AI coding agents, with a record your reviewers can check
Your engineers already use AI agents. Your security review already asks what those agents can reach. DeepSweep answers with evidence: a free local review of every capability an agent holds, a signed record of what it actually did, and a HIPAA Security Rule control mapping written so your counsel can verify it line by line.
DeepSweep maps controls and produces evidence. It does not certify anyone, and this page names no status that belongs to a regulator or an auditor.
The scope, stated first
DeepSweep evidences the AI agent tool layer: what coding and workflow agents can do, what they were authorized to do, and what they actually did. It does not observe your clinical systems, your EHR, or your general ePHI infrastructure. Every claim below is bounded by that scope, and the boundary is written into the mapping itself. A vendor that states its limits up front is easier to take through review, and that is the point.
Three things your review can hold in its hands
The review, free and local
The editor extension reviews the agent environment on the workstation. Analysis runs locally. Source code is not uploaded. For isolated networks, one environment variable removes every network call the extension would make, telemetry included.
The record, signed
The gateway sits in front of your MCP servers, applies allow, deny, or require-human rules to each agent tool call, and writes every decision to a signed, hash-chained ledger that verifies offline. The Breach Notification Rule puts the burden of proof on the regulated party. A record made for that burden is the difference between an answer and a scramble.
The mapping, verifiable
A HIPAA Security Rule control mapping covering the technical and administrative safeguards at the agent layer, with the boundary of what stays your control stated in every row. Each regulatory citation in it was checked against the Cornell LII text of 45 CFR, and each carries its source and the date it was read.
The business associate question, answered the honest way
Whether a vendor is a business associate turns on whether protected health information reaches it. That is an architecture question, and architecture can be inspected: the review runs locally, source is not uploaded, and in the local-first deployment no DeepSweep server receives ePHI. Where a deployment matches that architecture, your counsel may conclude that no business associate relationship arises from the software. Your counsel reaches that conclusion, or declines to. We state the conditions and hand over the inspection points, because a conclusion you can verify beats an assertion you have to trust.
Where people rather than software enter the picture, the analysis changes, and we say so. On-site engagements run under a written scope statement and a BAA prepared for exactly that situation.
On-site readiness, scope first
For teams that want hands-on help, a DeepSweep engineer works inside your environment under a written engagement scope: designated workstations only, no access to clinical systems, and a same-day notification procedure if protected health information is ever encountered. The scope statement exists before the engagement does, which is the order your compliance team would pick.
Start where your engineers are
The review is free, runs in the editor your team already uses, and takes under a second. Install it, run one command, and the first artifact for your security review exists before the meeting ends.