Screenshot 2026 08 17 at 9 21 08 AM
August 17, 2026

AI You Can Trust: A Conversation on Building Technology for High Stakes Environments

abstract background

Today, we're speaking with Zach Gardner, Chief Architect at Keyhole Software. Keyhole Software is a top-rated custom software development firm for mid-size to enterprise organizations across the United States. GlobalMed®'s virtual care platform combines telehealth software with diagnostic devices to deliver remote clinical care in some of the most heavily regulated environments in the country, so building AI responsibly into that kind of software takes more than a strong model. It takes an engineering discipline earned over years in high-stakes, closely scrutinized environments, and that's exactly what Zach brings. He's spent more than a decade working directly with healthcare clients on systems held to that same level of scrutiny, and that hands-on experience is why we wanted Zach's perspective on what this discipline actually looks like in practice. 

Q1: When you're building software for organizations that operate under a lot of regulation and oversight, like healthcare or government, what actually changes about how you approach the work? 

Zach Gardner: The biggest shift is that architecture decisions stop being purely technical and start being compliance decisions. Where data lives, who can touch it, and how a change gets reviewed all have to be decided upfront rather than patched in later. That's a different posture than typical commercial software work, where you can move fast and clean things up as you go. 

In practice, this means we design system boundaries first: what's isolated, what's auditable, and what gets logged, before we write a line of application logic. Keyhole works with organizations that need more than staff augmentation or offshore delivery. 1 Our consultants are 100% U.S.-based senior engineers, averaging 17+ years of professional experience,2 which matters here specifically because architectural and compliance decisions need to be made by someone who has seen the downstream consequences of getting them wrong, not someone executing a spec without that context. 

The honest answer is that regulated environments don't change what good software engineering looks like. They just remove your margin for getting it wrong later, which means the discipline has to be there from day one. And, along with understanding the technology, you have to have a well rounded understanding of the regulations and compliance requirements for whatever you need to build.

Q2: Your team has spent years working with organizations that can't afford to get this wrong. What has that experience taught you about earning a client's trust?

Zach Gardner: Clients in regulated industries have been burned before by vendors who overpromise on compliance or timeline. We'd rather tell a client a modernization effort will take longer than they hoped than deliver something that looks finished but can't survive an audit, much less crumble under a production workload. It may not make us the most popular folks in the room, but we like to treat others how we would like to be treated, and that starts with being honest and raising red flags when necessary.

Trust in this kind of work isn't won with a single project, it's won by showing up consistently over years. Roughly 78% of our project work last year came from existing clients,3 and a meaningful number of those relationships run 10 years or longer. That kind of continuity doesn't happen by accident.

What it comes down to is staffing intentionally. Our consultants average nearly 5 years of tenure with Keyhole,4 so we understand how our people actually perform across different industries and constraints. That lets us match the right engineer to the right engagement instead of rotating in whoever happens to be available, which is a common failure point with contractor-heavy or offshore delivery models.

Q3: A lot of companies are experimenting with AI right now. What's the real difference between AI that's just a proof of concept and AI that's actually running in production?

Zach Gardner: A proof of concept usually works because the environment around it was simplified to make it work. Production is the opposite: real data, real edge cases, real consequences when something breaks. Most AI initiatives stall in that gap, not because the model is bad, but because the surrounding system was never built to support it in a live environment.

We approach this through what we call architect-governed, test-gated delivery.5 AI accelerates specific parts of the workflow, like legacy code analysis, documentation, and test generation, but a senior engineer is still validating every change against the target architecture before it ships. Keyhole was recently invited to the Anthropic Partner Summit,6 reflecting our work building governed delivery pipelines around tools like Claude Code rather than treating AI as an unsupervised shortcut.

The distinction that actually matters to a client isn't how advanced the AI is, it's whether there's a disciplined process wrapped around it. AI that ships without that discipline creates code nobody can confidently maintain. AI that ships with it compresses real timelines without adding hidden risk.

Q4: As more organizations bring AI into serious, regulated environments, what should they be prioritizing as they figure out how to do it safely?

Zach Gardner: Start with where your data actually lives. A lot of AI tools route sensitive information through third-party infrastructure by default, which is a hard conversation to have after the fact in a regulated environment. We design retrieval-augmented generation systems that keep sensitive data inside the client's own environment rather than sending it out to be processed elsewhere, which changes the entire compliance conversation from the start.

Second, governance has to be built into the development process itself, not written up afterward as a policy document. That means test gates, architectural review, and clear ownership of every AI-assisted change before it reaches production, not a compliance checklist that gets filled out once a quarter.

Third, and this gets overlooked, the experience level of the people supervising the AI matters more than which AI tool you pick. We've found that AI in the hands of a junior team without architectural oversight tends to produce code that looks fine and creates real problems six months later. The organizations that do this well treat AI as an accelerant for experienced engineers, not a replacement for their judgment.

Q5: What do you think most companies get wrong when they're choosing a software partner for a big project?

Zach Gardner: The most common mistake is evaluating a vendor on price or speed without asking who is actually going to do the work. A lot of firms quote senior-sounding teams and then staff the engagement with contractors, offshore resources, or junior developers once the contract is signed. By the time that shows up in the delivery, it's expensive to unwind.

We'd encourage any organization vetting a partner to ask directly: who are the specific people on this engagement, how long have they been with your company, and what's your staffing model if someone leaves mid-project. Keyhole staffs every engagement with full-time, U.S.-based employees rather than contractors or offshore resources,7 specifically because continuity through a multi-year modernization or AI initiative is what determines whether the system is maintainable five years out or becomes someone else's cleanup project.

The second mistake is picking a partner based on their newest technology pitch rather than their architectural judgment. Tools change fast. The organizations that get the best long-term outcomes are the ones who chose a partner based on how that partner thinks through a problem, not which framework they're currently excited about.

References 

1 Keyhole Software, Services page, https://keyholesoftware.com/services/ 
2 Keyhole Software, Services page, https://keyholesoftware.com/services/ 
3 Keyhole Software, homepage, https://keyholesoftware.com/ (78% figure reflects share of project work from repeat clients in the prior year, not an overall client repeat rate) 
4 Keyhole Software, Services page, https://keyholesoftware.com/services/ 
5 Keyhole Software, Agentic AI Software Development Services, https://keyholesoftware.com/services/artificial-intelligence/agentic-ai-software-development-services/ 
6 Keyhole Software, "Inside Anthropic's Emerging Partner Ecosystem," https://keyholesoftware.com/enterprise-ai-development-anthropic-ecosystem/ 
7 Keyhole Software, Services page, https://keyholesoftware.com/services/