Interneuron - Clinical Orchestration Engine
A secure SaaS platform for AI orchestration and intelligent automation in healthcare. It deploys, manages and governs AI agents, large language models and medical imaging solutions across clinical workflows. Provides centralised control, regulatory compliance, and seamless integration of diagnostic tools and clinical decision support systems.
Features
- Orchestrates AI agents for autonomous clinical workflow execution
- Human-in-the-loop validation for safety-critical clinical decisions
- Explainable AI ensuring transparent, auditable clinical decision-making
- Federated Learning protects sensitive patient data during training
- Digital Twins enable clinical operational simulation and planning
- Native medical imaging and DICOM standard integration
- Zero Trust security architecture for maximum patient data protection
- Real-time drift detection for deployed clinical AI agents
Benefits
- Enhances clinical confidence with explainable transparent model outputs
- Ensures data sovereignty and compliance with healthcare security standards
- Reduces administrative burden through intelligent automation of tasks
- Prevents vendor lock-in with open, interoperable platform architecture
- Safely integrates medical imaging AI into existing clinical workflows
- Identifies optimal AI investments using real-world performance data
- Accelerates clinical transformation through scalable autonomous AI capabilities
- Integrated cost monitoring controls and optimises infrastructure spending
- Ensures alignment with healthcare AI ethics and regulatory standards
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 1 5 0 7 2 2 8 1 8 9 3 9 4 2
Contact
HEALTHCARE SOFTWARE SUPPORT CIC
Bids Team
Telephone: 07771532606
Email: bids@interneuron.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Interneuron's open Modular Care Record
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- No service constraints.
- System requirements
- Clinical Decision Support
User support
- Email or online ticketing support
- Yes
- Support response times
- Service Levels and Response Targets can be mutually agreed.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- We can provide 1st Line, 2nd Line and Specialist (3rd Line Support).
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- We can provide virtual, on-site and online training. All documentation, user guides are available through our customer portal.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- We can provide users extracts of all of their data during the offboarding phase.
- End-of-contract process
- We will ensure users have access to their data.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Our system is designed to work on tablet and desktop devices
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
- The system includes several services that provide API access to the system. We have 100% coverage of all data through our RESTful APIs.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- The system is extremely configurable and extensible. We provide a management tool for basic configuration.
Scaling
- Independence of resources
- Our service has been architected to auto-scale (both vertically and horizontally) should additional capacity be needed.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We can provide service metrics on usage, subject access and performance of the system.
- Reporting types
-
- API access
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Physical access control, complying with CSA CCM v4.0
- Data sanitisation process
- No
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- We can provide super-users access to export their data in CSV format.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Our standard SLAs are to meet a minimum of 99.95% availability. However, stronger SLAs can be mutually agreed.
- Approach to resilience
- Our application architecture is fault-tolerant and highly resilient by design. We use load balanced, redundant application servers and geographically disparate servers.
- Outage reporting
- Email alerts and user dashboard.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- We have a robust RBAC for all management interfaces and support channels.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- We have a robust ISMS and are ISO27001 accreditted.
- Information security policies and processes
- We have a robust ISMS and are ISO27001 accreditted.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We use a single front door for all of our change and configuration requests. Each request is managed in accordance of our ISMS and SMS, ensuring appropriate security, clinical and regulatory compliance.
- Vulnerability management type
- Undisclosed
- Vulnerability management approach
- We continuously scan our code for vulnerabilities using the latest software composition analysis tools - that checks CVE and other databases. We prioritise all vulnerabilities and fix accordingly.
- Protective monitoring type
- Undisclosed
- Protective monitoring approach
- We continuously scan our infrastructure logs using the latest software observability tools to identify any compromises. We prioritise any found compromises and react accordingly.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We have a single front door for all incidents, managed through our ISO 27001 compliant ISMS.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 7.5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 12.5%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Alcumus ISOQAR
- ISO/IEC 27001 accreditation date
- Thursday 26 September 2024
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Alcumus ISOQAR
- ISO 9001 accreditation date
- Friday 14 April 2023
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 8471cd46-6699-4a53-ad8b-3d2253a28ad3
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 052216c0-9430-4e8b-8d81-3cea4b47c30e
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
-