Hridhaan Systems — evidence-grade AI for regulated decisions

Screen every document. Prove every decision.

We read research and development documents, map them against the rulebook that governs them — at a dated version of that rulebook — and return findings that cite the passage each one came from. Your expert still decides. The evidence trail is written for them.

Frameworks the engine is pointed at
US DURC & PEPP criteria EU Regulation 2021/821 Annex I Australia Group lists EU Biotech Act 21 CFR Part 11 GVP
01 — The problem

Judgement at a volume no expert team can cover

Three different functions, one shape of work: read unstructured documents, apply an external rulebook, record the reasoning, decide. Then prove it years later to someone who was not in the room.

A funder

Several hundred proposals a cycle

Must confirm none of them creates a biosecurity risk — before money is committed.

A pharmaceutical company

Every collaboration and exchange

Must screen technical content against control lists, and prove which list version applied.

A quality team

Every deviation, every investigation

Must reconstruct its reasoning for an inspector who arrives without notice.

The cost is not the reading. It is the evidence.

Guidance issued to research funders by the Nuclear Threat Initiative instructs them to limit biosecurity review to shortlisted proposals in order to conserve resources. The organisations that need this most have already written down that they cannot afford to do it properly.

3 rewrites
US policy on high-risk life sciences research was rewritten in 2024, again in 2025, and again in July 2026. The EU Biotech Act extends duties from funders to companies and laboratories.
20 years
Export-control screening software has sold into European industry for two decades. The category is proven and the willingness to pay is established.
No vendor
None was found operating at the document layer in English, German or French. The existing tools classify catalogued goods, or hand you a self-assessment questionnaire.
02 — What it produces

Not an answer. An assessment you can defend.

Every question in the framework is answered explicitly, and every answer quotes the sentence that drove it. A reviewer checks the quotes rather than re-reading the document.

Input — submitted proposal34 pages
§ 2.1  Proposed work The programme will construct chimeric viruses carrying surface glycoproteins from bat-derived sarbecoviruses on a laboratory backbone, and passage the resulting constructs through a humanised animal model to characterise replication kinetics. § 2.4  Containment All work involving live virus is conducted under BSL-3 containment, with challenge studies performed in the partner facility. § 5.2  Prior work (excluded from assessment) Previously the group completed a serological survey using archived human sera…
Output — assessment recordrule pack 01
Q1 · Live pathogens or virus construction
Yes

Construction of chimeric viruses is explicitly proposed.

§ 2.1, ¶1
Q2 · Controlled-list, RG3/4 or novel agent
Yes

Sarbecovirus-derived constructs; containment level stated by the applicant corroborates.

§ 2.1, ¶1 · § 2.4, ¶1
Q3 · Enhanced epidemic or pandemic potential
Yes

Chimeric construction combined with passage through a humanised host is capable of enhancing a viral characteristic.

§ 2.1, ¶1
Scope control
Prior work excluded

§ 5.2 describes completed work and is not assessed. Only proposed work drives the outcome.

Outcome
Highest risk grade — mandatory expert review

Routed to a named assessor with the findings, the citations, and a drafted memo. Hridhaan does not approve or reject anything.

Illustrative example using publicly described policy criteria. No customer document is reproduced.

03 — The engine

One pipeline. Five rule packs.

The engine does not change between use cases — only the rulebook it is pointed at, and the dated version of that rulebook in force at the moment of assessment.

01

Read

Proposals, protocols, SOPs, technical files and submissions — in full, not titles and abstracts.

02

Map

Against an external framework, at a specific dated version of that framework.

03

Cite

Structured findings, each one quoting the exact source passage it came from.

04

Record

A complete audit trail: what was assessed, against which rule version, by whom, when.

05

Route

To a named human reviewer, who makes the decision and signs it.

04 — Evaluation

How we know a rule pack is right

Anyone can produce a confident classification. The question a regulated buyer asks is how you measured it, and what happens when you are wrong. Each rule pack is built against an expert-labelled evaluation set drawn from the customer's own historic decisions, and no version ships until it clears the gate.

Release gateEvery rule pack version, before it reaches production
  • Agreement with expert consensus Scored against the labelled set, at a threshold agreed with the customer in writing before work begins.
  • Zero misses on designated critical criteria The customer names the criteria where a false negative is unacceptable. Those are measured separately, and they gate the release.
  • Determinism verified The same document, against the same rule pack version, returns the same findings on repeated runs — and again months later.
  • Fails closed, never open A document the system cannot assess is escalated for mandatory human review, not returned as an error and quietly waved through.
  • Validation pack generated The documentation your quality function needs to sign the system off for its intended use is produced by the release, not written afterwards by hand.
05 — Rule packs

Five rule packs, in the order we intend to build them

Same engine. Different rulebook. Each one produces the artifact its buyer already has to write by hand.

06 — Deployment

It runs inside your tenant. Documents never leave.

Rule packs and logic arrive as signed, versioned bundles over an outbound connection — the same pattern any licensed enterprise software uses. Where no outbound connection is permitted at all, the same bundle is delivered as a signed offline package.

Residency

Your environment

Confidential proposals, patient data and trade secrets stay where they already are.

Updates

You choose when the rules change

A rule pack version changes when you accept it — and every assessment records which one it ran against.

Air-gapped

Offline delivery

Signed offline packages where an outbound connection is not permitted.

07 — The obvious question

Why not just use a general assistant?

Because it reads well. That is not the part you are being audited on.

General assistant Hridhaan
Same input, same output The model is upgraded underneath you, without your consent and on the vendor's schedule. Model, prompt and rule pack are pinned and recorded. The assessment is re-runnable years later.
Which rulebook applied Whatever version it happens to recall, unstated. The dated framework version is recorded on every assessment, because that is what you will be asked.
Evidence A fluent summary. Citations if you remember to ask, and not always to the right passage. Every finding quotes the passage that triggered it, located to section and paragraph.
Validation No vendor will sign that it is validated for your intended use. Validation documentation is generated per release, against an evaluation set built from your own decisions.
Your systems of record Reads. Does not write into a safety or quality system. Writes back under formal change control, with e-signature and audit trail.
Accountability Sits with whoever pasted the document in. Contractual, and named.

Intelligence gets cheaper with every model release. Accountability does not. Model releases commoditise intelligence, not evidence.

Start here

A fixed-scope assessment engagement, on your own documents

Four weeks. Your documents, your frameworks, inside your environment. It produces measured baseline numbers and a working prototype. Success criteria and the route to production are agreed in writing before it starts.

Book a call

Or write to hello@hridhaan.ai.