Compiler spine
Source -> tests -> findingsArtifact versions, source bindings, provider snapshots, source maps, citations, and package manifests stay linked.
Regulatory compiler for SaMD teams
Cairn turns source artifacts, work-system snapshots, strategy, and regulatory constraints into typed, cited, replayable compliance signals.
Start with read-only audit evidence, then graduate to gated workflow assistance after source, security, and legal posture are approved.
Compiler spine
Source -> tests -> findingsArtifact versions, source bindings, provider snapshots, source maps, citations, and package manifests stay linked.
CI-for-compliance
Runs on product changePRs, Jira changes, document updates, imports, and scheduled package checks can produce stable results and cited logs.
Write posture
Would-write firstExternal comments and tasks require trigger envelopes, deterministic validation, output records, idempotency, and replay.
Human floor
No AI approvalsAI can propose, draft, detect, explain, route, and prepare evidence; humans retain signatures and final dispositions.
How it works
Cairn fits around the work systems your team already uses, then makes source freshness, traceability, package gaps, and human decisions visible.
Map intended use, submission path, source systems, corpus boundaries, and what Cairn is allowed to mirror.
Cairn records artifact versions, external source bindings, provider snapshots, sync health, and stale-source warnings.
The compiler evaluates catalog checks against mirrored evidence, strategy, and traceability endpoints.
Suggested updates, comments, and package sections move through explicit review queues before any controlled decision.
Cairn shows freshness, changes, failures, approvals pending, and replay history while source systems remain authoritative.
CI-for-compliance
Results cite source versions, mirror freshness, test definitions, and review posture so teams can rerun, waive, or route them with evidence.
Launch paths
Cairn is launching around bounded pilot paths that keep source authority, human decisions, and external writes explicit from the first conversation.
Late-stage SaMD teams that need independent visibility into De Novo, 510(k), or internal audit evidence without changing source systems.
Output: Cited findings, traceability gaps, stale-source warnings, and a replayable audit report.
Teams that want compliance checks to run near product work while comments, tasks, and suggested updates remain gated would-writes.
Output: Review queues, prepared external outputs, validator records, and idempotent replay artifacts.
New product teams that want source mirror, strategy, compliance tests, and human review queues wired before evidence starts drifting.
Output: A governed compiler workspace for source freshness, traceability, findings, package readiness, and human decisions.
Product surfaces
Cairn does not need to become the authoring home for every artifact. It watches, compiles, routes, and records the evidence needed for regulated work.
Defensible mirrored state for GitHub, Jira, docs, uploads, and historical package exports, including freshness and provenance.
Versioned deterministic, evidence-check, AI-judgment, and manual-review checks that users can inspect before trusting outputs.
Candidate and confirmed links between requirements, risks, controls, tests, evidence, claims, and package sections.
Comments, draft tasks, and suggested document updates are prepared as would-writes with validation and replay records.
Quality, regulatory, consultant, and engineering owners keep final authority over approvals, releases, signatures, and risk.
Cited, replayable package views for audits, consultant review, signoff preparation, and submission readiness discussion.
Security and regulatory trust
Cairn can propose and prepare evidence, but controlled quality decisions remain bounded by human review, policy, permissions, and audit records.
Data posture
Trace redaction events and evidence package manifests
Security
Support access grants, sessions, and auth events
Source integrity
Source artifact versions, sync states, and compiler run artifacts
Regulatory authority
Catalog version, rubric snapshots, and review queue events
| Boundary | Posture |
|---|---|
| Approvals, release, and signatures | AI never signs, approves, releases, or closes controlled quality records. |
| External writes | Would-writes require trigger envelopes, deterministic validation, output records, idempotency, and replay. |
| Final risk and submission decisions | Humans retain final risk acceptance and final submission-required determinations. |
| Customer systems of record | Cairn mirrors source systems and routes work back to them; it does not force day-one QMS replacement. |
Pilot waitlist
Pilot conversations start with corpus scope, security posture, source-of-truth boundaries, and read-only audit fit.
SaMD founders, quality leaders, and regulatory consultants
Your request is stored for fit review only and never shared.