nxthreat

Decide what agents may do with PHI. Sign what they did.

nxthreat sits between your AI agents and your EHR. It evaluates every tool call against policy, blocks what exceeds scope, and writes a signed receipt your auditor can verify — without production access.

FHIR R4 · MCP · minimum-necessary policy · append-only receipts

Decision receipt

no. 182,401 of chain

Receipt
rcpt_0000182401
Recorded
2026-07-16T14:32:05.406Z
Agent
intake-agent-07 · midwest-health
Tool call
fhir.bulk_export → Patient/*
Stated purpose
intake_summarization
Policy applied
minimum-necessary / v41
Decision
Blockedbulk export exceeds task scope

Signature · AWS KMS tenant key

9f41c2…e708 ← links receipt 182,400

Illustrative receipt — one blocked call, recorded and signed

One gateway

in front of all agent tool traffic

Per operation

policy on the call, not coarse roles

Every decision

captured, chained, and signed

Your agent can act. Can you say why it was allowed to?

API gateways authenticate requests. SIEMs record what already happened. Neither can decide, at the moment of the call, whether this agent should touch this record for this task — and neither leaves proof that anyone decided at all.

Know the caller

Identity for every agent

Shared bearer tokens make every agent look the same. nxthreat issues workload identity scoped to one agent, one tenant, one job — so a decision can name who asked.

Control the action

Policy on every tool call

The exact operation, FHIR resource, patient context, tool schema, and stated purpose are evaluated before access is granted. Not roles. The call itself.

Prove the outcome

Signed evidence by default

Every allow and every deny lands in an append-only receipt chain, signed with your KMS key. The audit trail exists before anyone asks for it.

Security that runs at agent speed.

nxthreat sits where intent becomes action — the only place policy can still change the outcome instead of describing it afterward.

01

Intercept

Agent tool calls route through nxthreat before they reach MCP servers, FHIR endpoints, or internal APIs.

02

Decide

Identity, tool schema, operation policy, and returned content are evaluated in the request path — milliseconds, not batch review.

03

Attest

Each decision, allowed or blocked, produces a KMS-signed receipt chained to the one before it.

Decision register · production
Illustrative
Agent / operationResult

prior-auth-014

Patient.read

allowed

clinical-docs-03

Observation.search

allowed

intake-agent-07

fhir.bulk_export

blocked

prior-auth-014

Claim.search

allowed
Walk through the architecture

Fits between your agents and your systems.

Keep the models, tools, and observability stack you already chose. nxthreat adds the enforcement layer in the middle — nothing else moves.

  • Works with MCP, FHIR R4, and internal HTTP APIs
  • Feeds existing SIEM and evidence workflows
  • Tenant- and agent-scoped by design
Agent client

runtime

nxthreat control plane

Identity broker
Schema registry
Policy engine
Injection guard
Receipt ledger
EHR / FHIR / MCP
SIEM / auditor

audit plane

data plane
audit plane

Evidence your auditor can verify without production access.

Export signed receipts by tenant, agent, resource, action, and date range. Hand compliance the evidence produced at runtime — not a spreadsheet reconstructed three weeks before the audit.

Review the HIPAA control mapping

Evidence Pack

verifier included

AI Agent Activity Attestation

Audit Period
2026-04-01 - 2026-04-30
Tenant
midwest-health
Agents Covered
14
FHIR Resources Touched
Patient, Observation, Claim
Receipt Count
182,401
Signing Authority
AWS KMS tenant key
Receipt chain verified. 0 signature gaps.

MCP made agent tooling portable. It also made tool definitions and transports part of your attack surface.

Read the field report

Bring your agent architecture. Leave with a runtime threat model.

No generic deck. We screen-share the control and evidence flow against your actual deployment — agents, tools, and the systems they touch.

Book a technical walkthrough