Products
SCRS — the AI data firewall Other Me — the workspace Compare both products
Solutions
All solutions AI Assistants Email + Projects CRM Live Chat Ticketing Flows HR-lite Control Center
By industry
Accountancy Legal Mortgage & IFA Healthcare
Company
Custom Solutions Pricing Blog About Us
Log in
SCRS login Other Me — Business Other Me — Family Get started with SCRS
For healthcare providers

Patient data,
structurally private.

Run the admin side of care — intake, consent, comms, scheduling and records — with an AI that’s blind to patient identifiers by construction, plus the consent and DSAR tooling your information-governance lead expects.

Patient intake
Consent · captured
Booking · confirmed
patient_2741 🔒

Built for how providers work.

1

Intake & consent

Capture forms & consent via Flows, stored governed with receipts.

2

Schedule

Booking pages and reminders that cut no-shows.

3

Communicate

Governed Mail & Live Chat, with identifiers masked.

4

Records & DSAR

Locate, redact and respond to patient data requests.

Information governance built in

The AI never sees
who the patient is.

Names, NHS numbers and contact details are tokenised before any model. Consent is captured with receipts, access is masked by role, and DSAR responses are tooled — so privacy is the default, not an afterthought.

Consent & DSAR →

Tokenised identifiers

Names & NHS numbers masked before AI.

Consent & receipts

Capture, store and evidence consent cleanly.

DSAR tooling

Find, redact and respond within the deadline.

A patient’s admin journey

From first enquiry to signed-off record.

One governed workspace carries each patient from booking to follow-up — identifiers tokenised at every step, every action on the audit trail.

1

Enquiry & triage

A new enquiry arrives via the website Live Chat or a Flows form. The governed AI agent answers routine questions, then turns the conversation into a CRM lead or a ticket — with names already masked before any model sees the text.

2

Intake & consent

A Flows intake form collects history and explicit consent. Consent is captured with a receipt and recorded against the patient in Governance, so you can evidence the lawful basis later without hunting through inboxes.

3

Schedule & remind

A Flows booking page offers real availability; reminders go out automatically to cut no-shows. Appointments land on the shared calendar alongside Kanban tasks for the clinical and admin team.

4

Care comms

Follow-ups go through your own IMAP/SMTP mailbox with AI triage and rules. Anything sent to a third party is pseudonymised through SCRS, so identifiers never leak in outbound copy.

5

Record & respond

Everything is filed against the record with field-level access control. When a patient asks what you hold, DSAR tooling locates, redacts and helps you respond inside the statutory deadline.

Recordpatient_2741
CONSENT
On file
NEXT APPT
Thu
DSAR SLA
28 days
ACCESS
Masked
name → patient_2741 🔒
NHS no. → redacted 🔒
Audit trail on
Caldicott view
  • Justify the purpose
  • Use the minimum necessary
  • Access on a need-to-know basis
  • Everyone aware of responsibilities
  • Comply with the law
Need-to-know enforced before search
Information governance, by design

A workspace shaped by Caldicott thinking.

The Caldicott principles ask you to justify the purpose for using patient data, use the minimum necessary, and share strictly on a need-to-know basis. Other Me is engineered so that posture is the path of least resistance — not a policy you have to police by hand.

  • Need-to-know, enforced in code. The SCRS firewall removes out-of-scope data during retrieval, so results that fall outside a user’s remit never exist to be seen — block-before-search, not filter-after.
  • Minimum necessary by default. Identifiers are tokenised before any model and access is masked by role, so admin work happens without exposing the whole record.
  • Responsibilities stay visible. A full audit trail records who did what, and the leaver kill-switch revokes a person’s data access the moment they offboard.

Caldicott principles are quoted here as governance context to help you map your duties — not a certification or endorsement.

Where clinics put it to work.

Practical jobs across the admin side of care — each one governed, each one keeping identifiers off the model.

Enquiry handling

A governed Live Chat agent answers website enquiries around the clock and converts the transcript into a CRM lead or ticket — never asking the model to see a real name.

Digital intake

Replace paper forms with Flows intake and consent capture, complete with receipts, so the lawful basis is recorded the moment a patient says yes.

Booking & reminders

Self-service booking pages plus automated reminders cut no-shows, with appointments flowing onto the shared calendar and team boards.

Patient comms

Run follow-ups from your own mailbox with AI triage and rules; outbound to third parties is pseudonymised through SCRS.

DSAR responses

When a patient exercises their access rights, locate the data, redact third-party details, and respond inside the deadline — with the request logged.

Offboarding & HR-lite

A leaver’s access to patient data is revoked through the SCRS kill-switch the moment HR-lite records them as a leaver.

What clinics get

The whole admin side of care, under one governed roof.

Real, shipping capabilities — grouped the way a practice actually runs — with identifiers kept off the model at every step.

Patient records, access & DSAR

  • Contacts, companies and full activity history — notes, calls, tasks and emails logged against the record
  • Field-level access control: mark any field (contact details, notes, IDs) sensitive so plain members see it blanked
  • Matters / rooms with ethical walls isolate a case to its members only, even from teammates
  • Per-contact DSAR subject-access export, itself written to the audit trail
  • Tamper-evident SCRS audit hash-chain records who did what
  • CRM & Operations is a +£11/mo per-team add-on

Digital intake & consent

  • 12 question types including file upload — collect history, referrals or ID inside the form
  • Conditional sections and save-and-resume for longer intake
  • Consent captured and recorded against the patient, so the lawful basis is evidenced
  • Each submission can create a governed CRM lead with round-robin or first-rep assignment
  • Describe a form in plain English and the AI drafts it for you to publish

Booking & reminders

  • Self-service booking pages with real availability, buffers and minimum-notice
  • Group / class sessions with per-slot capacity
  • Automated email and in-app reminders to cut no-shows
  • Bookers cancel or reschedule themselves via a private link — no login
  • Auto Google Meet link, or bring your own Zoom / Teams / phone / in-person

Patient comms

  • Connect your own IMAP/SMTP mailboxes (encrypted credentials, up to five)
  • AI triage briefing sorts a folder into reply-today / worth-a-look — read-only, redact-before-LLM
  • Rules, templates, signatures, schedule-send and undo-send
  • Anything sent to a third party is pseudonymised through SCRS
  • Shared Kanban boards keep clinical and admin tasks moving

An AI blind to the patient

  • Redact-before-LLM: names, NHS numbers and contacts tokenised before any model, forcing NER and failing closed
  • Vision understands uploaded images and scans with faces blurred and PII text removed first
  • Transcription and OCR turn recordings and scanned PDFs into searchable text
  • Best model per job, with no per-tier gating
  • Free Document, Workbook and Deck editors with an in-editor Ask-AI

Staff, access & offboarding

  • People directory, org chart and joiner-mover-leaver lifecycle
  • SCRS kill-switch: marking a leaver logically revokes their access to records, mail, files and AI — fail-closed, reversible
  • Encrypted sensitive-PII vault (AES-256-GCM) for comp / immigration data, never sent to a model
  • Per-member module access, custom roles, 2-step login and single active session
  • Governed settings changes need a second approver, every change on the hash-chain
  • Employment-document e-signature is a £2/employee add-on

HR-lite, Flows (intake & booking) and Governance (consent & DSAR) are seat-included. Payments on the built-in invoice / pay page go through Revolut; bring-your-own gateways are owner-connected and off by default. Nothing here is certified.

Compliance posture — stated plainly

Honest about what’s in place today.

No badges we haven’t earned. Here is exactly where governance stands — so your IG lead can do their own assessment with the real picture.

UK GDPR & UK/EU storage

UK GDPR-aligned, customer data stored in the UK/EU, PII redacted before any third-party model, and no client data used to train models.

ISO 42001 on track

AI management standard on track; SOC 2 Type II and ISO 27001 are on the roadmap (Q4 2026 / 2027).

HIPAA & certifications

We make no HIPAA, ISO or SOC certification claim today. What’s real is generic governance — field-level RBAC, tokenise-before-LLM and a full audit trail. Discuss your regulatory needs with us before relying on it.

Patent-pending: UK application 2602911.6 for the SCRS firewall. Enterprise controls — SSO, BYOK and fine-grained data-residency — are coming soon; ask us about early access.

Why providers choose it

Less software, more governance.

Most clinics stitch together a booking tool, a forms tool, a CRM, a mailbox and a compliance spreadsheet — each one a fresh place for patient data to spill. Other Me is one governed workspace where privacy is built into the foundation.

  • One record, one audit trail — not five disconnected systems.
  • Identifiers tokenised before any model, every time.
  • Best model per job (GPT, Claude, Gemini, Grok) with no per-tier gating.
  • Free Document, Workbook and Deck editors with every AI plan.

“The first tool where the privacy story isn’t a checkbox bolted on at the end — the AI literally never sees who the patient is. That’s the conversation our IG lead actually wanted to have.”

Illustrative — how a practice manager might describe the difference. Not a real client.

The stack for a provider

AI base (free editors) + Flows for intake & scheduling (seat-included) + Governance for consent & DSAR. Enterprise controls (SSO, BYOK, fine-grained data residency) are coming soon.

AI suite · £24/seatFlows · includedGovernance · includedEnterprise controls · coming soon
Try →
Start in minutes

Give your clinic a governed workspace.

Spin up intake, scheduling, comms and DSAR tooling with structural privacy baked in — and an AI that’s blind to patient identifiers from day one.

Per seat, billed via Revolut. Enterprise controls coming soon.