HIPAA compliant LLM gateway · one API, one BAA

One API for every AI model. One BAA that covers all of them.

Garrison is the LLM gateway for healthcare teams that want the newest models without a contract process per provider. One-click BAAs with every AI model company, tokens at list price. When a provider covers a new model, so do we.

anthropicopenaigooglemetadeepseekalibaba / qwenmoonshot / kimi k3 · newtypesafe / jev · new

Stop managing contracts. Start shipping.

Every problem a healthcare team has with model providers, and the fix.

What you deal with todayWith Garrison
A separate BAA negotiation with every model provider→One BAA with GarrisonEvery provider you use sits behind it.
The newest models are not on your cloud's eligible list for weeks or months→When a provider covers a new model, so do weWe never route patient data to preview or beta models.
New labs publish no BAA at all→One negotiation, done by GarrisonGetting a new provider under the agreement is our work, not yours.
A different SDK and key for every provider→One base URL, one keyThe request shape your client already sends.
A base fee plus token usage→Tokens at list price, no markupTwo plans. The difference is retention, not price per token.
A sub-processor list you maintain for every security review→One sub-processor: GarrisonYour security review sees one list, maintained by us.

Built for teams that move

From a prototype on one model to production on whichever is best this month.

BAA

Every provider under one agreement

Closed labs, the three clouds, the open-weight hosts, and the new labs, behind one agreement with Garrison.

ZDR

Zero retention, one setting

Choose the plan where nothing is kept. Prompts and responses live in memory for the call and nowhere else.

PHI

Identifiers removed before storage

Names, dates, numbers and the rest of the Safe Harbor list are stripped from prompts and responses before anything is kept. The clause that allows it is explicit in your BAA.

LOG

Every call on the record

Caller, model, tokens, cost and time on every request, kept six years to match the Security Rule's documentation retention period. Exportable for your auditor.

# the whole migration
client = OpenAI(
    base_url="https://api.garrisonhealthsystems.com/v1",
    api_key=os.environ["GARRISON_API_KEY"],
)

client.chat.completions.create(
    model="anthropic/claude",   # or any provider/model
    messages=[...],
)
  • 01Sign the BAA. Garrison becomes your business associate for every provider on the list.
  • 02Change the base URL and the key. Your client library stays.
  • 03Name a model as provider/model. Switch by changing the string.

What each provider asks of you today

A BAA is a sales process, not a toggle. Here is the process, per provider.

The left column is each provider's own published route. The right column is yours.

ProviderTheir route to a BAAYour route
OpenAIEmail sales. Zero Data Retention or Modified Abuse Monitoring on the account. Covers listed endpoints only.covered
AnthropicContact sales. A dedicated organization with HIPAA controls. One organization per agreement. 30-day retention.covered
Google GeminiThrough a Vertex AI account, under the cloud's BAA, for the models the cloud lists as eligible.covered
Llama, Qwen, DeepSeekA host's enterprise tier (Together, Fireworks, Baseten, Groq), each with its own agreement and minimum.covered
Kimi K3, JevNo BAA published. No route at any price.covered
Next month's labUnknown.we sign with them, you do not

Pricing

Tokens at the provider's list price. We never mark them up.

Two plans. The difference is retention. The pricing page has the detail.

At cost

List price + $0

Standard retention. Identifiers on the HIPAA Safe Harbor list are removed, then usage data is kept as your BAA permits. The de-identification clause is explicit in the agreement.

  • Every provider, every model
  • Usage tracked per key and per team
  • Audit log on every call

Zero retention

List price + monthly fee

Nothing is kept. Prompts and responses exist only in memory for the length of the call. The plan most enterprise security reviews ask for.

  • Every provider, every model
  • No copy of any kind
  • Audit log holds metadata only

FAQ

Common questions.

What exactly does the BAA cover?

Every request you send through Garrison, to every provider on the list. Garrison is your business associate under HIPAA. Your security review sees one sub-processor list, maintained by us.

How fast is a new model covered?

When the provider covers it, we do. On AWS, Azure and Google that is the day a model goes generally available. On the OpenAI and Anthropic APIs it is when the model is on their covered list. We never route patient data to preview or beta models.

What is removed before anything is stored?

Identifiers on the HIPAA Safe Harbor list: names, dates finer than year, ages over 89, contact details, record and account numbers, addresses, and the rest of the eighteen. The clause that lets Garrison do this is written into your BAA.

What is the difference between the two plans?

Retention. On the standard plan, de-identified usage data is retained under the terms of your BAA. On zero retention, nothing is kept. Token prices are the same on both.

Is there a markup on any model?

No. You pay the provider's published price on every token, on both plans.

Start

Build with the newest models. Sign once.

Tell us where to send the agreement. A key follows the signature.