Technical leadership from decision
through real-world delivery.

Rule26 helps organizations make sound product and architecture decisions, evaluate vendors and internal systems, turn promising prototypes into production-ready systems, and create approved AI paths people can use successfully.

  • Independent review
  • Client-side oversight
  • Defined technical delivery

Start where the project is today.

Engage Rule26 for one defined decision, evaluation or delivery challenge, or continue across stages when the work requires sustained technical leadership.

  1. Decide

    AI Vendor and Architecture Review

    An independent basis for a build, buy, renewal, or architecture decision.

  2. Evaluate

    AI Evaluation, Testing and Assurance

    Determine what the evidence shows about how a system behaves and where it fails.

  3. Deliver

    AI Productization and Technical Delivery

    Close the engineering and operational gaps between a prototype and real use.

  4. Adopt

    Approved AI Adoption and Shadow AI Reduction

    Replace unmanaged AI use with approved tools people actually want to use.

The four services

Engagements can stay advisory or continue into delivery. Scope is agreed for each one.

Decide

AI Vendor and Architecture Review

Useful when you have a funded initiative, defined product opportunity, build-or-buy question, vendor choice, renewal, pilot, or architecture decision.

  • Technical feasibility, product constraints, and build-versus-buy
  • Vendor claims and the evidence behind them
  • Architecture, integrations, and data boundaries
  • Ownership, dependencies, and unresolved risks
  • Pilot or acceptance criteria

You get an independent basis for the decision.

Also in scope
  • System and responsibility map
  • Claims-and-evidence gap analysis
  • Technology-stack and architecture options
  • Delivery approach, ownership, and team requirements
  • Prioritized findings and vendor questions
  • Recommended pilot, remediation, or acceptance criteria where appropriate

We inform the decision. You make it.

Evaluate

AI Evaluation, Testing and Assurance

Useful when you need to know how a system actually behaves and where it fails.

  • Intended uses and unacceptable failures
  • Representative evaluation datasets
  • Grounding, retrieval, permissions, exceptions, human review
  • Failure taxonomy, regression approach, release thresholds

You get a clear picture of what the evidence shows.

Also in scope
  • Post-deployment evaluation or monitoring design where relevant
  • Evaluation plan and representative dataset
  • Scored findings and failure taxonomy
  • Release-readiness or post-deployment assessment
  • Repeatable regression approach
  • Prioritized remediation findings

We provide technical evaluation and evidence. You and appropriately qualified specialists make formal legal, clinical, regulatory, security, compliance, and acceptance decisions.

Deliver

AI Productization and Technical Delivery

Useful when something promising is not yet integrated, observable, testable, or supportable.

  • Technical leadership for a defined AI initiative
  • Prototype-to-production gap analysis
  • Target architecture, integrations, and data boundaries
  • Logging, observability, auditability, exception handling
  • Defined technical implementation workstreams

You get experienced technical leadership and a defined path for closing the engineering and operational gaps.

Also in scope
  • Authentication and authorization
  • Evaluation and regression infrastructure
  • Human review, escalation, deployment, rollback, and handoff
  • Development-team and vendor oversight
  • Cross-functional coordination among product, engineering, privacy, security, and business stakeholders
  • Target architecture and delivery plan
  • Prioritized productization backlog
  • Production ownership and handoff plan
  • Release or customer-acceptance evidence package

Scope depends on the system and the expertise available. We do not supply every specialized discipline, including clinical, EHR, medical-device, cybersecurity, and regulatory expertise.

Adopt

Approved AI Adoption and Shadow AI Reduction

Useful when people are already using AI and the approved path is not good enough yet. A five-step program, not a training day.

  1. Discover

    Current use, employee needs, workflows, and why people bypass approved systems.

  2. Select

    Tool requirements, candidate comparison, technical review, workflow-based pilot.

  3. Define

    Permitted, conditional, and prohibited uses. Data boundaries, human review, escalation.

  4. Enable

    Role-based training, champion sessions, realistic exercises, job aids, rollout support.

  5. Measure

    Feedback, adoption indicators, follow-up evaluation, program improvements.

You get approved tools people actually use, with boundaries that hold up in real work.

Also in scope
  • Workflow and current-use map
  • Approved-tool requirements and comparison
  • Practical use boundaries
  • Role-based training and supporting materials
  • Rollout and behavior-change plan
  • Adoption findings and follow-up recommendations

Durable change involves leadership, IT, HR, privacy, risk, security, and business owners. We do not provide endpoint detection, network monitoring, SaaS discovery, legal advice, or formal compliance determinations.

Running through all four

Privacy, security, verification and operational accountability are considered throughout the technical work, not added after delivery.

  • Testing
  • Traceability
  • Logging and observability
  • Human review
  • Ownership
  • Acceptance criteria

We do not determine legal sufficiency, insurance coverage, regulatory compliance, or formal acceptance. Where a legal, clinical, cybersecurity, insurance, or regulatory specialist is needed, we say so and coordinate the technical work alongside them.

Discuss an engagement

Entry engagement

Initial Technical Review

Before committing to broad architecture projects or signing vendor contracts, bring us one defined question or proposal: a vendor or architecture decision, an evaluation or testing concern, a productization obstacle, an approved-tool or Shadow AI question, or a specific evidence gap.

$500 fixed fee, up to 60 minutes

Book an Initial Technical Review

What you get

  • Up to 60 minutes of direct technical analysis with enterprise engineering leadership
  • Three prioritized risk and evidence observations
  • A concise executive follow-up document

Larger engagements begin with a defined discovery or review so that scope, responsibilities and expected outcomes are based on evidence. This is an initial technical perspective, not a complete assessment.

Not ready for that yet? The project-fit conversation is a short call to determine whether Rule26 is relevant to what you are building. It is not a free technical assessment, discovery engagement, or proposal workshop. The Initial Technical Review above is where the substantive analysis happens.

How Rule26 works

  1. UnderstandThe decision, the stakeholders, and the consequences of failure.
  2. MapSystems, data movement, vendors, integrations, ownership.
  3. ChallengeAssumptions, vendor claims, failure modes, supporting evidence.
  4. DefineTechnical controls, verification, acceptance requirements.
  5. SupportOversight or delivery alongside internal teams and vendors.
  6. EvidenceA record of what was decided, tested, implemented, and unresolved.

Examples of work

  • Examine whether a vendor’s claims are supported by usable technical evidence.
  • Build a representative evaluation dataset, failure taxonomy, and regression approach.
  • Test how a retrieval or agent workflow behaves, and where it fails.
  • Close the logging, evaluation, integration, or verification gaps in a prototype.
  • Compare approved tools against real workflows, then train the people using them.

Healthcare may include PHI movement, vendor and model boundaries, access controls, and qualified human review.

Legal may include privileged information, citation and source verification, and attorney supervision.

Why Rule26

  • Nearly 30 yearsApproximately 20 years in hands-on software development and 10 in engineering and delivery leadership
  • Regulated healthcare leadershipNearly five years leading a ten-person engineering organization in a HIPAA-regulated environment
  • Founder advisoryPrior paid work involving technical-team formation, estimation, stack selection, and initial AWS architecture
  • Privacy and AI governanceCIPP/US and AIGP knowledge incorporated into technical decisions
  • Applied AI verificationHands-on product and verification experience through GhostCite
  • Client-side leadershipExperience guiding internal teams, external partners, and complex technical change

Engagements are led by Salma Saad and may include additional specialists when the agreed scope requires them. We sit on the client side of the table and do not resell platforms. When appropriate, we can continue from independent findings into a clearly defined delivery workstream.

GhostCite checks supported legal citations and quotations against public court-record sources without asking a generative model to serve as the verification authority. It does not check healthcare outputs, general enterprise AI, or overall system readiness.

See experience and credentials