Skip to content
What we do

Digital Platforms

Portals, checkouts and operational dashboards that carry real traffic and real money.

Digital Platforms at a glance

// PRACTICE 03

Digital Platforms

Active Practice
What it is
Portals, checkouts and operational dashboards that carry real traffic and real money.
Platforms
React and TypeScript on the front, your existing back office behind it.
You get
An interface measured against WCAG 2.2 AA, a performance budget agreed before build, and the test suite that holds both.
Typical first step
A design and architecture sprint that ends with a clickable prototype and a fixed price.
Dedicated engineering squadExplore Digital Platforms

The boundary, stated up front.

Brochure sites. If the thing does not carry a transaction or a decision, we are the wrong firm and will say so.

The environments this practice is built for.

What each environment does to a system that was not designed for it.

Regulated & Public ServicesAccess, retention and approval are the design, not a layer added at the end.
E-commercePrices move faster than anyone can maintain by hand.
EducationThe signal that matters arrives early and quietly.

Reference designs, not case studies.

How we would approach three problems that come up often. No client’s numbers appear here, because none of these is a client’s system.

Voice AI · FHIR R4 · on-premise option

A voice agent connected to an EMR

How a phone call becomes a booking or a record in the EMR, with each step holding only the patient data it needs. Designed to run under a Business Associate Agreement.

Four stagesStage 01 of 04 Processing
ACTIVE
Node 01

Call audio

Streaming gateway
SIP or WebSocket, encrypted

Carries audio both ways within the latency budget agreed for the call.

Node 02

Understanding the caller

Speech recognition and a language model
Private network

Works out what the caller needs and strips details the next step does not need.

Node 03

EMR adapter

FHIR and HL7 v2
HTTPS / OAuth 2.0

Checks the booking against the practice’s own scheduling rules and writes it through the EMR’s interface.

Node 04

Audit store

Encrypted, access-controlled
AES-256 at rest

Keeps the record of what the agent did and who looked at it.

When something fails
Hard or unclear calls transfer to a person with the context attached, rather than guessing.
With the on-premise option, audio and transcripts never leave the practice network.
Every read of a patient record is written to an append-only audit log.

What your security review will ask about here.

OWASP ASVS 5.0Level 2 verification on every release
PCI DSS v4.0No cardholder data at rest; SAQ-D aware integrations
WCAG 2.2 AAConformance target on every interface
Read the control register

The first three gates, and what each one leaves you with.

01DiscoveryA written problem statement, in your words, that you own.
02Process mappingCurrent-state map with the manual steps costed in hours and money.
03System designArchitecture decision record, integration inventory, and a fixed scope with a price.