Healthcare · use case
Protected health information is detected on the way in; external models are removed from the candidates; the on-prem model answers; complex clinical questions go to a clinician; the decision is logged. Controls you configure for a regulated workload - data boundaries, regions, PII handling, audit - not a certificate.
Free plan, no card. Self-hosting is free forever; the rules below run the same way on both.
The situation
Clinical and administrative teams want the same AI tools everyone else has, and every application they use would need its own rule about what may leave the network. One missed rule is a breach. The decision has to live in one place, before any model is called.
What changes
One request
PII never leaves your boundary - a policy rule, not a promise. Everything else routes on cost.
The policy
This is the rules.yaml that produces the behaviour above; targets.yaml names the models, agents and people it refers to. Policies run before scoring, so no objective weight can trade the boundary away.
rules:
- name: phi-stays-onprem
when:
contains_pii: true
prefer: [llm-onprem]
avoid: [llm-frontier, llm-mid]
weight: 1.0
- name: clinical-review
when:
domains: [medical]
min_complexity: 0.6
prefer: [clinician-review]
pin: trueExample: Illustrative configuration or synthetic data, not a customer's.A reference configuration to start from - rules the router enforces as written, not a description of how a named customer runs it.
OpenSmartRoute is open source and the free plan keeps the full trace of every decision. Create a workspace, paste the rules, route a request.
Free plan, no card. Fifteen thousand decisions a month with the full trace.