Tuttify Carbon · For healthcare & medical AI · v1.0

The documentation
every regulator,
clinician, and auditor
is waiting for.

Carbon interviews the people who built your clinical product — the data scientist, the PM, the security engineer, the medical director — and generates the artifacts you need to ship. PRDs, threat models, model cards, IFUs, validation evidence. With every claim linked back to the moment it was said.

▶ Start your first interview See how it works
Audit coverage
100%
Every claim. Linked. Always.
Artifact types
14+
PRD · STRIDE · IFU · model card…
First-pass time
~40 min
Conversation to draft bundle
Built for
FDA · HIPAA
SaMD · ISO 13485 · IEC 62304
— The gap —

Your clinical AI works.
The paperwork is what's
holding the launch.

The model is validated. The clinicians are excited. Then someone asks for the threat model, the data flow diagram, the bias evaluation, the predicate device comparison — and the project stalls for three months while a PM reverse-engineers what already lives in five people's heads.

— 01 —

Knowledge trapped in heads

The data scientist knows the training cohort. The clinician knows the workflow. The security lead knows the threat surface. None of it is written down.

— 02 —

Documentation written retroactively

PRDs and threat models get drafted six months after the decisions were made. By then nobody remembers why — and the audit trail is fiction.

— 03 —

Reviewers ask the same questions

FDA, IRB, internal compliance, hospital procurement — all asking variations of the same questions. Each round costs another sprint.

— 01b — In the room

What a Carbon
interview looks like.

Carbon asks the question. You answer in your own words. The structured signal — thresholds, populations, risk classes, edge cases — is extracted while you speak. Provenance pills appear in the generated documents linking every claim back to this moment.

C
Carbon · 14:09 · Discovery · Q4 of 18

When the sepsis risk score crosses your threshold, who is the first person looking at it — and what are they doing the second before that alert fires?

DR
● Voice Dr. Reyes · Medical Director

The charge nurse — they're already doing rounds on the unit. We don't want a popup, that's alert fatigue. We surface it on the existing operator console at the threshold of sixty-five, and they get to it in the next thirty to sixty minutes on the normal monitoring rhythm. No interruptive alerts unless it crosses eighty.

Threshold · 65 Non-interruptive 30–60 min rhythm Hard alert · 80 First responder · charge nurse No alert fatigue
→ Appears later in the model card as

The frontline operator is the charge nurse, who reviews the operator console on the normal monitoring rhythm. The system surfaces a non-interruptive signal at a risk score of 65, escalating to a hard interruptive alert at 80design · 14:09 — a design choice made specifically to avoid alert fatiguedesign · 14:09.

— 02 — The Pillars

Four threads.
One bundle.

A clinical AI product that's missing any one of these doesn't get cleared — or it gets cleared and then gets pulled. Carbon runs all four pillars in parallel, in a single coordinated set of interviews.

E
— 01 — Evidence

What does the
data prove?

Training cohort, validation methodology, bias evaluation, performance across subpopulations, edge cases. The argument for clinical efficacy, written the way a reviewer reads it.

Model card
Validation report
Bias evaluation
W
— 02 — Workflow

How does it fit the
clinician's day?

User personas, the moment of use, alert thresholds, escalation paths, integration with the EMR. The grounded picture of what the bedside actually does with your output.

User journey · PRD
Sequence diagrams
IFU · labeling
D
— 03 — Design

How is it built?

System architecture, data flow, PHI handling, model lifecycle, API contracts, the decisions that defined the build. Captured as diagrams a developer or an auditor can actually use.

Architecture diagram
Data flow · ERD
Lifecycle plan
C
— 04 — Compliance & Security

What could
go wrong?

STRIDE threat models, HIPAA data classification, FDA SaMD scope, IEC 62304 mapping, audit checklists, risk register. The work auditors ask for — written upfront, not retrofitted at submission.

STRIDE threat model
HIPAA · HITRUST map
FDA SaMD checklist
— 03 — How it works

Conversation in.
Submission-ready
bundle out.

Carbon runs the interview. Your team talks — or types — and Carbon asks the follow-ups your reviewers would ask. It captures the structured signal hidden inside your team's story. When the conversation ends, the artifacts are drafted.

01 · Scope

Choose your pillars

Pick the artifacts you owe — model card, IFU, threat model, PRD. Carbon tailors the interview to exactly that scope.

02 · Interview

Have the conversation

Voice or text. Carbon listens, asks the next question, and challenges vague answers the way a reviewer would.

03 · Capture

Signal extracted live

Thresholds, cohorts, risks, escalation paths — pulled from the conversation as it happens, not transcribed after.

04 · Generate

Documents draft themselves

Model cards, threat models, IFUs, ERDs, sequence diagrams. Every claim linked to the transcript moment it came from.

05 · Ship

Review, sign, release

Export the bundle for the medical director, legal, the FDA pre-sub. The release package travels together.

— 04 — Who uses it

Built for teams
who can't afford
vague answers.

Health systems shipping internal AI. Digital-health startups preparing FDA submissions. Diagnostics vendors selling into procurement. Anywhere a claim about a clinical product needs to be sourced, not asserted.

Health systems

Document the AI you've already deployed.

Sepsis predictors, readmission models, triage assistants — most are running in production with documentation that wouldn't survive an audit. Carbon catches up the paperwork without taking the system offline.

Model inventory · Risk tier
Governance evidence
Incident response runbooks
Health-tech startups

From engineering team to FDA pre-sub in weeks.

When the founder, the data scientist, and the CMO each remember a different version of the product, Carbon reconciles it into one bundle. SaMD scope, predicate analysis, IFU draft — sourced from the people who built it.

FDA SaMD framing
Predicate comparison
Pre-submission package
Procurement & buyers

Answer the security review in a day, not a quarter.

HITRUST, SOC 2, HIPAA BAA, threat model on request. Carbon keeps the artifacts current as the product evolves, so the security questionnaire reads back what's actually in production.

HITRUST · SOC 2 mapping
STRIDE threat model
Live questionnaire library
— 05 — The principles

Show the work,
or it didn't happen.

— 01 — Provenance

Every claim links back.

If Carbon writes that the threshold is 65 and the alert is non-interruptive, the document cites the moment in the interview transcript where the medical director said so. No fabrication, no hedging.

— 02 — Honest about gaps

If a question isn't answered, it says so.

Open questions, missing owners, deferred decisions are surfaced — never papered over. You can publish with acknowledged gaps. You can't accidentally hide them.

— 03 — Built for the room

The format reviewers expect.

STRIDE for threat models. IEC 62304 lifecycle mapping for SaMD. Model cards in the standard shape. Carbon emits what FDA, HITRUST, and hospital procurement already know how to read.

— 04 — Stays in your tenant

PHI never leaves your environment.

Carbon runs inside your VPC or signed BAA. The interview transcript, the captured signal, the generated artifacts — all live where your data already lives.

What's the clinical
product you
haven't documented?

Forty minutes from now, the bundle is in your hands.

Start a Carbon project → Schedule a walkthrough
C
Tuttify Carbon
© 2026 Tuttify, Inc. · Carbon v1.0 · For healthcare