Saga Health · Trust & Data

The architecture
is the answer.

Compare what works — across programs and populations — without anyone, including us, being able to misuse the data it's built on. Here's how that's enforced, not promised.

01 · Tagged

Every element of data is tagged.

Nothing on the platform is just "data." Every element carries its own tags: what it is, whose it is, which regime governs it — general health, behavioral health, or 42 CFR Part 2 — which operator's tenant it lives in, and what consent covers it. The tags travel with the data everywhere it goes.

02 · Metered & enforced

Use is metered and enforced against the tags.

The tags aren't documentation — they're enforcement. Every use is metered and checked against them before it happens; access the tags don't permit doesn't occur. Every disclosure is accounted for, and any redisclosure is marked. The record of who touched what, and for what purpose, is kept — not taken on trust.

03 · Brokered

An independent third party holds the keys.

Separation of duties is the whole point. An independent trust broker — a separate party, not Saga — governs how every element of data is used. Saga does not get to grade its own homework: the enforcement sits with someone whose only job is to enforce it. That's what makes the guarantees above credible instead of self-reported.

Straight answers

The hard questions have architectural answers.

Many operators on one platform — how is the data kept separate?

Tagging plus tenant isolation. Each operator's data lives in its own tenant, tagged to it, and the enforcement layer keeps it there. One platform, no mixing.

How do you compare programs — and program elements — without exposing anyone's records?

We compare on tagged, governed data, not raw records. The comparison runs on what the governance permits, down to the individual program element, without PHI leaving the boundary it's tagged to.

What about behavioral-health and substance-use data?

It's handled to its regime. Behavioral-health and 42 CFR Part 2 data carry purpose-scoped consent; Part 2 protections are marked and every disclosure is accounted for. The stricter rule wins, automatically.

If participants are ever rewarded for their part, how is that kept legitimate?

Any such model rests on use that is metered and accounted for — not taken on trust. The same governance that meters every other use meters that one too.

Get started

Bring us your hardest governance question.

Agencies, operators, and partners with a data-governance bar to clear — bring it. We would rather answer it in the architecture than in a promise.

Request a demo