Skip to Main Content

Justina

Built at RAISE Summit Hackathon · Jul 4, 2026 · Paris, France

Justina — Demo video

SaMD Compliance Engine: AI proposes, evidence certifies. The problem: In 2025, US digital health startups raised $14.2B, 54% of it AI-focused (Rock Health). Everyone ships medical software fast, and almost nobody stops for compliance. Business logic ends up in the frontend, patient data unencrypted, no audit logs. This is software that handles prescriptions and guides treatment, so an error isn't a bug, it's a patient at risk. Existing AI compliance tools hallucinate: they mark controls as implemented without proof. The solution: An API you point at any codebase that assesses it against HITRUST CSF (e1 subset) and tells you if your medical software is actually safe. A multi-step agent (running on Vultr Serverless Inference) plans which controls to check and proposes findings, but only a deterministic validator certifies them, with verifiable evidence down to the exact file and line. If the AI assumes a control is there but there's no proof in the code, it's flagged as a gap, never certified. Core principle: AI proposes; only deterministic evidence certifies. Key features: - Multi-step retrieval agent: plans, retrieves from multiple sources, validates, and prioritizes gaps by clinical risk to the patient (Patient Risk Score). - Deterministic validators (no LLM): certify controls only with reproducible file:line evidence, zero false positives by design. - HITRUST-format report with PRISMA maturity model, coverage metrics, and Corrective Action Plans (CAPs). - Detects partial implementations (evidence found but incomplete), not just pass/fail. Tested on real medical software: I validated the engine against several open-source SaMD and health projects, including my own clinical decision support tool (prescription-AI), Medplum (an EHR platform that markets itself as HIPAA compliant), Metriport (a health data API), fhir-emr (a FHIR-based EMR), and OpenSaMD (an open-source Software as a Medical Device platform). The engine behaved differently on each: it validated real controls on mature platforms, flagged genuine gaps on early-stage projects, and on my own project it caught 5 missing critical controls plus an audit log I had started but left incomplete. That contrast is the point: it doesn't always say the same thing, it discriminates based on the actual evidence in each codebase. Use cases: on-demand readiness assessment, CI/CD compliance gate (block merges that break compliance), and continuous monitoring. It shifts compliance from the expensive, reactive end of the process to the moment you write the code. Tech stack: FastAPI (async), Vultr Serverless Inference (DeepSeek-V4-Flash), deterministic validators, HITRUST CSF e1 mapping. Note: This is an automated readiness/pre-assessment tool. It does not replace a certified HITRUST External Assessor.

Team