Horizon 1 live · R1–R7 on one kernel

Give clinicians more time to care.
One Health OS.

Sentia is an event-sourced, consent-bound Healthcare OS — ambient consult, Clinical Canvas Patient 360°, lab, pharmacy, and patient companion on a single FHIR-native graph.

0Release map R1–R10
0Identity-bound sessions
0AES-GCM key bits
Consent live
AI drafts · you sign

Ambient scribe

Listening

Audio → draft · you sign Nothing unsigned enters the kernel
app.sentia · Patient 360° · Clinical Canvas

Clinical pulse

Vitals

128/80
BP · shared stream

Risk

Moderate
Twin · advisory

Clinical Canvas

Problems · meds · lab alerts · timeline · care team — hash-chained on the patient stream.
Initiative · भारत

Digital health sovereignty for India.
आत्मनिर्भर भारत · Health OS

Sentia is built in India for Indian care — ABHA-ready identity paths, DPDP-aligned consent, FHIR R4 on an event-sourced kernel, and offline-tolerant clinics from metro OPD to tier-2 floors. Self-reliant infrastructure: Indian clinicians own the sign-off; patients own the stream.

Built for India first

Real OPD density, Hinglish ambient drafts, bilingual Rx paths, and clinic workflows that match how care already runs — not a Western EMR relabelled.

Local product DNA

ABHA / ABDM-ready path

Identity and linking ports sit on the Healthcare Cloud layer so beachhead clinics can grow into India’s digital public goods stack without a second patient truth.

Digital public goods

DPDP-aligned consent

Consent-bound reads, revoke-means-revoke Companion controls, and kernel enforcement — patient agency as system design, not a privacy PDF afterthought.

Data sovereignty

Offline-tolerant clinics

Tablets keep working when the tower doesn’t. Sync lands losslessly on return — essential for India’s uneven connectivity reality.

Tier-2 / tier-3 ready

Open standards kernel

FHIR R4 gateway, append-only events, one graph for doctor · nurse · lab · pharmacy · companion — no siloed “modules” inventing parallel charts.

Interop, not lock-in

Clinician-signed AI

Ambient drafts stay advisory. Licensed professionals sign. Indian clinical judgement remains the authority — AI never auto-writes the chart.

Human in the loop

Our pledge

Build a Health OS India can trust — secure by default, consent-bound by design, open where it should be open, and honest about what is live today (R1–R7) versus what is still on the road (R8–R10).

  • Self-reliant stack — run and evaluate locally; kernel you can inspect
  • Public-goods posture — ABHA-ready · DPDP-aligned · FHIR-native
  • Clinic-floor truth — designed with OPD rush, not only metro HQ demos

Built for people who already know the pain

Real clinic friction — not abstract “digital transformation.” Each persona maps to a live role in the app.

🩺 R1 · Doctor

Doctors

“I’m typing notes while the patient is talking — and still finishing charts after OPD.”

  • Ambient draft → you sign
  • Patient 360° Clinical Canvas
  • Orders on the same graph
Open Doctor workspace →
❤️ R2 · Patient

Patients

“I don’t know who can still open my file after last year’s hospital stay.”

  • See access · revoke anytime
  • Journey & results in plain language
  • Share card without clinical leak
Open Companion →
💉 R3–R4 · Care floor

Nurses & front desk

“Vitals and tokens never land where the doctor actually looks.”

  • Multi-vitals in one sheet
  • Acuity board · check-in consent
Open care roles →
☁️ Cloud · Kernel

Ops & IT

“Lab, pharmacy, and OPD are three products that don’t agree.”

  • One event-sourced kernel
  • FHIR gateway · consent on the wire
  • Offline path · AES sessions
See Cloud Kernel →

One nervous system under every role

Ambient voice feeds the doctor. Events feed the graph. The cloud substrate holds identity and consent — so lab, pharmacy, and companion never invent a second truth.

Append-only log Consent-gated reads AI never auto-writes One stream · many roles

Clinical power without the clutter

Doctor Workspace and Patient Companion are the wedge. Nurse, reception, lab, radiology, and pharmacy share the same graph — never a second chart.

Try Doctor Workspace
🎙

Ambient scribe

Listen → AI SOAP draft → human sign. Edit distance tracked. Nothing enters the kernel unsigned.

Clinical Canvas · 360°

Vitals, diagnosis, meds, lab alerts, filtered timeline, risk rail, care team, sticky notes.

🛡

Consent-first graph

Patient-owned streams. TREAT grants gate every clinical read and write. Revoke is real.

🧬

Healthcare Graph + DNA

Entity DNA, search, twin status over the event log — intelligence without PHI in ops views.

Rx safety · advisory

Flag-only interaction checks against active meds. Clinicians stay in control of prescribe.

📡

Follow-ups & offline

Clinic dispatcher, demo reminders, tablet sync when connectivity returns.

From door to discharge — one stream

Watch care events flow the kernel. Seed password sentia-demo · every step is the same patient fabric.

event · check_in append-only · consent-bound
STEP 01 · RECEPTION

Check in

Front desk registers the patient, grants clinic consent, and issues a token. No clinical detail on the desk surface — the kernel holds the stream.

patient.registered Start in the web app

Three layers. One nervous system.

Cloud substrate · OS graph & events · experiences that never invent a second source of truth — mapped like a brain: cortex, nerves, substrate.

LAYER 03 Cortex

Experiences

Flutter Doctor Workspace, Companion, care roles — same public API, role-bound sessions, premium clinical chrome. Ambient voice lives here; signing commits to the kernel.

  • R1–R7 role surfaces
  • Clinical Canvas · Patient 360°
  • Human always signs AI drafts
LAYER 02 Nerves

Healthcare OS

Event fabric, FHIR projections, Healthcare Graph, AI runtime, follow-up reflexes, offline sync — the pathways signals travel.

  • Append-only event log
  • Graph · DNA · twin
  • Workflow & offline sync
LAYER 01 Substrate

Healthcare Cloud

Identity (scrypt + HMAC), storage, ABHA ports, secure transport, multi-tenant path — the base everything stands on.

  • scrypt · HMAC tokens
  • AES-256-GCM sessions
  • ABHA-ready · multi-tenant

Security by default. Privacy by design.

Built for clinical safety and Indian compliance posture — mechanics, not checkbox theatre. Four seals around the clinical kernel.

🔑 01

scrypt passwords

Never cleartext. Never logged. Minimum length enforced on register. Demo seeds use a known password only for evaluation.

🪪 02

HMAC identity tokens

Role and subject bound — cannot forge another clinician’s principal or mint arbitrary roles on the wire.

🧊 03

AES-256-GCM sessions

API JSON bodies encrypt after login for the 8-hour session window — live timer and auto sign-out.

📜 04

Consent on every read

Kernel enforces TREAT grants. Revoke in Companion unlocks only when granted again — not policy theatre.

Full security detail → Privacy policy AI drafts stay advisory · humans sign · ambient never auto-writes the chart

Problems we design for

Real voices from the clinic floor — the friction ambient scribe, consent, and one kernel are built to remove.

I need the consult to write itself so I can look at the patient — not the keyboard.

OPD physician beachhead clinic

Straight answers from the OS

Evaluation guidance — not legal advice. Query the kernel; answers stream like a sealed read.

Talk pilots
sentia://kernel · faq sealed
// Human always signs. AI never auto-writes the chart.
sentia> query --topic=ai_chart
RESOLVED · advisory only

No. Ambient drafts are advisory. A licensed user must sign before events enter the kernel.

Built for the floor — not a demo stage

From registration tokens to signed notes and pharmacy queues, Sentia keeps one story of the patient. Ask Ayush (bottom-right) can walk you through roles, security, and how to open the live app.

Care team collaborating with Sentia

Open Sentia OS in your browser

Launch the Sentia OS web app to explore the full clinic day — Doctor Canvas, ambient consult, and care roles on one kernel.

Launch web app Product Team Contact