Research Use Only · Interpretation layer
BioGuard AI™ profiles biomarker patterns across a 12-marker panel and explains which markers contributed to each assessment — working only on measurements that have already passed AssuranceView QC™. Its current model is fitted to synthetic data and has never been applied to a human specimen, so the part that is finished today is everything surrounding the model: what it may emit, what it is forbidden to emit, when it declines to compute, and who must sign before a result leaves the system.
Where this actually stands
train.generate_synthetic_cohort, 14 August 2026.60d673d8091c8b04.This model's own metadata records clinically_validated: false. It was
trained on a cohort this project generated, so any accuracy figure measured against
that cohort describes how well the model recovered a pattern we invented. It is not
evidence about cancer, and no such figure is published on this page for that reason.
BioGuard AI is not a screening test, not a diagnostic, and not a risk calculator. It is a governed interpretation layer awaiting the specimen data that would let anyone make a performance claim at all. Acquiring that data, under an approved protocol with a clinical partner, is the current objective.
What it does
BioGuard AI™ is a research-stage analytical intelligence system. It is intended to support research and future clinical evaluation — not to independently diagnose cancer, and not to replace a qualified healthcare provider. Three of the five capabilities below are implemented and under test. Two are not, and are marked as such rather than described in the present tense.
Returns a composite feature index across the 12-marker panel with a per-marker contribution for each.
SHAP attribution, per marker, against the fitted model. Served in every mode and foregrounded in explain.
Stronger than it sounds: the quality verdict is read from the recorded batch, not accepted as an assertion in the request. Data that failed, or whose verdict is unknown, abstains.
Not built. feature_trend is an approved output class in app/policy.py that nothing currently emits, and no endpoint accepts a prior result to compare against. Listed here because it is the next capability, not because it exists.
Not built. Depends on the longitudinal comparison above.
This is what FFT-E™ is being built to do, and it is the purpose the validation work serves. It is not what BioGuard AI emits today, and saying otherwise would contradict the code: flagging a pattern as concerning is a risk category, a patient classification or a screening result depending on how it is phrased, and all three are prohibited output classes in both app/policy.py and app/governance.py. The current output carries no threshold and no category. Changing that requires outcome data this project does not have.
Where this sits
FFT-E™ is Omni Care Oasis’s blood-based multi-cancer early detection platform. Specimen stabilisation, integrity screening and fluidics are separate components with separate jobs; BioGuard AI is the last stage, and it only ever sees measurements that the stages before it have already cleared.
Specimen stabilisation at collection, holding the pH window the downstream assays were established in.
Specimen integrity gate. Runs before the model, not after: a specimen outside the hemolysis or pH limits is never scored, because a plausible-looking number computed on a degraded sample is worse than no number.
40-zone cassette with passive pulsatile flow, carrying the ELISA and qRT-PCR chemistries.
Interpretation. Takes measurements that passed analytical QC and returns a composite feature index with per-marker attribution — or names the condition under which it will not.
The panel
The tier decides how a marker is treated, not merely how it is labelled. Every marker declares the unit its range was established in, and a value supplied in a different unit abstains rather than being converted — the number is not wrong, it means something else.
12 markers · defined in app/markers.py
Operating modes
The modes change what evidence is demanded before an output is produced, not what kind of output it is. All three return a composite feature index with attribution and no threshold; none returns a screening call, a risk band or a classification, because those are prohibited output classes regardless of mode.
Attribution is SHAP, computed per marker against the fitted model.
Favours sensitivity. Still returns a composite feature index and attribution — never a screening call, which is a prohibited output class.
Demands Core 4 support before an output is produced at all.
Per-marker SHAP attribution for the index, so a researcher can see which markers moved it and by how much.
Default deny
The service permits output classes by enumeration, never by omission. An output class nobody has thought of yet is refused by default, because the check asks whether a class is on the permitted list rather than whether it is on a banned one. These eight are named explicitly so that a refusal can explain itself in the words a reviewer would use.
8 prohibited classes · enforced in
app/governance.py · asserted by the test suite
diagnosisA statement that a subject has or does not have a disease.
patient_facing_summaryOutput addressed to a patient rather than to a researcher. Permitted only under an intended use that does not currently exist.
prognosisA statement about expected course or outcome.
risk_categoryA banding of a subject into low/moderate/high risk. This requires a threshold established on outcome data, which does not exist.
risk_scoreA calibrated probability of disease. The composite index is not calibrated to outcomes and must not be presented as though it were.
screening_resultA positive or negative screening call.
treatment_recommendationAny suggestion about clinical management.
triage_priorityAn ordering of subjects for clinical attention.
Refusal to compute
Abstention is not an error path. Each condition below describes an input the model was never evaluated against, and in every one of them the service returns the named condition instead of a number. A result produced outside the envelope would look exactly like one produced inside it, which is the whole reason the envelope has to be declared before anything is computed.
8 abstention conditions · enforced in
app/interpretation.py
marker_out_of_rangeOne or more marker concentrations fall outside the range over which the model's performance was established. Reporting a value here would be extrapolation presented as a result.
matrix_mismatchThe specimen matrix differs from the one the model was evaluated on.
measurement_system_mismatchThe measurement system differs from the one that produced the model's training data. Recovery characteristics, precision and lot variation differ between systems; revalidation against the new system is required before its output can be interpreted.
missing_required_markerOne or more markers the model requires were not measured. The composite was evaluated on a complete panel; a partial panel is a different input.
no_envelopeNo validation envelope was declared. The conditions under which this model may be applied are unknown.
population_outside_envelopeThe subject falls outside the population the model was evaluated on.
qc_gate_not_passedThe analytical quality gate was not passed. Data that failed QC is not interpreted — interpretation of unreliable measurements produces an unreliable result that looks reliable.
unit_mismatchA marker was supplied in a unit other than the one its range was established in. The number is not wrong; it means something else. Converting silently would hide a reporting-system difference that the laboratory needs to know about.
Human in the loop
Escalation never de-escalates: where several conditions apply, the most senior role requested is the one required. The reviewer's conclusion is recorded and audited, including when the reviewer disagrees — a disagreement is preserved as a finding rather than resolved by recomputation.
6 escalation conditions
abstention_rate_elevatedThis batch abstained far more often than the model's established rate, which usually means the input differs from what was validated.
all_markers_at_boundEvery marker sits at the edge of its evaluated range. The result is inside the envelope by definition and at its limit in practice.
first_use_of_model_versionThis model version has not been used before. The first output from a newly released model is reviewed regardless of its content.
qc_failure_presentThe analytical quality gate failed or was unknown. Someone must see that a result was withheld, because a withheld result and a result nobody requested look identical downstream.
reviewer_disagreementA reviewer recorded disagreement with the output. The disagreement is a finding and is preserved, not resolved by recomputation.
version_disagreementA previous interpretation of the same input under a different model version differs materially. Which is right is not a question the software can settle.
Permitted
Three classes. Everything else, including anything not yet imagined, is refused until someone adds it here deliberately.
abstentionA refusal to compute, with the conditions that caused it named.
feature_attributionA composite feature index with per-marker attribution, carrying no threshold and no category.
quality_assessmentAn analytical quality verdict on measurement data, with the criteria applied.
Evidence record
None of this is a promise in a document. The refusals are code paths, and the suite asserts them. Measured 6 October 2026 against service 0.14.5.
Mutation score is the gate. Faults are injected into the governance
and interpretation code and the suite must catch them; a suite that cannot is not
evidence, whatever its coverage. Coverage is reported rather than gated because it
measures which lines executed, not which behaviour was asserted, and gating on it
rewards tests that assert nothing. Reproduce every figure with
python measure_quality.py --mutation. The run log is append-only and
hash-chained, which makes alteration detectable — not impossible.
What would change this
Every refusal on this page stays in force until a model is fitted to real measurements from a declared population, on a declared measurement system, with a validation envelope established from outcome data. Omni Care Oasis is seeking clinical and repository partners for exactly that step. Enquiries from institutions, repositories and reviewers are welcome.
Omni AssuranceView QC and the BioGuard AI interpretation layer are for Research Use Only and are not for use in diagnostic procedures. The interpretation layer produces a composite feature index with per-marker attribution, for use by a qualified researcher, on measurement data that has passed an analytical quality gate. It does not diagnose, does not assign risk categories or calibrated probabilities, does not screen, and does not address a patient. Every output requires a named human reviewer before it is used or reported.
Served verbatim at GET /governance/intended-use ·
contract 2.0.0