Software, AI & security for local business

Custom software and AI, built for your business.

Colab Technology builds custom applications and personal AI systems for local businesses, trains their staff on HIPAA, and tests their cloud and applications for security weaknesses. We're a working product studio — we build and run our own software — and we bring that same craftsmanship to solving your problems.

Custom applications Personal AI systems HIPAA training Security assessments
Custom Applications
Built to fit your business
Explore →
Personal AI Systems
Your own private AI
Explore →
Security & HIPAA
Pen tests, cloud reviews, staff training
Explore →
Services

Four things, done really well

Software built around how your business actually works, private AI that takes care of the busywork, HIPAA training your staff will actually remember, and security assessments that end in fixes, not just a report. Click any one to see how it works.

Custom Application Development

Software built around how your business actually works. Web and mobile applications designed to fit your operations — not force you to change them. From the first idea to a finished product you rely on every day.

Learn more →

Personal AI Systems

Your own AI, tailored to your business. We build private, practical AI tools — assistants and automations trained on the way your business runs — that save time and take care of the busywork, while keeping your data yours.

Learn more →

HIPAA & PHI Workforce Training

A short, evidence-based HIPAA course with an assessment, a verifiable certificate and the training record your organization has to keep. Built for clinics, care facilities and the vendors who serve them.

Learn more →

Security Analysis & Penetration Testing

An independent review of your AWS accounts and a penetration test of your application, graded on a published rubric. Every finding comes with a fix, every fix gets re-tested, and a clean result earns a verifiable certificate.

Learn more →

We build our own software, too

We don't just build for clients — we build and operate our own products, from consumer apps to real-time, high-reliability systems. You get a team that ships and maintains real software for a living, and holds your project to the same standard.

Let's talk about your business.

Tell us what you're trying to solve, and we'll take it from there.

Get in touch →
← Back to home
Services

Four services, built for local business

Custom software that fits how you work, private AI that handles the busywork, HIPAA training for your staff, and security assessments with a grade you can show. Choose one to see how it works.

Custom Application Development

Software built around how your business actually works. Web and mobile applications designed to fit your operations — not force you to change them. From the first idea to a finished product you rely on every day.

  • Fits your workflow
  • Web & mobile
  • Idea to finished product
Learn more →

Personal AI Systems

Your own AI, tailored to your business. We build private, practical AI tools — assistants and automations trained on the way your business runs — that save time and take care of the busywork, while keeping your data yours.

  • Private & yours
  • Works where you already chat
  • Handles the busywork
Learn more →

HIPAA & PHI Workforce Training

Six short modules, a 15-question assessment, a verifiable certificate and a training record, delivered to your whole team from one invitation link. Designed around how people actually remember things.

  • About 45 minutes per person
  • Certificate + training record, verifiable online
  • Organization dashboard and reminders
Learn more →

Security Analysis & Penetration Testing

An AWS infrastructure review and an application penetration test, graded A+ to F on a published rubric. You get a findings log with fixes, free re-tests, and a certificate your customers can verify.

  • CIS, OWASP and HIPAA Security Rule based
  • Starting grade that improves as you fix
  • Verifiable certificate at grade A or better
Learn more →

Not sure which one you need?

Tell us what you're trying to solve, and we'll take it from there.

Get in touch →
← Back to What We Build
Custom Application Development

Software built around how you work

Web and mobile applications designed to fit your operations — not force you to change them. From the first idea to a finished product you rely on every day.

What you get

Practical software that makes the day-to-day easier — built to last.

Fits your workflow

We build around the way your business already runs, instead of making you bend to off-the-shelf tools.

Web & mobile

Applications your team and customers can use from a computer or a phone, wherever they are.

Idea to finished product

We take you from the first sketch to something real and dependable that you use every day.

Built to last

We stick around — maintaining and improving what we build so it keeps working as you grow.

How we work with you

A clear, collaborative path from problem to product.

1

Understand

We learn how your business actually works and what's slowing you down.

2

Prototype

We build something real early, so you can see and shape it fast.

3

Build

We turn it into a finished product, done to a high standard.

4

Support

We keep it running and improving well after launch.

Have something in mind?

Tell us what you're trying to solve, and we'll take it from there.

Get in touch →
← Back to What We Build
Personal AI Systems

Your own private AI, built around your business

A private AI assistant that lives in the chat tools you already use, connects to your business systems under your own login, and gets smarter about your business every day — with the AI running inside your own secure cloud, not on someone else's servers.

Unlike a generic chatbot, you get your own private assistant — your own name and branding for it, your own logins, your own data. You talk to it in the apps you already use, from any device. And because it runs around the clock in the cloud, it keeps working even when you're away from your desk.

Connects with the tools you already use

Gmail Google Calendar Google Drive Slack Telegram GitHub Linear QuickBooks

How it works

An assistant that fits into your day and gets more useful over time.

Talk to it where you already work

Message it in Slack or Telegram like a colleague — no new app to learn. It remembers your conversations and can branch into focused threads.

Connects to your real business data

Works with Gmail, Google Calendar and Drive, Slack, GitHub, Linear, and QuickBooks — plus your own files. It reads and drafts freely, and always asks before sending anything out.

Gets smarter every day

It keeps its own notes on your business in a private notebook you own, so its understanding compounds over time instead of resetting.

Set up helpers, not just an assistant

Ask for scheduled jobs in plain English — a morning digest, follow-ups on leads, drafted campaigns — and they're live in minutes. No developer needed.

Cost-controlled by design

It shows the cost of every reply and runs efficiently — on the order of tens of dollars a month. Turn up the power for hard problems whenever you want.

Always on, from any device

It runs 24/7 in the cloud, so it's ready whether you're at your desk, on the road, or on your phone.

Your data stays yours

Private and secure by design

This is the part most AI tools skip. Here's how yours is different.

The AI runs in your own cloud

Your assistant lives in a dedicated cloud account (on Amazon Web Services), and the AI does its thinking right there — inside your environment. Your data is never sent to a consumer AI service, and never used to train anyone's models.

Your logins, never ours

Every connection is set up under your own accounts, through secure one-time links you complete in your own browser. We never see or store your passwords or keys.

HIPAA compliant, with a signed BAA

Built for regulated fields like healthcare: dedicated, single-tenant setup, HIPAA-eligible services, and a Business Associate Agreement signed as part of the engagement.

Nothing happens without your say-so

It asks permission before taking any real-world action, and you can grant or revoke what each tool is allowed to do at any time.

Two ways to run it: host it in your own cloud account for the strongest isolation, or let us run a dedicated account for you. Either way, your logins stay yours.

What you get

Everything included, in plain terms.

Your own private instance — never shared with other businesses
Works in Slack and Telegram, from any device
Connects to Gmail, Calendar, Drive, GitHub, Linear, QuickBooks, Slack, and your files
Set up helpers for marketing, sales, and reporting — just by asking
Keeps its own notes on your business, so it gets smarter over time
Asks approval before sending anything out
Shows the cost of every reply — typically tens of dollars a month
HIPAA compliant with a signed BAA
Runs in your cloud or ours — your logins stay yours
Private AI processing — your data is never used to train models

Want your own AI?

Tell us how your business runs, and we'll build an assistant around it.

Get in touch →
← Back to Services
HIPAA & PHI Workforce Training

HIPAA training your staff will actually remember

A roughly 45-minute privacy and security awareness course for the workforce of covered entities and business associates, with an assessment, a verifiable certificate and the training record your organization has to keep. Invite your whole team from one link; get a copy of every certificate.

Built for clinics, dental and therapy practices, home health and senior-care providers, billing and IT companies, and software vendors who sign Business Associate Agreements. The course teaches the Privacy, Security and Breach Notification Rules as they stand today, with scenarios from real workplaces instead of slides of legal text.

How it works

Short, scenario-first, and designed around how people actually learn.

Six short modules

Five to eight minutes each. Every module opens with a scenario question, teaches in short cards, and checks understanding with practice questions that come back until they're right.

A real assessment

Fifteen questions drawn from a larger bank, new scenarios rather than the practice items, 80% to pass. A retake draws different questions.

Certificate and training record

On passing, a two-page PDF goes to the learner and to your organization: the certificate, and a training record showing what was covered, the score and the course version. Each one is verifiable online by its ID.

Refreshers that stick

Three two-minute email refreshers at 7, 30 and 120 days, so the training is still there when it matters. Opt-out any time; they never affect the certificate.

Organization dashboard

Invite people individually or share one sign-up link. See who has started, passed and is due for renewal, download every certificate, and export the training log as CSV for your auditor.

Grounded in learning science

Pretesting, retrieval practice, spaced refreshers, explained feedback and self-explanation, each backed by published research. The course page explains the method and cites the studies.

What's covered

The rules your staff need to know

Mapped to the workforce training requirements in 45 CFR §164.530(b) and §164.308(a)(5).

What PHI is: the 18 identifiers, de-identification, and where PHI hides in everyday work
Permitted uses, minimum necessary, and when an authorization is required
Patient rights: access, amendment, restrictions and the 30-day clock
Security Rule safeguards: passwords, devices, phishing, screen locks, log-in monitoring
Recognizing and reporting a breach, the 60-day limit, and what to do in the first hour
Business associates, BAAs and subcontractors
Penalties, enforcement, and the non-retaliation rule
Why state law can be stricter, and how to find out

What this is, and what it isn't

HHS does not certify HIPAA training programs or individuals. Our certificate documents that a named person completed this general awareness course and passed its assessment; the training record supports your documentation under §164.530(b). Training on your own policies and procedures is still your job, and we say so on every record.

We hold no patient information of any kind, only workforce names, emails, scores and certificates, so we are not your business associate for this service. Training records are kept for at least six years. We recommend renewal every twelve months; the rules don't set an expiry, and neither do we.

Pricing is per seat, with a floor that works for a five-person practice. Ask us for a quote and a setup code.

Get your team trained this week.

Tell us how many people you need to train and we'll agree a start date and send a setup code.

Get in touch →
← Back to Services
Security Analysis & Penetration Testing

Find it, fix it, prove it.

An independent review of your AWS accounts and a penetration test of your application, graded A+ to F on a rubric we publish. You get a findings log with a specific fix for every issue, free re-tests until they're closed, and a certificate your customers, partners and insurers can verify online.

Two assessments

Take one or both. Both are grey-box: we read your infrastructure code and your application source as well as testing the live system, because that finds more in less time and lets us verify fixes precisely.

AWS Infrastructure Security Review

A read-only configuration review of your AWS accounts against the CIS AWS Foundations Benchmark v3.0, AWS Foundational Security Best Practices and, where you handle PHI, the HIPAA Security Rule safeguards.

  • Identity, access and root account controls
  • Logging, alerting and detection coverage
  • Encryption, key management, backups and recovery
  • Network exposure and the deploy pipeline's reach into production

Application Security Assessment & Penetration Test

Manual and automated testing of one web application and its API against the OWASP Web Security Testing Guide and ASVS Level 2, with the parts that protect patient or financial data tested to Level 3.

  • Authentication, MFA, sessions and password handling
  • Authorization and tenant isolation on every resource
  • Input handling, uploads, business logic, data protection
  • Dependencies, static analysis and secrets in your repository history

How an engagement runs

Typically two to four weeks from scoping call to first report, then re-tests as you fix.

Scope and authorize

We agree what's in and out, sign the rules of engagement, and get read-only cloud access and test accounts.

Assess

Inventory, benchmark scanning, code review and manual testing. Critical or High issues are called in the same day we confirm them.

Report and grade

A findings log and report with your starting grade, evidence, impact and a specific fix for each item.

Fix and re-test

You fix, we re-test, the grade moves. As many rounds as you need within 90 days. We can do the fixes too, and the report says so if we did.

Certify

At grade A or A+, with every Critical and High verified fixed, you get a certificate valid 12 months and listed on our verification page.

Published rubric

How grading works

Only open findings count. Your team saying "fixed" is recorded; the grade moves when our re-test confirms it. Accepted Critical and High risks count as Mediums; accepted Mediums count as Lows.

A+Nothing open
AOnly Lows (up to 3)
BMediums (1–2), no Highs
CAny High, or 3+ Mediums
DOne Critical, or 3+ Highs
FTwo or more Criticals

Severity follows CVSS v3.1 bands and is set against your data and your obligations: a logging gap on a system holding patient records is rated higher than the same gap on a brochure site. Four or more Lows produce a B; one unverified High produces a C or below.

What you get

Everything included, in plain terms.

A findings log: every issue with severity, CVSS score where it applies, evidence, reproduction steps and a specific fix
A written report with your starting grade and current grade, as PDF and spreadsheet
Re-testing of every fix, as many times as needed, for 90 days
Same-day notice by phone and email for anything Critical or High
A certificate per scope at grade A or A+, valid 12 months, verifiable at colabtech.us/verify
A one-page letter of attestation for your customers or a vendor questionnaire, on request
Assessment uses read-only cloud access; remediation changes require your authorization
Help fixing what we found, if you want it, from the team that builds software for a living

What this is, and what it isn't

This is not a SOC 2, HITRUST or ISO 27001 audit, and we are not a CPA firm or a certification body. Our certificate attests to our assessment and your remediation against the standards named on it, at a point in time. HIPAA compliance remains your own determination; our review is evidence for it.

We don't do denial-of-service testing, social engineering or physical testing. Where we built or operate the system under test, the report says so on its first page, and we'll recommend a second opinion for any certificate you intend to rely on externally.

Fixed fee per scope, quoted after the scoping call from the size of your estate or application. Re-tests and the certificate are included.

Know where you stand.

Tell us what you run and who's asking for proof, and we'll scope it with you.

Book a scoping call →
← Back to home
About Colab

A partner, not a vendor

We're a small, senior team that leads with engineering. Local businesses deserve software that's built well and built to last — and we're in it for the long run.

You'll work with a real person

Colab isn't a faceless agency. Ian takes the time to understand how your business actually works, then builds software that fits it — and he stays your point of contact from the first conversation onward.

Ian SchreuderColab Technology · (303) 513-5133
01

Engineering first

We build things properly. Solid engineering and thoughtful design, with no shortcuts and no surprises.

02

Built to last

Your software should keep working and keep improving as your business grows — not fall apart in a year.

03

In it for the long run

We work as a partner who sticks around, not a vendor who disappears after launch.

Let's talk about your business.

Tell us what you're trying to solve, and we'll take it from there.

Get in touch →
← Back to home
Contact

Let's talk about your business.

Tell us what you're trying to solve, and we'll take it from there.

Reach out to Ian Schreuder anytime:

[email protected]
Tell us the problem
Describe what you're trying to solve — no tech knowledge needed.
Quick reply
We aim to get back to you within a couple of business days.
A real partner
We're in it for the long run, from first idea onward.