NexLotus · The Aether platform
Hospital systems that hold no patient record.
Self-hosted wayfinding, operational notices and equipment custody. The fields a privacy office would have to protect are not redacted here, or access-controlled, or switched off. There is nowhere to put them.
0
patient or reader identity columns across both Prisma schemas. That is
one grep a reviewer can run themselves, and the build fails
if it ever returns a line.
Most health software asks how it will protect the data. This one asks why it has any.
Every field below is absent from the schema. Not disabled, not redacted, not access-controlled: there is nowhere in the database to put it. That is a property a hospital's privacy office can verify by reading the schema, rather than a promise it has to take on trust.
- −Patient namenot in schema
- −Health card numbernot in schema
- −Date of birthnot in schema
- −Symptoms, acuity, or any clinical fieldnot in schema
- −Reader accounts, tokens, or a lasting device idremoved 5 Sep 2026
- −Third-party requests, CDNs, analyticsstrict same-origin CSP
What a visitor is, to this system
An anonymous browser, and less of one than it used to be. Until 5
September 2026 the reader app minted a permanent id into
localStorage and the server stored it on three tables. It
has been removed rather than renamed. Acknowledging an announcement now
stores an announcement id and a timestamp and nothing else, and the one
id a browser still holds lives in sessionStorage, dies with
the tab, and is only ever seen by the server as a hash under a salt that
is regenerated daily and never written down.
The resulting count is an operational reach estimate, not proof anybody read or understood anything. Every screen that shows it says so.
It cannot call for help. There is no urgent button, no nurse call, no check-in, and no alert of any kind. Every reader is told so, unmissably, on the consent screen before anything else loads.
And what it does hold, said in the same breath
It holds staff personal information. Staff accounts, and the equipment custody history recording who took which device and when. That is personal information under PIPEDA, and it is electronic monitoring of employees under Ontario's Employment Standards Act, which carries a written-policy duty for the deploying hospital. Aether ships a policy template for it rather than leaving the hospital to discover the obligation.
The patient claim is strong because it is narrow. Widening it into "no personal information of any kind" is the version that gets the whole document dismissed by the first reviewer who opens the staff table, so it is not the version printed here. The product's own disclosure document says the same thing in the same order, and if this page ever drifts from it, that document is the one that is correct.
Pillar one · Patient Experiences
01 / Open
No account. No password. No session.
One waiting-room poster carries the same code for the life of the deployment, and the link carries it, so nothing is typed. Scanning opens the app. There is nothing to sign in to, because readers have no identity in this system at all. Before anything else loads, one screen states the limit of what the software can do.
02 / Route
Directions the person who never registered can follow.
The floor plan and turn-by-turn directions read with no token. The people most likely to be lost in a hospital are the ones who never checked in anywhere, so wayfinding is deliberately available before and without any registration. A step-free route is a checkbox on the same screen, not a separate mode.
03 / Read
What the building is telling everyone in it.
Operational notices and announcements, in the reader's language, with the scope printed on the notice itself. The clock says how long this device has been counting, and says plainly that it is not a place in a queue. A screen that cannot know something is not allowed to imply it.
04 / Report
One thing a reader can send back. Only one.
From a room or lift's card on the map, and from nowhere else, a reader can report that it is not working, blocked, or wrongly signed. Three of the four choices carry no text at all. There is no reply path, no severity, and no reader identity attached to it.
The same pillar, from the desk.
Staff raise an operational notice, message the building, schedule an announcement, or read what visitors have reported about a place. A notice can also take that place out of the router, which is the reason the two halves are one product rather than two.
Notices are keys, not text
A closed set of kinds travels to the device as an identifier, and each device renders it from its own shipped dictionary. Nobody machine translates an operational instruction while people are reading it.
Translated once, at send time
A staff-written announcement is rendered into every reader language when it is sent, so what each person saw is fixed and auditable afterwards. The English source is always kept verbatim beside it.
A notice can close a place
Publishing an AREA_CLOSED notice against a place removes it
from routing at the same moment. One action does both, so the banner and
the directions underneath it cannot disagree.
Thirteen languages, and an honest label on eleven of them.
The registry is ordered by census prevalence in Ontario, with right-to-left layout for Arabic, Urdu and Persian driven by the document direction rather than by a mirrored stylesheet. English and French are the human-verified source. Every other language carries a machine translation of the interface behind a disclaimer the reader meets before the content, which is the first screenshot here.
Fonts for every script are self-hosted and subsetted to exactly the characters the translations use. About 240 KB covers all thirteen where the unsubsetted faces would be roughly ten megabytes, and a test fails the build if the translations drift away from the committed font bytes.
Ordered by StatsCan 2021 census prevalence in Ontario. English and French are human-verified; the other eleven carry a machine translation of the interface behind a disclaimer the reader meets before the content.
Pillar two · Asset Tracking
Feature-complete · pre-pilot01 / Create
An administrator adds a machine and prints a label.
The label carries a QR and six characters a person can read aloud down a corridor. Anyone who scans it sees what the thing is and whether it is in service. No account, no sign-in wall, and nothing at all about where it is or who has it, because that label is stuck to the outside of a machine in a public corridor.
02 / Pick up
Take it. Nothing blocks a nurse.
Signed-in staff take equipment and name the place. Something somebody else is holding can be taken from them and the log records both halves. Even equipment a technician has taken out of service can be taken, with the reason shown loudly first. A block is a block somebody works around by not using the app, and then nothing is recorded at all.
03 / Put back
The record is never a present-tense claim.
It says last left at Tower 4, Clean Utility, three days ago. It never says currently in Tower 4. The system did not watch the machine after somebody put it down, and saying otherwise is the lie every tracking system tells first. The words real-time, live location and current location are refused by a test.
04 / Service
Counts, never a percentage.
When a schedule falls due a technician scans it, records the service, writes what they found, and grades whether it should be replaced. An administrator watches three counts and a feed of every movement. A percentage is a grade, and a grade points every incentive in the building at moving the number rather than servicing the machine.
The floor got a way to say something, and the equipment record learned to ask the map a question.
Two things arrived in Asset Tracking at the end of August 2026. One is a single room the whole hospital writes into, which absorbed an inbox only technicians could open. The other is what the equipment record can answer once it is allowed to ask the wayfinding graph how far away something is.
One room, and the whole hospital is in it
Nurses, doctors, porters and environmental services write into it; technicians and administrators read it and answer. A message can name machines inside the sentence, and each machine named is answered on its own, so servicing one of two pumps closes the message for that pump and leaves the other open. Nothing here pages, texts or phones anybody, and the composer says so in a line under the box.
Nearest first, on the map's own graph
One pass out from where a nurse is standing gives the walking distance to every node in the building, so the fleet can be ordered by how far away it is for the cost of one traversal rather than one per machine. A corridor an operational notice has closed is closed to this answer too. It still ranks where a machine was last left, never where it is.
J. Okafor · Clinical staff · 03:14
Both volumetric pumps in 4B stopped mid-infusion on nights. 7F3K9M did it twice and BQ2H4T once. Left both by the clean utility door.
◆ 1 of 2 still open
7F3K9M resolved by R. Vasquez
Illustrative, not data from any deployment.
Six sentences a tracking system says, and what this one says instead.
None of these is a competitor's fault in particular. They are the defaults, and each one is comfortable to build and comfortable to demo. The right-hand column is not an opinion about them: every line names something in this repository that makes the left-hand version impossible to ship by accident.
What a tracking system usually says
What this record says
"Currently in Tower 4."
"Last left at Tower 4, Clean Utility, three days ago." Nothing watched the machine after somebody put it down. real-time · live location · current location · all three refused by a test
"94% compliant."
"6 need service. 2 have never been serviced." A percentage is a grade, and a grade points every incentive in the building at moving the number rather than servicing the machine. counts only, and the printable device history has no field to put a ratio in
"This item is checked out to someone else."
"Take it." The log records the return and the new custody as one transaction. A block is a block somebody works around by not opening the app, and then nothing is recorded at all. nothing blocks a nurse, including equipment a technician has taken out of service
"Entry deleted."
Both lines stay. The wrong row keeps a rule through it and the correction sits underneath naming the row it supersedes, because the pair is the correction. the event log is append-only for everybody, an administrator included
"No issues recorded, so this one is fine."
A blank is not a verdict. No replacement grade means nobody has looked, which is a different fact from somebody looking and saying it is fine. A report that cannot tell them apart tells an administrator an unexamined fleet is healthy. null is never rendered as the lowest grade
"Sign in to see what this is."
Scan it and read it. What the thing is and whether it is in service, with no account and no sign-in wall, and nothing at all about where it is or who has it. that label is stuck to the outside of a machine in a public corridor
A record that says more than it knows is worse than the sheet of paper it replaced, because nobody trusts the paper by accident.
Four rules, and every one of them cost a feature that would have demoed well. They are written here because a hospital evaluating this will be shown the same four screens by everybody, and the difference is not in the screens.
01
Say what was seen, not what is true now.
Every custody line carries a place and a date and is written in the past tense. The present tense is the lie every tracking system tells first, and it is the one that gets a nurse walking to an empty cupboard at three in the morning.
02
Never stand between a person and the machine.
Equipment somebody else is holding can be taken from them. Equipment a technician has taken out of service can be taken too, with the reason shown loudly first. The alternative is not safety, it is a nurse who stops opening the app and a record that goes quiet.
03
Count. Do not grade.
There is no compliance percentage anywhere in this product, on a screen or in a printed pack, and the shape of the data has no field to put one in. A count has no denominator to argue about and no target to hit.
04
A mistake is struck out, never removed.
Nobody edits the event log, including whoever installed the system. The wrong entry stays with a rule through it and the reason beneath, so the record of the correction is as durable as the record of the error.
The number you type without thinking should reach the thing that cannot leave the machine.
One Express process opens three listeners. Two are served through the
tunnel, one for each pillar, because a session cookie is scoped to a host
and signing in to publish an announcement must not sign you in to the
equipment record. The third is bound to 127.0.0.1, so the
kernel refuses a connection arriving from the LAN or the tunnel before
Express and before any middleware. The bind address is not configurable.
Why the split exists
A staff account is not a low-value credential here: it can put arbitrary text in front of every device in the building. Issuing one should take physical presence at the hosting device on top of an admin role, a second factor, and a full session, rather than instead of them.
Pinned by a test, not by a policy
Every staff-administration path returns 404 on the public
app to a real admin holding a full session, and a listener bound to
loopback accepts a connection that the same app bound wide would take
from the LAN. Both are regression tests, not documentation.
And then it got a password anyway
The host console required no sign-in for a year, on the argument that whoever is at the hosting machine is already the administrator. That is true of a laptop on a desk and false of a box sited in someone else's building. Since September 2026 it authenticates like everything else. Reversing a decision in public costs less than answering "no" to the question every vendor questionnaire asks about administrative interfaces.
Where the administrator went
Asset Tracking's whole administrator surface moved onto the host console in August 2026. Adding equipment, printing labels, the equipment board, the fleet report and equipment access are unreachable through the tunnel by design, not by configuration. The corridor keeps the four verbs and nothing else.
Encryption at rest
AES-256-GCM at the application layer, in a versioned, key-identified envelope bound to its field by AAD. Retired keys still decrypt after a rotation, and old ciphertext is re-sealed lazily on its next write.
Key custody, enforced
A serving deployment refuses to boot with the key supplied inline, and refuses with no escape hatch if the key file sits inside the database's own directory. Whoever copied the database would otherwise copy the key with it.
Second factor
RFC-6238 TOTP, mandatory for every staff role by default. There is deliberately no account lockout, because an emergency department must never be locked out, so per-account backoff plus a mandatory second factor is the compensating control.
Or the hospital's own tenant
Sign in with Microsoft on both staff doors. The application is registered in the hospital's Entra tenant, not ours, so their conditional access applies natively and they can revoke it without asking. There is no multi-tenant credential to lose, because there is no multi-tenant application.
Service notes, and a design that was removed
One sealed document per machine: AES-256-GCM under the application keyring, bound to that machine by AAD, so notes cannot be moved between records. Technicians write, everybody reads, an administrator reads every note and can save none. Until September 2026 this was encrypted in the browser instead. That version never once worked, the panel that set the passphrase was gated on an authority no account held, and it was removed rather than quietly repaired.
A backup that stops is a failure, not a silence
The nightly dump seals the database and the audit archive to a public key whose private half is in escrow and never on the machine, and writes a local copy and an off-site one. It runs as a scheduled task rather than inside the application, because a backup living in the process it protects stops running exactly when that process is unhealthy. An aged backup is reported on the console banner and as a metric.
Permanent addresses
Every deployment gets its own hostnames, provisioned in one command, with the poster and label PDFs generated from them. A demo tunnel's URL changes on every restart, and a new hostname is a new origin: the printed poster on the wall stops working and the reach counts quietly become fiction.
Postgres, and no way around it
SQLite is what makes the build run with no external setup, and it is refused outright in a serving deployment along with a demo tunnel and any staff account without a second factor. Each refusal names its own remedy rather than failing with a stack trace.
An appliance, checked rather than asserted
NexLotus supplies and configures the hardware; the hospital sites it and powers it. A read-only script verifies the baseline before the box leaves, and it exits non-zero on a failure so it can gate a build. An unknown is never a pass: a check that could not run is reported as one that could not run.
A daily heartbeat
An alert cannot fire when the thing that is wrong is the machine. A dead disk, a pulled cable, or a box switched off to free a socket all produce exactly nothing, and nothing is indistinguishable from health. So the appliance reports in every day, and it is the absence of that report that raises the alarm.
Twenty-one screens, in a real browser, against the bundles a deployment actually serves.
The four apps had run an automated accessibility pass on every commit for months, under a test renderer that does not lay out or paint. Roughly the most consequential third of what those rules know had therefore never run against this product, colour contrast above all. The first run in real Chrome found six failures and every one of them was a contrast failure. A later pass found seventeen more that had made an earlier "zero violations" untrue. All of them are closed, each with a gate behind it, and the figures below are from the harness run of 7 September 2026 rather than from the prose written in August.
Screens audited
Every screen in all four apps, driven over the DevTools Protocol against the built bundles in the serving configuration. None were unreachable. The twenty-first is the recall workbench, which did not exist in August.
A and AA violations
WCAG 2.0 and 2.1, Level A and AA, across all twenty-one screens. Fifteen further results are recorded as needing a human decision rather than counted as passes.
Focus stops walked
Tab order driven with real key events. No stop lost its focus indicator, none trapped the keyboard, none was unreachable, and 191 interactive targets were measured for hit size.
Lighthouse accessibility
On all four apps. Reader performance moved from 72 to 98 in the same pass, once responses were compressed.
Self-assessed, not independently audited. These are the project's own figures from its own harness, reproducible from the repository. No audit with assistive-technology users has been done, and a formal one is a pre-deployment gate rather than something this page is claiming to have passed. Ontario's binding standard here is WCAG 2.0 Level AA under the AODA Integrated Accessibility Standards Regulation. The rules above were run at 2.1 AA as well, which is one version further than the law requires and is a choice, not a compliance claim.
What we are not claiming.
A vendor's limitations are the part a hospital's reviewer will find anyway. Publishing them is cheaper than being caught omitting them, and each of these is enforced somewhere in the system rather than promised here.
It is not an emergency notification system.
LOCKDOWN, EVACUATE and SHELTER were
deleted from the notice kinds, not disabled behind a flag. The one
free-text field is refused at the API boundary if it contains emergency
wording, with a message naming the overhead page instead. This is not a
substitute for a building's own emergency systems or a person walking the
room.
The reader app polls. There is no push.
Both feeds reach a device up to one poll interval (10 seconds) late, and reach a device with no network, a flat battery or a locked screen not at all. A device whose polls keep failing backs off to at most 80 seconds, because when a tunnel drops every device in the building fails the same request at the same moment. That is precisely why the emergency kinds were removed: a channel that cannot promise arrival must not carry a message whose value depends on arriving.
The accessibility result is self-assessed.
Twenty-one screens clear WCAG 2.0 and 2.1 Level A and AA with zero violations in a real browser. It is still the project auditing itself. Fifteen results need a human decision, no audit with assistive-technology users has been done, and a screen-reader script exists but has been walked by the author rather than by somebody who uses one daily. The written audit in the repository is dated August and still prints August's counts, which is drift in the vendor's own paperwork and is being said here rather than left for a reviewer to notice.
Only English and French are human-verified.
Every other registered language carries a machine translation of the interface behind an explicit auto-translated disclaimer, with the English source always retained verbatim. Operational notices are not translated at runtime at all. They are closed-set keys rendered from each device's own shipped dictionary, so the one message that must arrive never depends on a translation provider being reachable.
Asset Tracking is built, and it has never run in a hospital.
The module is feature-complete: four verbs, three signed-in roles, an append-only event log, sealed service notes, a recall workbench fed by Health Canada's daily feed, a printable device history, one room the whole hospital writes into, and an administrator surface that a network cannot reach. What it has not had is a corridor, a night shift, and a technician who did not help design it. Every figure it produces in a demonstration is seeded data, and it is labelled as such on the screen.
It holds staff personal information.
Staff accounts, and the equipment custody history recording who took which device and when. Personal information under PIPEDA, and electronic monitoring under Ontario's Employment Standards Act, which obliges the deploying hospital to have a written policy. Until 5 September 2026 the product's own disclosure document said "no personal information of any kind" and this site repeated it. Both were wrong, and the narrow claim is the one worth making.
There is an operations assistant, and it ships switched off.
A small language model fine-tuned for this application, running on the appliance itself and reachable only from loopback. It is not a chatbot: there is no free-text prompt path into it anywhere in the code, only four named tasks with fixed templates pinned byte-for-byte by a test. A site that wants it must switch it on, every capability degrades to its pre-AI form without it, and its own register records that the weights sit outside version control and outside the backup.
There are no deployments yet.
NexLotus is pre-pilot and seeking a first hospital partner. There are no customers to reference, no case studies, and no results to report, so this site does not contain any. What it contains instead is the design reasoning and the project's own audit output, which is the thing actually available for you to evaluate today.
The questions that come up first.
Answered at the length they deserve rather than the length that sells. If any of these contradicts the disclosure document in the repository, that document is correct and this page is the defect.
Where does the data live?
On a machine in your building. NexLotus supplies and configures the appliance and manages it remotely over an outbound tunnel; you site it and power it. There is no shared database, no tenant boundary to trust, and no copy of your data on our infrastructure. One deployment serves one facility, and the facility identifier is a partition key rather than an isolation boundary, which is stated plainly because the distinction matters to whoever asks this question next.
The nightly backup is sealed to a public key whose private half is held in escrow and is never on the appliance, and it writes an off-site copy. A backup that has stopped is reported as a failure, not as silence.
Does it hold any personal information at all?
Yes, and only about staff. Staff accounts and the equipment custody history, which records who took which device and when. That is personal information under PIPEDA and electronic monitoring under Ontario's Employment Standards Act, so the deploying hospital needs a written policy for it. A template ships with the product.
About patients and readers it holds nothing: no name, no health card number, no date of birth, no symptoms, no free text from any reader. That is a property of the schema rather than a setting, and CI fails the build if an identity-bearing column reappears.
Do our staff need another password?
Not if you would rather they did not. Both staff doors offer Sign in with Microsoft, and the application is registered in your Entra tenant rather than ours. Your conditional access applies natively, because it is your application, and you can revoke it at any time without asking us. The cost of that choice is that it is a per-site setup step rather than a one-click consent, which is the right trade for a system that can mint staff accounts.
Local accounts remain available and carry a mandatory second factor by default. There is deliberately no account lockout, because an emergency department must never be locked out of anything.
What happens when it goes down?
Nothing changes for the department, and that is the strongest thing about the risk profile rather than a way of dodging the question. There is no clinical workflow to interrupt: the map stops being available, the notice board stops updating, and printed signage and the desk carry on doing what they were already doing.
The published availability objective is 99%, not 99.9%, because there is no on-call rotation to staff the difference and a number that wins a meeting is worth less than one that can be met.
Can it tell staff a patient needs help?
No, and no configuration makes it one. There is no urgent button, no nurse call, no check-in and no alert of any kind. A reader's device is a receiver. The one thing a reader can send is a report that a room or a lift is broken, blocked or wrongly signed, with no reply path and no identity attached.
Every reader is told this once, unmissably, on the consent screen before anything else in the app loads. The emergency notice kinds were deleted from the type rather than hidden behind a flag, because a channel that polls and cannot promise arrival must not carry a message whose value depends on arriving.
Is there AI in it?
There is an operations assistant, and it ships switched off. It is a small model fine-tuned for this application on synthetic examples, running on the appliance itself and reachable only from loopback, so nothing leaves the building to answer anything.
It is not a chatbot. There is no free-text prompt path into it anywhere in the codebase: every call is one of four named tasks with a fixed template, pinned byte-for-byte by a test. Nothing it does is on the path of any clinical decision, and every capability it touches degrades to its pre-AI form when it is off, which is how it arrives.
Is the accessibility conformance independently audited?
No. Twenty-one screens clear WCAG 2.0 and 2.1 Level A and AA with zero violations in a real browser, measured against the bundles a deployment actually serves, and 117 focus stops were walked with real key events. All of that is the project auditing itself and is reproducible from the repository.
No audit with assistive-technology users has been done, fifteen results need a human decision rather than being counted as passes, and a screen-reader script exists but has been walked by its author. A formal audit is a pre-deployment gate, not something this page has passed.
Who else is running it?
Nobody. NexLotus is pre-pilot and looking for a first hospital partner in Ontario. There are no customers to reference, no case studies and no results, which is why there are none on this site.
What there is instead is the reasoning, the product's own audit output, and a written list of what it does not do. Being the first site carries real risk and it should be priced and scoped as such, in writing, before anybody signs anything.
The detail, one page at a time.
Patient Wayfinding
The map graph, the router, the anonymous read path, and why sensitive destinations are unreachable for every reader on this branch.
Operational Communication
The closed set of notice kinds, send-time translation, the scheduler's idempotency guard, and what happens to a place when a notice closes it.
Asset Tracking
Four verbs, three signed-in roles, the append-only event log, the correction that never deletes, the two answers one label gives, and the room the floor writes into.
Bring the reviewer who will ask the hardest question.
A briefing walks through the schema, the three-listener split, the audit trail, the accessibility output and every limitation above, with your privacy office or security reviewer in the room rather than afterwards.