Your protocol stays in your cloud. The intelligence still arrives.
Protocol Safe is the architecture that lets sponsors run attribution intelligence on protocols they hold: a fail-closed content boundary, inside your environment, auditable end to end.
audit · every crossing logged
row-level, end to end
sponsor cloud · your environment
content boundary middleware · fail-closed
G3 · Anemia
WHO-UMC · Probable
CTCAE v6.0 · 10002272
the protocol stays on this side of the line
Here is exactly where the line sits.
Attribution intelligence that runs on a protocol you keep. The protocol stays inside your cloud, and the boundary is fail-closed by architecture.
your cloud
Your protocol
Unpublished, and it stays here.
Your patient records
The notes, the labs, the PHI.
A retrieval agent you host
It reads the protocol and answers questions about it.
ours
The engine
It holds no copy of your protocol and stores none of your credentials.
a scoped question
“which CTCAE version does this study name?”
an answer, scoped to that question
“v6.0”
The engine sits outside and asks. Your protocol, your records and the agent that reads them stay inside. A question and its answer are the only things that cross.
The engine runs where your protocol already lives.
Decision support, human-led governance, auditable, defined context of use, inspection-ready.
- 01
Decision support
- 02
Human-led governance
- 03
Auditable
- 04
Defined context of use
- 05
Inspection-ready
Your team sees the whole record, and a citation is what travels.
YOUR TEAM SEES
Stays in your cloud
- The protocol
- Amendments
- Alert thresholds
WHAT CROSSES
Arrives from the engine
- Graded events
- Attribution scores
- Citations
Built so your counsel can say yes.