Healthcare

Patient data
never leaves your cloud.

Bunnyshell orchestrates your preview and test environments — PHI, databases, and application data stay inside your own AWS, GCP, or Azure account, encrypted with your keys, at all times.

We'll answer your security questionnaire

Clinician reviewing patient information on a mobile device
env-pr-intake-form
Your cloud account only
0 PHI records here
Works with
HelmHelm
DockerDocker
TerraformTerraform
K8sK8s
EKSEKS
AKSAKS
GKEGKE
Enterprise-grade security
SOC 2SOC 2
ISO 27001ISO 27001
ISO 9001ISO 9001

Trusted by over 30,000 engineers from

Manual tests on Argo CD PRs now take me seconds. When you review dozens of PRs a day, that's a game-changer.
Michael Crenshaw
Michael CrenshawCore Team Member
Automatically created a Bunnyshell environment based on PRs, speeding up the entire task implementation process.
Jacob Tobiasz
Jacob TobiaszCore Team Member
The automation and scalability that Bunnyshell provides complements the DigitalOcean platform, empowering developers to build amazing products.
Aaron Geller
Aaron GellerGP & Channel
Yieldstreettiket.comJustworksT-Pro
Clinician reviewing patient information on a mobile device

The constraint that can't be negotiated

PHI never leaves your infrastructure. That's not a policy — it's the architecture.

A shared staging server, a copied production database, a test environment nobody remembers is public — these are the ordinary ways PHI ends up somewhere it shouldn't. Bunnyshell was built so that path doesn't exist in the first place.

How Bunnyshell works — architecture diagram

$ cat how-it-works.md

How Bunnyshell works

01

Connect your repo

Link your GitHub, GitLab, or Bitbucket repository. Define your patient portal, EHR integration, or clinical workflow service using Docker Compose, Helm, or Terraform.

GitHubGitHub
GitLabGitLab
BitbucketBitbucket
DockerDocker
HelmHelm
K8sK8s
02

Open a pull request

Bunnyshell auto-provisions an isolated, full-stack environment for every PR, seeded with synthetic or anonymized data — never production PHI.

PR #142env-142.preview.bunnyshell.dev• Running
PR #143env-143.preview.bunnyshell.dev• Running
PR #144env-144.preview.bunnyshell.dev• Running
03

Merge and move on

Tests pass, code is reviewed, PR merges. The environment auto-destroys — logged and auditable, no manual cleanup.

End-to-end tests passed
Code review approved
Merged — environment destroyed

Built to keep PHI where it belongs.
Compliant by default.

Bunnyshell meets the security and compliance bar healthcare engineering teams require. Patient data, application data, and databases never leave your own cloud account — we orchestrate, you own everything.

SOC 2 Type II
ISO 27001
ISO 9001

BYOC Architecture

Bring Your Own Cloud. Bunnyshell never stores PHI, source code, or application data. Everything runs inside your own Kubernetes cluster.

Namespace Isolation

Every environment runs in a dedicated Kubernetes namespace — no shared tenancy between products, teams, or patient populations.

Secrets Encryption

All environment variables and database credentials are encrypted at rest and in transit. No hard-coded credentials, ever.

IP Whitelisting

Restrict preview environment access to approved IP ranges — keep test environments with real-shaped clinical data off the open internet.

Full Audit Logging

Every deploy, sleep, and teardown is logged — who did what, when, and where. Exportable for SOC 2 and internal compliance review.

SSO Integration

SAML and OIDC support for your identity provider. Your existing access policies extend to Bunnyshell automatically.

01

Zero-PHI Control Plane

Bunnyshell's control plane only ever sees metadata — deploy status, resource usage, namespace health. Patient records, clinical data, and application databases stay inside your own VPC, encrypted with your own keys, for the lifetime of every environment.

🩺env-pr-intake-formLIVE PREVIEW
EnvironmentPHI location
env-pr-intake-formYour cloud account only
env-stagingYour cloud account only
env-qa-portalYour cloud account only
PHI in Bunnyshell's infrastructure0 records
02

Know Before Your Patients Do

A patient portal or scheduling service degrading at 2am shouldn’t be discovered by a patient calling in. Health checks, custom alert rules, and an incident timeline that correlates deploys with metric changes mean your team sees the problem — and often the cause — before it becomes a support ticket.

  • Health checksHTTP, TCP, and exec probes for every component — automatic restart on failure
  • Resource monitoringCPU, memory, disk, and network metrics per pod, per component, per environment
  • Custom alert rulesset thresholds for latency and error rates — notified via Slack, PagerDuty, or webhook
  • Incident timelinecorrelate deployments with metric changes — see exactly which deploy caused the spike
patient-portal — productionHealthy
Uptime (30d)99.98%
P95 latency212ms
Alert ruleError rate > 2% for 5 min → PagerDuty
Last incidentNone in 47 days

Also Built In

From patient portals to clinical workflows.

Environment Drift Management

Get notified the moment a compliance-relevant setting quietly diverges between staging and production, with a built-in diff editor.

Multi-Cloud, Your Own Account

Connect your existing EKS, GKE, or AKS cluster — or a private, air-gapped cluster — and Bunnyshell provisions environments inside it.

Auto-Sleep & Auto-Destroy

Preview environments shut down automatically when idle, so cost stays proportional to actual testing activity.

Trusted by engineering teams
shipping fast

Book a Demo. Talk to our team about your compliance requirements.

Get a walkthrough tailored to your stack, your regulatory obligations, and your existing CI/CD.

Frequently asked
questions

Can’t find what you’re looking for? Talk to our team

No. Bunnyshell uses a BYOC (Bring Your Own Cloud) model. PHI, databases, and application data stay in your cloud account at all times. Bunnyshell orchestrates deployments via a lightweight agent — we never store or access your data.