Regulatory evaluation brief
Technical evidence for the artifact that is actually deployed.
DEEPBOM identifies a deployment artifact by hash, records its serialized contracts, and separates static derivations from target assumptions and imported runtime observations.
Use it as supporting technical evidence in a controlled process, not as a compliance, safety, performance, or approval determination.
Records it can produce
| Review HTML | A self-contained human review with artifact identity, findings, evidence classes, and interpretation boundaries. |
|---|---|
| Evidence JSON | The full machine-readable analysis envelope and Artifact Evidence IR identity. |
| Evidence package | Hash-bound evidence documents, the canonical IR, and verification metadata in one ZIP. |
| Artifact diff | Technical changes in interfaces, graph structure, parameter payload, metadata, and analysis coverage. |
Where it can help
- Configuration identification for the exact model file or package under review.
- Design verification records for serialized interfaces, quantization contracts, and graph structure.
- Change review between a controlled baseline and a candidate deployment artifact.
- Gap records that state which runtime, lineage, task-performance, or process evidence is still absent.
Standards context
Organizations may assess these records within processes that reference IEC 62304, ISO 13485, and ISO 14971. These identifiers are provided only as evaluation context; DEEPBOM does not reproduce licensed requirements or claim conformity.
Boundary
The output does not replace clinical validation, risk management, usability engineering, cybersecurity assessment, manufacturing controls, or validation of DEEPBOM for an organization's intended use.
Start with a verified sample in the browser, then preserve the analyzer version, artifact SHA-256, target identity, rulepack identity, and generated evidence package with the controlled review record.