We use essential cookies to keep the site working. We’d also like to use analytics cookies to understand which pages are useful — only if you’re comfortable. Your choice, revocable at any time from the footer.
For clinical & regulated
The next finding your sponsor logs could be about AI use in the protocol. When it lands, you have two choices: reconstruct the reasoning from memory, or open a packet. This is the packet — the traceability layer that sits alongside your writing and produces sponsor-ready audit records without asking anyone to take their word for it.
Who it is for
Regulated writing has never asked authors to be trusted. It has asked them to be verifiable. RedInkAI makes that possible for AI-assisted work.
Attach an Authorship Packet to any AI-assisted protocol, IB, or CSR section. Show sponsors and CROs which sections had AI input, what was accepted, what was rejected, and who reviewed each decision.
Preserve the human-review provenance behind every AI-drafted submission section. Package the record as a signed PDF ready for internal QA review and external audit trails.
Capture the reviewer decisions layered on top of any AI-drafted safety narrative or case report. The medical writer's judgment stays visible in the record — not lost between drafts.
What you get
Every AI-assisted draft produces a cryptographically chained record of consultations, decisions, and revisions. Your editorial board, IRB, or integrity office can verify any claim independently at /verify/{id}.
Per-institution policy controls, role-based access, audit log retention, and admin-grade visibility into AI use across departments and submissions.
Aligns with NIST AI RMF documentation expectations, COPE position on AI in scholarly writing, and emerging IRB AI policies. Independent verification endpoint included.
Cognitive Audit Reports are portable JSON + PDF artifacts. Your institution owns the data. We provide infrastructure, not gatekeeping.
The objection every committee will raise
Short answer: no. Long answer is the whole point of the product. Here is exactly how a committee can verify any record an institution generates.
Every event carries a UTC timestamp set by our server, not the user's machine. Backdating a session is not a question of permissions, it is mathematically prevented.
Each event is cryptographically linked to the state of the record before it. Any insert, delete, or modification is instantly detectable on the next read — the record self-verifies without needing us.
When an attestation PDF is generated, the underlying session is sealed. Any subsequent edits create a new linked session, preserving the original record verbatim. The lock is enforced server-side.
The exact AI prompt used at the time of each consultation is hashed and recorded. A future prompt change cannot retroactively alter what was logged.
Adversarial tests confirm a user cannot read, write, or modify another user's trail. Audit logged at the API layer.
Verify URLs (`/verify/{id}`) are public and stateless. A reviewer can verify chain integrity, source attribution, and adoption metrics without an account, without trusting RedInkAI, and without contacting us.
Adversarial testing, public
Our 21-test adversarial suite covers hash chain tampering, timestamp spoofing, lock bypass, and cross-user access attempts. The suite runs on every release and the results are available to any institution under NDA before signing. Most institutional buyers consider this the strongest single piece of evidence we can offer.
Institutional licensing
Pricing is set per institution against your scope, governance posture, and integration needs. Every tier includes a 6-month no-cost pilot for qualifying institutions in 2026.
A single department, journal, or IRB committee.
Up to 50 contributors
A research office, school within a university, or mid-size journal publisher.
Up to 250 contributors
Full universities, large publishers, government research offices.
Unlimited contributors
Start a pilot
We onboard up to 50 contributors at your institution, generate real attestations on real submissions, and produce an end-of-pilot report you can take to your governance committee.
Honest claims
We’d rather be under-claimed and defensible than over-claimed and questioned. The list below is what we intentionally leave off — and why.
Want the point-by-point Part 11 control mapping for your validation team?
Read the 21 CFR Part 11 readiness docEvery 90 days we run an adversarial audit against our own hash chain, timestamps, and access controls — and publish the pass/fail rollups.
Read the latest False-Positive Validation reportBringing this to a compliance officer or head of research? Read (or download) our 7-section pilot brief.
Read the Institutional Pilot BriefFAQ
We are 21 CFR Part 11-aware — RedInkAI is designed with the record-keeping principles of Part 11 in mind (timestamped events, tamper-evident chain, unique attribution, permanent audit trail, controlled access). We do not represent RedInkAI as an independently validated Part 11 system. Use of RedInkAI records inside a validated environment remains the sponsor or CRO's responsibility. We're happy to provide technical documentation supporting your own validation work.
No. Formal GxP validation requires a documented Computer System Validation package (IQ / OQ / PQ) that we do not currently ship. What we do provide is a technical control set aligned with GxP record-keeping expectations, and we cooperate fully with sponsor-side validation efforts.
Every event is timestamped by our server (not the user's machine), cryptographically chained to prior events, and verifiable at a public /verify/{id} endpoint that does not require an account. A sponsor auditor can independently confirm chain integrity, timestamps, and source attribution without contacting RedInkAI. That is what "tamper-evident" means in practice.
The Enterprise tier includes single-tenant cloud or on-prem deployment for pharma/CRO buyers with confidentiality requirements above what a shared multi-tenant environment can satisfy. That deployment mode retains the same public verify endpoint scheme via keys the sponsor controls.
When a sponsor asks "which parts of this protocol had AI involvement?", the Authorship Packet answers with specifics: which sections, which models were used, what was prompted, what the human writer kept vs. rejected, and when. That is materially more auditable than a signed disclosure box.