Celbridge Science

The layer between your AI and your highest-stakes decisions.

The Celbridge Trust Platform sits between the people and systems that use AI and the models that answer — enforcing who may ask, which model may answer, what data may be retrieved, what it may cost, and what gets recorded as proof. Access to the platform begins with an engagement, and expands into portfolio governance.

Approved surfaces
Scientists & clinicians
Governed workspaces
Internal applications
Scoped API access
Developers
Governed IDE access
Agent identities
Scoped agent keys
The Celbridge trust layer
Identity context
Policy evaluation
Budget check
Permissioned retrieval
Model routing
Evidence record

Every step enforced at request time · every decision recorded to the audit ledger

High-stakes decisions
Regulatory filings
IND / DDT credibility dossiers
Clinical deployment
Gated, monitored point-of-care use
Qualification & diligence
Federal programs, partners, boards

Three questions decide whether AI earns a place in the work.

The Boundary

Where can it be trusted?

For which specific decisions, patient sub-populations, assay protocols, and clinical conditions does the empirical evidence support confidence — and exactly where does that boundary stop?

The Durability

Is it still trustworthy?

Populations shift, biological assays evolve, and underlying model weights update. Trust established once during initial validation is not trust maintained across operational lifecycles.

The Utility

Is it creating value?

Does deploying this method reduce decision uncertainty enough to justify changing clinical, scientific, or capital allocation decisions beyond what legacy evidence already allowed?

Six pillars. One living evidence chain.

Each pillar operationalizes specific links of the 7-link evidence chain. Every screenshot below is the real platform interface, captured from a seeded demonstration environment — never a mockup.

Executive oversight of every governed system

Portfolio Command Center

One evidence-backed view of every model, method, and AI tool in the organization: usage, spend, savings, risk posture, and operating health. A stale signal is labeled with its age; a missing signal shows an honest zero — never a fabricated 'healthy.'

What this pillar includes
  • Portfolio-wide KPI and operating-status overview
  • Health matrix with drill-down to the evidence behind every tile
  • Department, workspace, and model usage breakdowns
  • Review queue flagging high-cost model usage eligible for validated, cheaper routing
Link 6 · OutcomeLink 7 · Decision Utility
Celbridge Trust Platform · Seeded demoLive estate view
Portfolio command center estate overview with configured workspaces, assistants, models, and policies
The governed estate at a glance — every count backed by real records, never a fabricated status. View full size

Tamper-evident proof of every governed action

Trust Records & Audit Ledger

The substrate of the Celbridge Trust Record™. Every governed action writes a hash-chained, tamper-evident audit record. Every AI request produces a full evidence trace: identity, policy, data retrieved, model route, response, and cost — written atomically with the request.

What this pillar includes
  • Per-organization cryptographic hash chain, with the chain head anchored outside the application database
  • Per-request evidence traces from identity to cost, with server-side chain verification
  • Evidence-package generation and reviewer-ready export
  • Retention policies, legal hold, and security-log forwarding
Link 4 · Trust Record
Read the technical note: how the ledger works
Celbridge Trust Platform · Seeded demoEvidence traces
Request trace ledger with allowed and blocked governed requests
The evidence trace feed — a high-risk engineering request beside a blocked critical one, each with its trace ID. View full size

Validation that re-runs on demand — not a certificate that expires

Continuous Validation Engine

Configurable test sets score models, assistants, and retrieval configurations with deterministic rubrics or judge-model scoring that fails closed — a failed scoring call returns no score, never a fabricated one. Every run is versioned and repeatable.

What this pillar includes
  • Test sets, golden answers, and versioned evaluation runs against live routes
  • Model comparison and win-rate analysis
  • Retrieval-quality scoring for knowledge-grounded systems
  • Quality thresholds and publish gates before any system goes live
Link 3 · Validation
Celbridge Trust Platform · Seeded demoValidation runs
Model comparison win-rate analysis
Model comparison: quality wins, ties, and pass rates per validation test set. View full size

The non-compensatory gate engine

Runtime Boundary Enforcement

Policy chooses the route — users do not. Request sensitivity is classified into four levels; sensitive content is held under a hard privacy ceiling and never escalates to an external model, even on failure. Policy changes are approval-gated, audited, and previewed for blast radius before going live.

What this pillar includes
  • Scoped routing policies with priority, precedence, and version history
  • Four-level sensitivity classification with automatic pattern detection
  • Content-safety preflight across multiple classifier backends, failing safe
  • Policy conflict detection and pre-change blast-radius preview
Link 2 · Context of UseLink 5 · Governed Use
Celbridge Trust Platform · Seeded demoPolicy directory
Policy directory with scope, task type, sensitivity tier, status, and fallback guardrail per routing policy
The policy directory — every route carries a scope, a sensitivity tier, a status, and a fallback guardrail. View full size

The governed alternative to shadow AI accounts

Governed Research Workspaces

The surfaces scientists, clinicians, and developers actually use. Governed assistants bundle instructions, knowledge, tools, budget, and access rules behind a publish-approval lifecycle with segregation of duties; workspaces scope people, budgets, and audit. Retrieval is permission-aware: the same question returns different answers depending on who asks.

What this pillar includes
  • Governed assistants with a draft-to-published approval lifecycle; workspaces scoping users, budgets, and audit
  • Permission-aware retrieval with allow/deny rules evaluated inside the query itself
  • Tiered data connectors to enterprise document, data, and code systems
  • Enterprise SSO/SCIM identity, access reviews, and governed developer/IDE access
Link 5 · Governed Use
Celbridge Trust Platform · Seeded demoGoverned directory
Governed assistant directory with owner, workspace, risk tier, and review status per assistant
The governed directory — every assistant carries an owner, a workspace, a risk tier, and a review status. View full size

Economics, discovery, and managed operations

AI Portfolio Intelligence

Cost attribution by department, model, and user; savings evidence from validated routing; budget hierarchies enforced at request time. Unsanctioned AI usage is discovered through identity-provider and network signals — metadata only. Recommendations never auto-apply: every change passes through a human-approved change request.

What this pillar includes
  • Cost events, savings ledger, hierarchical budgets, and alerts
  • Shadow-AI discovery with onboarding nudges (metadata-only)
  • Monthly generated, evidence-backed operating reviews
  • Private, self-hosted, and VPC model deployment with route approval
Link 6 · OutcomeLink 7 · Decision Utility
Celbridge Trust Platform · Seeded demoOperating posture
Operating status across providers, connectors, knowledge spaces, and routing policies
Operating posture — providers, connectors, knowledge spaces, and policies, with review flags surfaced per owning team. View full size

Built honest, by design.

A trust platform has to be more trustworthy than the systems it governs. These properties are engineered into the platform’s core — not written into a policy document.

Honest status, everywhere

The platform never fakes a healthy status. If a number is missing or stale, it says so — in plain sight, right where the number would be.

A stale rollup falls back to a live count labeled as live, never a false zero, and every rollup tile can open the source rows behind it.

Fail-closed scoring

If the judge scoring a validation test cannot render a verdict, the platform reports no score. It never quietly makes one up.

A refused or failed judge-model call returns no score rather than a fabricated one — a deliberate integrity property, distinct from deterministic rubric scoring.

A tamper-evident ledger

Every governed action is stitched into one cryptographic chain per organization, with the chain head kept outside the main database.

Each audit record is HMAC-linked to the previous one with an out-of-database key; the chain head is periodically anchored to an external append-only sink, so even a database rewrite is detectable.

Single-use approvals

An approval only unlocks the exact change it was granted for. If the policy shifts after approval, the old approval cannot push the new version through.

Approvals are bound to a content fingerprint and consumed atomically with activation — spent first, before the status flip.

Humans approve every change

The platform suggests changes and shows its evidence. A person always has to approve before anything actually changes.

No write path exists that lets a recommendation apply itself; the only route to a real change is a human-reviewed, audited change request.

A privacy hard ceiling

Sensitive information is always routed to your private infrastructure — even if that route fails, the system will not fall back to an external model.

Sensitivity classification is wired directly into the routing decision; sensitive content is pinned to the private route with no failure-triggered escalation path.

From zero to the first governed request.

What deployment actually looks like — told the way it happens, honest empty states included.

Zero

An honest empty state

A platform admin signs in for the first time. Nothing looks broken, because nothing has happened yet — the platform frames the empty state honestly, with one clear next step.

Connect

A verified private model

The admin connects a model — often one running inside the organization's own VPC. The platform runs a real, authenticated probe and stays visibly 'connecting' until the credential is genuinely verified, not merely present.

Govern

Policy, workspace, assistant

A routing policy pins sensitive work to the private route. A workspace scopes the research team. A governed assistant is published against a permissioned knowledge space — each step gated on its real prerequisites.

Request

The first governed request

A scientist asks a real question. Identity, access zone, and budget are checked before anything is retrieved; permission-aware retrieval returns only what this person is cleared to see; routing pins the sensitive request to the private model; the answer streams back with source citations.

Evidence

One durable receipt

A trace, a cost record, a routing decision, and a hash-chained audit record are written together, atomically. The admin opens one entry and sees the whole story: who asked, what was retrieved, which model answered and why, what it cost, and the policy that governed it.

The identical journey is fully reachable in Test Mode with zero external provider keys — the same governed pipeline, the same trace, cost, and audit receipt, honestly labeled as a test everywhere it appears.

The chain the platform keeps alive

The chain runs forward once — model to decision utility. Assurance runs underneath it continuously.

1
Model
2
Context of Use
3
Validation
4
Trust Record
5
Governed Use
6
Outcome
7
Decision Utility

The crosswalk: each link maps to named external standards.

01Model

NIST AI RMF 1.0 (Map), ISO/IEC 42001

02Context of Use

FDA DDT Qualification Program, FDA–EMA Joint AI Principles

03Validation

OECD GD 34, ISO/IEC 23894 Risk Evaluation

04Trust Record

FDA Risk-Based AI Credibility Framework, 21 CFR Part 11

05Governed Use

ONC HTI-1 Decision Support Interventions, EU AI Act Article 14

06Outcome

FDA Postmarket Surveillance, Good Clinical Practice (GCP)

07Decision Utility

Health Technology Assessment (HTA), Executive Governance

† Alignment describes the standards each link is structured to satisfy — not certifications held or issued.

Deployed inside your walls. Independent by design.

Your VPC, your data

The platform deploys in your VPC, on-prem, or on private infrastructure — distributed as signed containers with a production-grade deployment chart. You own the environment, the records, and the models it governs.

Private models, first-class

Self-hosted and private model endpoints are a first-class provider type — probed, approved for production routes, and governed alongside cloud and frontier providers.

Isolation enforced in the database

Organization isolation is enforced by database row-level security on every scoped table — not by application filtering alone.

Secrets stay in your secret manager

Credentials are encrypted, never re-displayed after saving, and integrate with the major cloud secret managers and Vault.

Humans approve every change

Recommendations never auto-apply. The only path from a recommendation to a system change is a human-approved, audited change request.

Records built for scrutiny

Retention policies and legal hold are first-class: a held record cannot be purged, and evidence packages can be exported for counsel-directed or reviewer-directed examination — the record protects the organization that kept it.

Framework references describe alignment and readiness, not certifications held. Celbridge provides readiness, governance, and assurance advisory services; it does not issue ISO certification.

The platform is where an engagement leads.

Access begins with one scoped engagement — a bounded claim, an independent assessment, and a first Trust Record — and expands into portfolio governance and continuous assurance.

or write to [email protected]

Prefer to see the work first? Walk through an eight-week pilot, step by step