Anjo.ai is building an AI-enabled platform for managing severe and life-threatening allergies — analysing physiological signals from wearables to deliver remote monitoring, early detection, and personalised allergy insights. Protected health information moves through every layer of that stack, so the compliance program had to be engineered in, not retrofitted before a launch date.
Anjo.ai develops an AI-enabled platform for people living with severe and life-threatening allergies. The system continuously monitors physiological data from smartwatches and similar wearables, and applies a patent-pending model to detect the early signs of an allergic reaction before severe symptoms present.
Around that core, the platform surfaces daily risk factors, alerts users when they are separated from their epinephrine auto-injector, and logs allergic events for clinical review. It is designed to be useful across the whole arc of care — diagnosis, therapy, and everyday life — including in clinical settings such as Oral Food Challenge testing. The company is headquartered in New York with an office in Tel Aviv, and works with partners including Mount Sinai, Samsung Health, Intrommune, and the Allergy Fund.
Why this is a hard compliance problem: a connected-device company does not have one system holding PHI. It has a wearable, a mobile application, a cloud backend, an inference pipeline, and a clinician-facing review surface — plus every partner and subprocessor in between. Each is a place where protected health information is created, transmitted, or stored, and each has to be inventoried, risk-assessed, and evidenced.
Anjo.ai came to Iron Fort with the problem every pre-commercial digital health company eventually hits: the compliance obligations arrive before the compliance headcount does.
Iron Fort deployed as the system of record for the whole program, rather than as a checklist run at the end of a development cycle.
Iron Fort connected to Anjo.ai's cloud infrastructure and inventoried where protected health information is created, transmitted, and stored across the device-to-clinician pipeline. That inventory feeds a continuous risk analysis that updates as infrastructure changes — satisfying the HIPAA Security Rule's risk analysis requirement without an annual scramble to rebuild the picture from scratch.
The platform's HIPAA policy library gave the team an approved administrative, physical, and technical safeguard set to work from instead of a blank page, with the AI policy analyser flagging missing required elements against the Security Rule's implementation specifications.
Every Business Associate Agreement — clinical partners, cloud providers, and downstream subcontractors — is tracked centrally through its lifecycle, with alerts ahead of renewal or expiry, and the subcontractor chain mapped rather than assumed.
Control tests, policy approvals, risk decisions, and workforce training completions land in the evidence vault with tamper-evident timestamps. When a partner sends a security questionnaire or asks for an audit response package, the answer is assembled from evidence that already exists.
Because the Security Rule safeguards and the SOC 2 Trust Services Criteria share a substantial control base, both frameworks are maintained against a single evidence stream — so commercial diligence does not start a second compliance project from zero.
A note on scope: Iron Fort is a compliance management platform, not an application database. Anjo.ai's patient data stays in Anjo.ai's systems — Iron Fort analyses infrastructure, policies, and controls, and Iron Fort signs a BAA with every customer.
The program Anjo.ai runs today is documented, continuously maintained, and produced from the same platform their engineers already work in.
One maintained picture of every system, integration, and subprocessor touching protected health information across the device-to-clinician pipeline.
Partner security reviews are answered from a maintained evidence set, so a data-sharing conversation is not gated on weeks of document collection.
Every agreement in the partner and subprocessor chain tracked centrally, with renewal alerts before an expiry becomes an exposure.
HIPAA and SOC 2 maintained on a shared control set, so enterprise diligence does not restart the program at launch.
Running a compliance program worth writing about? We partner with a small number of customers each year to document the work in depth — and you keep everything we produce.