Human.Readable turns opaque AI output into reviewable, cited, and defensible decisions — so regulated teams can safely put AI to work on their routine workload while keeping every judgment auditable by a human, a regulator, and a court.
e.g. claims adjudication · clinical data verification · permit review
A layer, not a rip-and-replace
Sits underneath the systems you already run. No replacement project, no multi-year procurement.
Humans make the calls
It never removes a person from a consequential judgment. It proves the person was there.
Knows when it is unsure
The system measures its own uncertainty and flags exactly those moments for human review.
Evidence, not just output
Every step becomes a defensible record you can hand to an auditor or regulator.
$ cat claim.txt
The claim, in one sentence
claim.txt
Most AI pitches are a speed claim. Ours is a claim about provable review: the system flags the specific moments the AI isn’t sure, and proves a named human took a reasoned action on exactly those moments — regardless of whether the AI underneath is fast, slow, cheap, or expensive.
It is a provenance layer for AI-assisted decisions. It does not replace or improve the model you already use. It sits underneath that model and turns every output into something a human can catch, question, replay, and defend.
$ how-it-works
The core loop
The same six steps run for every document, in every vertical.
01
Upload
A claim, a clinical record, a permit application. No manual document-type pre-selection.
02
Automatic match
Cosine-similarity comparison against previously-seen document types. The system recognizes what it’s looking at.
03
Extract & validate
Against a schema and reference data specific to that document type — CARC/RARC codes, CRF fields, or code sections.
04
Flag uncertainty
Repeated sampling measures whether the model’s answers agree. Disagreement routes to a human; agreement doesn’t.
05
Human review
Inspect the flagged field directly or ask about it in a scoped conversation — inside the audit trail, not beside it.
06
Durable log
What was proposed, what a human changed, when, and why. Reconstructable after the fact. Exportable as an audit artifact.
Secure and transparent by default
Least-privilege access
Humans stay in control
Auditable by design
Your data stays yours
$ ls engine/
The engine underneath every vertical
Five primitives. Only the schema and reference data change per workflow — that’s one substrate proven across three unrelated regulated domains, not a portfolio of point solutions.
Template match
Every upload is compared by cosine similarity against document types the system has already seen, then routed to the right schema — no manual “what kind of document is this” step.
Distinguishes a corrected claim from a duplicate, a repeat lab draw from a data-entry error, a resubmission-after-violation from a coincidentally similar new permit. The daily judgment call in every vertical.
Schema-driven extraction
Fields are pulled against a versioned schema using four comparison modes: exact code, date window, numeric bounds, and semantic similarity.
Validation runs against real reference data where it exists — 65 CARC codes from X12 ANSI 835, 18 HUD REAC categories from 24 CFR Part 5 — and we are explicit about where it doesn’t.
Entropy-based uncertainty flagging
The model is asked the same question multiple times and we measure how much its answers actually agree — not how confident any single answer sounded.
Confidence is measured, not assumed. Disagreement gets flagged for a human; agreement doesn’t. Safety-critical fields always require review regardless of score.
Human review, in the record
Reviewers inspect a flagged field or ask about it in a document-scoped conversation. Every exchange is logged like an extracted field, and overrides carry a mandatory attributed rationale.
Proves a review action occurred — who, when, and why — rather than leaving query resolution in email and phone calls with no structured trail.
Provenance ledger & replay
An immutable event log of old and new decisions, corrections, reviewer identity, entropy scores, and the schema version at creation. Any field’s sampling run is replayable.
ALCOA+ by construction — the original value is never overwritten, the correction is visible, the reason is attached, and a named human is on every override. Exports to CSV as a standalone audit artifact.
We turn AI output into evidence. The domain changes; the capability does not.
$ ls examples/
Work you can automate with these steps
The engine doesn’t specialize. It takes a schema and reference data — the same six steps then run for any document-driven workflow that is tedious, critical, and documented. These are three we’ve already pointed it at.
Claims adjudication
The tedium: Corrected claims, modifier changes, and coordination-of-benefits updates arrive looking identical to duplicates.
The steps: Each document is matched to a known type, fields are extracted and validated against reference codes, near-identical records get flagged, and a person reviews exactly those moments.
You end up with: Proof of which document the AI actually saw — and that a human made the call on every uncertain one.
Clinical data verification
The tedium: Source documents arrive in whatever format each site uses, and the same lab value legitimately recurs.
The steps: Extraction runs against the trial’s schema, repeated values are checked rather than assumed duplicates, and every decision to skip, sample, or flag is itself logged.
You end up with: Risk-based review that is more rigorous than a blanket 100% check — with the log to show it.
Permit application review
The tedium: Applications for the same parcel resurface constantly and look nearly identical.
The steps: Each submission is matched against prior filings, changed fields are surfaced, resubmission-after-violation is distinguished from a new application, and flagged cases route to a reviewer.
You end up with: A trail showing review actually happened — reusable as the reporting artifact.
$ mkdir examples/yours
A new workflow is a schema and reference tables, not a rebuild. If the work is tedious, critical, and documented, it fits.
Every general counsel raises the same objection early: “if your system logs a human approving a wrong decision, haven’t you just built the plaintiff’s exhibit?”
The answer turns on how negligence is actually judged. Discovery never turns on whether you kept records — in claims, clinical, and permitting you are already legally required to retain them. It turns on whether you ran a reasonable process. The case that loses is a foreseeable harm with no oversight trail: the absence of documented review, not its presence.
Human.Readable produces the opposite artifact — evidence that the uncertain moments were flagged, that a named human engaged them, and that a recorded rationale stands behind each judgment. That is reasonable process, made legible.
One honest caveat, which is also the point: the record only defends a review that actually happened. We don’t manufacture a defense; we make good-faith oversight provable. If your process is sound, this is your strongest exhibit.
$ diff --exclusions
What this product explicitly is not
Sharp positioning requires sharp exclusions. Anyone evaluating us should hear these first.
- not:A replacement for systems of record
Not a new claims processor, EDC, or permitting platform. A layer underneath, not a rip-and-replace — which kills the multi-year procurement conversation before it starts.
- not:A decision-maker
It never removes a human from a consequential judgment. It makes that involvement visible and reconstructable — categorically different from automating people out of the loop.
- not:Focused on model accuracy
Improving the underlying AI’s correctness is out of scope. Our job starts at the moment the AI might be wrong.
- not:A speed claim
Speed is a downstream effect, not the pitch. A demo that leads with “10× faster” has already conceded the regulatory story that gets the yes.
$ compliance --tiers
How the regulatory anchor works
Not every regulation mandates our artifact — so we place each at the tier the law actually supports. That’s what lets the regulatory story survive a compliance counsel’s read.
Mandated
Where a statute explicitly requires human review and a retained, inspectable record of it, we are the compliance artifact — and we quote the clause.
Demonstrable
Where the statute requires human involvement or audit-readiness but is silent on the form of proof, we are the cheapest, most defensible way to demonstrate the oversight the law already demands. Most current AI-in-claims laws sit here.
Anticipatory
Where rules are proposed or emerging, we position you ahead of them rather than retrofitting after.
references.txt
Reference points we build against
Indiana HB 1271 — AI human review & disclosure in downcoding
Alabama SB 63 — licensed human finalization of denied claims
Maryland HB 820 — human oversight & auditing in utilization review
21 CFR Part 11 — electronic records and signatures
FDA ALCOA+ data-integrity guidance · ICH E6(R3)
HUD REAC — 24 CFR Part 5 Subpart G violation categories
NIST AI Risk Management Framework (AI RMF 1.0)
X12 ANSI 835 CARC/RARC code sets
$ history
Why we built this
01
The boring stuff
It started with email and a book called Automate the Boring Stuff. We automated our own tedium: inboxes, security monitoring, audit log review.
02
But we’re security people
Trust but verify is not a slogan to us; it is the job. Automation we could not verify was automation we could not use.
03
So we built the verification in
AI is an amazing tool, and we use it everywhere. We just refuse to ship it without the receipts.
// the principle
When AI makes a mistake, it’s your mistake.
That is not acceptable. It is why everything we ship stays reviewable, cited, and defensible.
Where this goes: bring a document type you already process, and we’ll run it through the steps in front of you.
>If your system logs a human approving a wrong decision, haven’t you just built the plaintiff’s exhibit?
Discovery never turns on whether you kept records — in claims, clinical, and permitting you are already legally required to retain them. It turns on whether you ran a reasonable process. The case that loses is a foreseeable harm with no oversight trail: absence of documented review, not its presence. We produce the opposite artifact — evidence that the uncertain moments were flagged, that a named human engaged them, and that a recorded rationale stands behind each judgment.
>Do we have to replace our claims system, EDC, or permitting platform?
No. Human.Readable sits underneath whatever you already run. It is a layer, not a rip-and-replace, and it does not ask you to migrate a system of record.
>Will this make our AI model more accurate?
No — deliberately. Its entire value depends on that restraint: it exists to know when the AI it’s watching doesn’t actually know, not to make that AI guess better.
>How is uncertainty actually measured?
By asking the model the same question multiple times and measuring agreement across the answers. That catches disagreement-type uncertainty. Systematic error — where a model is confidently and consistently wrong — is caught by schema validation and an always-review guard on safety-critical fields such as adverse event grade, denial reason code, and violation category. A low entropy score can never let a genuinely critical field skip review.
>Which regulations does this help us meet?
Current AI-in-claims statutes — Indiana HB 1271, Alabama SB 63, and Maryland HB 820 — mandate human review and disclosure, and increasingly audit, inspection, or annual certification. None mandates a per-decision audit artifact. Human.Readable is the cheapest, most defensible way to prove the review those laws already demand. In clinical work it maps to 21 CFR Part 11, ALCOA+, and ICH E6(R3).
>Does the audit trail leave the product?
Yes. The provenance ledger exports to CSV as a standalone audit artifact, so a regulator or auditor can read it without being given an account.
$ contact --request-demo
Contact us.
Tell us about the work you want to automate — we’ll show you what a defensible audit trail looks like on your own documents.
contact — request-demo
Email us directly.
Prefer your own mail client? Every message reaches a founder.