Find the patient data you forgot you had.

Iris scans your disks, shares and Microsoft 365 for PII and PHI, tells you which files hold it, how much, and who can reach them, without a byte leaving your network.

Tell us what you need scanned. We come back with the appliance it needs, which comes with the contract, and what a deployment would involve.

iris / flagged files scanning
All sources SMB SharePoint OneDrive Exchange
Scan progress · clinical-share1,284 / 1,902
smb › \\clinical-share\referrals
2019_referral_batch.xlsx
JM412 records
MRNDoBaddressname
critical
sharepoint › cardiology / handover
discharge_summaries.pdf
DK38 records
health IDclinical code
high
onedrive › o.stanton
ward_whiteboard_0311.jpg OCR
OS6 records
nameMRN
medium
exchange › reception@
Re: patient transfer.msg
RC2 records
emailDoB
low
Showing 4 of 47 flaggedSorted by severity
Illustrative view of the Iris findings dashboard.

Where is your patient data?

Most organisations cannot produce a list of which files hold it.

Where it is

Local disks, SMB and CIFS shares, SharePoint, OneDrive and Exchange, all scanned from a single place, including inside archives and scanned images.

Who owns it

Every flagged file is attributed to an owner, so a finding becomes someone’s task instead of a line on a report nobody acts on.

How bad it is

Findings are ordered by severity, weighing the class of data against how much of it sits in one place. The worst thing you own appears at the top.

How Iris works

Four stages, in order, from connecting a source to closing a finding.

01

Connect your sources

Point Iris at local disks, SMB and CIFS shares, and Microsoft 365 (SharePoint, OneDrive and Exchange), then manage them all from one console.

02

Read everything

Documents, spreadsheets, databases, mail, text and archives are parsed directly. Images and scans go through OCR, so a photographed form is read like any other file.

03

Classify the content

A fine-tuned NER model and heuristic detection flag names, addresses, dates of birth, record numbers, health IDs and clinical codes. Images run through a medical-tuned classifier, and uncertain flags get LLM verification.

04

Triage and resolve

Findings land in the dashboard ranked by severity. Owners and administrators are alerted by email, Teams or Slack, and every action is written to the audit log.

Nothing leaves your network.

Iris runs completely on-premises. No sensitive data is sent externally, and none is retained in telemetry, alerts or findings. For most healthcare organisations that is the only arrangement they can actually sign off.

What this means in practice. The classifier, the OCR pipeline and the LLM verification step all run inside your own environment. Alerts carry the location and severity of a finding, not its contents. There is no external service to review, no data-processing agreement to negotiate with us, and no third-party sub-processor in the path of patient data.

Real models need real hardware. We bring it.

Iris runs a fine-tuned NER model, a medical-tuned image classifier and an LLM verification step. All of that runs inside your network, which means the compute has to be inside your network too.

The appliance that runs it is included in your Iris contract on loan, so there is no GPU to specify, no capital request and no hardware to write off at the end. Running Iris on thin hardware would force smaller models, and smaller models find less, so we size and supply the machine rather than leaving it to chance.

This is also why there is no instant demo link: there is a physical machine to size, ship and place before Iris can show you anything honest.

What we work out with you.

  • Which sources are in scope, and how much data sits in each
  • The appliance tier that volume needs, supplied on loan with the contract
  • Where it sits on your network, and who holds administrative access
  • How it is patched and monitored, and how it is returned at the end

What Iris can read

Documents

PDFDOCXODTPPTXHTMLXHTMLGoogle Doc pointers

Spreadsheets

XLSXXLSMXLSCSVTSV

Databases

SQLiteACCDBMDB

Mail

MSGEML

Text

JSONJSONLXMLYAMLMarkdownSQLINICFGlogstxt

Images

PNGJPGTIFFBMPGIFWEBPHEIC

Medical imaging

DICOM

Archives

ZIP7ZRARTARGZBZ2XZ

What you get in the console

The dashboard, alerting, analytics, how detection works, and what Iris will not decide for you.

Review and resolve in one place

A web dashboard for working through flagged documents and content. Filter by source, owner, data type or severity, open a finding to see what was detected and where, then mark it resolved. Administrators get a full audit log of who reviewed what and when.

Finding the data is the first half.

Knowing a legacy share holds four hundred patient records is only useful if the machine it sits on is patched, monitored, access-controlled and recoverable. CraftSupport does that side too, so the systems holding what Iris finds are looked after by the same team.

Two halves of the same job. Iris answers where the sensitive data is and who can reach it. The managed-server stack answers whether the systems holding it are patched, monitored, logged and restorable. Either is useful alone; together they cover both the data and the ground it sits on.

Start with the share everyone worries about.

You do not need a programme of work to begin. Tell us which sources are in scope, and we will come back with the appliance it needs and what a deployment would involve.

On-premises throughout. Nothing is sent anywhere, at any stage.