Open Protocol

Squyr

Bilateral Cryptographic Data Exchange

A clean-room-native primitive for pharma audience data partnerships.

What Is Squyr

Bilateral cryptographic exchange
for healthcare data partnerships.

Squyr's purpose-built protocol for matching two parties' data without either party's underlying records ever leaving its environment. Built on standard cryptographic primitives: Ed25519 signatures, HKDF key derivation, AES-256-GCM encryption, SHA-256 hash matching. The architecture is what makes it distinctive — bilateral key contribution, hash-chain auditability, no central credential pool, no vendor in the data path.

The result: a brand and Squyr can compute the overlap between their patient panels in under 90 seconds, with cryptographic proof on both sides that no PII transited, and an immutable audit trail of every operation.

Clean Rooms
Brand data enters a vendor environment.
Vendor controls the keys, the audit, and the data path. Per-match fees. Vendor-side risk.
Identity Vendors
Both parties' data flows into a central match graph.
Vendor sees both sides. Per-match fees compound. Vendor middleware in every transaction.
Squyr
Neither party's data leaves its environment.
Both parties contribute key material. Match runs bilaterally. No middleware fees. No central credential pool. Hash-chain integrity verified on both sides.

How Squyr Works

Bilateral protocol.
No data leaves its environment.

01
Brand
Local Hashing
Brand hashes their first-party patient identifiers locally using Squyr's specification (SHA-256, lowercase, normalized). No PHI leaves the brand environment.
02
Squyr Protocol
Bilateral Exchange
Both parties exchange hashed identifiers via Squyr's signed transport. Ed25519 signatures on both sides. AES-256-GCM encryption in transit. HKDF key derivation per session.
03
Squyr
Hash Match + Overlap Computation
Squyr verifies brand signatures, computes overlap against Squyr's hashed cohort, signs the matched ID references, and returns them. Squyr's underlying data never leaves Squyr's environment.
04
Both Parties
Audited Results
Both parties receive the matched cohort size and identifier references for their own use. Hash-chain integrity verified on both sides. Audit trail of every operation immutably logged.

Who Benefits

A better data ecosystem
for every stakeholder

Pharma Brands
Match your first-party patient panel against Squyr's 15.3M+ condition-confirmed inquiries without your PHI ever leaving your environment. Compute overlap, attribute campaigns, and build look-alike audiences from real intent — with cryptographic proof of compliance on every operation.
DSPs & Data Partners
Run bilateral matching against Squyr's data without a clean room, without a central vendor, and without per-match middleware fees. Hash format compatibility with existing DSP onboarding workflows. Audit-ready for HIPAA BAA flow-down and state privacy frameworks.
Healthcare Data Companies
Integrate Squyr as the matching primitive in your own data workflows. The protocol is published. The cryptographic primitives are standard. The architecture is purpose-built for healthcare's compliance posture — HIPAA, MHMDA, CMIA, CPA, BAA-compatible by default.

Bilateral Architecture

Brand brings their data. Squyr brings ours.
We find the overlap. Nobody loses control.

Squyr runs the bilateral exchange under the hood — the brand's PHI never leaves their environment, Squyr's data never leaves Squyr's environment. Hashes exchange. Overlap surfaces. Both parties see the matched cohort size and identifier references; neither sees the other's underlying data.

Brand Side
Local hashing in brand environment
Hash · sign · transmit one-way · verify Squyr signatures · receive matched IDs.
Brand's data never left brand environment.
Squyr Protocol
< 90 second exchange
Hash · encrypt · sign · transmit · verify · unwrap.
Bilateral · Auditable · Hash-chain verified
Squyr Side
Local hashing in Squyr environment
Receive · verify · respond signed · compute overlap · receive matched IDs.
Squyr's data never left Squyr's environment.