A foundation model is retired
Your team swaps an upstream model on the lab's schedule, not yours. What changed for each hospital customer?
For health-tech vendors selling into hospitals
Bring one real change from your stack (a model swap, a prompt edit, a new subprocessor). In 15 minutes you’ll know exactly what a hospital customer can ask you to prove about it. And whether you could, today.
The trigger is already in your stack
Your team swaps an upstream model on the lab's schedule, not yours. What changed for each hospital customer?
Behavior changes without a new product release. Can you reconstruct the deployed policy and decision path?
A dependency or security fix changes the stack. Who needs notice, what evidence goes with it, and by when?
What happens in 15 minutes
Use a recent model swap, a planned release, or the next deprecation you know is coming. If you have contract language, redacted snippets are plenty. If you don’t, that itself is worth knowing.
Name the model, prompt, policy, guardrail, subprocessor, or patch that moved.
Check the notice window, approval path, evidence language, and delivery channel.
Identify the runtime record and customer-ready proof you can actually produce.
Leave with the missing owner, artifact, or workflow—not another governance deck.
The proof layer
Gatekeeper is a proxy that sits in front of your AI calls. Every call gets logged with the policy that ran, the model and provider, timestamps, and what was redacted. In our 1,000-call production test, all 1,000 calls came back with a complete audit record: 4,407 entities redacted, about 0.44s of added latency. That record is what becomes customer-ready evidence, instead of a reconstruction after someone asks.
Traceable. Policy-version lineage and timestamped decisions.
Reviewable. Evidence mapped to relevant SOC 2 and HIPAA controls.
Honest. Ungoverned calls are flagged; detection is never described as perfect.

If the check finds a real gap
One change, one obligation, one honest answer on what you can prove today.
We go through your last 12 months of AI changes, match them against what your customer contracts require, and hand you the evidence baseline. Fixed scope, fixed price, quoted on the call.
Where the gap is proof itself, Gatekeeper’s proxy writes the audit record on every AI call, so the next change shows up with its evidence already attached.
This is for you if
This is not
I won’t claim your contracts already contain these duties, that Gatekeeper catches every instance of PII, or that a control mapping makes you certified. If a claim isn’t provable, it doesn’t go on this page.

Who you’ll talk to
No SDRs, no deck, no follow-up sequence you didn’t ask for. Every check is run by Dilip Adityan — years of engineering at Broadcom, a Chicago Booth MBA, and too many health-tech deals watched stalling in hospital security reviews. That’s the experience your one change gets checked against.
Before you book
No. It's a working session on one real change from your stack. If runtime evidence turns out to be your gap, that's what Gatekeeper makes, and you'll hear that plainly. If it isn't, you still leave knowing where the gap is.
No. Your redacted clause text is ideal, but describing the obligation from memory works fine. The full agreement is never needed, and nothing you share is kept without your say-so.
That's most vendors right now, honestly, and it's the best time to look. Hospital-side playbooks (HSCC, Joint Commission) now tell health systems to ask for change-notification clauses, so we map you against what your next renewal or security review will probably ask.
You leave with the gap named: the missing owner, artifact, or workflow. If you want it closed, there's a fixed-fee change-evidence audit. And where the gap is runtime proof itself, that's Gatekeeper's product.
One change. One contract. Fifteen minutes.
Bring the last AI change you shipped, or the next one you know is coming.
Book the free gap check Or email dilip@shaachi.com