Skip to content
Get in touch
Architecture

Eight layers. One sealed stack, in a cloud you own.

Each layer here exists to prevent a specific failure. This isn't a feature list — it's a list of what can go wrong when AI enters a business whose data is protected, and what stops each one.

01

The projectthat was never ours

The failure: the vendor holds a copy. Once the data sits with the vendor, every assurance is policy — and every breach on their side is a breach on yours.

The deployment lands in a cloud project you open: your network, your IAM, your region, your billing.

We operate the software. The data plane is yours.

There is no second copy on our side to secure — because there is no our side.

02

The keysthat were never issued

The failure: a long-lived key. A key that never expires is a key that can leak, be inherited, or be forgotten — and it stays valid long after the person who received it has gone.

Access runs on short-lived federated credentials that expire on their own. No API key, no long-lived secret.

Every use appears in your audit log, not ours.

There is nothing to revoke in an emergency, because nothing stays valid.

03

The filterthat runs before the search

The failure: filtering after retrieval. If the model saw a document and you hid it afterwards, it already had influence — it ranked, it phrased, and it can surface inside a summary without ever citing itself.

Entitlements are enforced at retrieval, in code, before the model sees anything.

A document a user isn't cleared for is never a candidate. For that query, it doesn't exist.

And a superseded version is out of play — answers rest on the live document, not the one that used to be right.

04

The verifierthat has to agree

The failure: a convincing answer with no source. A model that phrases well sounds right exactly when it is wrong — and that alone is why tools like this don't enter regulated businesses.

Every answer is broken into individual claims, and each claim is checked against the source it came from.

The checker is a separate model from the writer. A model checking itself is not a check.

One unsupported claim rejects the whole answer — and then it says not found, not a guess.

05

The harnessevery agent runs inside

The failure: an agent that improvises. The more freedom an agent gets, the likelier it does something nobody asked for — and in a real business, that is measured in money and clients.

One runtime, one contract: scoped permissions, budgets and timeouts on every tool.

Single-writer ingestion, and no merge without an explicit instruction.

No agent gets a private path around the rules.

06

The consolewhere you watch it work

The failure: a black box. If you can't see what the agent did and what it cost, you can't manage it — and you can't show a regulator anything.

Every turn, tool call, decision and cost — in one place, in your project.

It's the same view we build against, not a log export made for customers.

In build: what runs today is a staging deployment on synthetic data.

07

The personwho takes it from there

The failure: a request that falls through. An agent that tries to close everything will close what it shouldn't — and the item that genuinely needed a person quietly disappears.

Anything the agent cannot finish goes to a person on your side, with the full context.

The open item stays until someone takes it — whether or not the alert arrives.

A sensitive question isn't answered “carefully”. It's handed over.

08

The switchin your hands

The failure: an exit that depends on the vendor. If ending the relationship requires our cooperation, you don't hold the system — you rent it from us.

Our access closes when the deployment ends. You switch it off and revoke it yourselves, without asking us.

The project, the data and the record stay with you — even after we are done.

This isn't a contractual promise. We don't hold the permission to do otherwise.

Eight layers,one decision.

Not one layer here was chosen because it's impressive. Each exists because without it there's a failure you can't live with when the data is protected by law. Together they say one thing: the agent works in your project, and we couldn't reach the data if we wanted to.

Want to see how this sits in your cloud?

Book an architecture review