Spectralgraph
Health systems

Certifications check the paperwork. We measure the model.

We are an independent testing lab and a no-PHI vendor by design. We measure how often the language model your system hosts makes things up, using your own question types, and hand you a signed, dated report for the governance file.

FIXED PRICE · FIVE BUSINESS DAYS · NO MEETINGS, EVERYTHING IN WRITING · NO PHI, NO PATIENT DATA
The regulatory moment

RUAIH made AI governance a certification question. The model is still the open item.

Certification pathways opened in June 2026, and governance reviews check that policies and oversight exist. A quality committee eventually asks a different question out loud: how does the model itself behave on our question types. That one takes a measurement, and measurement is all we do.

The instrument works from the model's internal signals while your real clinical and operational question types run against an endpoint you designate. What comes back is a map of where the model fabricates and how often, with each flagged answer quoted in full so your clinicians can judge it themselves. The deliverable is a signed, dated screening measurement for the governance file. Detection performance so far: 0.852 AUC on models the instrument had never seen, fabricated-entity discrimination, length-controlled, leave-one-model-out. Method paper DOI: 10.5281/zenodo.21365654.

What it needs from you

No PHI, ever. Nothing installed. Five business days.

Spectralgraph is a no-PHI vendor by design. The test needs representative question types and a model endpoint you designate, never patient data, so there is no BAA to negotiate. In scope: a self-hosted open-weight model, a vLLM-class private-cloud deployment, or an internal fine-tune your system controls. Private Azure OpenAI exposes probabilities on output tokens only, so that takes behavioral testing instead. Epic-embedded and vendor-scribe AI that the vendor attests to is out of scope, and we say so up front.

For tribal health systems the same posture serves data sovereignty. The measurement comes to your designated endpoint, and your data goes nowhere.

Terms

The price is published and it never depends on what I find.

The LLM Validation Report is $9,500. Continuous Assurance is $6,500 per quarter for one model. The pre-deployment Model Selection Study is $4,500 for two candidates, up to $7,500 for four. Full terms are on the pricing page. No work begins without a signed engagement letter, and no fee is ever success-based.

Straight answers

Questions health compliance teams ask first

Do we need a BAA with you?
No, by design. Spectralgraph is a no-PHI vendor: the measurement never touches patient data, so there is no PHI to cover. We provide a written no-PHI statement for your vendor file instead.
How is this different from AI certification programs?
URAC's and CTA's programs do real work reviewing an organization's AI governance. We are the other half: an independent measurement of how your specific model behaves, which is the evidence a certification file points to when someone asks what the testing showed.
We run Epic's AI and an ambient scribe. In scope?
Mostly no, and we will tell you plainly. Vendor-hosted AI the vendor attests to is out of scope, since there is nothing of yours to measure. What we can measure is a model your system hosts or designates, at any deployment that exposes prompt-side token probabilities.
What does the deliverable look like?
A signed, dated screening measurement: fabrication frequency mapped by topic across your real question types, with each flagged answer quoted individually so your clinicians can verify it with their own eyes.

Read the report before you decide anything.

Email us and the sample validation report comes back the same day, so your quality and compliance teams can see exactly what the certification file would hold.

Email the lab
REPLIES SAME DAY · EVERYTHING ANSWERED IN WRITING, ON THE RECORD