
The patient walks in.
The record is already there.
Carter Med is an offline-first, FHIR-native EHR designed so any participating provider — first across the U.S., then globally — can securely access and contribute to a patient's record, even when the internet is flaky, metered, or gone.
- Offline-first
- Local SQLite + delta sync. The clinic keeps working when the internet doesn't.
- Portable by design
- FHIR R4 / US Core. TEFCA, Carequality, CommonWell from day one.
- HIPAA-grade
- Granular consent, audit-by-default, encryption everywhere — including the cached record on a kiosk.
One record. Wherever the patient is.
Vision
Carter Med is a cloud-connected, offline-first EHR that lets any participating clinician — starting in the U.S. and extending globally — securely access and contribute to a patient's longitudinal record. We don't replace hospital systems; we ride on top of TEFCA, Carequality, CommonWell, and FHIR US Core so the record actually moves.
Non-goals
- — Not a billing/RCM platform. We integrate; we don't compete with Epic Resolute.
- — Not a hospital-replacement EHR for large IDNs. MVP targets ambulatory, community, and rural settings.
- — Not a national HIE. We use the ones that exist.
- — Not a research/AI data lake. Secondary use comes later, with explicit consent.
Own and carry their history. Contribute symptoms, vitals, allergies offline.
Credentialed via NPI / state license / DEA. Document encounters, place orders.
Edge node keeps the clinic running when the WAN drops.
FHIR endpoints to publish results and consume public-health signals.
Four users. One record between them.
Each persona is on the critical path of the marquee journey. Anyone we drop, the journey breaks.
Re-tells her asthma history at every new clinic. Carries paper printouts that get lost.
Carries a QR card. New clinics see her meds and allergies before she sits down.
Spends 20 min/visit faxing for outside records. Can't trust med lists.
Pulls a TEFCA record in 3 seconds, charts offline when the line drops.
Epic is too expensive; current system has no portability.
Deploys an edge node per site, syncs to cloud, integrates one lab feed.
Manual CSV exports, weeks of lag, no consent provenance.
FHIR endpoint with consented, real-time feeds tagged by source.
An unknown patient. A new clinic. No prior link.
This is the make-or-break flow. If this works, the product works.
- 01
Patient walks in
No prior connection to this clinic. They present a Carter Med QR card (or just their name + DOB).
- 02
Identity resolved
Local MPI matches probabilistically on demographics + QR token. If the WAN is up, query QHIN/Carequality for a federated match.
- 03
Record retrieved
FHIR bundles pulled from the patient's home network or cached on the edge node. Imaging on-demand, text-first.
- 04
Encounter documented
Clinician charts offline against US Core resources. Orders, problems, meds, allergies — all queued for sync.
- 05
Synced when possible
Delta sync over CRDT-friendly version vectors. Conflicts surfaced to clinician, never silently overwritten.
- 06
Patient leaves with their record
QR/wallet updated. Next provider — across town or across a border — can repeat the cycle.
Ruthless scope, two pilots, one discipline.
Each MVP item earns its place by being on the critical path of its pilot. US: Carter Med · TEFCA-ready. Burkina: Sankofa FOS · off-grid by construction. Everything else waits behind explicit acceptance criteria.
- Patient PWAAccount, demographics, allergies, meds, history; QR identity card; offline cache.
- Clinician PWAEncounter note, problems, meds, allergies, orders (lab + Rx); offline-first.
- FHIR core serverUS Core resources via Medplum or HAPI FHIR — adopt, don't build.
- Edge clinic nodeSingle-tenant local FHIR replica + sync agent (Docker, runs on a $400 mini-PC).
- MPI + QR identityProbabilistic match (demographics) + patient-held UUID token.
- Provider credentialingNPI lookup + state license + DEA verification at onboarding.
- Consent ledgerPatient-controlled share grants, default deny, audit trail.
- TEFCA query stubOne QHIN integration (treatment purpose) to retrieve external records.
- Patient PWA + QR cardOffline-first PWA · French + local language · QR identity card for lookup at any Sankofa clinic.
- Clinician PWA on rugged tabletsLocked Android tablets · OpenMRS encounter writes via FHIR · works through Starlink blackouts.
- OpenMRS clinical coreAdopt OpenMRS as the record engine · Sankofa OS branded UI overlay.
- AWS Outpost edge nodeLocal OpenMRS replica + telemetry DB + sync agent · survives WAN loss indefinitely.
- DHIS2 sync agentAggregate indicators · notifiable disease push · alignment with BDHI national registries.
- Starlink QoS routingLinux TC rules · Tier 1 clinical / Tier 2 admin / Tier 3 IoT.
- FOS telemetry dashboardSingle-pane-of-glass · Tesla Powerwall · solar · generator ATS · Watergen AWG.
- i-STAT HL7 daemonMLLP listener on port 2575 · injects CHEM8+ / CG4+ / cTnI results directly into OpenMRS.
- TytoCare webhook bridgeJSON telemetry → FHIR · otoscope / stethoscope / tongue depressor capture.
- AI Triage Kiosk (TRG-301/302/303)Patient-facing PWA · LLM ESI scoring · local algorithmic fallback tree on grid loss.
- Imaging (DICOMweb viewer, deferred fetch)
- ePrescribing — Surescripts (US) / national e-Rx (BF)
- Surgical scheduling, anesthesia, oncology pathways
- Multi-clinic regional rollout (BDHI Phase 3 national scaling)
- Biometric (fingerprint) patient identity
- openEHR archetype layer for clinical longevity
- Secondary-use / research data marts
- Bahmni-style admin/billing overlay for revenue-cycle clinics
Defense: imaging, ePrescribing, and full lab interface engines each carry months of integration and compliance work. Including any of them in either MVP guarantees we ship none of them well. We pilot read-only on records and basic charting first, with i-STAT + TytoCare as the diagnostic surface in Guéré.
Three layers, four pillars, on purpose.
The most resilient architecture for BDHI is a hybrid open-source strategy — rather than bending a single software package into something it wasn't designed to be. Three layers carry the data; four engineering pillars carry the facility.
- ▹Battle-tested for multi-facility, low-resource deployments.
- ▹Owns encounters, problems, meds, allergies — the source of truth at the facility.
- ▹Module surface lets us adopt, not bend, the package.
- ▹Aggregate indicators and notifiable-disease push out of the box.
- ▹Aligns Sankofa facility data with BDHI national registries.
- ▹Already the de-facto standard across MoH / WHO programs.
- ▹FHIR contract surface — the long-term portability layer.
- ▹Branded clinician / patient PWA, identity, consent, audit.
- ▹Owns the offline-first sync that ties OpenMRS at the edge to the cloud.
Linux TC rules on the Outpost prioritize clinical traffic (Tier 1) over admin (Tier 2) and IoT telemetry (Tier 3), so an ATS event or a Powerwall heartbeat never crowds out a lab result reaching the chart.
Tesla Powerwall, Watergen AWG, generator ATS, and solar inverters report into a single-pane FOS dashboard. The facility's lights, water, and power become a first-class part of the clinical operating picture.
An HL7 MLLP daemon listens on port 2575 for i-STAT CHEM8+ / CG4+ / cTnI results and TytoCare otoscope / stethoscope / tongue-depressor captures, injecting them directly into the OpenMRS chart and firing real-time provider alerts.
Patient-facing PWA on rugged tablets calls a HIPAA-compliant LLM for ESI scoring. On connectivity loss it transparently flips to a local algorithmic ESI fallback tree — the kiosk never goes dark.
Every pillar maps to a line in the $80k → $120k bridge in Engagement. Nothing in the architecture doc is in scope but unfunded.
An offline-first Facility Operating System for a clinic the grid forgot.
The Burkina Digital Health Initiative (BDHI) brief is unambiguous: 100% operational uptime for clinical care, regardless of municipal grid failures or internet blackouts. We've mapped our build to the four engineering pillars and the hybrid OSS stack already chosen by the Sankofa / BDHI team.
Guéré is the proving ground. The architecture assumes municipal power is unreliable, Starlink is metered and intermittent, and cold-chain logistics for cartridges and meds is non-trivial. The platform's job is to keep the clinic running anyway — and to look identical to staff whether the WAN is up or down.
We're aligned with the Sankofa / BDHI strategic call: no monolithic EHR. Three layers, each chosen for what it already does best in a low-resource, multi-facility African deployment.
- Sovereign experienceSankofa OSFHIR-native microservices · branded UI · SAHEL / YILFU modules · advanced lab trackers · FOS telemetry dashboard.
- Clinical foundationOpenMRSMulti-facility, offline-capable clinical record engine. Charting, orders, problem list, meds, encounters at the facility.
- National intelligenceDHIS2 + ENDOSAggregate indicators, notifiable disease reporting, alignment with Burkina MoH national registries.
- Edge computeAWS OutpostsLocal OpenMRS replica + sync agent + telemetry DB. Survives WAN loss indefinitely. Snowball Edge / mini-rack acceptable fallback.
Linux traffic-control rules on the local Outpost enforce hard QoS over Starlink. Tier 1: clinical (OpenMRS sync, HL7, FHIR). Tier 2: admin sync. Tier 3: IoT telemetry. Clinical payloads never compete with administrative or telemetry traffic during low-bandwidth windows.
Python microservices poll the off-grid hardware every 15 minutes against a unified infrastructure_telemetry SQL schema. Tesla Gateway via local Ethernet API + bearer token, generator ATS via Modbus TCP (holding registers 40001/40002), Watergen GEN-M Pro AWG via REST for humidity, filter saturation, and production volume.
Persistent Python systemd daemon on port 2575 intercepts MLLP/HL7 payloads from the Abbott i-STAT 1 analyzer (CHEM8+, CG4+, cTnI cartridges). A secure webhook bridge translates TytoCare JSON telemetry — otoscope, stethoscope, tongue depressor — into standard FHIR resources and writes directly into OpenMRS with real-time provider alerts.
Patient-facing PWA on locked rugged tablets. Node.js middleware routes symptoms to a HIPAA-compliant LLM to generate Emergency Severity Index (ESI) scores. If Starlink drops, the kiosk transparently fails over to a local algorithmic decision tree so triage never halts. Results push into OpenMRS via the Clinical Decision Support integration (TRG-303).
| Frenchy / Sankofa OS delivers | BDHI provides (or we procure as pass-through) |
|---|---|
| Sankofa OS edge image (Outpost AMI) | AWS Outpost rack power & rack space |
| Telemetry Python services, HL7 daemon, webhook bridges | Tesla Powerwall + solar inverters (already on site) |
| Triage PWA + LLM middleware + offline fallback tree | Generator + ATS controller (Modbus TCP reachable) |
| OpenMRS configuration + DHIS2 sync agent | Watergen GEN-M Pro AWG (REST-reachable on LAN) |
| Rugged clinical tablets (procurement pass-through) | Starlink terminal + local network switch |
| i-STAT MLLP listener + TytoCare webhook config | Abbott i-STAT 1 + TytoPro workstation + refrigerated cartridge storage |
One platform, four facility realities.
Chris's on-the-ground observation in Burkina Faso: hospitals and clinics don't live on a single rung. Sankofa FOS deploys the same software stack across four tiers, with the hardware footprint, sync model, and training load tuned per tier. Guéré sits at Tier 4 — the hardest case, on purpose.
Bobo-Dioulasso class · capital regional center
- Connectivity
- Fiber or commercial broadband · existing IT staff
- Hardware
- Existing server room · full rack space · UPS already deployed
- Software footprint
- Full Sankofa OS · all SGH module groups · multi-tenant OpenMRS + DHIS2 + Bahmni overlay
- Sync model
- Real-time bidirectional · sub-second to other Tier 1 nodes
- Training load
- Train-the-trainer · existing clinical informatics team takes over
- Cost delta
- Phase 2 · ~Guéré baseline + $20–40k (reused hardware, more module config)
Paper-based today · 1950s/60s workflows · 1–3 per country
- Connectivity
- Limited broadband · intermittent Wi-Fi · spotty power
- Hardware
- Add Outpost or Snowball Edge + UPS + Starlink failover
- Software footprint
- Full OpenMRS clinical core · DHIS2 sync · Sankofa OS · selected specialty modules (LIS, OB, pharmacy)
- Sync model
- Hourly bulk + real-time clinical events · degrades gracefully on outage
- Training load
- On-site 2-week embed · paper-to-digital change-management included
- Cost delta
- Phase 2 · roughly Guéré baseline · main cost is digitization + training, not hardware
5–10 staff · no Wi-Fi, no cloud · district health office
- Connectivity
- Starlink + LTE failover · no LAN beyond what we install
- Hardware
- Mini-rack edge node · 4–6 rugged tablets · UPS · Watergen + generator optional
- Software footprint
- OpenMRS clinical core · Triage Kiosk · selected diagnostics (i-STAT or TytoCare) · DHIS2 push
- Sync model
- Daily bulk + real-time triage events · queue-on-disconnect, replay on reconnect
- Training load
- 1-week on-site for clinical lead + 2 nurses · runbooks left behind
- Cost delta
- Phase 2 · −$20k vs Guéré (smaller hardware footprint, fewer telemetry sources)
Fully off-grid · no municipal power, no broadband · the pilot
- Connectivity
- Starlink primary · LTE backup · weeks-long blackouts assumed
- Hardware
- AWS Outpost or Snowball mini-rack · Tesla Powerwall + solar · generator + ATS · Watergen GEN-M Pro · Abbott i-STAT 1 · TytoPro workstation · 4 rugged tablets
- Software footprint
- OpenMRS clinical core · Sankofa OS branded UI · AI Triage Kiosk with grid-free fallback · full FOS telemetry dashboard · DHIS2 + ENDOS push
- Sync model
- Local-first writes · opportunistic bulk sync when Starlink is up · zero data loss across 72h disconnect
- Training load
- 1-week train-the-trainer on-site · 30-day hypercare with 2 engineers on rotation
- Cost delta
- Phase 1 pilot · $120k fixed software + hardware pass-through · 18 weeks (see Engagement)
Bobo sees Guéré drop off the grid in real time.
Phase 2 capability previewed during the Guéré pilot. Chris asked for it in plain terms on the call: 'sitting in the mega hospital in Bobo-Dioulasso, the clinic in Guéré village five hours south goes offline — we can be proactive about the data, the downtime, the syncing and the recovery.' Phase 1 lights up the Guéré node; the fleet view is built and scoped separately as Tier 2/3 sites come online.
- Bobo-Dioulasso GeneralTier 1 · Hauts-BassinsOnlineFiberLast sync: liveUptime: 99.94%Queue14
- Ouagadougou Teaching Hosp.Tier 2 · CentreOnlineBroadbandLast sync: liveUptime: 99.71%Queue8
- Banfora District ClinicTier 3 · CascadesDegradedStarlink (low BW)Last sync: 12 min agoUptime: 98.4%Queue3
- Guéré Village ClinicTier 4 · Sud-OuestOffline · queueing locallyStarlink downLast sync: 4h 22m agoUptime: 94.1% (30d)Queue2
- Tenkodogo OutpatientTier 3 · Centre-EstOnlineLTE failoverLast sync: 2 min agoUptime: 99.2%Queue1
- Kaya Maternal ClinicTier 3 · Centre-NordOnlineStarlinkLast sync: liveUptime: 99.0%Queue5
- Regional supervisor sees the outage before the clinic calls in — and dispatches a tech with parts already loaded.
- Patient records charted offline at Guéré are queued locally and replay automatically on reconnect — zero data loss.
- DHIS2 / ENDOS national feeds keep flowing from healthy nodes even while one site is dark.
- Telemetry alerts (low battery, low water filter, generator fuel) escalate to the on-call before they become outages.
~50 SGH modules. A Tier 4 pilot ships ~15.
The Sankofa Appendix lists ~50 modules across the full SGH ecosystem. For Guéré, ruthless scope: build only what the pillars require, adopt OpenMRS and DHIS2 where they already do the job, defer the rest behind explicit acceptance criteria. Tier 1/2 deployments unlock more of the matrix.
- SGH AmbulatoryAdopt · OpenMRSOpenMRS encounter + visit module · Sankofa OS UI overlay
- SGH Inpatient clinical documentationAdopt · OpenMRSOpenMRS forms + note templates
- SGH Emergency ManagementBuild (Frenchy)Driven by AI Triage Kiosk (ESI scoring + offline fallback)
- SGH Surgical SchedulingPhase 2+Out of Guéré pilot · roadmap for Tier 1/2 facilities
- SGH AnesthesiaPhase 2+Out of pilot · single-OR or no-OR clinics only
- SGH Infection ControlAdopt · DHIS2Notifiable conditions push to DHIS2 / ENDOS
- SGH ObstetricsAdopt · OpenMRSOpenMRS OB module + Sankofa SAHEL maternal tracker
- SGH OncologyPhase 2+Phase 3 — needs imaging + chemo pathway
- SGH Laboratory (LIS)Build (Frenchy)Abbott i-STAT HL7 daemon · MLLP listener on port 2575
- SGH Radiology (RIS)Phase 2+DICOMweb viewer on-demand · Phase 2
- SGH CardiologyBuild (Frenchy)TytoCare stethoscope + cTnI cartridge ingestion
- SGH PharmacyAdopt · OpenMRSOpenMRS pharmacy module + cold-chain telemetry
- SGH Ophthalmology / Orthopedics / Endoscopy / Dental / Nephrology / Transplant / FertilityPhase 2+Not in Guéré pilot scope
- SGH Patient RegistrationAdopt · OpenMRSOpenMRS registration + Sankofa QR identity card
- SGH Outpatient SchedulingAdopt · OpenMRSOpenMRS appointment module
- SGH Bed Management (ADT)Adopt · OpenMRSOpenMRS bedside module · light-weight for Guéré
- SGH Hospital / Professional BillingPhase 2+BDHI grant-funded pilot · billing deferred
- SGH Managed CarePhase 2+Not applicable to public clinic pilot
- SGH Patient Portal / PHRBuild (Frenchy)Offline PWA · QR identity card · French + local language
- SGH KioskBuild (Frenchy)AI Triage Kiosk (TRG-301) · grid-free fallback (TRG-302/303)
- SGH Healthcare CRMPhase 2+Phase 2
- SGH Population HealthAdopt · DHIS2DHIS2 aggregate indicators · regional rollups
- SGH Care Coordination (SDOH)Build (Frenchy)Sankofa YILFU module · household-level context
- SGH Home Health / HospicePhase 2+Phase 3 community health worker module
- SGH Integration EngineBuild (Frenchy)FHIR microservices + HL7 v2 + Modbus/REST telemetry
- SGH Health Information ExchangeAdopt · DHIS2DHIS2 / ENDOS national exchange
- SGH Community Provider PortalAdopt · OpenMRSOpenMRS provider directory
- SGH Payer PortalPhase 2+Not applicable to pilot
- SGH Enterprise DashboardsBuild (Frenchy)Single-pane-of-glass FOS dashboard + facility-network view
- SGH Enterprise Data WarehouseAdopt · DHIS2DHIS2 + Postgres warehouse on Outpost
- SGH Operational ReportingBuild (Frenchy)Node.js /api/telemetry/latest + clinical KPIs
- SGH Visual Data DiscoveryPhase 2+Metabase / Superset overlay · Phase 2
- SGH Core DBMSAdopt · OpenMRSOpenMRS Postgres + unified infrastructure_telemetry schema
- SGH Universal Frontend (GUI)Sankofa OS layerSankofa OS branded React shell · Bahmni-style overlay
- SGH Web-based ClientBuild (Frenchy)Browser PWA · offline-first
- SGH Mobile Physician App (tablet / phone)Build (Frenchy)PWA on rugged Android tablets · locked-down kiosk mode
- SGH Mobile Clinical Staff AppBuild (Frenchy)Same PWA · role-scoped views
Five roles. One walk-through each.
The demo is wired for every user type. Sign up as each role, see their profile, upload a document, check the calendar, browse their views. Mock data, no PHI.
- Verify identity with email + phone OTP (ID.me / Login.gov in prod).
- Generate a portable QR card + Apple/Google Wallet pass.
- Grant first consents (treatment, lab, public-health).
Demographics, allergies, meds, problem list, immunizations — pulled from every connected source and de-duplicated.
Upload prior records (PDFs, CCDAs, lab images). OCR + FHIR-mapping queued; raw file kept for provenance.
Upcoming visits across clinics, lab draws, refills due. Add a visit manually when offline.
- NPI lookup + state license + DEA verification.
- Attach to a facility (or request one).
- Choose specialty templates (FM, peds, urgent care).
Provider profile (NPI, taxonomy, licenses, DEA) — surfaced to patients before they consent.
Drop in encounter notes, attach scanned forms, sign orders. All resources US Core compliant.
Today's panel with offline indicator, CDS alerts inline, room status, and walk-in slots.
- Register clinic NPI + tax ID + sites.
- Provision an edge node per location (one-line installer).
- Invite clinicians; bulk-import via CSV.
Facility profile: addresses, hours, services, accepted insurance, TEFCA participation.
Policies, BAAs, OCR-uploaded credentialing PDFs, lab interface configs.
Site-wide schedule grid across providers and rooms; on-call rotations; downtime windows.
- Register agency with NPI / DUNS + jurisdiction.
- Scope the read: immunizations, ILI, reportable conditions.
- Sign DUA — automatic consent enforcement.
Agency profile + scoped data-use agreement on file, visible to every contributing patient.
Outbreak briefs, DUAs, exported aggregate reports (CSV / FHIR Bundle).
Reporting cadence (daily ILI, weekly imms), DUA renewal dates, scheduled exports.
- Invite-only. Hardware key (WebAuthn) required.
- Role-scoped: support, SRE, compliance, finance.
- Every action audited; break-glass requires justification.
Internal staff profile with role, on-call status, last access, last key rotation.
Tenant contracts, BAAs, SOC2 evidence, post-mortems, key-rotation logs.
On-call schedule, release windows, audit reviews, customer business reviews.
- Start as Patient — generate a QR, upload a prior record, grant consent to "Westside Clinic".
- Switch to Clinician — scan the same patient, chart an encounter offline, sign an e-Rx.
- Switch to Facility — watch the sync queue drain and resolve a merge conflict.
- Switch to Public health — see the immunization count tick up under the consented scope.
- Switch to Super admin — open the audit log; every step above is there.
Offline is the default state.
Built so a clinic with one bar of LTE feels the same as one on fiber — just slower to sync.
┌─────────────────────────────────────────────────────────────────────┐
│ PATIENT DEVICE (PWA) │ CLINICIAN DEVICE (PWA) │
│ ─ IndexedDB / SQLite WASM │ ─ IndexedDB / SQLite WASM │
│ ─ Service worker, queue │ ─ Service worker, queue │
│ ─ Local FHIR cache │ ─ Local FHIR cache + drafts │
└────────────┬──────────────────┴──────────────┬──────────────────────┘
│ │
│ ⇅ Delta sync (CRDT / vector) │ ⇅ USB / Wi-Fi / WAN
▼ ▼
┌────────────────────────────────────────────┐
│ CLINIC EDGE NODE (Docker, $400 mini-PC) │
│ ─ Local FHIR replica (HAPI / Medplum) │
│ ─ Sync agent, conflict log │
│ ─ Cached value sets (SNOMED/LOINC/RxNorm) │
└────────────────────┬───────────────────────┘
│ ⇅ TLS, OAuth2/SMART
▼
┌────────────────────────────────────────────┐
│ CARTER MED CLOUD (US region · HIPAA) │
│ ─ FHIR R4 / US Core (Medplum or HAPI) │
│ ─ MPI · Consent ledger · Audit │
│ ─ Identity (SMART on FHIR, OIDC) │
└──┬───────────────┬──────────────┬──────────┘
▼ ▼ ▼
TEFCA/QHIN Carequality CommonWell
(treatment) (broker) (broker)Conflict-aware delta sync
Per-resource version vectors with CRDT semantics for append-only resources (observations, notes). Conflicts on mutable resources (problem list, meds) are surfaced to a clinician — never silently merged.
Text-first, image-last
Bundles gzip + CBOR over the wire. Large binaries (DICOM, PDFs) are referenced, not embedded; fetched on tap. Value sets pre-cached on the edge node.
Graceful tiers
Tier 1: rich PWA. Tier 2: stripped low-end Android view. Tier 3: SMS/USSD lookup ("CMED LOOKUP <token>"). Tier 4: physical sneakernet via signed USB bundles.
We ride the rails that already exist.
In the US, that's TEFCA. In Burkina, it's OpenMRS + DHIS2 + ENDOS. Building a new national network from scratch is a 10-year, $100M project. We aren't doing that — in either country.
| Standard / network | Role | Build · adopt · integrate |
|---|---|---|
| FHIR R4 + US Core / USCDI | Primary API and data model for the US pilot. Sankofa OS microservices speak FHIR everywhere. | Adopt |
| OpenMRS | Clinical record engine for the Sankofa FOS pilot. Multi-facility, offline-capable, low-resource native. | Adopt (Burkina pilot) |
| DHIS2 | Aggregate national health intelligence layer. Indicators, dashboards, regional rollups. | Adopt (Burkina pilot) |
| Bahmni | UI/UX overlay over OpenMRS for charting + registration where useful. Branded by Sankofa OS. | Adopt (Burkina pilot) |
| ENDOS · Burkina national registry | Notifiable conditions + national identifier sync per BDHI compliance posture. | Integrate (Burkina pilot) |
| WHO SMART Guidelines + ICD-11 | Computable clinical guidelines + global terminology roadmap. | Adopt (Burkina pilot) |
| HL7 v2 (MLLP) | Ingest legacy ADT/ORM/ORU feeds + Abbott i-STAT diagnostics on port 2575. | Adopt |
| DICOMweb | Imaging fetch on-demand; never embedded in encounter bundles. | Adopt (Phase 2) |
| TEFCA / QHIN | Treatment-purpose record retrieval at national scale in the US pilot. | Integrate (US pilot) |
| Carequality / CommonWell | Brokered record location and exchange — most existing US EHRs are on these. | Integrate (US pilot) |
| SMART on FHIR + OAuth2/OIDC | Provider auth, app launch, scoped access. | Adopt |
| ICD-10-CM / SNOMED CT / LOINC / RxNorm | Coded terminologies, offline-cached value sets. | License + cache |
| openEHR | Archetype-based clinical modeling for long-term semantic stability. | Roadmap |
US build vs. adopt
Adopt Medplum as the FHIR backend for the U.S. MVP. TypeScript-native, US-Core conformant, MIT-licensed, SMART on FHIR built in. Fall back to HAPI FHIR (Java) if Medplum's hosted constraints conflict with our edge-node story.
Burkina build vs. adopt
Adopt OpenMRS as the clinical record engine and DHIS2 as the aggregate layer per the BDHI strategy. Sankofa OS sits above as FHIR-native microservices — branded UI, telemetry dashboard, AI triage, i-STAT / TytoCare ingestion. We don't rebuild what the global health community already maintains.
Patient identity without a national ID.
The U.S. legally bans a national patient identifier. Probabilistic matching isn't a fallback — it's the design.
A four-layer identity stack
- 1 · Patient-held token (QR card or wallet pass)
A Carter Med UUID signed by our root. Scannable offline. Works on paper. Re-issuable but the prior token is revoked, not orphaned.
- 2 · Master Patient Index with probabilistic matching
Demographics-based (name, DOB, sex, address history, last-4 SSN where consented). Scoring tuned with held-out evaluation set. Match / possible-match / no-match thresholds reviewed by a human queue.
- 3 · Optional biometric (Phase 2)
Fingerprint or face template stored as a hash, never raw. Opt-in only. Disabled by default in jurisdictions that restrict it.
- 4 · Federated reconciliation
When online, query TEFCA/Carequality/CommonWell matching. Reconcile their UUIDs to our patient. Same mechanism extends internationally — swap the broker, keep the token.
Offline match flow
Clinic edge node holds an MPI shard for the region. New patient: scan QR → exact UUID match against shard. No QR: probabilistic match against cached demographics. Unresolved patients get a provisional ID and reconcile upstream on next sync.
Anti-fraud / anti-duplicate
Every encounter signed by a credentialed provider. Token re-issuance requires either prior provider attestation or a step-up identity proof. Duplicate detection runs nightly server-side and proposes merges, never auto-merges.
Compliance is an architectural property, not a checklist.
HIPAA, by construction
AES-256 at rest, TLS 1.3 in transit, access-controlled per resource, audit log on every read/write. BAAs with every infra vendor. Breach-notification runbook from day one.
Provider trust chain
Onboarding verifies NPI (NPPES), state medical licensure (state boards / FSMB), and DEA registration for prescribers. Trust is rooted in our CA and travels via signed JWTs when the provider operates outside their home org.
Granular, portable consent
Patient-controlled share grants per data category (e.g., behavioral health, reproductive, HIV) and per recipient. Grants are FHIR Consent resources, portable across networks, and evaluable offline.
Cached-record encryption
Records cached on shared/kiosk devices are encrypted with a key derived from the clinician's session + device attestation. Logging out wipes the cache. Stolen kiosk = useless data.
Data residency hooks now, federation later
Single-region U.S. cloud at MVP, but the API surface assumes a region attribute on every patient. Phase 3 deploys EU and other regional instances; data crosses borders only via consented exchange, not replication.
Sovereignty · BDHI owns the data
All third-party APIs (AWS, OpenMRS hosting, LLM gateway, Twilio, observability) are provisioned under BDHI-owned accounts from day one. Frenchy operates as a user with revocable access — never the account owner. Source code lives in BDHI's GitHub org.
Data residency · Contabo Germany or EU sovereign
Off-Outpost workloads (analytics, DHIS2 mirror, backups) hosted in Contabo Germany or Scaleway Paris by default — low-latency to West Africa, GDPR perimeter. Replaceable with an in-country sovereign host once available, without code changes.
Compliance posture beyond local law
SOC 2 controls applied throughout the SDLC. ISO 27001 certification track. HIPAA/FERPA-equivalent controls applied even where Burkina law is silent — we standardize up, not down.
Penetration testing before beta, not after
Two passes: (1) automated scanning at T+12 wks; (2) external manual red-team (ex-offensive-security operators) at T+14 wks. Findings remediated before beta testers in two countries get keys. No 'pen test on launch day' theatre.
Optional non-US contracting entity
If procurement prefers a non-US counterparty for sovereignty reasons, the engagement can be signed with Frenchy Digital France (Paris), Switzerland (Geneva), or Algeria. Same team, same code, same SLAs — different paper.
Contract signed to turnkey in Guéré — 18 weeks.
The Sankofa / BDHI team asked for a timeline mapped from contract signature to a working clinic. Seven milestones, 18 weeks, $120k fixed software billed against each one — including the demo milestone we committed to on the call.
- T+0Contract signed · 20% upfrontSankofa MSA, BDHI DUA, and BAA-equivalents executed. Repo provisioned in client GitHub org. AWS / Contabo accounts linked under BDHI tenancy. $24k upfront invoice ($120k × 20%) triggered on signature.
- T+2 wksModule Matrix lock + connectivity auditSDP reviewed · Module Matrix locked line-by-line (build / adopt / Phase 2) · on-site or remote Starlink + power + hardware inventory audit. This is what makes the $120k defensible — anything that drifts here is a change request, not a scope creep.
- T+8 wksDEMO MILESTONE · 40% billedOpenMRS + DHIS2 standup complete on Contabo (DE) · Burkina implementation guide loaded · offline sync layer passing 72h soak in staging · clinician PWA + Triage Kiosk walkthrough recorded. Matches the 'demo in two months' commitment from the kickoff call. Triggers $24k milestone (cumulative 40%).
- T+12 wksHardware telemetry adapters + sovereignty wiringPowerwall · Modbus · Watergen · i-STAT adapters ingesting into the FOS telemetry dashboard. BDHI-owned cloud tenancy live with revocable key management. Automated pen test #1 executed; remediations merged.
- T+14 wksHardware shipped to Guéré · 70% billedOutpost / mini-rack + rugged tablets + UPS shipped, customs-cleared, racked on-site. LTE/VSAT failover commissioned. Smoke tests pass from local LAN. Hardware is billed pass-through at cost — software milestone triggers $12k (cumulative 70%).
- T+16 wksUAT + manual red-team pen test · train-the-trainerExternal red-team penetration test by ex-hacker firm · all findings closed. One on-site week with clinical + technical leads: triage flow, encounter charting, telemetry dashboard, fallback procedures. Runbooks + on-call escalation finalized.
- T+18 wksGo-live · first consented encounter · final 30% billedLive patient triaged through the kiosk, charted in OpenMRS, diagnostic injected from i-STAT, indicator aggregated into DHIS2. 30-day hypercare begins. Final $36k invoice (cumulative 100%) due on go-live. Source code + runbooks handed to BDHI ops.
Team shape (Sankofa pilot)
If real team size is smaller, we drop the AI-triage offline-fallback ML tuning and defer the second telemetry source. If larger, we pull a Tier 3 second clinic into Phase 1.
What will kill this if we ignore it.
- 01MPI accuracy
Mismatched or merged charts are the worst-case clinical event. Mitigation: conservative thresholds, human-in-the-loop merge queue, audit every match.
- 02TEFCA integration drag
QHIN onboarding is months and lawyer-heavy. Mitigation: start in Phase 0, treat it as a parallel workstream, ship pilot without it if it slips.
- 03Offline conflict resolution UX
CRDTs are easy; clinical merge UX is hard. Mitigation: limit conflicts by making most resources append-only; design merge UI with pilot clinicians.
- 04Provider credentialing fraud
An imposter writing notes is catastrophic. Mitigation: NPI + state board + DEA verification at onboarding, signed encounters, periodic re-verification.
- 05HIPAA breach via kiosk
Shared devices leak data. Mitigation: session-scoped cache encryption, auto-wipe, device attestation, no PHI in browser localStorage.
- 06Vendor lock-in to Medplum
If we adopt Medplum and outgrow it, migration is real work. Mitigation: keep all data in standard FHIR — Medplum's gift is that exit is just an export.
- 07Clinical liability ambiguity
Who's responsible when a federated record is wrong? Mitigation: clear provenance on every resource; display source + last-verified date in the chart.
- 08Team capacity collapse
One developer leaves and the project halts. Mitigation: adopt over build, document ruthlessly, no bespoke infrastructure.
- 09Regulatory drift (state-by-state)
42 CFR Part 2, state reproductive-health laws, minor consent — all vary. Mitigation: consent engine is data-driven, not coded per state.
- 10Sustainability / business model
EHRs that don't get paid die. Mitigation: not a tech problem — surface to founders as a Phase 2 decision (per-provider SaaS vs. grant-funded vs. health-system contract).
What only you can decide.
Each comes with my recommendation. You overrule, you don't ask permission.
Build vs. adopt the FHIR foundation?
Adopt Medplum.
TypeScript, MIT-licensed, US Core conformant, SMART on FHIR built in. A one-dev team cannot also build a FHIR server. HAPI as a fallback if edge-node licensing is awkward.
Centralized vs. federated data architecture?
Centralized U.S. region for MVP — but assume regional federation in the schema.
Every resource carries a region attribute from day one. We don't deploy EU until we need to, but we never have to retrofit the data model.
Connect to TEFCA/Carequality/CommonWell from MVP, or run a closed pilot first?
Closed pilot first; TEFCA in parallel.
Pilot proves the offline + chart loop. TEFCA onboarding runs as a 6-month parallel track. We connect when the paperwork lands, not when we're ready to demo.
MVP user scope — also lab/imaging on day one?
No. Patients + 2–3 pilot clinics only.
Lab and imaging are each a 3-month integration with its own compliance and vendor surface. Ship the chart loop first; integrations come in Phase 3.
Funding / runway and real team size?
Open question for the founders.
This plan assumes ~4 people / 1 FTE dev for ~9 months to pilot. If runway is shorter, drop the edge node and consent UI. If longer, pull lab forward.
Biggest load-bearing assumption?
Pilot clinics will tolerate a thin chart in exchange for portability.
If pilot clinicians demand feature parity with Epic before they'll use us, the MVP scope is wrong and we need a different beachhead (free clinics, NGO sites, refugee health) where portability is itself the killer feature.
"The patient walks in. The record is already there."
If we can't deliver that one sentence in the pilot, nothing else matters.
What's included, and what it costs to start.
Fixed-fee build with milestone-based delivery. All payment due at publish. Edits during the first month of maintenance are included.
We run the full build end-to-end. No external dev team to coordinate with, no committee approvals between milestones. Fastest path to publish.
- Single point of contact
- Direct decisions with founder
- Fixed scope from locked SOW
We build alongside a developer on your team. Adds code reviews, paired sessions, hand-off documentation, and integration overhead.
- Paired reviews & PR cycles
- Shared repo conventions
- Onboarding & handoff docs
We work with your developer and wait on multi-stakeholder sign-off before each milestone advances. Adds meeting load and idle time.
- Stakeholder approval gates
- Extended decision cycles
- Meeting & alignment time
You build it. We act as embedded consultants — reviewing architecture, auditing code, validating FHIR & security work, and unblocking decisions.
- Weekly reviews & QA
- Architecture & security audits
- 12-month retainer
All tiers follow the same milestone structure below, anchored on the $120k Sankofa FOS base scope. Fixed-price tiers include 10% monthly maintenance ($12k–$14k/mo) once published, with first-month edits included. The consulting tier is a 12-month retainer paid monthly.
$24,000 due at signing. Remaining $96,000 paid against milestones, with full balance due on publish to production. After the domain is live, a 10% monthly maintenance fee ($12,000/mo) begins in month 1 and covers hosting oversight, dependency updates, security patches, and platform support. Edit requests submitted during the first month of maintenance are included at no extra cost.
The US pilot anchor is $80k. Guéré adds four line items the FOS email made non-negotiable. Every dollar of the delta maps to a specific capability — nothing aspirational is folded in here.
- US pilot baseline carried forward$80,000Medplum-class hosted core, identity, dashboards, marketing site — unchanged scope
- + Swap Medplum → OpenMRS + DHIS2 standup & module config — Layers 1 & 2+ $15,000Self-hosted record engine · ~20 modules to enable, configure, and test vs. a hosted API
- + Offline-first sync layer (queue + conflict resolution) — prerequisite for Pillar 1 (QoS) & Pillar 4 (AI Triage fallback)+ $12,000Required for intermittent Starlink uplink · 72h disconnect, zero data loss
- + Hardware telemetry adapters (Powerwall · Modbus · Watergen · i-STAT) — Pillars 2 & 3+ $8,000Four device classes · dashboard surface · alerting
- + Data sovereignty wiring (Contabo DE, BDHI-owned tenancy, DPA) — Layer 3 (Sankofa OS)+ $5,000Separate cloud account model · key management · revocable access
- Total fixed software$120,00018-week engagement · milestone-billed
AWS Outposts hardware, Starlink terminals + service, Tesla Powerwalls, Watergen GEN-M Pro, Abbott i-STAT cartridges, on-site networking. BDHI procures direct, or we procure at cost with no markup.
- · 100% uptime SLO + 24/7 on-call posture (~$30–40k / yr retainer)
- · Full ENDOS / WHO SMART / ICD-11 terminology mapping beyond core modules
- · Multi-site rollout beyond Guéré (Tier 1–4 facility network)
- · Burkina regulatory filings beyond the DUA template
Tier 2/3 deployments cost roughly the Guéré baseline ± $20k–40k depending on hardware reuse and module footprint — see Facility Tiers above. Those are Phase 2 expansions, not Phase 1 commitments.
Quick checklist to firm the estimate above into a signed SOW. None of this is a blocker for the Friday follow-up — these are the inputs we'd ingest after.
- ▹Full SDP + System Architecture Plan (to validate edge / cloud split and Outpost spec)
- ▹BDHI National Project Overview (DHIS2 / ENDOS scope, data residency, MoH compliance posture)
- ▹Proof of Concept Outline (success metrics + hardware constraints in Guéré)
- ▹EHR Module Mapping spreadsheet (so we lock build / adopt / defer per row of the matrix above)
- ▹On-site connectivity audit (Starlink bandwidth profile, LTE backup, power reliability) — remote or we send a tech
- ▹BDHI / MoH regulatory contacts for the Data Use Agreement
- ▹Existing Tesla / generator / Watergen / i-STAT / TytoCare inventory + firmware versions
- ▹Preferred contracting entity (Frenchy US / France / Switzerland / Algeria) for sovereignty alignment
If BDHI's procurement posture prefers a non-US counterparty for sovereignty or perception reasons, we can sign through any of our cross-border entities. Same team, same code, same SLAs — different paper.
Every engagement starts with a short discovery loop. The $80,000 figure is our anchor estimate for the scope on this page — final pricing is confirmed only after these three steps are complete and both sides sign the locked SOW. No build work or upfront invoice until then.
- 01Week 0Onboarding callIntro, stakeholder map, working agreements, NDA.
- 02Week 0–1Discovery & design workshopsUser-journey deep-dive per role, EHR/aggregator decisions, brand & UI direction.
- 03End of week 1Scope confirmation & pricing lockFinal SOW, fixed-fee pricing confirmed, signature required before any build work begins.
- FHIR-native data model & US Core R4 resources
- Patient, clinician, facility, public-health & owner dashboards
- Signup & identity flows (NPI, license, DEA, MFA, WebAuthn)
- Aggregator connectors (Metriport, Health Gorilla, Particle, Zus)
- SMART on FHIR & CDS Hooks demo surfaces
- Consent engine, tamper-evident audit log, Inferno conformance views
- Labs (HL7 v2 → FHIR), e-Prescribing, X12 eligibility/prior-auth
- Marketing site, SEO, sitemap, responsive design system
- Kickoff & upfrontSigned SOW (after scope lock)$24,00020%
- Design system & dashboard prototypesWeek 2–3$24,00020%
- Core platform & dashboardsWeek 4–7$24,00020%
- Integration & trust layerWeek 8–11$24,00020%
- Publish to productionLaunch day$24,00020%
20% ($24k) upfront after scope is confirmed and SOW is signed. Balance billed by milestone and fully due at publish.
A 3% processing fee is added to all invoices and paid by the client (card, ACH, wire, or platform fees).
All API, hosting, and SaaS subscriptions (e.g., Metriport, Health Gorilla, AWS, Twilio, Stripe) are provisioned under client-owned accounts for easy handover and direct billing.
10% of total ($12k/mo) starting month 1 once live. Edits during month 1 included; later change requests scoped separately.
Month 1 of maintenance covers unlimited small edits to the shipped scope so the platform settles cleanly into production. From month 2 onward, ongoing maintenance keeps the lights on; anything that changes what the product does is scoped and billed separately as a change request.
- Bug fixes on shipped, in-scope features
- Copy, label, and image swaps on existing pages
- Minor style tweaks (spacing, color, typography within the design system)
- Dependency updates, security patches, hosting oversight
- Monitoring, backups, and platform support
- Up to 2 hours/month of ad-hoc edits to existing flows
- +New pages, dashboards, roles, or user types
- +New integrations or third-party connectors
- +Schema / data model changes and migrations
- +Redesigns, rebrands, or new design components
- +Compliance or certification work outside the original SOW
- +Any edit estimated above 2 hours of build time
Email or shared tracker. Each request gets a written estimate (scope, hours, fixed price, ETA) within 3 business days.
Fixed-price per request, or $175/hr blended rate for ad-hoc work. Pre-paid blocks (10h / 25h / 50h) discounted 5–15%.
Work begins after written approval of the estimate. Urgent (<48h) requests carry a 1.5× rush multiplier when capacity allows.
Unused maintenance hours do not roll over. Pausing or cancelling maintenance is allowed with 30 days' notice; source code and infrastructure handover terms follow the Frenchy Digital Terms of Service.
Milestone payments tied to code that ships.
Every payment unlocks against a concrete, verifiable deliverable in the repo — not a slide deck. You see the commits, click the preview, and approve before the next milestone starts.
- M0120%Kickoff & repo bootstrapSigned SOW · Week 0
- GitHub repo provisioned, CI/CD pipeline live (preview + prod)
- Design tokens, Tailwind theme, shadcn/ui baseline committed
- TanStack Start scaffold with __root, routing, and auth shell
- Environment + secrets management wired (Lovable Cloud / Supabase)
$16,000 - M0220%Design system & dashboard prototypesWeek 2–3
- Reusable Section, Panel, Stat, Tag primitives shipped
- Five role shells (patient, clinician, facility, public-health, admin) navigable
- Marketing site published to preview domain with SEO meta + sitemap
- Component library documented in repo (Storybook-style index page)
$16,000 - M0320%Core platform & dashboardsWeek 4–7
- FHIR-native data model + US Core R4 resources implemented
- All persona dashboards built (≈120 routes) with seeded demo data
- Server functions: createServerFn for reads, RLS-aware mutations
- Auth flows: signup wizards, NPI/license verification stubs, MFA
$16,000 - M0420%Integration & trust layerWeek 8–11
- Aggregator connectors (Metriport / Health Gorilla / Particle) wired
- SMART on FHIR launch + CDS Hooks demo surface
- Consent engine, tamper-evident audit log, Inferno conformance views
- X12 eligibility/prior-auth + HL7 v2 → FHIR lab pipeline
$16,000 - M0520%Publish to productionLaunch day
- Custom domain live with TLS, CDN, and edge functions deployed
- Lighthouse / a11y / SEO audits ≥95 on all marketing pages
- Runbook, on-call docs, and rollback procedure handed off
- Source code transferred to client-owned GitHub org
$16,000
Most work happens in Linear + Loom + GitHub PRs. One live demo per week (30 min), one written status update every Friday. No standing daily meetings.
You see every commit. Preview URLs auto-deploy per branch so you can click through changes before they hit main. Your team can review or merge directly if they want.
Repo lives in your GitHub org from week zero. All third-party services (Supabase, Stripe, Twilio, aggregators) are provisioned under your accounts — we just have access.
BAA-ready hosting, RLS on every table, audit log on every mutation, secrets in Cloudflare/Supabase vaults — not in code. We document it as we ship it.
Full payment at publish. Month 1 of maintenance is included — unlimited small edits while the platform settles. From month 2: $8k/mo for hosting oversight, patches, and ad-hoc edits.
More of how we build for healthcare and association clients at Frenchy Digital.
How we work across the healthcare industry — telemedicine, patient platforms, provider tooling.
End-to-end member platform for a national dental association: auth, dues, content gating, and admin.
Full redesign and rebuild of the Student National Dental Association's public site.
Built by Frenchy Digital — Hollywood & Paris.
A 49-person mobile & web app studio founded in 2019. 4.8★ on Clutch, 50+ apps and 100+ web platforms shipped across healthcare, wellness, education, and professional associations.
1517 S Bentley Ave, Unit 204
Los Angeles, CA 90025
European hub: Paris, France · North Africa delivery
49 designers & engineers across iOS, Android, React Native, web, and AI integration.
HIPAA-compliant work for CGSA, ClinicalEdify, National Dental Association, IglowMed, plus Y Combinator startups and Fortune 500 brands.

Founded Frenchy Digital in 2019. Leads engagement strategy, technical architecture, and stakeholder alignment. Direct point of contact for the $80k tier.

Co-founder. Runs UX research, design systems, and delivery quality across LA and Paris. Oversees milestone reviews and acceptance.


Your dedicated PM keeps sprints on rails — agendas, recaps, design reviews, QA passes, and the weekly status note. One PM, named at kickoff.
On the $80k tier you work directly with Chris and a dedicated PM. Yasmine signs off on contracts, billing, and delivery. Engineers and designers are pulled from the 49-person bench as the milestone requires — no offshore handoffs.
A live call rhythm by phase, plus daily async. Every call has an agenda 24h in advance and a written recap within 24h after.
- 3× / weekWeek 0–1Onboarding & scope lockTwo 60-min discovery workshops + one 30-min stakeholder sync. Daily async on Slack/Loom. Ends with signed SOW.
- 2× / weekWeek 2–3Design system & prototypesMonday kickoff (45 min) + Thursday design review (60 min). Figma walkthroughs recorded. Async feedback in under 24h.
- 2× / week + daily asyncWeek 4–7Core build & dashboardsMonday sprint planning (30 min) + Friday demo (45 min). Daily Loom standups from the PM. Milestone sign-off at end of week 7.
- 2× / weekWeek 8–11Integration & trust layerMid-week integration review + Friday demo. Security & FHIR conformance walkthroughs at week 10 and 11.
- Daily during launch weekWeek 12Publish & handoffPre-launch checklist call, publish day war-room, post-launch retro. First-month maintenance edits start immediately after.
- 01Discovery loop completes (week 0–1). Scope, deliverables, and milestones locked in writing.
- 02SOW + Master Services Agreement issued, referencing the Frenchy Digital Terms & Conditions (effective Jan 1, 2024, last updated Dec 17, 2025).
- 03Both sides sign digitally. The 20% upfront invoice ($16,000) is issued only after signature.
- 04Per the Terms, payment by any method (wire, ACH, card) constitutes full acceptance of the Agreement. No oral modifications — changes go through written amendment signed by an authorized officer.
Governing law: California. Mandatory arbitration on an individual basis applies to disputes (per §2 and §15 of the Terms).
Per §3.3 of the Frenchy Digital Terms, on full payment you receive a limited, non-exclusive, non-transferable, revocable license to the Developed IP for your internal business purposes as scoped in the SOW.
- →At each milestone: code is pushed to a private GitHub repo you have read access to from day one.
- →At publish (final 20% paid): repo ownership transferred to your GitHub org, environment variables and credentials handed over, deployment runbook delivered.
- →What's included in the license: all custom application code, design files, FHIR mappings, and documentation produced under the SOW.
- →What stays with Frenchy: internal frameworks, reusable libraries, methodologies, and the Frenchy Brand Assets (§4).
Source code is not released before the final invoice clears. Reverse engineering of Frenchy's internal tooling is prohibited under §3.2. Full Terms: frenchydigital.com/terms-and-conditions.