Speed you can sign
Deploy your GxP and SaMD apps in weeks, not years.
T2R2 builds the regulated software you need, fitted to your process, and produces its evidence at the same time. Our agentic AI engine does the work. Your experts review, decide and sign.
Say yes to your sites. A request becomes a working application in weeks, not a line on a backlog.
Every release comes with its Evidence Pack, which your validation team reviews and signs.
Replace the spreadsheets that fill the gaps before an inspector finds one.
Your trial applications are built in fixed cycles, with dates agreed at the start.
Your quality lead receives evidence to review and sign with every release.
The application and its data stay yours, across trials and after the CRO contract ends.
Carry the prototype your clinicians already trust beyond the end of its research grant.
The technical documentation arrives with the software, ready for your regulatory lead to review.
Your clinicians keep their rules, and the application runs on your own infrastructure.
Your software and its technical file are built at the same time, by the same process.
When a requirement changes, the file changes with it, through the same gates.
Your AI feature gets a record of what the model saw, what it answered and who decided.
Agents act only through the permissions you grant, and nothing happens without a human decision.
Every exchange with a model is recorded and can be replayed exactly, years later.
You choose the models and where they run, including on your own servers.
The idea
Software and compliance used to be two projects. T2R2 makes them one.
In pharma and healthcare, one team builds the software and another documents it. The two efforts run side by side and meet at the end, where the gaps appear and the documents are written again. Meanwhile the people who need the tool open a spreadsheet, and it stays.
Today, the compliant route
Two efforts in parallel
Requirements, risks, tests and the trace matrix are written by hand, next to the software, and rewritten each time something changes.
Today, the workaround
A spreadsheet fills the gap
It works by Friday. Nobody has validated it, and it is still running when the inspector arrives.
With T2R2
One piece of work
Every requirement, risk, specification, test and release belongs to one linked record, written as the software is built. When something changes, the record changes with it.
The work is done once, not twice.
How it works
T2R2's agentic AI engine does the work. Your people decide.
The engine drafts every document, links every step and checks the whole chain. At five points in that chain, nothing moves forward until a named person on your side has approved it.
1
Start from the purpose.
The intended purpose is agreed with your project sponsor and approved. Every requirement branches from it, and every feature traces back to it.
2
Build in fixed-length cycles.
Your needs become approved requirements, with their risks and tests linked. Working software arrives in weeks.
3
Release with the evidence.
Each release carries its Evidence Pack. When the software changes, the evidence changes through the same gates.
A requirement changes, and the evidence follows.
What T2R2 is
One platform that does three things for your application.
T2R2 stands for Transparent, Traceable, Replicable and Reproducible. We have been building it since 2022.
1 · The platform
It builds your application.
A regulated development process, from intended purpose to release, in which AI agents draft and named people approve.
- Requirements, risks, specifications and tests in one linked record
- Fixed-length cycles
- An Evidence Pack with every release
2 · The library
It runs inside your application.
The T2R2 library powers every application built on the platform, so each one starts with the same foundations.
- A complete, tamper-evident record of every change
- Any past state shown as it was
- Erasure of personal data that keeps the audit trail whole
3 · The agentic AI harness
It keeps AI agents under control.
If your application uses AI, the harness holds the agents in place and records what they do.
- Agents act only through the permissions you grant
- Nothing happens without a human decision
- Every exchange with a model can be replayed exactly
The Evidence Pack
Evidence your team can review and sign.
Every release comes with its Evidence Pack. It is built as the software is built, on the T2R2 templates, and mapped to your SOPs. Your experts challenge the evidence. They no longer type it.
- User requirements✓ included
- Risk assessment✓ included
- Specifications✓ included
- Trace matrix✓ included
- Test evidence✓ included
- Release manifest✓ included
- Intended purpose✓ included
- Requirements✓ included
- Risk file✓ included
- Threat models✓ included
- Architecture✓ included
- Trace matrix✓ included
- Test evidence✓ included
- Release manifest✓ included
Built for the expectations of: GAMP 5 · 21 CFR Part 11 · EU Annex 11
Evidence for: EU MDR · IEC 62304 · ISO 14971 · IEC 62366-1 · IEC 81001-5-1 · EU AI Act · ISO 13485
| TitleRequirements trace matrixSoftware traceability matrix | DocumentEP-007-TMXTF-003-TRC | |
| Version1.1 | Mapped toYour validation SOPYour QMS procedure | StatusIn review |
| Requirement | Risk | Specification | Test | Result |
|---|---|---|---|---|
| REQ-011 | RSK-004 | SPC-018 | TST-027 | ✓ Pass |
| REQ-012 | RSK-004 | SPC-019 | TST-028 | ✓ Pass |
| REQ-013 | RSK-005 | SPC-020 | TST-029 | ✓ Pass |
| REQ-014 | RSK-006 | SPC-022 | TST-031 | ✓ Pass |
| REQ-015 | RSK-006 | SPC-023 | TST-032 | ✓ Pass |
Illustration with synthetic content.
Already built this way
Two recent examples.
Both applications were built in 2026 for a European university hospital, with a recent version of T2R2.
Medical-device software
Perioperative monitoring
Patients report their recovery after surgery, and care teams see who needs attention first. A companion AI, hosted locally, answers questions about surgery within set limits. The application is built to the highest medical-device class, EU MDR Class III and IEC 62304 Class C, with its technical documentation.
In hospital user testing ten weeks after the first commit.
GxP · clinical research
Electronic consent
Participants in clinical research give their consent electronically, with signed evidence of every step. The application is built for the expectations of 21 CFR Part 11 and EU Annex 11.
Running on the hospital's own infrastructure since August 2026.
Built since 2022
Four years of work on one question: can you show what the software did?
- 2022
T2R2 starts as a distributed multi-agent system. It runs AI and data-science pipelines that are traceable and reproducible by design.
- End of 2022
It goes into use for pharmaceutical companies and contract research organisations.
- 2024
We begin the second generation, rebuilt for regulated software and for AI agents that answer to people.
- 2026
The second-generation core is in place, and the first applications are built with the platform.
What stays yours
You keep the decisions, the application and the way out.
A regulated application lives for years. These are the commitments we make for that time.
Your decisions
Nothing is released without the approval of your named experts.
Your application and your data
You own the application, its documentation and its data. It can run in your own data center.
Your models
You choose which AI models are used and where they run, including on your own servers.
An open core
We are preparing the T2R2 core for open-source release under the Apache 2.0 licence.
Your audit
Supplier audits are welcome.
The early-adopter pilot
Your first Evidence Pack, on your own requirement.
Scope
One applicationChoose the one that hurts most today.
Time and price
One fixed-length cycleThe price is fixed and the exit criteria are agreed at the start.
Result
Yours to keepYou receive the application with its Evidence Pack, reviewed by your own team.
Contact
Tell us about the one application you would start with.
An engineer replies, not a sales sequence. You can also write to weeksNotYears@t2r2.ai.