We read research and development documents, map them against the rules that govern them, and return citation-backed, auditable output. The decision stays with the expert. The evidence trail is produced for them.
Illustrative output. Every finding cites the passage that triggered it, against a dated version of the rulebook.
Regulated organisations are asked to assess documents faster than their experts can read them, then to reconstruct the reasoning years later for someone who was not in the room.
Must confirm that none of them creates a biosecurity risk — before money is committed.
Must screen technical content against export control lists, and prove which list version applied.
Must reconstruct its reasoning years later, for an inspector who arrives without notice.
All three are the same shape of work: read unstructured documents, apply an external rulebook, record the reasoning, decide.
Today this is done by hand. The cost is not the reading — it is the evidence. Guidance issued to research funders by the Nuclear Threat Initiative instructs them to limit biosecurity review to shortlisted proposals in order to conserve resources. The organisations that need this most have already written down that they cannot afford to do it properly.
General assistants have made the reading cheap. They have not made the evidence admissible.
The engine does not change between use cases — only the rulebook it is pointed at, and the dated version of that rulebook in force at the moment of assessment.
Proposals, protocols, SOPs, technical files and submissions — in full, not titles and abstracts.
Against an external framework, at a specific dated version of that framework.
Structured findings, each one quoting the exact source passage it came from.
A complete audit trail: what was assessed, against which rule version, by whom, when.
To a named human reviewer, who makes the decision and signs it.
The output is not an answer. The output is a decision-ready evidence pack.
Findings, citations, confidence, and the documentation a reviewer or an inspector will ask for.
Same engine. Different rulebook. Each one produces the artifact its buyer already has to write by hand.
Screens research proposals for content that could create biosecurity or dual-use risk, before funding is committed.
Screens technical content and intangible transfer against control lists, and records the dated version applied.
Triages incoming adverse event cases and drafts the narrative, inside a validated environment.
Assembles the evidence base for a quality investigation and drafts the reasoning, on top of the existing quality system.
Checks a submission for internal contradiction across modules before it goes to the agency.
Rule packs and logic arrive as signed, versioned bundles over an outbound connection — the same pattern any licensed enterprise software uses. Where a customer permits no outbound connection at all, bundles are delivered as signed offline packages.
Confidential proposals, patient data and trade secrets stay where they already are.
You choose when a rule pack version changes, and every assessment records which one it ran against.
Where no outbound connection is permitted, the same bundle is delivered as a signed offline package.
This matters commercially as much as technically: it removes the largest procurement objection before it is raised, and it keeps a single codebase across every customer.
Intelligence gets cheaper with every model release. Accountability does not. Four things survive the next frontier model, and they are the product.
A regulated workflow needs the same input to return the same output three years later, or a documented reason why not. That guarantee cannot be given by a vendor whose business depends on continuous upgrade.
Someone must sign that the system is validated for its intended use. The foundation model vendors will not sign. Transferring that accountability is the product.
The model knows the world. It does not know this organisation's interpretation of Annex I, or its SOP hierarchy. That is curation work — labour, not intelligence — and model releases do not erode labour.
A general assistant reads. It does not write into a safety database or quality system under change control, with e-signatures and an audit trail that satisfies 21 CFR Part 11.
The product is partly unglamorous plumbing — versioning, signatures, documentation, audit. That is the good news: model releases commoditise intelligence, not plumbing.
US policy on high-risk life sciences research was rewritten in 2024, again in 2025, and again in July 2026. The EU Biotech Act extends duties from funders to companies and laboratories.
Closing the evidence gap works against the general assistants' own business model, because it would mean freezing model versions on a customer's behalf.
The adjacent export-control software market has sold list-based screening for twenty years — the category and the willingness to pay are established. No vendor was found operating at the document layer in English, German or French.
The window is real but not permanent. Established vendors can build this once the market is visibly large. The defence is to be inside a validated workflow before that happens.
Four weeks. Your documents, your frameworks, inside your environment. It produces measured baseline numbers and a working prototype. Success criteria and the route to production are agreed in writing before it starts.
Book a callOr write to hello@hridhaan.ai.