Investor brief · Equestro Labs

Fund the compliance layer. Unlock the product we already built.

ProofCare is a Personal Medical ID: Epic MyChart, Apple Watch, and Oura in an AES-GCM vault, with SHA-256 integrity proofs on a permissioned ledger—never diagnoses on-chain. The next dollar should not go to another feature. It should go to the counsel, BAAs, and insurance that let us take off.

Product is ahead of paperVault, SMART on FHIR, wearables, grants, and chaincode exist. Cloud insights and PEPM are coded—and gated off on purpose.
Compliance is the bottleneckNo Firebase BAA, no Kaleido operator agreement, no cyber E&O, no employer BA template. Those unlocks are binary.
Honest takeoffHIPAA-aligned, not certified. Not a medical device. We raise to finish the legal stack—not to pretend it is finished.

The thesis

Patients already own a Watch and a MyChart login. They do not own a portable identity that can prove a file was not swapped and that a share was revoked. Portals trap the chart in one system. Public-chain health apps overclaim. ProofCare is the patient-owned ID with a proof layer those tools were never designed to give.

Own

Clinical + wearable data in one offline vault. The record survives a job change and a new city.

Prove

Permissioned Fabric anchors hashes and consent events. The ledger never sees the chart.

Share

Clinician-ready PDF and time-limited grants the patient can expire. Clinics do not need a new EHR.

Where this raise goes

We are not asking you to fund a slide-deck architecture. We are asking you to fund the stack that turns a working beta into a shippable health product.

Counsel

Healthcare privacy + entity memo

Outside counsel on consumer PHR vs business associate, FTC Health Breach Notification Rule, wearable aggregates, and residual risk on our HIPAA-aligned architecture. Required before we lean on the live Privacy Policy and Terms for launch.

Vendor paper

BAAs and the ledger operator agreement

Google Cloud / Firebase (Auth, Firestore, FCM, Gemini—no training on customer data). Kaleido operator agreement before CHAIN_MODE=kaleido. Crash tools only with a BAA. Stripe stays billing-only, no PHI in metadata.

Risk transfer

Cyber / tech E&O

Health-data endorsement, incident response retainers, and a named privacy officer. Our IRP already says we will not launch without this.

What it unlocks

The gates we already wrote

Cloud insights stay off until CLOUD_INSIGHTS_BAA=true. Employer PEPM stays off until BA templates exist. Production Fabric stays off until the operator agreement is signed. Capital flips those switches.

What you are not buying

  • A claim that we are HIPAA certified. We are HIPAA-aligned until the paper is signed.
  • A public blockchain, a token, or diagnoses on-chain. That is a hard no.
  • A remote clinician portal that is not live. We share PDFs and grants today.
  • Vanity user counts. The site is live; the raise is to do this correctly, not loudly.

If that honesty is a problem, we are the wrong company. If it is the reason you write checks in digital health, request a conversation.

Or write natalie@equestrolabs.com with subject “ProofCare investor intro.”