Auditable clinical AI
The safety layer is code, not a model.
Every clinical output carries its source, its strength, the model version that produced it, and a tamper-evident record of how it was produced — and the layer that decides when to stop reasoning and route to a human cannot be reasoned past, because it is not doing any reasoning.
Deterministic safety routingHash-chained decision provenanceEvidence graded, never conflatedSeven localesRegion resolved per patient
What this is
Most clinical AI asks you to trust the model. This asks you to check.
Every serious vendor in this market will tell you their AI is safe. Almost none of them can hand you the artifact that shows it. The difference is architectural rather than rhetorical: when a safety layer is a prompt, its guarantees are probabilistic and its evidence is a demo. When it is a code path, its guarantees are structural and its evidence is a test suite you can read.
We built the second kind. Emergency routing is a deterministic rule set that no model output can override — there is no temperature to tune and no prompt to jailbreak, because there is no model in that decision. Evidence grades from different appraising bodies cannot be compared, because attempting the comparison raises an exception rather than returning a number. A patient's content region is resolved from where they live, never from what language they speak, and the function that resolves it has no parameter through which a language could be passed.
None of that is a feature you would notice in a bake-off. All of it is what a security review is actually looking for.
Two surfaces, one spine
A clinician is a licensed professional. A patient is not.
The same appraised evidence backs both platforms. Only the register changes — and the boundary between them is enforced by the surface, not by a system prompt asking the model to remember who it is talking to.
Praman
प्रमाण · proof, valid evidence
The clinician console
Clinical content is legitimately in scope for a licensed professional. What is never in scope is the assistant crossing from decision support into decision making — claiming it took an action, issuing a directive, or asserting a diagnosis as its own settled conclusion.
- Ambient documentation with a draft buffer — dictated text lands visibly outside the note and enters the record only on explicit clinician acceptance
- Grounded clinical assistant that refuses rather than guesses
- Drug-interaction screening at order entry, where an unconfigured engine reports "screening unavailable" and never a false "no interactions"
- FDA labelling and preventive-screening recommendations reproduced verbatim, as their licences require
- Care plans authored here that publish to the patient's platform
Anvesh
अन्वेष · to seek out, investigate
The patient platform
For the person whose records are spread across four systems, whose first language is not English, and who may not belong to a health system at all. Patient-facing content stays in the general-wellness lane — deterministically, not by instruction.
- Bring your own records: FHIR and payer imports, or a photograph of a lab report, reviewed and confirmed by the patient before anything persists
- Imported records never overwrite or merge into clinician-authored or self-attested ones
- Seven languages, with health-critical copy held back to authoritative English rather than machine-translated
- Guidance resolved against where the patient lives — dietary advice built around idli and roti where that is the diet
- Nudges with frequency caps and quiet hours enforced outside model configuration
Three claims, three mechanisms
A claim without a mechanism is marketing
Each of these is enforced by a type, a constraint, or a test rather than by a prompt — which is why each one names the thing that makes it true.
01
The safety layer is not a model
Red-flag routing — chest pain with breathlessness, stroke signs, suicidal ideation, anaphylaxis, haemorrhage, loss of consciousness — is a deterministic pattern set evaluated before any model is consulted. Competitors offering "configurable human oversight" are describing a settings page. This is a code path with no override.
Mechanism: deterministic rule evaluation, never LLM-judged, with the routing decision written into the audit chain.
02
"We didn't check" and "nothing's wrong" are different sentences
An empty findings list is not reassurance. Every other product in this category renders an empty result set as a clean bill of health. Ours distinguishes four states, and only one of them reassures — the others name why we cannot: a source went quiet, every source failed, or the record is empty. Reading an empty record succeeds, so complete coverage is not sufficient grounds for telling someone they are fine.
Mechanism: a NOT NULL database constraint on the reason a thing was not assessed, and coverage flags that default to unchecked so an unmarked source counts as unread rather than silently clean.
03
Prove which model wrote this, and that nobody changed it
Every AI decision records the agent, the model identifier, the prompt version, the guardrail results, the evidence source, and a SHA-256 content hash chained to the one before it. In an audit or a malpractice context, "show me which model version produced this note and that it has not been altered since" is a question the category leaders answer with a log file.
Mechanism: hash-chained decision provenance, satisfying ONC HTI-1 algorithm-transparency requirements.
04
An AYUSH Grade A is not a USPSTF Grade A
Where evidence carries a grade, we show it, and we never let one appraisal scale be mistaken for another. Most Western vendors avoid this problem by not indexing traditional medicine at all — which does not make the question go away, it just means the patient searches elsewhere and gets the answer unappraised. We index it and refuse to launder it.
Mechanism: a grade is a (scale, level) pair; comparing strength across scales raises rather than returning a boolean. Verified exhaustively in CI over every cross-scale comparison that exists.
05
Language is not a country
A Hindi speaker in New Jersey and a Hindi speaker in Pune get the same interface language and different clinical guidance. That distinction sounds obvious and is the single most tempting inference to write, because a locale header is right there and it is usually correlated with a country. It is correlated, not equal, and the population it fails is the diaspora.
Mechanism: region resolves from residence, tenant, or explicit setting — the resolver has no language parameter to pass. Verified across every shipped locale and locale tag.
06
We do not sell the tests
Platforms that make money when you order another biomarker panel have a structural incentive to surface findings. That is the opposite of what a person needs from a health product. Having no diagnostic revenue is what lets us treat "did this make the user anxious?" as a release gate that can block a change, rather than a metric somebody quietly stops reporting.
Mechanism: no laboratory or diagnostic revenue line. A counter-metric only constrains you if it can cost you something.
What we are not claiming yet
A platform whose entire argument is verifiability does not get to be vague about its own evidence. We hold ourselves to a rule that a claim we have not measured is a claim we do not get to make, so here is what we are deliberately not saying — and what would have to be true before we did.
- No performance percentages. Our guardrail evaluation runs in CI on every build and reports its numbers with confidence intervals. It currently reports failures against our own declared thresholds. We will publish it when an independent reviewing clinician has signed off the evaluation corpus — not before.
- No time-savings figure. The instrumentation exists; the weeks of data behind a defensible number do not yet.
- No quality-of-life outcome claim. That is the mission, and it needs a longitudinal study we intend to publish whichever way it comes out.
- No named reference customers. We would rather say so than imply otherwise.
What we will hand you today, under NDA: the guardrail evaluation report including its current failures, the model card for any agent in the catalog, the audit-chain verification for a note you choose, and the architecture documentation for every mechanism named on this page. Ask our competitors for the equivalent four.
Who this is for
Built for the places a single-EHR assistant cannot reach
If your patients are all inside one health system, that system's own assistant is a reasonable answer and we will tell you so. This is built for the situations where it isn't.
Independent telehealth groups
Encounter-metered economics that match how you already think about cost, with no installed EHR incumbent to displace.
Multilingual and safety-net care
Seven locales, verbatim authoritative sources, and a refusal to machine-translate safety copy. Here that is a requirement, not a nicety.
Compliance, risk and counsel
The buyer who cares about the hash chain, the model card, and the evaluation. Usually not the person who bought the scribe.
Patients between systems
Records in four places, or in a shoebox, or on a phone camera. The population a single-system portal structurally cannot serve.
The evaluation question
"How do I know your AI is safe?"
The honest answer to that question is not a sentence. It is a set of documents, and any vendor who answers it with a sentence is asking you to take their word for it.
01
The model card
Per agent: intended use, explicitly out-of-scope use, targeted population, guardrail configuration, evidence sources, and known limitations. Generated from the agent registry, so it cannot drift away from what the code actually does.
02
The guardrail evaluation
Recall and precision on emergency routing, scope-violation rates under adversarial pressure, and citation enforcement — each with a 95% confidence interval and a declared threshold that blocks a release when it is not met. Including, currently, ours.
03
The audit chain
Pick a note. We will show you the model version that drafted it, the guardrails that ran, the evidence it cited, and cryptographic proof that no link in the chain has been altered.
04
The architecture documentation
Every mechanism named on this page, with the file that implements it and the test that holds it in place.