When privacy, verification and accountability cannot be afterthoughts

Technical leadership for AI systems that must work in the real world.

We help healthcare and legal leaders shape, evaluate, and deliver AI systems with privacy, verification, and operational accountability built in from day one.

What reliable AI requires in practice

  1. Legal reputational risk

    $31,100

    A top firm sanctioned for citations that did not exist.

    Lacey v. State Farm, C.D. Cal. K&L Gates and Ellis George, 9 of 27 citations wrong. One of more than 1,500 court incidents now catalogued worldwide.

  2. Deterministic verification

    Never let AI verify itself.

    Purpose-built legal AI still hallucinates in 17 to 33 percent of queries (Stanford RegLab). GhostCite checks each citation against the public court record instead.

    See how GhostCite works
  3. Vendor and data risk

    Vendor limits and data paths need examining.

    AI vendors may limit their contractual responsibility, while data can move through models, connectors or subprocessors that were not fully examined.

  4. Healthcare AI vendor review

    Examine vendor commitments. Verify data boundaries.

    Connect contract and BAA requirements to the actual architecture, data flow, access controls and audit trail, with qualified legal and security specialists involved where required.

    Discuss Your Project
  5. Technical evidence gap

    Know what your technical evidence can support.

    External reviewers may request evidence that the system’s actual operation, documented controls and stated risk practices align.

  6. Defensible AI assurance

    Deploy AI with the technical evidence reviewers need.

    Independent technical review, client-side oversight, and audit-ready logging across the workflow.

    Discuss Your Project

Illustrative examples, not client data

Six panels alternate between real-world AI risks and technical responses: a documented sanctions order involving fabricated citations; deterministic checking against public court records; sensitive data crossing an insufficiently examined vendor or model boundary; technical review of data flow, access controls and audit evidence; a gap between system operation and the technical evidence available to reviewers; and the independent technical review, client-side oversight and logging Rule26 can provide.

Nearly 30 years in enterprise softwareNearly 5 years leading a 10-person engineering organization in HIPAA-regulated healthcareCIPP/USAIGPBuilder of GhostCite

Bring in Rule26 before critical AI decisions are locked in.

For funded initiatives where privacy, verification, security and operational accountability must shape the system, not be added after implementation.

  1. A funded initiative is taking shape

    The organization needs to define the architecture, data boundaries, evaluation approach, human oversight and operating responsibilities before development decisions become expensive to reverse.

  2. A vendor or technical direction must be evaluated

    The organization needs an experienced, independent view of the claims, evidence, architecture, data movement and unresolved implementation risks before committing.

  3. The client needs technical representation

    Vendors, developers and internal stakeholders are involved, but no experienced technical leader owns the client’s objectives across architecture, implementation and acceptance.

  4. An approved AI path must work for employees

    The organization needs appropriate tools, workflows, training and boundaries that protect sensitive information while supporting how people actually work.

Regulated-system experience

Engineering leadership shaped in a real healthcare environment.

For nearly five years, Salma Saad led a ten-person engineering organization at the American College of Surgeons. She improved development tools, delivery processes, operational efficiency and security while guiding complex work involving enterprise architecture, interoperability and cross-functional stakeholders.

Rule26 brings that operating perspective to AI. Privacy, security, reliability and accountability are treated as architecture and delivery requirements, not documentation added after the system is built.

  • Regulated enterprise and architecture

    “Salma and her team worked with my team to complete several complex projects. She is mindful of important security, interoperability, and enterprise architecture considerations.”

    Jack King, MBA

    Chief Information Officer, American College of Surgeons

    View on LinkedIn ↗
  • Sustained change leadership

    “She not only recommended changes but guided us throughout the transition.”

    Jeff Gravely

    Engineer who reported to Salma for four and a half years at the American College of Surgeons

  • Founder and technical advisory

    “She assisted me in the recruitment of my initial tech team and provided the needed time estimates, tech stack selection, and laid out the initial AWS architecture.”

    Tal Moise

    Startup founder and former client

  • Independent technical judgment

    “Her analysis skills are a layer or two deeper than most… Salma will tell me what I need to hear, whether I want to hear it or not.”

    Brian Barthelt

    Former manager; Chief Technology and Innovation Officer

The American College of Surgeons is a former employer, not a Rule26 client. Each recommendation is attributed to its author. Experience and credentials.

Delivery informed by privacy and AI governance.

Many teams address privacy, verification, human oversight and technical evidence only when legal, security or enterprise reviewers raise them. Rule26 considers those requirements while the system, architecture and acceptance criteria are still being shaped.

Technical delivery

  • Architecture and integration
  • Productization and operations
  • Vendor and team oversight
  • Testing and release readiness

Risk-aware implementation

  • Privacy and data boundaries
  • AI evaluation and traceability
  • Human review and accountability
  • Evidence and unresolved-risk documentation

CIPP/US and AIGP knowledge informs the work. Rule26 does not replace legal counsel, clinical specialists, security assessors or formal compliance professionals.

Technical leadership from decision through real-world use.

Start where the project is today. Rule26 can provide an independent review, lead a defined technical workstream, or represent the client across internal teams and vendors.

  1. Decide

    AI Vendor and Architecture Review

    Whether and how to proceed.

  2. Evaluate

    AI Evaluation, Testing and Assurance

    How the system actually behaves.

  3. Deliver

    AI Productization and Technical Delivery

    Engineering and operational gaps closed.

  4. Adopt

    Approved AI Adoption and Shadow AI Reduction

    Tools, boundaries, enablement and measurement.

What changes when AI reaches real work.

  • Inconsistent answers

    The same request, or a slightly rephrased one, can produce conflicting outputs.

  • Hidden failure points

    Vendor demonstrations rarely exercise all of the failure conditions that matter.

  • Shadow AI usage

    Employees bypass approved tools when those tools do not fit their workflows.

The principles are reflected in GhostCite.

GhostCite is a functioning legal citation and quotation verification system. It separates probabilistic extraction from deterministic checks against public court records, records the supporting evidence, and states its limitations explicitly.

  1. Citation submitted
  2. Court record located
  3. Citation or quotation assessed
  4. Result and evidence recorded
A four-step flow: a citation is submitted, the public court record is located, the citation or quotation is assessed against it, and the result is recorded with its supporting evidence.

Rule-based checks against CourtListener public data. A generative model does not decide the result. GhostCite does not determine whether authority is still good law, and does not replace KeyCite, Shepard’s, primary-source review or professional judgment.

Try GhostCite

Two ways to start.

Project-fit conversation

A short conversation to establish whether Rule26 is relevant to the initiative.

Not a free technical assessment or a proposal workshop.

Describe your project

Initial Technical Review

  • Fixed fee$500
  • DurationUp to 60 minutes
  • One defined technical question
  • Three prioritized risk and evidence observations
  • A concise executive follow-up
Book an Initial Technical Review

Larger engagements begin with a defined discovery or review, so scope, responsibilities and expected outcomes are based on evidence.

Tell Rule26 what you are building.

If it is funded, in flight, or heading for a decision that is hard to reverse, that is the right moment.

Discuss Your Project