When privacy, verification and accountability cannot be afterthoughts
Technical leadership for AI systems that must work in the real world.
We help healthcare and legal leaders shape, evaluate, and deliver AI systems with privacy, verification, and operational accountability built in from day one.
What reliable AI requires in practice
-
Legal reputational risk
$31,100
A top firm sanctioned for citations that did not exist.
Lacey v. State Farm, C.D. Cal. K&L Gates and Ellis George, 9 of 27 citations wrong. One of more than 1,500 court incidents now catalogued worldwide.
-
Deterministic verification
Never let AI verify itself.
Purpose-built legal AI still hallucinates in 17 to 33 percent of queries (Stanford RegLab). GhostCite checks each citation against the public court record instead.
See how GhostCite works -
Vendor and data risk
Vendor limits and data paths need examining.
AI vendors may limit their contractual responsibility, while data can move through models, connectors or subprocessors that were not fully examined.
-
Healthcare AI vendor review
Examine vendor commitments. Verify data boundaries.
Connect contract and BAA requirements to the actual architecture, data flow, access controls and audit trail, with qualified legal and security specialists involved where required.
Discuss Your Project -
Technical evidence gap
Know what your technical evidence can support.
External reviewers may request evidence that the system’s actual operation, documented controls and stated risk practices align.
-
Defensible AI assurance
Deploy AI with the technical evidence reviewers need.
Independent technical review, client-side oversight, and audit-ready logging across the workflow.
Discuss Your Project
Illustrative examples, not client data
Nearly 30 years in enterprise softwareNearly 5 years leading a 10-person engineering organization in HIPAA-regulated healthcareCIPP/USAIGPBuilder of GhostCite
Bring in Rule26 before critical AI decisions are locked in.
For funded initiatives where privacy, verification, security and operational accountability must shape the system, not be added after implementation.
-
A funded initiative is taking shape
The organization needs to define the architecture, data boundaries, evaluation approach, human oversight and operating responsibilities before development decisions become expensive to reverse.
-
A vendor or technical direction must be evaluated
The organization needs an experienced, independent view of the claims, evidence, architecture, data movement and unresolved implementation risks before committing.
-
The client needs technical representation
Vendors, developers and internal stakeholders are involved, but no experienced technical leader owns the client’s objectives across architecture, implementation and acceptance.
-
An approved AI path must work for employees
The organization needs appropriate tools, workflows, training and boundaries that protect sensitive information while supporting how people actually work.
Regulated-system experience
Engineering leadership shaped in a real healthcare environment.
For nearly five years, Salma Saad led a ten-person engineering organization at the American College of Surgeons. She improved development tools, delivery processes, operational efficiency and security while guiding complex work involving enterprise architecture, interoperability and cross-functional stakeholders.
Rule26 brings that operating perspective to AI. Privacy, security, reliability and accountability are treated as architecture and delivery requirements, not documentation added after the system is built.
-
Regulated enterprise and architecture
“Salma and her team worked with my team to complete several complex projects. She is mindful of important security, interoperability, and enterprise architecture considerations.”
Jack King, MBA
Chief Information Officer, American College of Surgeons
View on LinkedIn ↗ -
Sustained change leadership
“She not only recommended changes but guided us throughout the transition.”
Jeff Gravely
Engineer who reported to Salma for four and a half years at the American College of Surgeons
-
Founder and technical advisory
“She assisted me in the recruitment of my initial tech team and provided the needed time estimates, tech stack selection, and laid out the initial AWS architecture.”
Tal Moise
Startup founder and former client
-
Independent technical judgment
“Her analysis skills are a layer or two deeper than most… Salma will tell me what I need to hear, whether I want to hear it or not.”
Brian Barthelt
Former manager; Chief Technology and Innovation Officer
The American College of Surgeons is a former employer, not a Rule26 client. Each recommendation is attributed to its author. Experience and credentials.
Delivery informed by privacy and AI governance.
Many teams address privacy, verification, human oversight and technical evidence only when legal, security or enterprise reviewers raise them. Rule26 considers those requirements while the system, architecture and acceptance criteria are still being shaped.
Technical delivery
- Architecture and integration
- Productization and operations
- Vendor and team oversight
- Testing and release readiness
Risk-aware implementation
- Privacy and data boundaries
- AI evaluation and traceability
- Human review and accountability
- Evidence and unresolved-risk documentation
CIPP/US and AIGP knowledge informs the work. Rule26 does not replace legal counsel, clinical specialists, security assessors or formal compliance professionals.
Technical leadership from decision through real-world use.
Start where the project is today. Rule26 can provide an independent review, lead a defined technical workstream, or represent the client across internal teams and vendors.
-
Decide
AI Vendor and Architecture Review
Whether and how to proceed.
-
Evaluate
AI Evaluation, Testing and Assurance
How the system actually behaves.
-
Deliver
AI Productization and Technical Delivery
Engineering and operational gaps closed.
-
Adopt
Approved AI Adoption and Shadow AI Reduction
Tools, boundaries, enablement and measurement.
What changes when AI reaches real work.
-
Inconsistent answers
The same request, or a slightly rephrased one, can produce conflicting outputs.
-
Hidden failure points
Vendor demonstrations rarely exercise all of the failure conditions that matter.
-
Shadow AI usage
Employees bypass approved tools when those tools do not fit their workflows.
The principles are reflected in GhostCite.
GhostCite is a functioning legal citation and quotation verification system. It separates probabilistic extraction from deterministic checks against public court records, records the supporting evidence, and states its limitations explicitly.
- Citation submitted
- Court record located
- Citation or quotation assessed
- Result and evidence recorded
Rule-based checks against CourtListener public data. A generative model does not decide the result. GhostCite does not determine whether authority is still good law, and does not replace KeyCite, Shepard’s, primary-source review or professional judgment.
Two ways to start.
Project-fit conversation
A short conversation to establish whether Rule26 is relevant to the initiative.
Not a free technical assessment or a proposal workshop.
Describe your projectInitial Technical Review
- One defined technical question
- Three prioritized risk and evidence observations
- A concise executive follow-up
Larger engagements begin with a defined discovery or review, so scope, responsibilities and expected outcomes are based on evidence.
Tell Rule26 what you are building.
If it is funded, in flight, or heading for a decision that is hard to reverse, that is the right moment.
Discuss Your ProjectFind detailed answers on the FAQ page.