Opsy
Opsy runs OpsyOne, a Swedish B2B platform for insurance medicine that connects insurers' claims handlers with medical advisers on sickness, accident and personal-injury cases. All data is stored and processed in Sweden, and AI only assists human decisions.
What is Opsy?
Opsy is a Swedish technology company that describes itself as "den öppna standarden för försäkringsmedicin", the open standard for insurance medicine. Its product, OpsyOne, is a business-to-business platform on which insurers and medical advisers work the same case files: sickness, accident and personal-injury claims. It covers the chain end to end, case administration, medical opinions, quality assurance, regulatory compliance and follow-up, and is used through a web application at app.opsy.one; there is no self-service sign-up.
Six modules carry the product. OpsyScore grades every medical opinion automatically, giving medical managers a basis for coaching and pushing towards assessments that do not depend on which adviser happened to take the case. OpsyVault holds the data: stored in Sweden, no third-party access, full audit trail. OpsyForms serves standardised forms that adapt to the case type and the insurer, cutting back-and-forth. OpsyDocs categorises, tags and structures incoming medical records so a file is built faster and an adviser finds what matters. OpsyIQ shows turnaround times, cost and quality in real time, in the platform or exported through an API to a BI system. OpsyGO, announced for customer availability on 1 October 2026, produces an AI-generated decision basis from the case documentation and the applicable guidelines, either as a standalone service for cases where no physician is required, or embedded to give advisers better material.
AI support was launched across OpsyOne on 19 March 2026 and is implemented customer by customer, with workflow and decision logic fitted to each insurer. The vendor's line is explicit: AI is decision support, and every medical assessment remains a human caseworker decision with full traceability.
Opsy runs an open ecosystem: customers may use their own medical advisers, connect external parties, or draw on Opsy's network, which reached 100 advisers in June 2026, without exclusivity or lock-in. Twenty-nine Swedish insurance and claims companies were on the platform in March 2026. Compliance is presented as built in rather than bolted on, GDPR, the Patient Data Act, DORA, the AI Act, and ISO 27001 certification since 13 October 2025. The publisher is Opsy AB in Stockholm; its listed parent is Opsy Holding AB.
What it does
- Centralise insurance-medicine case handling between claims handlers and medical advisers in a single shared platform.
- Score the quality of every medical opinion automatically, so follow-up and coaching rest on measurement rather than impression (OpsyScore).
- Store and trace medical case data inside Sweden, with no third-party access (OpsyVault).
- Serve dynamic forms that adapt to the case type and to the insurer, cutting resubmissions and delay (OpsyForms).
- Categorise, tag and structure incoming medical records automatically (OpsyDocs).
- Track turnaround times, cost and quality in real time, in the platform or through an API into a BI system (OpsyIQ).
- Generate an AI-drafted decision basis from the case documentation and the applicable guidelines (OpsyGO, available to customers from 1 October 2026).
When to use Opsy / When not to
A quick filter to help you decide if Opsy is the right fit.
When to use Opsy
- Swedish insurers and claims-handling companies working sickness, accident and personal-injury claims: 29 insurance and claims companies were on the platform in March 2026, among them Hedvig Försäkring, SEB Pension och Försäkring, Svedea, Vitea Life, Kommunassurans and three regional Länsförsäkringar companies.
- Claims handlers who need one shared, traceable workspace with their medical advisers instead of scattered email threads and loose attachments.
- Chief medical officers and medical advisers who want assessment quality measured rather than assumed: OpsyScore grades every medical opinion automatically and feeds follow-up and coaching.
- Compliance, risk and data-protection officers operating under GDPR, the Swedish Patient Data Act, DORA and the EU AI Act, who need health data to stay inside Sweden.
- Independent medical specialists looking for insurance-medicine assignments: the adviser network reached 100 members in June 2026, covering the specialties relevant to personal-injury assessment, with no non-compete clause.
When not to use Opsy
- Private individuals, patients and claimants: OpsyOne is infrastructure sold to insurers, with no consumer access.
- Clinical care teams: the platform serves medical assessment for insurance purposes, not the treatment of the patient.
- Organisations outside Sweden at the time of writing: site, product and customer base are Swedish, and Nordic expansion only began in 2026, with Norway and Finland named as the first markets.
- Teams that expect self-service sign-up and a published price: entry runs through a mandatory strategy meeting, and no rate is disclosed anywhere on the site.
- Anyone who needs mobile or offline access: there is no iOS or Android app and no browser extension, access is through the web application only.
How to use Opsy
A typical end-to-end flow, from setup to results.
- Book a 30-minute demo from the home page to see OpsyOne in action, there is no self-service trial to sign up for.
- Start with a strategy meeting, in which Opsy reviews the bottlenecks in your current claims-handling process.
- Have your environment tailored: permissions, security levels and the connection of the medical advisers you choose.
- Go through the compliance check before signing, a legal and technical review with full access to the security architecture.
- Complete onboarding and training for claims handlers and administrators; the vendor states OpsyOne is ready to use within a couple of days.
- Log in day to day through the web application at app.opsy.one.
- Route cases to advisers through OpsyForms, with forms that adapt to the case type and to your company.
- Let OpsyDocs categorise and structure incoming medical records, and read the OpsyScore grade on each returned opinion.
- Follow turnaround, cost and quality in OpsyIQ, in the platform or piped through the API into your BI system.
- Medical advisers take a separate route: they apply through the adviser page, with no non-compete clause attached.
Pros & Cons
Pros
- Explicit data sovereignty, which is rare: storage and processing entirely in Sweden, with the vendor stating that no customer data leaves the country and that no third party has access.
- ISO 27001 certification with a stated date (13 October 2025), and regulatory compliance presented as part of the platform rather than an add-on, covering GDPR, the Patient Data Act, DORA and the AI Act.
- AI deliberately kept in a support role: the final medical assessment remains a human caseworker decision, with full traceability on AI-assisted opinions.
- Open model with no exclusivity and no lock-in on either side, customers may keep their own advisers, and advisers face no non-compete clause.
- Quality made measurable rather than declarative through automatic scoring of each medical opinion; OpsyScore was recognised at the Insurance Evolution Awards 2026 as technology innovation and marketing innovation of the year in the life category.
- Verifiable adoption: 29 insurance and claims companies on the platform in March 2026, named customers including Hedvig Försäkring, SEB Pension och Försäkring, Svedea, Vitea Life, Kommunassurans and Länsförsäkringar regional companies, and more than 6,000 closed cases.
- A legal and technical compliance check offered before contract signature, a stated go-live within a few days, and a listed parent company that publishes quarterly reports and named governance.
Cons
- No public pricing at all: no pricing page, no rate card, no order of magnitude, an absence confirmed by the site's own sitemap. No free trial or free plan is announced, and there is no self-service sign-up.
- Very thin public legal documentation: no terms and conditions, no legal notice, no dedicated contact page, and neither a data processing agreement nor a sub-processor list, for a product that handles health data.
- The privacy policy is short (around 2,700 characters), dated 25 March 2025, states no numeric retention period, and covers the public website rather than platform processing.
- Site, product and market are entirely Swedish, Nordic expansion only began in 2026 with Norway and Finland, and no interface or processing language is declared anywhere.
- OpsyGO, the most explicitly AI-driven module, was not yet available at the time of writing, with delivery announced for 1 October 2026.
- No mobile application and no browser extension; an API is asserted for BI export, but no public documentation of it exists.
- The publisher is small and loss-making: 7 employees at the end of Q1 2026, EBITDA of -1,487 TSEK for the quarter and 2025 revenue of 6,691 TSEK, figures that belong to the listed parent Opsy Holding AB rather than to Opsy AB alone.
Pricing & Plans
No free plan and no free trial are announced, and no price is published: the site carries no pricing page, an absence confirmed by its sitemap. Commercial terms take the form of negotiated B2B contracts entered through a strategy meeting, so no lowest price point can be stated. The only public figures are the annual values of individual customer contracts disclosed in the listed parent's market announcements: approximately SEK 0.8 million a year for Hedvig Försäkring (21 August 2026), and approximately SEK 1 million a year each for SEB Pension och Försäkring AB (27 March 2026), Svedea (28 October 2025) and one unnamed customer (17 December 2025). These are contract values, not list prices, and cannot be converted into a unit rate. Revenue is recognised as cases are closed, which suggests billing tied to case volume.
Data, GDPR & hosting
A consolidated view of how Opsy handles your data.
GDPR overview
GDPR compliance is claimed as built into the product rather than sold as an add-on, alongside the Swedish Patient Data Act, DORA, the EU AI Act and ISO 27001 (certified 13 October 2025). Concrete elements exist. A data protection officer is named, Ludwig Andersson Granados, reachable at dpo@opsy.se or by post at Dataskyddsombud, Opsy AB, Gamla Brogatan 27, 111 20 Stockholm. The policy lists rights of access, rectification, erasure and restriction, names Datainspektionen as the supervisory authority, and states that all processing of personal data takes place within Sweden's borders. As the publisher is established in Sweden, no Article 27 representative is required and none is named. What is missing: no data processing agreement and no sub-processor list are published, and the privacy policy, last updated 25 March 2025, is short and covers the public website rather than the platform.
Who owns the data?
Opsy presents customer data as the customer's own. The OpsyVault module is sold under the line "Er data. Era regler.", your data, your rules, with storage in Sweden, no third-party access and full traceability, and the privacy policy adds that Opsy never sells personal data. Two limits matter. That policy covers the public website, not the processing carried out inside the platform, and no terms and conditions are published anywhere on the site, so no contractual clause on intellectual property or ownership of customer content can be read before negotiation. Ownership is therefore asserted by the vendor rather than documented publicly.
Reuse rights
No terms of service are published, so nothing states what a customer may do with data taken out of the platform, or under what licence Opsy holds it. What the vendor does state is narrower and should be read literally: "ingen information används för extern modellträning", no information is used for external model training, and no customer data leaves Sweden. The qualifier "external" leaves internal training unaddressed, and no opt-out mechanism is documented anywhere. For the website itself, Opsy says it collects only what visitors submit voluntarily, sets no cookies, and never sells personal data. Operational reuse is provided for: OpsyIQ exposes turnaround times, cost and quality in the platform or through an API into the customer's own BI system.
Data retention & training
Hosting summary
Opsy states that hosting is exclusively Swedish. The home page's OpsyVault block says all data is stored in Sweden, with no third-party access and full traceability. The March 2026 AI announcement is more explicit: all storage and processing take place in Sweden, and no customer data leaves the country. The privacy policy repeats the same for personal data, all processing occurs within Sweden's borders. The commercial argument attached to this is stated plainly by the vendor: no patient file or sensitive personal data should risk ending up in the hands of US authorities. What is not specified matters too. No hosting provider, cloud region or data centre is named anywhere on the site, and no sub-processor list is published. One technical note, so that it is not misread: the marketing website itself resolves to 75.2.60.5, an AWS anycast node geolocated in Seattle. That concerns the public website only, and says nothing about where platform data lives.
Things to keep in mind
Risks and trade-offs to weigh before adopting Opsy.
- The price is only revealed after a sales meeting, so budgeting ahead of that conversation is impossible.
- No terms and conditions, no legal notice and no dedicated contact page are published, so contractual commitments only surface during negotiation. Note also that the financial figures and governance you can read belong to the listed parent Opsy Holding AB, a small loss-making micro-cap, not to the publisher Opsy AB: supplier viability belongs in your due diligence.
- Read the training claim literally: the vendor states that no information is used for external model training. Internal training is not addressed, and no opt-out is documented.
- Neither a data processing agreement nor a sub-processor list is published, for a product that processes health data. Ask for both before any pilot.
- The privacy policy covers the public website rather than platform processing, dates from 25 March 2025, and sets no numeric retention period.
- Two vendor claims need checking before you rely on them: OpsyGO is announced for 1 October 2026 rather than shipped, and the ISO 27001 certification is stated with no certificate number and no certification body named on the site.
- Automatic scoring and an AI-drafted decision basis can quietly become the default answer. The vendor insists the final call stays human, but a caseworker who signs off on a generated basis under time pressure is still the one accountable, and judgement that is not exercised erodes.
Setup & Integrations
Technical difficulty
Low on the customer's side, because most of the work is done by the vendor. There is no self-service sign-up: a strategy meeting comes first, then Opsy configures permissions, security levels and the connection of the medical advisers you choose, followed by a legal and technical compliance check before signature and by onboarding and training for claims handlers and administrators. Opsy states OpsyOne is ready to use within a couple of days, and promises replacement of an existing system without migration headaches. Access is web-based with nothing to install; an API to a BI system exists but is undocumented.
Deployment
Behind Opsy
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Opsy.
Frequently asked questions
What does OpsyOne actually do?
Where is the data stored?
Is our data used to train AI models?
Does the AI decide instead of the caseworker?
What is OpsyGO?
What does the platform cost?
Is there a security certification?
Do we have to use Opsy's medical advisers?
How long does it take to go live?
Is the product available outside Sweden?
Should you pick Opsy?
Opsy is a narrow, deliberately unglamorous tool: a platform for Swedish insurance medicine, sold to insurers rather than to end users. Within that niche it is coherent. Data sovereignty is stated without hedging, storage and processing in Sweden, no third-party access, no customer data leaving the country, and it is backed by ISO 27001 certification dated 13 October 2025 and by compliance claims covering GDPR, the Patient Data Act, DORA and the AI Act. The AI is deliberately kept in a support role: OpsyGO drafts a decision basis, but the final medical judgement remains a human caseworker's, with an audit trail. The open ecosystem model, with no exclusivity and no lock-in on either the customer or the adviser side, is a genuine differentiator in a market where exclusivity is common.
The weaknesses are just as clear. Pricing is entirely opaque, no page, no range, nothing before a sales meeting. The public legal documentation is very thin: no terms and conditions, no data processing agreement, no sub-processor list, and a privacy policy that covers the website rather than the platform. The scope is Swedish, with Nordic expansion barely started. And OpsyGO, the most explicitly AI-driven module, was not yet delivered when this record was written.
Adoption is real and growing, 29 insurance and claims companies, 100 connected medical advisers, more than 6,000 closed cases, case volume up 19% in Q1 2026, but the vendor remains small: seven employees and a loss-making quarter at the listed parent, Opsy Holding AB. For a Swedish insurer handling personal-injury claims, Opsy is worth a serious look; for anyone outside that description, it is not the tool.
- Choosing a selection results in a full page refresh.
- Opens in a new window.