Three design rules
In this order. The first is non-negotiable; the second and third are what make the system usable in regulated work.
Private by design
The system runs on hardware you control. Documents, questions and answers stay inside your perimeter. No cloud model, no external API, no telemetry. This is a design principle, not a configuration option.
Traceable
Every answer points to the document and passage it came from. You can open the source and check. An answer without a source is not an answer.
Refuses rather than guesses
When the documents do not contain the answer, the system says so. A confident wrong answer is worse than no answer — in regulated work it is a finding waiting to happen.
Boundaries
- We do not host your data or route it through any cloud AI service.
- We do not claim our tools are validated GxP systems. They are demonstrators; validation happens in your quality system, with your evidence.
- We do not put language models in the path of GMP-critical decisions. The draft EU GMP Annex 22 (consultation text of 7 July 2025; final text expected end of 2026) excludes generative AI from critical GMP applications, and we design accordingly.
- We do not build systems that synthesise, summarise or "interpret" regulations across documents and present the result as fact.
Where you can check
Whether the three rules hold with today's open-weight models is a fair question. OwnedPulse is built on exactly these rules and published as open source, so the approach can be inspected rather than taken on trust. Client systems follow the same rules and remain private.
What "demonstrator" means here. OwnedPulse shows that private, traceable, refusal-capable document AI works on modest hardware. It has not been validated under any client's quality system. Any deployment in a GxP context requires your own validation, and we will tell you so in the first call.