Where it is
Local disks, SMB and CIFS shares, SharePoint, OneDrive and Exchange, all scanned from a single place, including inside archives and scanned images.
Iris scans your disks, shares and Microsoft 365 for PII and PHI, tells you which files hold it, how much, and who can reach them, without a byte leaving your network.
Tell us what you need scanned. We come back with the appliance it needs, which comes with the contract, and what a deployment would involve.
Most organisations cannot produce a list of which files hold it.
Local disks, SMB and CIFS shares, SharePoint, OneDrive and Exchange, all scanned from a single place, including inside archives and scanned images.
Every flagged file is attributed to an owner, so a finding becomes someone’s task instead of a line on a report nobody acts on.
Findings are ordered by severity, weighing the class of data against how much of it sits in one place. The worst thing you own appears at the top.
Four stages, in order, from connecting a source to closing a finding.
Point Iris at local disks, SMB and CIFS shares, and Microsoft 365 (SharePoint, OneDrive and Exchange), then manage them all from one console.
Documents, spreadsheets, databases, mail, text and archives are parsed directly. Images and scans go through OCR, so a photographed form is read like any other file.
A fine-tuned NER model and heuristic detection flag names, addresses, dates of birth, record numbers, health IDs and clinical codes. Images run through a medical-tuned classifier, and uncertain flags get LLM verification.
Findings land in the dashboard ranked by severity. Owners and administrators are alerted by email, Teams or Slack, and every action is written to the audit log.
Iris runs completely on-premises. No sensitive data is sent externally, and none is retained in telemetry, alerts or findings. For most healthcare organisations that is the only arrangement they can actually sign off.
What this means in practice. The classifier, the OCR pipeline and the LLM verification step all run inside your own environment. Alerts carry the location and severity of a finding, not its contents. There is no external service to review, no data-processing agreement to negotiate with us, and no third-party sub-processor in the path of patient data.
Iris runs a fine-tuned NER model, a medical-tuned image classifier and an LLM verification step. All of that runs inside your network, which means the compute has to be inside your network too.
The appliance that runs it is included in your Iris contract on loan, so there is no GPU to specify, no capital request and no hardware to write off at the end. Running Iris on thin hardware would force smaller models, and smaller models find less, so we size and supply the machine rather than leaving it to chance.
This is also why there is no instant demo link: there is a physical machine to size, ship and place before Iris can show you anything honest.
What we work out with you.
The dashboard, alerting, analytics, how detection works, and what Iris will not decide for you.
A web dashboard for working through flagged documents and content. Filter by source, owner, data type or severity, open a finding to see what was detected and where, then mark it resolved. Administrators get a full audit log of who reviewed what and when.
Built-in email, Microsoft Teams and Slack alerting for both file owners and administrators. The person who created the problem file hears about it directly, rather than the finding sitting in a queue nobody owns. Alerts carry location and severity, never the sensitive content itself.
Severity distributions, patterns in which data types keep appearing, and live scan data as a job runs. Useful for spotting that one department generates most of your exposure, or that a single legacy share accounts for half the critical findings.
A fine-tuned NER model plus a heuristic detection system flags email addresses, dates of birth, medical record numbers, health IDs, names, addresses and clinical codes. Images are read via OCR and classified with a medical-tuned classifier. Where a flag is uncertain, an LLM verification step resolves it locally, like everything else.
Iris tells you where sensitive data is and how severe each concentration looks. It does not decide what should be deleted, moved or restricted, and it does not make an organisation compliant on its own. Classification is the input to those decisions, not a substitute for them. Findings are reviewed by your team, and detection accuracy depends on the quality of the source material, particularly for scanned images.
Knowing a legacy share holds four hundred patient records is only useful if the machine it sits on is patched, monitored, access-controlled and recoverable. CraftSupport does that side too, so the systems holding what Iris finds are looked after by the same team.
Two halves of the same job. Iris answers where the sensitive data is and who can reach it. The managed-server stack answers whether the systems holding it are patched, monitored, logged and restorable. Either is useful alone; together they cover both the data and the ground it sits on.
You do not need a programme of work to begin. Tell us which sources are in scope, and we will come back with the appliance it needs and what a deployment would involve.
On-premises throughout. Nothing is sent anywhere, at any stage.