MA Technologies LLC — Governed AI

Governed & Compliant AI For Regulated Clinical Workflows.

AI built for regulated clinical workflows — with governance, privacy, human oversight and auditability built in.

  • PHI & PII protected
  • HIPAA-ready architecture
  • 21 CFR Part 11-ready controls
  • Human oversight built in
SOURCEProtocolSKILL v3VersionedREVIEWHumanAPPROVEDTraceableIMMUTABLE TRAIL — WHO, WHAT, WHICH VERSION, WHEN

Source → versioned skill → human review → approved output

The problem

Consumer AI has already entered the workflow

Coordinators paste protocol sections into whatever tool is open. The output is useful. What is missing is everything a regulated organization depends on afterwards.

  • No traceabilityNobody can say which source text produced which paragraph.
  • No version controlThe prompt that produced last month's document is gone.
  • No review recordApproval happened in conversation, not in a system.
  • Interpretation driftTwo sites read the same protocol two different ways.
  • Uncontrolled data pathsSource material leaves the boundary without a decision being made.

What it is

A governed workspace, not another chatbot

Step 1

Upload once

The protocol and its source documents enter a study workspace.

Step 2

Run a skill

A versioned workflow produces a structured draft.

Step 3

Review

A named person reviews and accepts, or sends it back.

Step 4

Keep the record

Source, skill version, run, artifact, and reviewer stay linked.

It deliberately does not replace your CTMS, EDC, eTMF, or any clinical decision system. It sits alongside them and governs the document work that currently happens outside all of them.

The four pillars

Governance, compliance, privacy, and human oversight — built in, not bolted on

01

Governance

Know what happened. Every action can be logged with the relevant user, workflow, timestamp and AI version. Changes are traceable. Outputs are reviewable. Records can be reconstructed.

02

Compliance

Built with regulated workflows in mind. Our architecture is designed to support controls relevant to HIPAA, 21 CFR Part 11 and GxP environments — access controls, electronic records, electronic signatures, audit trails and validation. Not bolted on after deployment.

03

Privacy

Your patient data stays protected. We design workflows around controlled data access, least-privilege permissions, and secure handling of sensitive information. HIPAA's Security Rule specifically addresses the confidentiality, integrity and availability of electronic PHI.

04

Human Oversight

AI can assist. People stay accountable. Define what AI can do on its own, where human review is required and when an action needs escalation. A person clicking “Approve” isn't necessarily meaningful oversight.

Capabilities

What is actually in the workspace

Study workspace

Organization, client, project, study, and location hierarchy so every piece of work happens inside a protocol-bound context.

Skills registry

Prompt, code, and hybrid skills with metadata, lifecycle states, lineage, and retained versions. Workflows become managed assets, not personal prompts.

Execution engine

Asynchronous jobs with status tracking and timeout handling, so long document work runs reliably instead of being retried by hand.

File ingestion

PDF, DOCX, XLSX and other source documents uploaded to object storage and extracted for use — no email chains or desktop handoffs.

Artifact generation

Word, Excel, PowerPoint, PDF and schema-versioned JSON from a single run: deliverables people can use and structured results systems can read.

Human review

Every AI output stays a draft. Reviewer and timestamp fields, blocked QA states, and clear AI-draft labeling keep a person accountable.

Audit logging

Invocations, administrative actions, and internal data access are recorded so you can reconstruct how a given document came to exist.

Role-based access

Sponsor, site, and internal roles with scoped visibility across clients, studies, and locations — including what internal staff can see.

Deployment portability

Designed to run inside your boundary, with configurable data controls and PHI-minimization requirements rather than a shared tenant you cannot inspect.

Use cases

Starting skills for clinical research

Each one is a versioned workflow bound to the protocol, producing a draft for human review — not an answer presented as fact.

  • Protocol summaryA consistent, readable synopsis derived from the protocol itself.
  • Schedule of eventsStructured visit and assessment tables extracted rather than retyped.
  • Feasibility summarySite-facing assessments of what the protocol will actually require.
  • Consent draftA starting draft for informed consent, written for human review and approval.
  • Source worksheetsVisit-level worksheets aligned to the protocol's own requirements.
  • Patient materialsPlain-language documents derived from the same approved source.
  • Amendment regenerationWhen the protocol changes, regenerate the dependent documents from it.

Governance and control

The controls your quality function will ask about

Human oversight

AI output is labeled as draft and cannot pass as final without a named reviewer.

Versioned skills

The exact workflow version behind a document is retained, not overwritten.

Traceable execution

Source file, skill version, run, and reviewer stay connected.

Role-based access

Access is scoped by client, study, and location, including internally.

Data controls

PHI minimization and redaction are treated as configuration, not an afterthought.

Private deployment

The workspace can be deployed within your own environment boundary.

These are engineering and process controls we implement and hand over. They are not a certification, and we do not present them as one. Where a deployment needs validation evidence, that is scoped and delivered as part of the engagement.

How we engage

Delivered in stages, on fixed fees

01

Discovery

Two to three weeks, fixed fee. We map the documents your teams produce, where unmanaged AI is already being used, and the record you need to keep.

02

Pilot

One protocol, one or two sites, three to five skills. A working proof point with real source documents and real reviewers, on a fixed fee.

03

Deployment and validation support

Deployment into your environment, with the evidence, procedures, and configuration work your quality function will ask for.

04

Ongoing skill authoring

New workflows built, versioned, and maintained as protocols and standard operating procedures change.

Beyond clinical research

The same problem exists wherever documents are regulated

Clinical research is where this is most developed, and where we start. The same governed pattern applies to financial services recordkeeping, privacy-intensive enterprises, and quality-regulated life sciences functions outside the trial itself.

Those are engagements we take on individually, with their own regulatory mapping.

Briefing

Get the governance briefing

A short document covering the architecture, the control model, what a pilot looks like, and the questions to ask before letting AI near protocol material. Written for clinical operations and quality leaders.

We use your details to send the briefing and follow up once. Nothing else.