Regulated clinical AI

Evidence infrastructure for AI-enabled medical products.

Glacis helps clinical AI teams generate signed operational records for PCCP change review, post-market oversight, and drift analysis. The records bind reported outcomes for a configured path; selected sensitive payload fields can be excluded from the portable artifact.

Why now

Regulated AI medical products need proof from real operation, not after-the-fact documentation.

AI medical products change, drift, touch clinical workflows, and generate outputs that reviewers and health-system buyers will question. Screenshots and retrospective logs are weak evidence when the important question is whether the right controls ran at the right time.

Glacis turns consequential runtime events into signed receipts, then assembles those receipts into evidence packs for regulatory review, PCCP updates, post-market oversight, and internal quality review.

What gets instrumented

Runtime evidence for the AI lifecycle.

Model-change evidence

Version, policy, threshold, and deployment context tied to the behavior that changed.

Control execution

Which guardrail, review rule, redaction, escalation, or block executed at decision time.

Drift and near misses

Operational patterns that show where performance, population, or workflow behavior is moving.

Post-market proof

Receipts that support lifecycle management, health-system review, and audit readiness.

Runtime artifact

Receipts first. Evidence packs second.

Receipts are generated at runtime. Evidence packs are assembled from receipts.

That distinction ties the evidence to what the configured path reported at runtime rather than relying only on a document created after the fact. Source truth, control effectiveness, and coverage still require separate evidence.

Workflow
Control
Decision
Receipt
Evidence Pack
AI medical product model update
PCCP change rule and clinical review threshold
Escalated for review
Timestamp, composite hash, model version, guardrail action, operator and witness signatures
Regulatory review and lifecycle management artifact

Sensitive environments

Built for PHI and proprietary clinical context.

Glacis generates runtime records of what configured controls reported within a defined coverage boundary. The portable artifact can carry verification metadata, reported outcomes, model/version context, threshold decisions, drift signals, and commitments while excluding selected protected clinical content; the deployment architecture determines actual data flows and control effectiveness.

Runtime controls

Observe, allow, block, redact, escalate, or require review at the AI boundary.

Signed evidence

Each in-scope decision can carry a tamper-evident record of covered fields and the reported control outcome.

A bounded evidence path

A portable record can carry commitments and bounded metadata while excluding configured prompt, output, PHI, customer-data, or proprietary-context fields. Review surrounding data paths separately.

Verify it yourself

Proof you can check.

A real signed runtime receipt. Verification runs in your browser.

Bring one regulated AI workflow.

We’ll map the scoped operational records and corroborating evidence a clinical AI review may need for change records, post-market oversight, drift review, and reported control outcomes.

Discuss a consequential AI workflow