responsibility for something you cannot reconstruct.

What should keep management up at night

Not that the AI can be wrong. But that it's already being used: in the browser, in the EHR (Electronic Health Record system), in e-mails. Nobody decided it, and nobody can see it. It is called shadow AI because it happens in the shadows where management is not looking. The day the question comes, from a regulator, a relative or a customer, the answer is "we don't know". Not because anyone did anything wrong, but because it cannot be reconstructed.

The risk is not the AI's mistake. It is that you cannot prove what happened. Light is what kills the shadow.

In their own words

Those who build AI say it themselves.

This is the first time AISI has seen deception of this severity that was targeted at a real person, unprompted, in the real world.

UK AI Security Institute
incident report, 4 August 2026

During a test, an AI agent tried to deceive a real engineer and cover its tracks. The originals survived because they were stored in an append-only log that the agent could not touch.

Given the scale of the review required, and the need to verify each case, this work will take months to complete.

OpenAI
on the review of its own AI agents, 25 September 2026

Even with full access to its own systems, OpenAI needs months to find out what its agents did. A hospital does not have months.

Partner with an independent external auditor or evaluator to carry out independent assessments of whether the controls, monitoring, and detection are operating as intended.

White House Accord on Super Intelligence
signed by Google, Anthropic, Meta, OpenAI, xAI and Nvidia, 29 September 2026

Layer three of four in the accord: an independent party must verify whether the controls work.

It sounds like science fiction. It happened this summer, in real systems. The question is not whether the AI does something unexpected. It is whether you can see it afterwards.

And the human in the loop?

It only helps if you can see what the human did.

When experienced radiologists (with over 15 years of experience) were given confident but incorrect AI suggestions in mammography, the rate of correct assessments dropped from 82% to 45.5%. A ''human in the loop'' is not a safeguard in itself. Without an audit trail, no one can subsequently distinguish a deliberate override from a reflex click.

That is why Suvard seals both what the AI delivered and what the human did with it.

Imagine

What if the decision and the outcome were recorded?

Every AI recommendation, what the human did with it, and the final outcome, in one place, independent and verifiable. That gives you more than proof when questions are asked; it gives you the data to see for yourself where AI actually helps and where it does not. You cannot improve a decision that was never recorded.

What Suvard is

A control and evidence layer that runs on your own network.

It sits in the path of the AI traffic, between staff and systems on one side and the AI models on the other. For every AI request it does four things.

Finds

names, CPR numbers, addresses, account numbers and whatever must never leave the building, including what no list knows. The detector is trained for the sector; in healthcare a Danish clinical language model.

Masks

the findings with placeholders before the AI sees them, and shows the user what was found. No new workflow.

Stops

what must not happen, by your own rules for who may send what to which model.

Seals

every event in a signed chain where later changes can be detected, and which can be verified without trusting us.

What a sealed trail looks like.

Each line binds what the AI delivered, what the human did, and a digital fingerprint of the outcome into a single seal. The keys are yours. The content never leaves the premises. If anyone alters a line afterward, the seal breaks, and anyone can verify this using a small, standalone utility that requires zero trust in us.

Sealed trailkeys with you
Hash-chained and signed. No content leaves the building.

Illustration. The events are examples, not real data.

The engine

Healthcare first. The same engine for the other regulated sectors.

We start in Danish healthcare deliberately because it is the hardest environment: sensitive data, life-or-death decisions, and the strictest regulations. The engine remains the same across energy, finance, legal, defence, space, and the public sector; only the detector and rulebook change. We will not enter a new sector before securing a Danish healthcare reference.

HealthcareEnergy, laterFinance, laterLegal, laterDefence, laterSpace, laterPublic sector, later
IN: text, documents, calls OUT: masked + sealed ENGINE CPR · clinicalSCADA · OTIBAN · MNPIcase no · clientclassificationtelemetry · orbitCPR · clinical detector Healthcare · nowEnergyFinanceLegalDefenceSpace

Why now

The law demands the evidence. The professionals say the infrastructure is lacking.

The AI Act already requires everyone who uses high-risk AI to be able to document how it worked and how it was used. In healthcare, the MDR adds to that. Neither defines an independent format for what the human did.

AI Act, art. 72(2)

“…actively and systematically collect, document and analyse relevant data which may be provided by deployers … on the performance of high-risk AI systems throughout their lifetime …”

The provider must continuously collect data on how the system performs in practice, also from those who use it. How that is captured, the law does not say.

AI Act, art. 26(6)

“… keep the logs … for a period appropriate to the intended purpose of the high-risk AI system, of at least six months …”

The duty to keep logs lies with the one who uses the system. A shared, verifiable format does not exist.

In healthcare also: MDR 2017/745, Annex XIV Part B

“… proactively collect and evaluate clinical data from the use in or on humans of a device which bears the CE marking …”

The manufacturer of CE-marked equipment must monitor its use in the clinic. One cannot follow up on advice if one does not know whether it was followed.

… clearly established in principle by active current regulations, but not enacted upon, given unclear standardization and requirements at the moment.
European Society of Radiology, consensus recommendations, December 2025An example from healthcare: the physicians' own society on monitoring AI devices in use. The requirement exists. The standard for meeting it does not.

Everyone demands the result. Nobody defines the format. That is what we build: an independent seal on top of the standards that already exist.

2 December 2027

The EU's high-risk requirements apply to Annex III: e.g. acute triage in healthcare, credit scoring of individuals in finance, and the management of critical infrastructure like energy.

2 August 2028

The requirements apply to AI that is part of CE-marked products (Annex I), e.g. medical devices, where most clinical decision support lives.

The dates cannot be moved. What can be changed is whether a format and references exist on the day they bite. Evidence cannot be produced retroactively.

Where are you?

Two tracks, one layer.

The question belongs when the budget is set, not when the regulator calls.

AI in use today, without control?
The gateway
  • Mapping of which AI services are used, and how much, without personal data.
  • Danish recognition of people and sensitive details before data reaches a model. In healthcare: patient identity with a clinical model.
  • Guided redaction: the user approves the placeholders.
  • A signed log for every call, on your own network.
Validated in Treat Systems' technical environment
Ready for the requirements in 2027 and 2028?
The evidence layer
  • An independent seal on what your AI delivered and what the human did with it.
  • Also for AI without a chat interface, such as drafting case notes or clinical records, or decision support embedded directly in your core software.
  • Can be verified offline by others, without trusting us or the vendor.
  • No personal data to Suvard. The keys are yours.
Built, in pilot phase
The vendor ownsThe workflow

What the AI delivered and what the human did are recorded directly within the vendor's own interface using an open data model. We never build the user's graphical interface.

Suvard ownsThe seal

The event is sealed independently of the source system: hash-chained, cryptographically signed, with encryption keys held strictly by you. Never the underlying content - only tamper-evident proof of what occurred.

Open to allThe verifier

Anyone can run it and check the seal without asking us. That is what makes the independence verifiable instead of a promise.

Proof is only truly independent if the entity sealing it has no stake in the outcome. That is why Suvard operates entirely outside the operational workflow, and why we never supply the language model itself.

The rules behind

What Suvard helps you comply with.

GDPR

Data minimisation in practice: people's identity is masked before data reaches an AI model, and the user sees what was found.

NIS2

Danish law applies from July 1, 2025, covering healthcare, energy, finance, and public administration, among other sectors. The legislation mandates logging, monitoring, and that log data is protected against tampering. A signed chain where alterations can be detected provides precisely that.

AI Act (and MDR in healthcare)

Logs kept for at least six months by the deployer of the AI (Art. 26), and continuous operational performance data fed back to the provider (Art. 72 and MDR post-market surveillance). The evidence layer delivers both in a single audit trail.

The standard

Help set the norm.

An evidence layer is only valuable if it is shared. That is why we build on top of existing standards rather than reinventing the wheel. Anyone who adopts the standard does not need to build anything from scratch: Suvard drops straight in. Denmark can lead the way and show the rest of Europe how to achieve verifiable AI.

1Open standard

An extension to HL7's standard for AI transparency and a Danish profile through the channels that already exist: integrity, an independent seal and the event "no action".

2Open verifier

A free, standalone utility, making verification completely cost-free, so anyone can independently verify the seal.

3References first

Private healthcare operators adopt the seal first. That serves as the living reference that the public sector can later write into tender specifications as a functional requirement.

A network that sets the norm together, before it becomes a requirement.For clinics, vendors, regions and other regulated organisations. The chain is simple: the law demands the evidence, the standard provides the format, Suvard delivers the seal. Denmark first. Then the rest of Europe.

Join

Where we stand

Built in Aalborg. Validated in Denmark.

Validated with a Danish vendor

The engine with Danish detection, masking and a signed log is validated in Treat Systems' technical environment.

Trained without a single patient record

The Danish clinical model is trained on synthetic text only, on our own hardware in Aalborg.

Danish Championship in Entrepreneurship 2026

Winner of the life-tech category.

Next step

A 30-minute check on where AI is already running in your organization.

We start with a mapping, not a sale. You get an honest picture of what passes through your network, and what it would take to be able to prove it afterwards.