Skip to content

CRM and data infrastructure for regulated industries

A white-label CRM and an on-premises data lake for organisations that answer to regulators.

Relay is a CRM you run under your own brand, for your own teams or for your whole network. Basin is a data lake with its own analytics that runs inside your network, so nothing leaves and nothing new goes on your sub-processor list.

Hospitals, insurers, banks and public bodies run them separately or together.

SOC 2 Type II audited. HIPAA and GDPR compliant. Runs in your cloud account or your datacentre. Never ours.

Two products

Relay creates the record. Basin analyses all of it.

Relay is where your customer data is created: contacts, deals, tickets, consent. Basin is where all of your data is analysed, from Relay and from everything else you already run, your EHR or core banking system included. Each stands on its own. Together they take you from first contact to board report without a third-party analytics vendor in the middle.

Relay

White-label CRM platform

A CRM platform sold or run under your own brand, either for your own teams or for a network of agencies, franchisees, members or the customers of your own software.

Your brand, top to bottom
Logo, colours, typography, custom domain, email sending domain, login page, and iOS and Android apps published under your name and icon. No "powered by" anywhere.
Workflows, approvals and SLA timers
A workflow builder with triggers, conditions and actions, scheduled jobs, approval flows, email sequences and SLA timers on tickets.
SSO, SCIM and field-level permissions
SAML 2.0 and OIDC single sign-on, SCIM provisioning, enforced MFA, role-based and field-level permissions, and a separate encryption key for every tenant.
Every read and every write logged
An immutable audit log that records reads as well as writes, exportable to Splunk, Sentinel or any SIEM.

Included in the platform subscription: £250 a month covers Relay and Basin, with a £500 one-off setup fee.

Relay in detail

Basin

On-premises data lake with first-party analytics

A data lake and analytics platform that runs entirely inside your network: your datacentre, your private cloud or an air-gapped environment. No telemetry, no phone-home, and licence keys that work offline.

Zero sub-processors
Basin runs on infrastructure you control, so nothing leaves and nothing new goes on your data-processing agreements.
Open formats you can walk away with
Parquet on any S3-compatible store (MinIO, Ceph, NetApp StorageGRID, Dell ECS, Azure Blob, AWS S3) in Apache Iceberg tables, readable by any tool.
More than 60 connectors
Postgres, SQL Server, Oracle, SAP, Salesforce, Dynamics 365, Epic and Cerner over HL7 v2 and FHIR, Kafka, SFTP drops and log-based change data capture.
Governance your auditor can check
Automatic PHI and PII tagging, column-level encryption with keys you hold, row and column policies, Safe Harbor de-identification, and erasure workflows that leave an evidence record.

One node included in the subscription, £100 a month per additional node. No per-user, per-seat or per-query charges.

Basin in detail

Deployment

Where your data lives

Both products run where your regulator, your DPO and your security team need them to: your own AWS, Azure or GCP account, or your own datacentre. We don't offer a hosted version of either, which keeps every byte inside your existing compliance boundary. Relay in your cloud account next to Basin in your datacentre is a pairing we've built many times.

OptionYour cloud account AWS, Azure or GCPOn-premises or air-gapped Your datacentre or a disconnected network
Relay Yes. Deployed into your own AWS, Azure or GCP account with Terraform. Yes. In your own datacentre, typically alongside Basin.
Basin Yes. Into your own VPC via Helm chart or Terraform. Yes. Kubernetes via Helm, or a single-node VM installer for small sites. An air-gapped install bundle is available.
Sub-processorsNone. Your cloud provider is already in your agreements.None.
Who runs itTao's managed operations team, working inside your account through scoped, logged access you can revoke, or your own team once we've trained them. Under our managed service the SLA is 99.95% monthly uptime, RPO 15 minutes and RTO 4 hours, with encrypted backups kept in your account and a restore test every quarter.Tao on site or over your VPN or bastion with P1 response within 15 minutes, or your own team.

The full sub-processor list and supported regions are on the security page.

Compliance

Audited every year, and built to be audited.

SOC 2 Type II, HIPAA and GDPR are what most customers ask about first. Beneath them sit controls you can check for yourself.

Read-level audit logs

Relay records every read as well as every write. Basin logs every query with the user, the tables and columns touched and the row count returned. Relay's log is immutable, Basin's is tamper-evident, and both export to Splunk, Sentinel or any SIEM.

Keys you hold

AES-256 at rest and TLS 1.2 or higher in transit, with customer-managed keys in AWS KMS, Azure Key Vault or your own HSM. Relay uses a separate key per tenant; Basin encrypts sensitive columns individually.

Erasure with an evidence record

Right-to-erasure workflows propagate deletions across every connected table and produce an evidence record your auditor can read. Subject access requests have built-in tooling too, and the DPA comes with SCCs and the UK Addendum.

The SOC 2 report, penetration test summary, security policies, BAA and DPA are available under NDA.

Security overview

Results

Three deployments, in numbers

What changed after go-live for a pharmacy network, a broker network and a hospital group.

Basin, own datacentre

Same-day

compliance reporting, down from three weeks

A US specialty pharmacy network deployed Basin in its own datacentre and connected 14 source systems, including its pharmacy management system and Epic feeds. It replaced a cloud analytics vendor it could no longer justify under its BAA review.

Relay, white-label

9,000 users

across 1,200 member agencies

A UK insurance broker network runs Relay, branded as its own product, for its member agencies. Migration from a twelve-year-old on-premises system took five months, including a parallel run.

Basin, private cloud

40 systems

covered by every erasure request

A European private hospital group runs Basin in its Frankfurt private cloud. Erasure requests now propagate across all 40 connected systems with an evidence record per request, replacing a manual process that took a data team two days each.

Most customers don't allow logo use, so these are anonymised.

Services

How we work

Small teams with engineers on every call, a fixed price for discovery, a demo every week and no offshore hand-offs. Most engagements run 8 to 24 weeks.

Services in detail
01

Implementation

A fixed-price two-week discovery, then delivery with a named engineering lead and a demo every week until go-live.

02

Migration

From legacy CRMs, warehouses and cloud analytics vendors, reconciled with row counts and checksums, with a parallel run before cut-over.

03

Managed operations

24/7 managed operations for Relay and Basin inside your cloud account or datacentre, with P1 response within 15 minutes.

04

Compliance support

Evidence packs for your own auditors, DPIA drafting, BAA and DPA templates, and control mapping for SOC 2, HIPAA, GDPR and ISO 27001.

Tell us where your data has to live.

Send us the constraints: the regulator, the residency requirement and the systems you need to connect. An engineer will reply within one working day with a straight answer on fit, timeline and cost.