SpeakLogIQ - Technical and GDPR Audit of a German Medical Voice AI Platform
Key Features
- Technical findings register with 35 documented issues across four severity levels
- Root cause analysis covering conversation state, prompt design, entity memory, and latency
- 12-point GDPR and security compliance assessment
- Code review of around 6,000 lines across the full call pipeline
- Redesigned conversation architecture with a state machine, separated prompts, and structured memory
- Prioritized 8-week remediation roadmap with milestones and effort estimates
- Platform health scorecard across six system areas
- DPIA and data protection gap analysis ahead of the clinic pilot
About This Project
The Client
SpeakLogIQ is a German healthcare startup building an AI telephone assistant for medical practices. When a patient calls a clinic, the AI answers in natural German and handles the conversation, mostly appointment booking. The product is built for the EU healthcare market, where GDPR compliance is a legal requirement, not a feature. As the founders prepared to move from internal testing to their first clinic pilot, they wanted an outside expert to give them an honest picture of their platform before real patients started calling.
The Challenge
The platform worked in demos but struggled in real conversations. The voice agent asked patients for the same information more than once, lost details the caller had already given, and in some cases told patients the clinic was closed after they had finished providing their booking information. Responses took several seconds, long enough that callers assumed the line had dropped.
The founders faced a harder problem underneath these symptoms. They did not know whether these were surface bugs or signs of deeper architectural issues, and they had no independent review of their GDPR position before onboarding real medical practices. Fixing the wrong layer would have cost months. Scaling on an unaudited foundation could have created compliance risk with patient data.
They brought Zetaver in as a senior technical consultant to audit the platform end to end, covering architecture, code quality, security, and compliance, and to separate what needed a targeted fix from what needed to be rebuilt.
Our Approach
Zetaver delivered a structured technical and compliance audit covering around 6,000 lines of production code and the full call pipeline, from Twilio telephony through the Azure serverless backend, the GPT-4o-mini conversation layer, and ElevenLabs voice synthesis.
- A register of 35 documented issues. Each issue included an ID, a severity rating across four levels, the impact on patients, and a specific fix. Every finding traced back to code or actual call behavior. No vague observations.
- Root cause diagnosis. The audit traced dozens of surface symptoms back to a small set of architectural causes: conversation flow controlled by the language model instead of an explicit state machine, one large prompt handling intent detection, data extraction, and response generation at the same time, no structured memory tracking what the patient had already said, and delays that stacked up across four external services. This diagnosis turned a confusing bug list into a clear engineering plan.
- GDPR and security review. A 12-point compliance assessment covering data processing, consent capture, personal data in logs, data deletion capability, and third-party processor agreements. The incomplete DPIA was flagged as the critical blocker before any clinic pilot.
- A remediation roadmap. A prioritized 8-week fix plan with effort estimates, milestones, and success criteria, designed so the founders' own team could execute it. It included a redesigned conversation architecture with an explicit state machine, separated prompts, and structured memory with per-field confirmation.
The Results
The founders received something they did not have before: an honest, independent picture of their platform. The core finding was that the foundation, meaning the infrastructure and voice quality, was solid. The platform needed targeted architectural improvements, not a rewrite. That single conclusion protected them from the most expensive mistake an early-stage team can make.
The audit gave their team a severity-ranked backlog they could work through internally, a compliance checklist that made their GDPR gaps concrete and fixable, and a blueprint for the conversation engine. After delivery, the SpeakLogIQ team took the plan forward in-house, which is exactly what the engagement was designed for.
Why It Matters
Voice AI in healthcare fails in ways normal software does not. A lost detail is not a UI glitch. It is a patient repeating their date of birth for the third time and hanging up. This engagement shows what Zetaver brings when the product already exists: the ability to read a production AI system, explain why it misbehaves at the architecture level, and hand a founding team a plan they can execute. For teams building conversational AI in regulated markets, an audit like this is the difference between scaling with confidence and scaling into a compliance problem.
Technologies Used
Interested in this case study?
Contact us to learn more about how we can build a similar solution for your business.
Get in Touch