Adverse-event capture
Potential adverse-event mentions are flagged as they occur and routed into a pharmacovigilance review queue, with per-tenant configuration for where those flags go and who receives them.
Safety & governance
Guardrails are validation stages, not prompt instructions. A response that breaches one is not softened or re-tried into acceptability — it is blocked before it reaches a patient.
The guardrails
A prompt asking a model to behave is a preference. These run on the generated text itself, which is why they hold when a question is phrased in a way nobody anticipated.
The system does not tell a patient what to do. It explains what sources say and routes the decision back to a clinician.
Responses do not diagnose, stage, or assess an individual’s condition, however the question is phrased.
Comparative and superlative claims about a therapy must carry an attributed source, or they do not ship.
Outbound text is scanned for personal health information before it is shown, in addition to redaction on the way in.
A substantive medical claim without a source reference is treated as a validation failure, not a stylistic one.
Review workflows
Potential adverse-event mentions are flagged as they occur and routed into a pharmacovigilance review queue, with per-tenant configuration for where those flags go and who receives them.
Questions the system should not answer become tasks in a human-response queue rather than approximate answers. The handoff is recorded as an event, so the path from question to human response is reconstructable.
Content changes move through pull-request review, which produces a reviewer, a timestamp and a diff for every published claim — the evidence trail an MLR process needs.
Operational logs cover system activity, usage and deployment behaviour, including guardrail outcomes, so a review can ask what the system did and get an answer.
Questions we get asked
The fastest way to evaluate the boundaries is to try to cross them. We will give you a deployment to do exactly that.