AI lifecycle governance for the public sector

Govern every AI system,from first look to retirement.

xplAInable Scorecards evaluates enterprise AI across regulatory, ethical, security, and operational risk, then keeps scoring it after the contract is signed. Build a scorecard, monitor drift and incidents, and watch legislation move in all 50 states.

0
risk domains
0
states tracked
0h
evidence refresh

Interactive scorecard builder

Clinical Triage Copilot v3

Composite

72

Watch
  • Governance

    Oversight boards, review gates, escalation paths

    84
    Weight
  • Transparency

    Model cards, data provenance, explainability

    61
    Weight
  • Regulatory compliance

    FDA pathways, state statutes, federal guidance

    72
    Weight
  • Privacy & security

    Residency, retention, subprocessors, attestations

    88
    Weight
  • Incident history

    Recalls, adverse events, breaches, enforcement

    43
    Weight
  • Corporate accountability

    Ownership, durability, remediation record

    69
    Weight

Procurement gateCleared for contracting

Evidence: 214 sources · refreshed daily

FDA device databaseopenFDA adverse eventsState legislative feedsFederal registerSAM.gov entity dataCISA advisoriesNIST AI RMFHHS OCR breach portalFDA device databaseopenFDA adverse eventsState legislative feedsFederal registerSAM.gov entity dataCISA advisoriesNIST AI RMFHHS OCR breach portal

The framework

Six domains a review board can audit.

Every score traces to a source document. Nothing is asserted that cannot be shown to an inspector general.

Open the builder

Governance & oversight

Review gates, escalation paths, and named accountability for every model in the estate.

Regulatory compliance

FDA pathways, state statutes, and federal guidance mapped clause by clause to the product.

Privacy & data handling

Residency, retention, and subprocessor exposure reviewed against contract terms.

Incident surveillance

Recalls, adverse events, enforcement actions, and breach disclosures traced to the vendor.

Transparency

Model cards, training-data provenance, and explainability of decision logic.

Corporate accountability

Ownership structure, financial durability, and remediation track record.

The platform

A full AI lifecycle platform, not just pre-procurement scoring.

Risk does not stop at award. Each stage carries its own evidence, controls, and owners, and every stage feeds the same living score.

Stage 01

Intake & discovery

Register every AI system in use or under consideration, classify its risk tier, and map it to the mission it supports.

01

Automated AI inventory

02

Use-case risk tiering

03

Shadow-AI discovery

Scorecard builder

Weight the domains your agency actually cares about.

Start from a live vendor profile, adjust domain scores against your own evidence, and set weights by mission criticality. The composite and the procurement gate recalculate instantly.

  • Six evidence-backed risk domains01
  • Configurable weighting per use case02
  • Automatic gate recommendation03
  • Exportable, audit-ready rationale04

Interactive scorecard builder

Clinical Triage Copilot v3

Composite

72

Watch
  • Governance

    Oversight boards, review gates, escalation paths

    84
    Weight
  • Transparency

    Model cards, data provenance, explainability

    61
    Weight
  • Regulatory compliance

    FDA pathways, state statutes, federal guidance

    72
    Weight
  • Privacy & security

    Residency, retention, subprocessors, attestations

    88
    Weight
  • Incident history

    Recalls, adverse events, breaches, enforcement

    43
    Weight
  • Corporate accountability

    Ownership, durability, remediation record

    69
    Weight

Procurement gateCleared for contracting

Evidence: 214 sources · refreshed daily

Risk intelligence pipeline

Automated collection, APIs, and RPA, running continuously.

Scores are generated from live source data rather than vendor questionnaires. FDA databases, regulatory dockets, and emerging AI policy feed the same evidence graph behind every scorecard and every lifecycle stage.

0

evidence sources per card

0%

collection automated

  1. 01

    Automated collection

    Crawlers and RPA agents harvest filings, documentation, and disclosures on a continuous schedule.

  2. 02

    Authoritative APIs

    FDA device and adverse-event databases, registries, and legislative feeds pulled directly at source.

  3. 03

    Normalized scoring

    Evidence is deduplicated, weighted by domain, and resolved into a defensible composite score.

  4. 04

    Alerting

    Score movement, new legislation, or a fresh incident notifies the contract owner within the hour.

Policy surveillance

AI health policy legislation across all 50 states.

Every bill, amendment, and enacted statute touching clinical AI is tracked and mapped to the products it affects. Explore the map to see where each state stands and agencies holding an affected contract are alerted automatically.

50-state AI health policy tracker

CA

Selected state

California

In committee
Bills tracked
6
Latest action
Referred to health cmte.
Last updated
2026-02-14
Affected contracts
2

Hover, tap, or tab through any state to inspect legislative activity. Agencies holding an affected contract are alerted automatically when a bill advances.

In the field

Trusted where the decision has to hold up.

Case study

A statewide health agency cut AI review time from eleven weeks to nine days.

Twenty-two AI systems were inventoried, tiered, and scored against a shared weighting model. Three vendors moved to conditional status with contractual remediation deadlines; one was declined before award.

Request the full write-up
0
systems inventoried
0d
average review
0
conditional awards
0
declined pre-award

Questions

What review boards ask first.

Where does the evidence come from?

Authoritative sources only: FDA device and adverse-event databases, federal and state registries, legislative feeds, regulatory dockets, and public filings. Vendor questionnaires are supporting evidence, never the basis of a score.

Can we set our own weighting?

Yes. Every domain weight is configurable per use case and per agency, and the rationale is captured with the score so a reviewer can reconstruct the decision months later.

How does this fit our existing procurement process?

Scorecards output a board-ready evidence package and clause-level contract language, so they slot into an existing gate review rather than replacing it.

What happens after award?

Monitoring continues. Drift signals, incidents, and new legislation update the score and notify the contract owner, with a full lifecycle record waiting at renewal.

Request a briefing

Bring evidence to your next procurement review.

We will walk your team through a live scorecard for an AI product currently under evaluation by your agency, with no questionnaire required.

Typical response within one business day.