The system checks every page of the batch record against the procedure — missing signatures, blank fields, out-of-range values, entries out of sequence — and hands your reviewer a marked-up pack with everything questionable already flagged.
Three lists, because these are the three things a quality director asks in the first ten minutes.
Signatures and dates · required fields left blank · values outside specification · entries recorded out of sequence · disagreements between pages of the same pack · attachments that should be there and are not.
A marked-up pack · a list of questions ordered by severity · a page and location reference for every question · everything else marked as checked. Anything the system could not read comes back as unreadable, human check required — never as a confident value.
The input · the model and rule versions in effect · what was flagged and on what basis · who decided what, on each question. Versions are pinned and dated from the first build, not assembled at handover.
The shape underneath: the model reads and proposes, deterministic rules verify, a person signs. The rules are the control — which is what keeps the validation package tractable, because a rule has a finite set of test cases and a model has a distribution. The full argument, and what validation demands of the architecture →
This line is the whole commercial relationship. It is short on purpose.
| Ours | Yours |
|---|---|
| The system, the deployment, the pinned versions | Validation of the system — CSV and qualification |
| An update procedure that never reaches the network | Acceptance and the quality unit’s signature |
| The evidence chain, logged per record | The decision on every flagged question |
| — | Batch release — always |
Three phases, each with what we need from you. The first is a product you can buy on its own.
The first two disqualify more enquiries in this sector than everything else combined.
Air-gapped is usually taken to mean “on our servers”. Properly it means no network path outside the perimeter — and everything the network used to do needs a replacement an inspector will accept.
| What the network normally does | What we put in its place |
|---|---|
| Pulls model weights and updates | Physical media transfer under a defined procedure — checksum verification, approval before import, an entry in the version inventory. No package manager reaches out. |
| Resolves dependencies at build time | A frozen, mirrored dependency set imported once and versioned. A build that cannot be reproduced offline is not a validated build. |
| Ships logs and telemetry out | Retention inside the perimeter, with a controlled export path for the rare case where something must leave. |
| Provides time synchronisation | A local time source. Audit-trail timestamps nobody can vouch for undermine every record they appear on. |
| Delivers security patches | A scheduled, approved cycle under the same import controls, with an agreed position on the lag between disclosure and application. |
Two roles have to exist by name and usually do not at the start — an owner of the version inventory and an owner of the import procedure. We name both in the Blueprint. The hardware we supply directly: local inference nodes sized to the site’s document volume, quoted in the same contract as the software. See private AI infrastructure.
Client names withheld under NDA. See full case studies →
A 12-person computational chemistry team whose IP counsel ruled out any cloud path — proprietary compound structures could not leave the perimeter, not even encrypted to a trusted provider. We supplied NVIDIA DGX Spark systems and RTX 6000 Ada workstations and took it from quote to a powered-on lab in four weeks. Read the case →
The same mechanic under a different rulebook: pages classified into six document types, missing signatures and stamps detected, unfilled checklist cells found, numbers cross-checked across the pack — an annotated report, then a specialist signs. Advisory by construction, exactly as here. Read the case →
The pharmaceutical project was a compute deployment, not a validated document system — it proves we put AI infrastructure inside a closed perimeter on a four-week timeline. The aviation project proves the document mechanic under a regulation, with the machine annotating and a specialist signing. Neither is a completed GxP validation package. A supplier who runs on someone else’s hosted endpoint cannot offer you either half; we would still rather you knew the limits of ours before the first call than after it.
We have not completed a GxP validation package as a supplier, and we would rather say that here than have you find out on a capability call. What we hand over is the material that makes your validation tractable: an intended-use statement approved by your process expert, a written specification with acceptance criteria agreed before testing begins, pinned and dated versions of the model, prompts, rules and runtime, a build that reproduces offline, a deterministic control layer that is cheap to qualify, and an evidence chain per record. Your quality unit executes the protocol and signs. Responsibility for validation evidence rests with the regulated company regardless of who built the system, so this is the correct division rather than a limitation of ours.
Scope first, price second, and both numbers are published. The specification is a product: the AI Solution Blueprint, one system, 5–6 weeks, from $30,000, credited in full against the build if implementation starts within 90 days. In a validated environment it also produces the intended-use statement, the version-control approach and the acceptance criteria your quality unit will test against. Builds of this kind typically start around $150,000 over 4–6 months, plus hardware where the deployment is air-gapped.
Usually the blocker is change control rather than security. A hosted model is updated on the provider's schedule: a system qualified against one version can be running on another the following week, with no notification and no record of when it changed. That is an uncontrolled change to a qualified system whatever the new version's quality. Add the inability to freeze the surrounding service and the retirement of versions you qualified against, and the evidence chain has holes you cannot close from your side.
Local inference hardware, which we can quote in the same contract, plus the procedures that replace everything the network would have done: physical media transfer with checksums and documented approval, a frozen mirrored dependency set so the build is reproducible offline, retention of logs inside the perimeter, a local time source, and a named owner for the version inventory. The hardware is the straightforward half; the procedures are what an inspector asks about.
No, and we will not build it that way. Batch release, disposition and any judgement on product quality stay with the qualified person. The system reads, checks against a specification and presents what a human must look at — it decides what needs attention, never what the answer is. If a supplier offers to automate the decision itself, that is the point to ask how they intend to validate it.
More than in any other document process we build, for a specific reason: you have to validate whatever acts as the control, and a rule is far cheaper to qualify than a model. A rule has a specification and a finite set of test cases; a model has a distribution. So the model reads unstructured input and proposes, deterministic rules verify, and the rules are what your validation package covers.
Why cloud fails on change control, what air-gapped really requires, and where the deterministic layer sits.
Read →What a review assistant can catch in a batch record, and where it has to stop.
Read →The hardware side of a closed perimeter, quoted in the same contract.
Explore →Pick one batch record type. We map it, build the check against your procedure and show you the marked-up output on your own documents — inside the Blueprint, from $30,000, credited against the build.
Not sure a project is the right first step? Free AI Readiness Score — 3 minutes.