The de-identification engine healthcare finally needed
Sandy strips PHI from clinical text and records in-house, with our own models. Available as an API, over isolated networking, or inside the platform, always on your own data.
Three signals, one clean record.
Structure, pattern, and language, combined so nothing slips through.
Measured against the alternatives
Overlap F1 on a 600-sample labeled set, against the de-identification approaches teams usually reach for. Higher is better.
Built to fit in and stay safe
One engine, reachable your way and safe on its own.
Three ways to reach it
As an API
Call the REST endpoint on demand, the same pipeline that runs everywhere.
Over isolated networking
A private, isolated network path with no public internet exposure.
Inside the platform
Already running on every note, summary, and record flowing through Sandy.
Safe by default
Nothing sensitive comes back
Detected values are stripped from the response by default.
A failed record never passes
Failed items are flagged, never forwarded as if they were safe.
We log the shape, not the text
Telemetry logs counts and timing, never payload text.

