Simulation Licensing Trust FAQ Request an assessment
Trust · Engineering & Security

Built to be trusted with regulatory work

How ReGentra constrains model outputs, protects your data, and preserves auditability across every medical device assessment.

Request an assessment

Why generic AI isn't enough and
why data handling can't be an afterthought

A general purpose model can produce plausible sounding technical files, but its claims often lack traceable links to regulation. That taught us to build the other way round: verify regulation and evidence first, then constrain every generation to what the sources support.

ReGentra's principle is to structure what can be structured, automate what scales, and keep a human reviewer in control.

ReGentra applies data controls aligned with EU requirements: EU hosting, minimal collection, explicit retention windows, tenant isolation, strong authentication, and full audit logging, all designed in from the start.

Three boundaries inside the Simulation module

Evidence in
Closed boundary
The system works only with uploaded documents and a verified standards database. Nothing outside this boundary enters the process.
Closed boundary
AI constrained
Evidence-only generation
The model generates output using only the evidence it was given. It cannot reference external knowledge or produce claims beyond what the sources contain.
Constrained
Human decides
Approval required
Every output stays in draft until a reviewer approves it. The system cannot finalize its own work — the human is always the final authority.
Required

Why the system is built this way,
and how your data is protected

Engineering
Fabrication

Closed evidence boundary

The model cannot access external knowledge or generate claims beyond what the evidence base contains. This isn't a prompt instruction — it's an architectural constraint that holds regardless of what the model attempts.

Unchecked automation

Human approval required

Every output remains a draft until a reviewer explicitly approves it. There is no override, no batch-approve, and no silent promotion. The human is the final authority at every decision point.

Traceability

Traceability & verification

Generated outputs are verified against their source material and every claim is linked to the source it came from. Anything that cannot be traced back is treated as an error and flagged for reviewer action.

Accountability

Full audit trail

Every generation, edit, approval, and rejection is recorded. The trail exists so the process can be demonstrated and defended — who reviewed what, when, and what they decided.

Ad-hoc design

Specified before built

The system's rules, structures, and boundaries were defined by regulatory domain expertise before implementation began. The specification came first; the code was built to meet it.

Silent failure

Defensive by default

The system is built to fail visibly rather than continue silently. Missing data, failed processes, and unmet conditions are surfaced as explicit errors — never suppressed or worked around.

Data & Security
Hosting

EU data residency

The application and its data are hosted within the European Union. Technical documentation does not leave EU infrastructure in the course of normal operation, keeping processing within a single, known jurisdiction.

Data protection

GDPR-aligned handling

Data is collected only where it serves a purpose, retained only as long as needed, and removed on request. Retention windows are explicit, and right-to-erasure is supported as a first-class operation, not a manual exception.

Access

Authentication & access control

Accounts are protected with hashed credentials and email-based two-factor authentication. Access is role-aware, and no account can reach data it was not granted — confirmed at the application layer on every request.

Isolation

Strict tenant isolation

Each organization's data is isolated from every other. Documents, audits, and findings are scoped to their owner, so one account's material is never visible or retrievable by another.

Encryption

Encrypted at rest and in transit

Data is encrypted in transit over TLS and at rest on disk. Stored documents and database contents remain protected even at the storage layer, beyond application-level access controls.

Accountability

Audit logging

Security-relevant actions — authentication, access, and changes to data — are logged. The record supports traceability and accountability, and underpins the usage and retention controls applied to each account.

Additional mechanisms include a 4-layer N/A determination model, cross-document consistency checks, and question-level re-run capability. The underlying model is constrained to retrieved document content — it cannot reference external knowledge or generate claims beyond what the evidence base contains. Every output is verified against source location, and remains draft until the reviewer confirms.

From upload to deletion

Upload
Encrypted in transit
Process
Runtime inference only
Store
Encrypted at rest
Retain
Explicit time window
Erase
On request or expiry
Document contents are used for runtime inference only; they are never sent to model training. When AI processes a document, it does so within a single session boundary. The data informs the response; it does not become part of the model.

"A system you can trust with regulatory work has to be able to show its reasoning — and the sensitive data behind it deserves to be handled in one known jurisdiction, under clear controls, with deletion always on the table."

Structure what can be structured. Automate what can be automated. Keep the human in control.

Request an assessment

Something went wrong. Please try again or email us at info@regentramd.com.