Build on our health platform
Build your health product on our platform, with our team, and the clinical safety, privacy and security groundwork is in place from the first release instead of starting from nothing.
It is for health startups, clinicians with an idea, digital health services, private providers and insurers building patient or member apps. You get a working product early, AI agents that each do one task under a named person's control, and a safety case, DPIA and DTAC evidence that grow with every release. You decide what the product does and when it goes live; we build it with you.
Last updated
What does start compliant mean?
It means the controls, the evidence and the clinical safety process are there from your first release, rather than added once the product is built. It does not mean someone else takes on your responsibilities.
- What is in place from day one
- A DCB0129 clinical risk management process, a hazard log, a safety case structure, DPIA templates, privacy controls, logging and control over where AI requests go.
- What stays with you
- You remain the manufacturer of your product and are responsible for it, including its safety case, its data protection and every claim you make about it.
- What we do not do
- We do not certify products, guarantee compliance or give legal advice. A product built on our platform is not approved by the NHS or by any regulator because of it.
- Medical device status
- Whether your product is a medical device depends on its intended purpose. The MHRA's guidance sets out how software is assessed, and we look at the question with you in discovery. Clinicians starting from an idea can read how we build with clinicians.
Source: MHRA: medical device stand-alone software including apps
What do you build on?
The same groundwork we use for our own products, set up for yours: clinical safety, privacy, secure AI and agent governance, with the evidence NHS and private buyers ask for.
-
Clinical risk management under DCB0129
A clinical risk management process, a hazard log and a safety case structure set up for your product, with our Clinical Safety Officer working with your clinicians.
Clinical safety for AI -
DPIA templates
Data protection impact assessment templates that follow how the platform handles data, ready for your data protection officer to complete for your product.
-
Anonymisation and privacy engineering
Personal data removed or masked before it reaches places it does not need to go, and only the data each feature needs is collected.
How anonymisation works -
Secure AI infrastructure
Control over where each AI request goes and which model answers it, so you decide which data can leave your systems.
Secure AI infrastructure -
AI answered on the device where it can be
Prime Edge AI decides where each AI request is answered: on the device when it can be, and in the cloud only when a feature needs it.
Prime Edge AI -
Agent governance
Each agent logs what it read and did, and hands over to a named person at the points you set before it can act.
How agents stay under control -
DTAC version 2 evidence
Evidence prepared against the Digital Technology Assessment Criteria form that NHS buyers now use, drawn from the same records as your safety case and DPIA.
DTAC version 2 was published in February 2026, and NHS England stopped accepting the old form after 6 April 2026, so evidence prepared now follows the new version.
We use the same clinical safety method on our own products. Prime Assist has a clinical safety case under DCB0129, signed off by our Clinical Safety Officer.
Source: NHS Innovation Service: updated DTAC form and guidance
Who decides: Your Clinical Safety Officer signs off the safety case, your data protection officer approves the DPIA, and your product owner decides which data each AI feature may send and where.
How do we build with you?
Five stages, from the first conversation to running the product. Safety and evidence work runs alongside the build at every stage, not after it.
How we work with startups-
Discovery
We agree who the product is for, the one problem the first release solves, its intended purpose and the questions to answer about medical device status.
-
First release
A small working product on the platform, used by real people in a controlled setting, with the hazard log and DPIA started alongside it.
-
Safety and evidence
Hazard workshops with your clinicians, the safety case written up, the DPIA completed with your data protection officer and DTAC evidence gathered.
-
Launch
Go-live checks against the hazard log, so the controls are in place, staff know how to report a problem and there is a fallback if a feature is unavailable.
-
Run and improve
Small releases, each with a safety review of the change, and the safety case, DPIA and DTAC evidence kept up to date as the product grows.
Who decides: Your product owner approves the scope of each release, and your accountable officer decides when the product launches, once your Clinical Safety Officer has signed off the safety case.
What do agentic and lean mean here?
Agentic means AI agents that each do one task, under a named person's control. Lean means small releases and a working product early, so you learn from real use before you spend on features nobody needs.
Read about AI agents- One task per agent, such as answering booking questions or summarising a form, so each one can be tested, logged and switched off on its own.
- A named human checkpoint before an agent takes any action that matters, and anything clinical goes to a person.
- Logs of what each agent read and did, so you can review it and so the safety case can point to evidence.
- Small releases, each with a safety review of the change, rather than one large launch.
- A working product early, in front of real users, so decisions rest on how people use it.
Who decides: You name the person who approves each agent's actions, and you decide which tasks an agent may take on.
Who is it for?
Anyone building a health product for patients or members who wants the safety and privacy groundwork in place before the first user signs in.
-
Health startups
Founders who want a working product in front of users early, without rebuilding the safety and privacy groundwork later.
-
Clinicians with an idea
Doctors, dentists, nurses and pharmacists who know the problem and want a team to build it.
Build with clinicians -
Digital health services
Teams adding patient-facing features or AI agents to a service that already runs.
-
Private providers
Clinics and hospital groups building their own patient app or booking and follow-up tools.
Private healthcare -
Insurers and health payers
Insurers building member apps for cover questions, claims updates and access to care.
Insurance and payers
Questions people ask
Does building on your platform make our product compliant?
No platform can do that for you. You start with the controls, the evidence and a clinical safety process already running, so the work of showing compliance is under way from the first release. Your organisation remains the manufacturer and stays responsible for the product and for meeting each rule.
Will our product be a medical device?
It depends on its intended purpose. Software intended to diagnose, treat, monitor or prevent a condition can be a medical device under MHRA rules. We look at this in discovery and point you to the MHRA's guidance; the decision on your intended purpose is yours, with your regulatory advisers.
Who is the Clinical Safety Officer for our product?
Our Clinical Safety Officer works on the DCB0129 process with you. As the manufacturer, you name the Clinical Safety Officer who signs off your safety case, and we go through the options with you in discovery if you have not named one yet.
Is this the right fit if we already have a product?
It can be. We can move features onto the platform one at a time, or add AI agents to what you already run, with the safety and privacy work applied to each change.
Do you give legal or regulatory advice?
No. We prepare the technical, clinical safety and privacy evidence and work alongside your legal and regulatory advisers, who advise you on how the law applies.