The complaint file, the technical file, and the evidence behind both.
Complaints arrive as anything and the clock starts at awareness. Submissions are assembled from documents you already hold. The literature behind your CERs, PERs and PSURs never pauses. Exemplary AI reads it all and drafts what your procedure requires, with the source cited on every value — and nothing is decided, filed or sent until a person signs. Inside your network, where those files already live.
The backlog is made of documents.
A complaint queue, a submission deadline and an evidence review run on different clocks, at every device and diagnostics company alike — and underneath, they are the same work: reading, extraction, drafting, and a signature. None of it is a knowledge gap.
The complaint queue.
A call-centre transcript, a sales rep’s email, a distributor’s spreadsheet, a returned-goods form. The aware date must be captured where awareness actually happened, the reportability decision tree must run, and the vigilance windows are counted in days.
The submission.
A technical file under MDR or IVDR, an eSTAR section, a remediation backlog measured in product lines. The material exists — test reports, prior filings, standards — and assembling it is the schedule. Every gap is a future audit finding.
The evidence treadmill.
The literature did not pause because the CER shipped. Screening, appraisal and the periodic reports — PSURs, PMCF, the PER’s next revision — run on a fixed clock, and every statement must trace to the paper it came from.
Three queues every device company runs.
From orthopedics to diagnostics to surgical robotics, the portfolios differ and these queues do not. Each one below is read, extracted and drafted by an agent — and closed by a person.
- Event description
- p.1
- Aware date
- p.2
- Product identifiers
- p.3
Reportable? — left for the specialist
From awareness to a filed report — drafted.
Intake in any format is classified, the aware date is captured where awareness happened, the fields your procedure names are pulled with their source pages, and the decision criteria are quoted from the procedure in effect. The assessment is drafted with the reportability line left blank — that line is a person’s — and the signed file joins the record your trend review reads.
- Any intake format: emails, transcripts, portal exports, scans
- The aware date, captured at awareness
- Criteria quoted verbatim, decision left to a person
- The signed file feeds trending and the periodic reports
- 01Device descriptioncited
- 02Risk managementcited
- 03Verification & test reportscited
- 04Clinical evaluation
Listed as a gap — not written over
Assembled from what you already hold.
Technical-file and submission sections drafted from the documents that already exist — test reports, prior filings, risk files, standards — with every statement cited to its source, and every gap listed as a gap before an auditor or a notified body lists it for you. The same machinery reads a remediation backlog, or an acquisition’s entire document estate.
- MDR and IVDR technical documentation, eSTAR-shaped sections
- Every statement cited to the document behind it
- Gaps listed as gaps, not written over
- Remediation and integration backlogs, read at machine speed
- includedappraised · cited to the page
- excludedcriterion quoted
- includedappraised · cited to the page
- excludedcriterion quoted
The literature never pauses. The treadmill can.
Search results screened against your criteria, appraisal drafts cited to the paper and page, and the living documents they feed — the CER, the PER, the PSUR, the PMCF report — kept moving on their clock. Your medical writers review evidence instead of formatting it, and your clinical judgement stays yours.
- Screening against your inclusion criteria, every exclusion reasoned
- Appraisals cited to the paper and the page
- CERs, PERs, PSURs and PMCF reports fed on schedule
Drafts for the person who signs.
Nothing here decides. Each of these reads, extracts, drafts and cites — and stops at the signature line, where your procedure puts a person.
CAPA and audit responses
Investigation write-ups drafted from the complaint record, the nonconformance history and the device file, with every statement cited to its source. Effectiveness checks assembled against the actions actually taken. Audit findings answered from the documents that answer them — and a quality engineer signs every one, because that is what your procedure requires.
The file joins the trend
Complaint codes rolled up across the queue, recurring failure modes assembled for review, and the inputs your trend reports and PSURs ask for, gathered on their clock. The roll-up is drafted; what it means is a person’s call.
Answers from controlled documents
Your SOPs, specifications and standards, answered with the revision and the page — quoted verbatim, never paraphrased, and it declines what the documents do not cover.
Medical information replies
Inquiry responses drafted from approved labelling and standard response documents only, in the reader’s language — and a person still signs before anything goes out.
The archive is scans
The technical file from 2009 is a scanned PDF and the legacy complaint record is a filing cabinet. OCR, figures and tables included — it is still readable, and still citable.
A release is not a redeploy.
Every agent ships as a versioned package. Before it ships, it replays real cases against an assertion suite, is compared against the release it supersedes, and is proven to describe the same documents at the same revisions — or the build fails. This is the evidence your software-validation process asks for, and the paper trail your supplier qualification inspects.
A release, not a redeploy
Everything the agent is ships together — the prompt, the index, the graph, the tools, and a registry of every document it may cite, at its revision. One package, one version, one thing to qualify under change control.
It arrives at 16:50 on a Friday.
An emailed form and two attachments, and the clock is already running. By Monday’s queue review, everything below has happened except the one line that matters — which is still a person’s.
Draft assessment
- The event description is on the covering email and one attached form. p.1
- The aware date is the email's received date; the form states an earlier event date. p.2
- The applicable decision criteria are quoted from the reporting procedure in effect, row by row. p.4
Marked for a person
- Reportable, or not?The draft cites the criteria rows it read. The decision is not the agent’s to make.
- Two required fields have no source pageListed as missing, not guessed.
left blank — a person decides
Nothing is filed with a regulator until this row is signed.
It lands in the queue.
Forwarded from a shared inbox, or dropped into a watched folder. OCR runs, the file is indexed, and it is visible only to the quality group that owns it. The aware date is captured now — where awareness actually happened, not where the paperwork caught up.
The agent reads all of it.
Not a keyword scan. It identifies what the file actually contains — a covering email, a complaint form, a photograph of a label — and treats each as its own document type.
It pulls the fields the procedure names.
The event description, the dates, the product identifiers your form asks for — each value carrying the page it was read from, so checking is opening a citation.
It quotes the criteria in effect.
The decision rows from your reporting procedure, at its current revision, quoted verbatim beside the extracted facts. Not a summary of the rule — the rule.
It drafts the assessment, decision blank.
The draft assembles the facts against the criteria and stops. The reportability line is empty on purpose: it is not the agent’s to write, on this platform or anywhere.
A person decides, signs — and the file joins the trend.
The specialist makes the call inside the window, the signature closes the record, and the audit trail names who decided what, and when. The closed file feeds the roll-up your trend review and periodic reports read. Nothing reaches a regulator without that signature.
The first agent pays for the index. The second costs a configuration.
The corpus indexed for the complaint queue is the corpus the CAPA investigation reads, and the one the evidence review screens against, and the one the next submission assembles from. One security review, one deployment, many desks. And when the corpus itself moves — an acquisition to integrate, a business to separate — that is an entire document estate landing on the same few people. Indexed, it becomes review work rather than a records project.
A gap in a technical file is listed as a gap, before an auditor or a notified body lists it for you.
The complaint file, the CAPA record and the periodic report all cite the same indexed set — so they can never quietly disagree about what a document says.
The next workflow starts from the registry that already exists, so it costs a configuration, not a project.
The unfiled submission never leaves. Neither does anything else.
A complaint file, trial data and a submission that has not been filed yet are exactly the documents you cannot send to someone else’s cloud. So the platform installs inside your network — inference included — and the AI conversation stops being a data-sharing negotiation.
Inference inside your perimeter
Bare-metal, private cloud, or fully air-gapped. No document, extracted field or embedding is sent to a third party — not even for inference.
Never training data
Your documents and outputs are never used to train a model. AES-256 at rest, TLS 1.3 in transit, and updates arrive as secure offline transfers.
Scoped to the desk
Groups and IAM, least privilege, deny overrides allow. The complaint queue, the submission desk and the surveillance file each answer only to the team that owns them.
Deployed inside your perimeter under controls that already exist — and an air-gapped site never needs a connection.
The same platform, pointed at the quality system.
Nothing here is a med-tech product. It is the platform, configured — and where a workflow needs more than configuration, we build the agent with you, on the same deployment your security team has already reviewed.
- Document intake
- Watched folders, shared inboxes, upload or API
- Formats
- Emails, scans, faxes, portal exports — read as documents
- Reading
- OCR, indexing, entity linking, vision captioning of figures and tables
- Retrieval
- Grounded retrieval, revision-aware, quoted verbatim
- Structure
- Knowledge Graph over documents, sections and figures
- Releases
- Versioned agent packages, gated by replayed evals
- Access
- Groups and IAM — least privilege, deny overrides allow
- Oversight
- Human sign-off gates and a full audit trail
- Systems
- 170+ integrations via MCP
- Deployment
- On-premise, private cloud or air-gapped
What quality and regulatory teams ask first.
See Exemplary AI in action
Book a demo and we'll show you purpose-built agents grounded in your own knowledge — deployed on your infrastructure.