Software the NHS will buy. Evidence the trust can trace.
Information governance due diligence, DTAC and DSPT all ask the same thing in different words: where does this evidence come from. An engineer joins your team for four weeks, and what stays is a record that answers it.
The evidence exists. Nobody can say where it came from.
- The technical file is a folder, and the evidence pack is hand-built from email and a spreadsheet.
- “I don’t know where it comes from” is the honest answer when a trust asks.
- Someone has to review a document and someone has to approve it, and today the approver is often the author.
- DTAC asks whether your product meets WCAG 2.2 AA and for a link to your statement.
- Every buyer repeats the same due diligence, and a framework listing does not reduce it.
- Selling at all means building evidence, and it is the slowest part of the sale.
The buyer is not asking whether you are careful. They are asking you to show where each answer came from.
In. Build. Leave. Prove.
One job, four weeks, in production. Then it keeps proving itself.
In
The job, the documents or product it touches, and who reviews and who approves.
Build
Built in your environment, alongside your team, with the review order enforced from day one.
Leave
Your team runs it, and the evidence keeps assembling itself as you work.
Prove
Every version: who reviewed, who approved, when, and whether it has changed since.
Three jobs a four-week deployment could take.
- AI drafts and updates your controlled documents, with nothing approved without a named signature, no self-approval, and edits outside the process showing up.
- The evidence pack a trust asks for, assembled from the approved record, each item tracing to its source.
- The accessibility audit and statement a public buyer asks for, run in-house on every release and kept current. Live today, and no AI judges it.
- Whichever we start with, the record is the same: what was allowed, what happened, who signed.
Where does this evidence come from, and was it approved by someone other than its author?
What the AI is allowed to do is written down first.
Every decision is checked against those rules before it happens.
A named person signs it off. The check produces the evidence; a person judges.
You can replay the whole history any day and get the same answer.
If anyone changes it later, it shows. Patent pending, UK application GB2620101.2.
That is what a deployment leaves running for your job. In the accessibility product today, a person on your team accepts every finding before it reaches your record.
Who this is for.
- Digital health and medical software teams selling into the NHS.
- Quality and regulatory leads who assemble the evidence pack by hand today.
- Founders whose sale stalls on information governance due diligence rather than on the product.
Not for
A certification service. We do not audit you or issue a mark; we build the job and leave the record.
Two people, on every call and in your standup.
Simon Milner, Founding Architect
He designed the record: what the AI is allowed to do, checked before it acts, and replayable afterwards. Twenty-five years in Silicon Valley before that.
Jason Crispin, Founder
He owns the customer side of every deployment: what the job is, what it is worth, and that it lands. He is on the first call and every one after.
Patent pending, UK application GB2620101.2. Meet the team
Four weeks, then it keeps proving itself.
Week 1
The baseline
What the job is, what allowed means for it, and who signs. Written down before anything runs.
Weeks 2 to 4
The build
Our engineer works in your codebase next to your developers. The old way and the new way run side by side.
Week 4 on
The proof
Every decision checked and recorded. Replay it any day. We maintain it, or you run it without us.
What you keep
- The job, live, in your product or your quality system.
- The code, assigned to you in writing.
- The approved record, with every version traceable.
- The accessibility audit and statement, kept current by your team.
What people ask.
Does this give us DTAC or DSPT?
Does this give us DTAC or DSPT?
It gives you the evidence those ask for, assembled from a record rather than from email and a spreadsheet. DTAC asks whether your product meets WCAG 2.2 AA and for a link to your accessibility statement; the accessibility product answers both, today.
Do you do ISO 13485 or IEC 62304 packs?
Do you do ISO 13485 or IEC 62304 packs?
Not today. The sign-off and record layer is live, and accessibility evidence is live. Clause-mapped packs for those standards are designed, not built, and we will not sell you something that does not exist.
Can AI write our controlled documents?
Can AI write our controlled documents?
It can draft and update them. Nothing is approved without a named human, the review runs in a fixed order with no self-approval, and an edit made outside the process shows. A named person always re-reviews.
Is the accessibility audit automated?
Is the accessibility audit automated?
No. It is a guided audit your team answers, page by page or screen by screen, and every verdict is recorded against the person who made it. There is no AI judging compliance.
Where does the evidence come from?
Where does the evidence come from?
From the approved record itself. Each item traces to the version it came from, who reviewed it, who approved it and when, which is the question an information governance review actually asks.
What does it cost?
What does it cost?
The accessibility product has published pricing. A deployment is scoped on the call.
Which piece of evidence takes longest to assemble?
Thirty minutes with Simon and Jason. Bring the due diligence questionnaire or the document set, and you leave knowing what it would take.