Trust center · AI governance

Useful AI,
with a leash it cannot slip.

The interesting question is not whether AI can draft something plausible. It is whether the system around the AI can prove restraint. That is what we build and test.

Source-grounded by design

No invented context.

Where drafting is approved and enabled, drafts compose from approved product records with visible citations. What cannot be established from a source is withheld and shown as a gap — not guessed.

Review required

No draft applies itself.

AI output in the clinical workflow is review-required by construction: it cannot self-apply, self-send, or become a clinical decision. The reviewing human, the sources, and the producing configuration remain inspectable.

Gated availability

Designed is not enabled.

AI capabilities are disabled by default for every organization. Activation is a deliberate, named decision per organization and workflow, behind clinical, privacy, security, and operational approval — and it is designed to be reversible.

Default state

Off, per organization and per capability.

Activation

Named approvals against a specific workflow and cohort.

Rollback

Deactivation and version rollback are designed paths, not emergencies.

Adversarial evaluation

We attack it before anyone else can.

Governance controls are exercised by a standing internal adversarial evaluation program before capabilities are considered for activation. Findings are recorded and must be formally adjudicated — the process is designed so that an inconvenient finding cannot be silenced.

Patient-facing boundary

Support, not substitution.

Where an experience is patient-facing, it operates inside an organization-approved, consented workflow with explicit boundaries: it does not diagnose, prescribe, provide emergency response, or pretend to be a person.