For clinical & regulated

A verifiable record of AI use in clinical and regulated writing

The next finding your sponsor logs could be about AI use in the protocol. When it lands, you have two choices: reconstruct the reasoning from memory, or open a packet. This is the packet — the traceability layer that sits alongside your writing and produces sponsor-ready audit records without asking anyone to take their word for it.

SOC 2 Type II
Readiness in progress
GDPR / CCPA
Rights honored
21 CFR Part 11-aware
Record-keeping principles
Independent verify endpoint
Public-key signed

Who it is for

Built for the teams who have to prove — not promise — AI usage

Regulated writing has never asked authors to be trusted. It has asked them to be verifiable. RedInkAI makes that possible for AI-assisted work.

Clinical trial sponsors & CROs

Attach an Authorship Packet to any AI-assisted protocol, IB, or CSR section. Show sponsors and CROs which sections had AI input, what was accepted, what was rejected, and who reviewed each decision.

Regulatory affairs teams

Preserve the human-review provenance behind every AI-drafted submission section. Package the record as a signed PDF ready for internal QA review and external audit trails.

Pharmacovigilance & medical writing

Capture the reviewer decisions layered on top of any AI-drafted safety narrative or case report. The medical writer's judgment stays visible in the record — not lost between drafts.

What you get

Four pillars of institutional governance

Tamper-evident authorship records

Every AI-assisted draft produces a cryptographically chained record of consultations, decisions, and revisions. Your editorial board, IRB, or integrity office can verify any claim independently at /verify/{id}.

Institutional governance built-in

Per-institution policy controls, role-based access, audit log retention, and admin-grade visibility into AI use across departments and submissions.

Built for compliance review

Aligns with NIST AI RMF documentation expectations, COPE position on AI in scholarly writing, and emerging IRB AI policies. Independent verification endpoint included.

No proprietary lock-in

Cognitive Audit Reports are portable JSON + PDF artifacts. Your institution owns the data. We provide infrastructure, not gatekeeping.

The objection every committee will raise

"Can someone fabricate an InkTrail after the fact?"

Short answer: no. Long answer is the whole point of the product. Here is exactly how a committee can verify any record an institution generates.

Server-side timestamps

Every event carries a UTC timestamp set by our server, not the user's machine. Backdating a session is not a question of permissions, it is mathematically prevented.

Tamper-evident integrity

Each event is cryptographically linked to the state of the record before it. Any insert, delete, or modification is instantly detectable on the next read — the record self-verifies without needing us.

Locked attestation states

When an attestation PDF is generated, the underlying session is sealed. Any subsequent edits create a new linked session, preserving the original record verbatim. The lock is enforced server-side.

Prompt versioning

The exact AI prompt used at the time of each consultation is hashed and recorded. A future prompt change cannot retroactively alter what was logged.

Cross-user access prevention

Adversarial tests confirm a user cannot read, write, or modify another user's trail. Audit logged at the API layer.

Independent verification endpoint

Verify URLs (`/verify/{id}`) are public and stateless. A reviewer can verify chain integrity, source attribution, and adoption metrics without an account, without trusting RedInkAI, and without contacting us.

Adversarial testing, public

Our 21-test adversarial suite covers hash chain tampering, timestamp spoofing, lock bypass, and cross-user access attempts. The suite runs on every release and the results are available to any institution under NDA before signing. Most institutional buyers consider this the strongest single piece of evidence we can offer.

Institutional licensing

Three scopes. One annual contract.

Pricing is set per institution against your scope, governance posture, and integration needs. Every tier includes a 6-month no-cost pilot for qualifying institutions in 2026.

Department

Custom
tailored to your scope

A single department, journal, or IRB committee.

Up to 50 contributors

  • All of Premium and Professional, organization-wide
  • Branded /verify/{id} subdomain
  • Per-document attestation PDFs with custom institutional template
  • Basic admin dashboard with user-level audit visibility
  • Quarterly check-in with the founder
  • Email support, 1 business day response
Most pilots start here

Institution

Custom
tailored to your scope

A research office, school within a university, or mid-size journal publisher.

Up to 250 contributors

  • Everything in Department
  • Multiple departments under one billing
  • SSO via SAML or OIDC
  • Dedicated success contact
  • Custom IRB / journal / department attestation templates
  • Quarterly aggregate compliance report
  • Phone + email support, 4 business hour response

Enterprise

Custom
tailored to your scope

Full universities, large publishers, government research offices.

Unlimited contributors

  • Everything in Institution
  • On-prem or single-tenant cloud option
  • Custom data retention policies
  • White-label / co-branded option
  • Dedicated CSM with quarterly executive review
  • Priority feature requests
  • 99.9% uptime SLA

Start a pilot

Six-month pilot, no cost, real results

We onboard up to 50 contributors at your institution, generate real attestations on real submissions, and produce an end-of-pilot report you can take to your governance committee.

The founder will personally reply within 24 hours.

Prefer email? Reach the founder directly at redinkaistudio@redinkai.com

Honest claims

What we deliberately do not claim

We’d rather be under-claimed and defensible than over-claimed and questioned. The list below is what we intentionally leave off — and why.

  • ×"21 CFR Part 11 compliant" — formal Part 11 compliance requires a validated system context we do not currently ship. We are 21 CFR Part 11-aware.
  • ×"GxP validated" — requires a full IQ/OQ/PQ validation pack the sponsor typically owns. Not us.
  • ×"Replaces sponsor validation obligations" — our record is an input to your validation work, not a substitute for it.

Want the point-by-point Part 11 control mapping for your validation team?

Read the 21 CFR Part 11 readiness doc

Every 90 days we run an adversarial audit against our own hash chain, timestamps, and access controls — and publish the pass/fail rollups.

Read the latest False-Positive Validation report

Bringing this to a compliance officer or head of research? Read (or download) our 7-section pilot brief.

Read the Institutional Pilot Brief

FAQ

Common clinical & regulated questions

Is RedInkAI 21 CFR Part 11 compliant?

We are 21 CFR Part 11-aware — RedInkAI is designed with the record-keeping principles of Part 11 in mind (timestamped events, tamper-evident chain, unique attribution, permanent audit trail, controlled access). We do not represent RedInkAI as an independently validated Part 11 system. Use of RedInkAI records inside a validated environment remains the sponsor or CRO's responsibility. We're happy to provide technical documentation supporting your own validation work.

Do you claim GxP validation?

No. Formal GxP validation requires a documented Computer System Validation package (IQ / OQ / PQ) that we do not currently ship. What we do provide is a technical control set aligned with GxP record-keeping expectations, and we cooperate fully with sponsor-side validation efforts.

How does the record survive a sponsor audit?

Every event is timestamped by our server (not the user's machine), cryptographically chained to prior events, and verifiable at a public /verify/{id} endpoint that does not require an account. A sponsor auditor can independently confirm chain integrity, timestamps, and source attribution without contacting RedInkAI. That is what "tamper-evident" means in practice.

Can we run RedInkAI on our own infrastructure for sensitive studies?

The Enterprise tier includes single-tenant cloud or on-prem deployment for pharma/CRO buyers with confidentiality requirements above what a shared multi-tenant environment can satisfy. That deployment mode retains the same public verify endpoint scheme via keys the sponsor controls.

How does this help with sponsor-side AI-use disclosure?

When a sponsor asks "which parts of this protocol had AI involvement?", the Authorship Packet answers with specifics: which sections, which models were used, what was prompted, what the human writer kept vs. rejected, and when. That is materially more auditable than a signed disclosure box.