One record, first lecture to last credit

Medical training,
remembered.

VeloLibrary is an AI-native learning platform built for institutions. It adapts, explains itself, and carries one learner record from medical school through residency into lifetime CME.

Items answered1,400this term
meridian.velolibrary.com / learn / block
Renal › Acid–base · item 7 of 20● timed

A 61-year-old woman with vomiting for three days. Sodium 138, chloride 88, bicarbonate 34, pH 7.49. Which best explains her acid–base status?

AMetabolic alkalosis from gastric losses
BRespiratory alkalosis
CRaised anion gap metabolic acidosis
Why this itemmastery 38% · weight 11%
Your weakest area, and the heaviest on the blueprint. Queued ahead of three easier topics for that reason.
MASTERY
38 → 41
DUE TONIGHT
+1 card
PREDICTION
218 ± 9
FERPA · tenant-isolated
Tonight’s misses become tomorrow’s cards

Built against the standards institutions are audited on

FERPAHIPAAACGMEACCMEWCAG 2.1 AASOC 2 Type IILTI 1.3OneRosterQTI 2.xAzure SovereignFERPAHIPAAACGMEACCMEWCAG 2.1 AASOC 2 Type IILTI 1.3OneRosterQTI 2.xAzure Sovereign
M1 → CME
One continuous learner record
Tenant isolation enforced independently
~20 min
Sovereign deploy, variables to running
WCAG 2.1 AA
Accessibility target, VPAT included

The problem

Medical training is one continuum. The software never is.

A student learns on one bank, a resident on another, a physician chases CME on a third. Nothing carries forward. The program director rebuilds milestone evidence by hand every cycle, and the registrar reconciles rosters by CSV. The learning is continuous; only the record is broken.

The record dies at graduation

Four years of calibrated performance data becomes a transcript line. The residency program starts from zero, and so does the learner.

AI is bolted on, not built in

A chat box beside a static bank is not adaptivity. If the model cannot see the blueprint, the psychometrics, and the schedule, it cannot plan a day of study.

Procurement stalls on data

FERPA, PHI in case content, and where the model sends prompts. Products that cannot answer these lose the deal regardless of the feature list.

The platform

Six systems that share one record

Each of these exists elsewhere as a separate purchase. Here they read and write the same learner record, which is what makes the daily loop coherent.

Adaptive QBank

A daily queue built from your blueprint, not a generic bank. Item selection is calibrated against real psychometrics and explains itself — learners see why each question was chosen.

Spaced repetition

Every miss becomes a card automatically. Reviews are scheduled around duty hours and rotation load, so the queue respects clinical time instead of ignoring it.

Clinical case simulation

Branching cases with an AI tutor that probes reasoning, then scores against a deterministic rubric before any model judgement is applied.

Authoring & psychometrics

Faculty draft with an AI assistant, a deterministic flaw linter catches item-writing violations, and published items carry live difficulty and discrimination statistics.

Cohorts & curriculum

Blueprint-true heatmaps show where a cohort is thin before the exam does. Curriculum mapping ties every objective to the evidence that it was actually taught.

Milestones & CME

ACGME sub-competency evidence accumulates from real learner work, then exports as a CCC review packet. The CME data model is built in from day one.

Who it serves

Three audiences, one system of record

The institution is the customer, but the product has to earn its place with the learner every single day. Both things are true, and the design follows from holding them together.

Learners

Students, residents, physicians

  • One record that survives graduation and program transfer
  • A 25-minute post-call session that is actually worth 25 minutes
  • Board-readiness forecast with a confidence interval, not a vibe
  • Full offline practice with conflict-free sync
Educators

Faculty and program directors

  • Objective to published item in under fifteen minutes
  • Cohort heatmaps that point at the remediation, not just the gap
  • Milestone evidence assembled continuously, not the week before CCC
  • Every AI draft badged and human-signed before it counts
Institutions

Registrars, IT, CME offices

  • Nightly SIS roster sync and SSO your IT team already runs
  • Tenant isolation enforced twice — middleware and row-level security
  • Deploy in our cloud or entirely inside your own Azure tenant
  • Every action in an immutable audit log, exportable as a binder

Trust

Data sovereignty is the feature

Every claim below is enforced by a technical control, not a policy document. That distinction is the entire reason procurement moves.

Your data never trains a model

Zero-data-retention terms with our model provider, contractually. Learner PII never reaches a model, a log, or an index — pseudonymisation happens before the gateway, not after.

Isolation you can prove

A failed cross-tenant isolation test blocks the deploy. Not a warning, not a ticket — the pipeline stops. Two seeded organisations, zero permitted reads across the boundary.

AI drafts, humans sign

Models draft items, tag content, and explain misses. No model publishes an item, rates a milestone, or issues a credit. Those require a human identity, and the audit log records it.

The shift

The way it’s done. The way it should be.

The question bank you have
A question bank bought per student, ending the day they graduate.
Adaptivity you are asked to trust, with no way to see why an item appeared.
A percentile against strangers.
Institutional banks stay small because authoring starts from a blank page.
Milestone evidence transcribed by hand the week before the CCC.
Cloud-only, so procurement stops at the CISO.
The VeloLibrary way
One learner record carried from first lecture to last CME credit.
Every queued item states the signal that put it there.
A calibrated score that reports its own error.
Faculty draft with AI, a linter catches the flaws, and a human signs.
Evidence assembled continuously from work learners already did.
The same codebase runs inside the institution’s own tenant.

What we hold ourselves to

The bars the product is measured against.

These are engineering targets we build and test against, not results from a customer deployment. We will replace them with measured numbers from the pilots as those land.

<15m

Faculty time from objective to an item in review

<48h

Draft to published, through human review

≥80%

Published items passing their first nightly stats run

72h

Offline practice window, syncing without data loss

AI drafts. Statistics flag. Only a named human publishes, rates and certifies. That line is load-bearing for FERPA, ACGME and ACCME — so it is enforced in the schema, not in a policy document.

Build principle 3 — from the VeloLibrary specification

See it running with real seeded data

Meridian School of Medicine is a fully seeded demo tenant. Enter as a second-year student, a PGY-2 resident, a faculty item writer, a program director, or the registrar — and see the same record from each side.

Enter the demo