Compiler spine
Source -> tests -> findingsArtifact versions, source bindings, provider snapshots, source maps, citations, and package manifests stay linked.
Regulatory compiler for SaMD teams
Cairn turns source artifacts, work-system snapshots, strategy, and regulatory constraints into typed, cited, replayable compliance signals.
Start with read-only audit evidence, then graduate to gated workflow assistance after source, security, and legal posture are approved.
Compiler spine
Source -> tests -> findingsArtifact versions, source bindings, provider snapshots, source maps, citations, and package manifests stay linked.
CI-for-compliance
Runs on product changePRs, Jira changes, document updates, imports, and scheduled package checks can produce stable results and cited logs.
Write posture
Would-write firstExternal comments and tasks require trigger envelopes, deterministic validation, output records, idempotency, and replay.
Human floor
No AI approvalsAI can propose, draft, detect, explain, route, and prepare evidence; humans retain signatures and final dispositions.
How it works
Cairn fits around the work systems your team already uses, then makes source freshness, traceability, package gaps, and human decisions visible.
Map intended use, submission path, source systems, corpus boundaries, and what Cairn is allowed to mirror.
Cairn records artifact versions, external source bindings, provider snapshots, sync health, and stale-source warnings.
The compiler evaluates catalog checks against mirrored evidence, strategy, and traceability endpoints.
Suggested updates, comments, and package sections move through explicit review queues before any controlled decision.
Cairn shows freshness, changes, failures, approvals pending, and replay history while source systems remain authoritative.
CI-for-compliance
Results cite source versions, mirror freshness, test definitions, and review posture so teams can rerun, waive, or route them with evidence.
Product surfaces
Cairn does not need to become the authoring home for every artifact. It watches, compiles, routes, and records the evidence needed for regulated work.
Defensible mirrored state for GitHub, Jira, docs, uploads, and historical package exports, including freshness and provenance.
Versioned deterministic, evidence-check, AI-judgment, and manual-review checks that users can inspect before trusting outputs.
Candidate and confirmed links between requirements, risks, controls, tests, evidence, claims, and package sections.
Comments, draft tasks, and suggested document updates are prepared as would-writes with validation and replay records.
Quality, regulatory, consultant, and engineering owners keep final authority over approvals, releases, signatures, and risk.
Cited, replayable package views for audits, consultant review, signoff preparation, and submission readiness discussion.
Security and regulatory trust
Cairn can propose and prepare evidence, but controlled quality decisions remain bounded by human review, policy, permissions, and audit records.
Data posture
Trace redaction events and evidence package manifests
Security
Support access grants, sessions, and auth events
Source integrity
Source artifact versions, sync states, and compiler run artifacts
Regulatory authority
Catalog version, rubric snapshots, and review queue events
| Boundary | Posture |
|---|---|
| Approvals, release, and signatures | AI never signs, approves, releases, or closes controlled quality records. |
| External writes | Would-writes require trigger envelopes, deterministic validation, output records, idempotency, and replay. |
| Final risk and submission decisions | Humans retain final risk acceptance and final submission-required determinations. |
| Customer systems of record | Cairn mirrors source systems and routes work back to them; it does not force day-one QMS replacement. |
Pilot waitlist
Pilot conversations start with corpus scope, security posture, source-of-truth boundaries, and read-only audit fit.
SaMD founders, quality leaders, and regulatory consultants
Posts to /api/v1/waitlist. Stored as metadata_hash_redacted_excerpt; live delivery is false.