The foundation · IRIS

The instrument that reaches what was never written down.

IRIS reads the code and the written record like any capable tool would — and then sits down with the people who still understand the system and captures the reasoning that never reached a document. Deployed inside your own cloud.

Weeks, not quartersIn your own cloudNothing leaves your environment
Where the intelligence comes from

Three sources. The third is the one that matters.

FROM THE SOURCE

What the system actually does

Custom and bolt-on applications distilled into business process, interface by interface. COBOL, RPG, PL/I, ABAP, PL/SQL, .NET, C/C++, Java, Python, device firmware. Volume is not the limiting factor.

FROM THE RECORD

What the documents claim it does

Functional and technical specifications, SOPs, design history files, validation protocols, Confluence and SharePoint — reconciled against the running system, so the two are compared rather than assumed.

FROM THE PEOPLE

Why it works that way

Elicited conversationally, in the expert’s own language, with the follow-up questions an experienced practitioner would ask. This is the part no tool reads and no connector reaches.

The differentiator

Any tool can read your code. That is not the hard part.

There is now a whole category selling the context your AI is missing — architectural maps, indexes across your documents and applications. It is real work and it helps. But all of it is built from what somebody already recorded.

We capture what your experts know that was never written down, and hand you a specification a regulator will accept, with a named engineer’s signature on it and the IP assigned to you outright. Capability is commoditising toward zero. A validated artifact, signed and owned, is not.

What you are left holding

Artifacts your team can sign, not a tool they have to learn.

  • A business specification of the system you namedReviewed and signed by your own analyst — who reviews rather than authors.
  • Traceability from requirement to design to test to riskGenerated from what the system actually does, not from what the file says it does.
  • A gap view against the standard that governs itQMSR, IEC 62304, ISO 14971, Annex 11 — as applicable.
  • Provenance on every statementThe code path or the named expert it came from.
  • The IP, assigned to you outrightAnd a named engineer’s signature on the deliverable.
~6 weeks
To production specifications, in your own cloud
80%+
Specification accuracy, confirmed by your reviewer
What goes in the SOW
POC at near-zero cost — we underwrite it Production engagement under $100K, fixed fee Runs in your own cloud Zero data retention — your code trains no model A named engineer signs IP assigned to you outright
Procurement

Listed on AWS Marketplace — buy through your existing AWS agreement and draw it down against commitment you have already made. No new-vendor onboarding, no separate procurement cycle.

The boundary

Deliberately bounded — and that is what makes it defensible.

IRIS drafts, maps and explains. A named human reviews and signs before anything enters your programme record. It is decision support with provenance, not an automated decision-maker inside a validated process — and that distinction is the whole basis on which a regulated organisation can use it at all.

The sentence that governs everything

IRIS is deliberately bounded, and that boundary is what makes the intelligence defensible. The reviewer reviews rather than authors.

Security & standards

Aligned to the standards your auditors already use.

FDA QMSRISO 13485:2016IEC 62304ISO 1497121 CFR Part 11Section 524BEU MDRAnnex 11
◆ Runs in your private cloud◆ Zero data retention◆ Human in the loop◆ ISO 13485 / SOC 2 — in progress
Start here

The how is a conversation.

Thirty minutes to find where your knowledge risk is highest. If there is a fit, we start with a proof of concept on one system you name — at near-zero cost, in your cloud, with the deliverable assigned to you.

Contact page