Powered by your policies. Nothing else.
Not the internet. Not another organisation's documents. Not guesswork. Here is exactly how CareStreamAI works, and why you can trust it with your compliance-critical information.
Answers you can trust
Every answer cites the policy it came from.
Staff ask in the hub, in their own language, and get the answer with a reference to the exact policy and section. Nothing is invented, and everything is traceable.
Every answer ends with the policy and section it was drawn from, so anyone reading it can go and check.
When nothing in your library covers the question, CareStreamAI tells the member of staff that, rather than filling the gap from general knowledge.
A carer can ask in their first language and read the answer in it. The policy behind the answer does not change.
Queries and system actions are written to an append-only audit trail you can show an inspector.
- Carry out and record post-fall observations.
- Complete the accident and incident form.
- Tell the next of kin if any injury is suspected.
How the AI works
Explained for every audience.
The same architecture, described three ways, because the person on shift, the quality lead and the board each need a different level of detail.
For everyone
Think of CareStreamAI as a colleague who has read every policy in your library, and nothing else. When a member of your team asks a question, CareStreamAI searches your policy library, finds the most relevant sections, and uses them, and only them, to write the answer. It does not search the internet. It does not use general knowledge. It does not guess.
For operations and quality leads
CareStreamAI uses Retrieval Augmented Generation (RAG), the gold standard for AI systems that need to answer from a specific, trusted document set. Every query searches your private policy index first. The AI receives only the retrieved content as its input, and is explicitly instructed not to use anything outside it.
For boards and legal leads
CareStreamAI's architecture eliminates the primary governance risk of AI in professional settings: confident but incorrect answers. Every response is bounded by your approved documents and logged in an append-only audit trail. The system cannot contradict your policies. It cannot extend beyond them.
What we promise
Your data, seven commitments.
These are the terms we hold ourselves to, and the same terms set out in the Data Processing Agreement every subscriber receives.
Your policy library, query history, training records and staff data are logically isolated, so no other subscriber can access them in any form.
Your documents and data are never used to train AI models, by us or by the providers we use. This is set out in our Data Processing Agreement.
All data is encrypted at rest (AES-256) and in transit (TLS), using industry-standard encryption.
Your documents, records and logs are stored in the UK/EEA. AI processing is carried out by vetted providers under agreements that forbid training on your data.
CareStreamAI operates in full compliance with UK GDPR. A Data Processing Agreement is provided to all subscribers.
Every query and every system action is recorded in an append-only, tamper-evident audit log.
Query logs are retained in line with your configured retention policy, then securely deleted.
Common questions
Security questions, answered.
Will the AI make things up?
No. CareStreamAI is explicitly designed to prevent this. If no relevant policy is found, it says so, it does not generate content from general knowledge.
Can other organisations see our policies?
No. Your policy library is completely isolated. No other subscriber can access it in any form.
Is our data used to train AI models?
No. Your data is never used to train AI models, by us or by the AI providers we use, and this is set out in our Data Processing Agreement.
Where is our data stored and processed?
Your documents, records and logs are stored in the UK/EEA. AI processing is carried out by vetted providers under data processing agreements that prohibit using your data to train their models. We are happy to share the detail in our DPA.
What if our policy has an error in it?
CareStreamAI will accurately reflect what your policy says. This surfaces the need to keep policies accurate, which is the right incentive in a compliance setting.
What happens when we update a policy?
The old version is immediately retired from the retrieval system. All subsequent queries return answers based on the new version. The old version is retained in your audit archive.
The documents
Everything in writing.
The commitments above are not marketing copy. Each one is carried by one of these documents, all of them current and all of them public.
What personal data we hold, why we hold it, and the rights you and your staff have over it.
Read the policy →Data Processing AgreementThe processor terms, sub-processor list, transfer safeguards and retention rules, in full.
Read the DPA →Terms of ServiceThe terms your subscription runs on, including uptime, support and how either side ends it.
Read the terms →Cookie PolicyThe cookies this site sets, what each one does, and how to change what you allow.
Read the policy →How our AI worksThe retrieval pipeline in detail, stage by stage, including what the model is and is not given.
Read the explainer →Client Services AgreementThe full commercial agreement for organisations that need it for procurement.
Read the agreement →Have more questions about security or data?
Send us the question, or bring your information governance lead to a demo and ask us live. We answer in plain English and we put it in writing.




