Guardian AI Services
Frequently asked questions
What emotive AI is, how zero-trace architecture works, and who can hear your conversations.
What is emotive AI?
Emotive AI is artificial intelligence built to support a person through an emotional moment rather than to extract data from it. Where most AI is optimized for engagement, retention, and data capture, emotive AI is optimized for the person's recovery. Guardian AI Services designs emotive AI for vulnerable populations: hospice patients, people recovering after hospital discharge, clinicians and first responders carrying occupational stress, and families navigating the child welfare system. The measure of success is not how long someone stays engaged. It is whether they are able to get back up and rebuild.
What is zero-trace architecture?
Zero-trace architecture means the conversation is never written down, never uploaded, and never recoverable after the fact, because it was never stored in the first place. Guardian's zero-trace units, GRACE and Lily, run entirely on local edge hardware. They are air-gapped by design and never activated on a network. There is no account, no transcript, and no server holding a copy. Lily's memory is erased on demand. This is an architectural guarantee you can inspect rather than a privacy policy you are asked to trust.
If a Guardian unit never connects to the internet, how does my care team get updates?
Not every Guardian unit is offline, and that is deliberate. Guardian is built in two families because the two jobs are different. GRACE and Lily are zero-trace: nothing leaves the room, ever. PAL and FAM are reporting units: PAL sends patient-approved updates to the care portal, and FAM reports progress into county systems. In both reporting units, what travels is the outcome, never the conversation. Your care team learns that you reported dizziness on day three. They do not receive a recording of you saying it.
What does patient-centered privacy mean in practice?
Patient-centered privacy means the person speaking decides what leaves the room, and the system is built so that nothing else can. In practice this means three things. First, the conversation itself is never stored or transmitted on any Guardian unit. Second, on reporting units, updates are patient-approved before they are sent. Third, the device holds no account, no login, and no history that could later be subpoenaed, breached, or sold. Privacy is enforced by the architecture rather than by policy, which means it does not depend on the company continuing to behave well.
Why build on local edge hardware instead of the cloud?
Because a promise about data you are still holding is not the same as never holding it. Cloud AI requires that your words travel to a server, be processed there, and be retained at least briefly, which creates a record that can be breached, subpoenaed, sold, or repurposed later. Running on local edge hardware removes that record entirely. It also means the unit works in a hospice room with no reliable Wi-Fi, in a rural home, and during an outage. The constraint that makes Guardian private is the same one that makes it dependable.
Guardian builds offline voice companions for the moments that should not be tracked.
Reserve a unitEnterprise & clinical