Use cases · by sector and by job

Who R2 is designed for

Two ways in: the regulator you answer to, or the team doing the work. Both end in the same place — models your people want, inside the apps they already use, with a record you can hand to an examiner.

By industry

HEALTHCARE AND LIFE SCIENCES

PHI that cannot go to a public model

PHI cannot enter a public LLM without a signed Business Associate Agreement, and consumer AI tiers do not sign one. Clinical summaries, prior authorisation letters, claims review and patient correspondence run through R2 instead, inside Outlook and Word, with PHI rules applied before anything leaves and the interaction logged for the compliance file.

Regulators: HIPAA, HITECH, state privacy law. TAM: 822,600 covered entities plus roughly 1M business associates.

FINANCIAL SERVICES

Supervision does not stop at the vendor boundary

SEC, FINRA and NYDFS Part 500 hold the firm accountable for third-party AI. Research summaries, client correspondence, KYC files and model documentation stay inside the perimeter, with role-based access, books-and-records retention and an audit trail an examiner can read.

Regulators: SEC, FINRA, NYDFS 500, GLBA. TAM: 123,000 registered US regulated firms.

GOVERNMENT

Where public-cloud AI is simply not allowed

FedRAMP and CJIS rule out public-cloud AI for citizen records, case files and law-enforcement data. R2 deploys into AWS GovCloud, Azure Government or an air-gapped environment, with open-weight models running on your own hardware.

Frameworks: FedRAMP, CJIS, state and federal records law.

DEFENSE AND ITS SUPPLY CHAIN

Controlled data that cannot leave the perimeter

ITAR restricts where technical data may travel, and DFARS 7012 binds 221,000+ defense suppliers to NIST 800-171 self-assessment. Engineering, proposal and contract work runs against models inside your own environment.

Frameworks: ITAR, DFARS 7012, NIST 800-171.

LEGAL AND PROFESSIONAL SERVICES

Privilege survives the draft

Contract review, discovery summaries, memo drafting and client correspondence on privileged material, without it entering a vendor's retention window or training set. Matter-level access rules, and a log that shows which model saw what.

Obligations: privilege, client confidentiality, conflicts, professional conduct rules.

MANUFACTURING AND ENGINEERING

Trade secrets and source code

Specifications, designs, supplier terms and source code are the assets. R2 keeps them out of a vendor's training set and out of a vendor's storage, while the team still gets the model that writes the test plan.

R2 holds Microsoft Manufacturing AI certified-software status.

INSURANCE, BANKING AND PUBLIC SECTOR

High volume, high sensitivity

Claims handling, underwriting notes, complaints correspondence and citizen-facing communications, where the volume argues for AI and the data class argues against the public tools.

Obligations vary by jurisdiction and line of business. Deployment mode is chosen accordingly.

By team

Inside each of those organisations, the same four people have the same four problems.

Security and IT

Shadow AI is already in the building. You need a governed path people prefer to the unapproved one, and evidence that it is being used.

Compliance and legal

You need to answer the AI question in an audit from a record rather than from memory, and to show the controls that produced it.

Operations and finance

You are paying for four AI subscriptions across three departments and cannot see who has access to what.

The people doing the work

You want the model that is actually good at this task, in the app you are already in, without asking anyone.

337 enterprise customers and 220,000 users across these sectors.

Bring us the workflow your regulator cares about

We will map the right applications, controls, models and deployment boundary around it.