Trust center · AI governance
Useful AI,
with a leash it cannot slip.
The interesting question is not whether AI can draft something plausible. It is whether the system around the AI can prove restraint. That is what we build and test.
Source-grounded by design
No invented context.
Where drafting is approved and enabled, drafts compose from approved product records with visible citations. What cannot be established from a source is withheld and shown as a gap — not guessed.
Review required
No draft applies itself.
AI output in the clinical workflow is review-required by construction: it cannot self-apply, self-send, or become a clinical decision. The reviewing human, the sources, and the producing configuration remain inspectable.
Gated availability
Designed is not enabled.
AI capabilities are disabled by default for every organization. Activation is a deliberate, named decision per organization and workflow, behind clinical, privacy, security, and operational approval — and it is designed to be reversible.
Default state
Off, per organization and per capability.
Activation
Named approvals against a specific workflow and cohort.
Rollback
Deactivation and version rollback are designed paths, not emergencies.
Adversarial evaluation
We attack it before anyone else can.
Governance controls are exercised by a standing internal adversarial evaluation program before capabilities are considered for activation. Findings are recorded and must be formally adjudicated — the process is designed so that an inconvenient finding cannot be silenced.
Patient-facing boundary
Support, not substitution.
Where an experience is patient-facing, it operates inside an organization-approved, consented workflow with explicit boundaries: it does not diagnose, prescribe, provide emergency response, or pretend to be a person.