Draft boundary
What it is for
Helping authorised healthcare staff find, organise and review time-sensitive coordination work. The draft does not authorise diagnosis, treatment, autonomous action, or relying on it without a person checking.
Trust and safety
controls, not claims
This is our public control plan. It says what has to exist before anything is released, and keeps that separate from what is actually in place today.
We do not claim FDA clearance, proven clinical benefit, or a finished quality system. None of those are true yet.
The control plan
status attached
Each item below carries its real status. Where it says a decision or an owner is still required, that is because one is.
Draft boundary
Helping authorised healthcare staff find, organise and review time-sensitive coordination work. The draft does not authorise diagnosis, treatment, autonomous action, or relying on it without a person checking.
Formal determination required
Whether this counts as clinical decision support, or as a medical device, has to be assessed against the final intended use, the outputs, who uses it, how explainable it is, and how much independent review sits in front of it.
Implementation roadmap
Requirements, design inputs, hazards, controls, tests, evidence, releases, changes, complaints and corrective actions all have to stay traceable to each other.
Named ownership required
A clinical safety officer has to own hazard review, escalation criteria, use restrictions, incident analysis and release recommendations. That person does not exist yet.
Validation gate
Real clinicians, patients and support people have to test comprehension, teach-back, workflow fit, overrides, abstention, alert burden, accessibility, language access, and the ways it could foreseeably be misused.
Secure-by-design target
Threat modelling, Zero Trust, mutual authentication, role-based access, encryption, secrets management, dependency control, SBOM maintenance, vulnerability response, auditability, incident containment and recovery testing.
Minimum necessary
No patient data belongs on this website. In the product, collection has to be purpose-limited, consent-aware, jurisdiction-aware, kept only as long as needed, and governed by contract. Access granted to someone acting for a patient must be scoped, reviewable, and expiring or revocable.
First BAA
RootBound Health is our first BAA-governed healthcare relationship. It has no ownership or operating role. The agreement creates contractual privacy and security duties; it does not on its own authorise research, secondary use, model training, publication, or commercialising protected health information.
Ship gate
Performance and workflow effects have to be evaluated across dimensions chosen in advance. A model that looks accurate overall but fails a subgroup does not pass.
Revalidation required
Material changes to the data, the features, the architecture, the output, the intended use or the setting require an impact assessment and proportionate revalidation.
Pre-launch requirement
Drift, calibration, alerts, overrides, incidents, subgroup performance, uptime, data quality, complaints, whether messages arrived, whether they were understood, and whether the repair actually worked.
Accountability
before, during, after
Before a pilot
Intended use, regulatory classification, data governance, quality ownership, clinical safety ownership, threat model, human-factors protocol, and the monitoring plan.
During a pilot
One workflow, trained users, no autonomous clinical action, metrics agreed in advance, documented overrides, stop rules, and a path for escalating incidents.
After a pilot
Independent analysis, subgroup evaluation, complaint and incident review, change assessment, and a written decision to stop, revise, validate further, or proceed.
The eight rules a build has to pass, and the gates a model has to clear, are on the evidence page.