New Research The Proof Gap in Healthcare AI — Why compliance claims aren't enough Read the White Paper →
AI2 Incubator · Cloudflare Launchpad

Your AI works. Prove it to procurement.

The Evidence Pack Sprint gives your security and legal teams the evidence they actually need — proof your controls ran, not just that policies exist.

Days Not months
Board-ready Deliverables
Proof Not just policy PDFs
evidence-pack
# Your Evidence Pack includes:

Controls Mapping (NIST AI RMF + ISO 42001)
Architecture Security Summary
Evidence Attestation Report
Vendor Security Ready-Pack
Board Summary (1-pager)

→ Exports: PDF, OSCAL, questionnaire formats
Cloudflare Launchpad AI2 Incubator
Built in Rust
Ed25519 + Merkle
The Problem

Why Your Deals Are Stuck

Your product works. Your compliance story doesn't.

Missing Evidence

Security questionnaires ask for evidence you don't have structured. You have controls — you just can't prove they ran.

Endless Reviews

BAA reviews drag because your AI architecture isn't documented their way. Every new prospect means starting from scratch.

Policy ≠ Proof

Compliance teams want proof controls actually ran — not policy docs. A Google Doc saying "we follow HIPAA" doesn't cut it.

The Solution

The Evidence Pack Sprint

A focused engagement that produces the compliance evidence healthcare buyers actually request. Documentation your security team can hand directly to procurement — plus proof your controls work, not just exist.

1

Scope

We review your architecture and align on your prospect's security requirements.

2

Build

Integrate attestation, generate evidence, map controls to their framework.

3

Package

Format deliverables for security team, legal, and board consumption.

4

Handoff

You receive the Evidence Pack. We brief you on how to present it.

Controls Mapping

Maps your existing controls to NIST AI RMF + ISO 42001 frameworks buyers recognize.

Evidence Attestation Report

Proves your safety controls executed — timestamped, cryptographically signed, verifiable.

Vendor Security Ready-Pack

Pre-formatted answers to the security questionnaire items healthcare procurement teams actually ask.

Board Summary

Executive-ready 1-pager for internal approvals and investor updates.

Fit Check

Is This For You?

Healthcare AI Vendors
Your product works, but deals stall in security review
Founders
Fielding the same compliance questions on every enterprise call
Teams with Controls
You have the right controls — you just can't prove they ran
Pre-SOC 2 / HITRUST
You need AI-specific evidence those frameworks don't cover

Not a fit if: You're pre-product (no AI in production yet), or you need general IT compliance (try Vanta, Drata, etc.)

The Difference

Why Evidence Beats Documentation

Policy docs describe what you should do. Evidence proves you did it.

Security Teams Are Skeptical

They've seen too many vendors check boxes without real controls. Timestamped attestations that controls ran shift the burden from interrogation to verification.

"We Follow HIPAA" Isn't Enough

They want proof your AI doesn't leak PHI, hallucinate clinical guidance, or make undocumented decisions. The Evidence Pack provides that proof.

Accountability, Not Just Attestation

Security teams want proof you can enforce controls — not just attest to them. Evidence of runtime execution changes the conversation from "trust us" to "verify us."

FAQ

Questions We Hear

We already have SOC 2 / are working toward HITRUST.

Great — those cover IT controls. The Evidence Pack addresses AI-specific risks (model behavior, decision audit trails, content safety) that SOC 2 and HITRUST don't. They're complementary.

Is this just documentation? We can write docs ourselves.

The Evidence Pack includes documentation, but the core value is proof. We generate verifiable evidence that your controls actually executed — something a Google Doc can't do.

What if we're not ready for a full compliance program?

The sprint is designed for teams who need to unblock deals now. It's a fixed-scope engagement, not a multi-month program. You can expand later if needed.

Research

The Proof Gap in Healthcare AI

Why compliance claims are no longer enough — and the evidence standard healthcare organizations should demand.

White Paper
16 Pages • December 2025
  • The Three-Layer Problem in AI security
  • Case studies: Ambient scribe hallucination, chatbot PHI disclosure
  • Regulatory timeline: Colorado, EU AI Act, California ADMT
  • 10 questions for your AI vendor security review
"Static compliance documentation — SOC 2 reports, architecture diagrams, policy attestations — demonstrate that controls exist but cannot prove they ran for any specific interaction."
JS
Jennifer Shannon, MD
Chief Medical Officer, GLACIS
Read the White Paper
Why This Exists

Built by People Who've Been There

"We built GLACIS because we shut down our own healthcare AI company over compliance risk. The evidence problem isn't theoretical — it's why good products die in procurement."

— Joe Braidwood, CEO
Previously: SwiftKey (1B+ devices, acquired by Microsoft)

AI2 Incubator
Cloudflare Launchpad

Stop Losing Deals to Security Review

Book a 30-minute call. We'll confirm fit and scope your Evidence Pack Sprint.

We'll usually respond within a day. No sales deck — just a fit conversation.