Governance that survives an examination.
Our wedge is not accuracy — accuracy is table stakes. It is that an operator, an auditor, or an autonomous agent can verify what we say without trusting us: replay it, hash it, open it, or receive an honest no.
Every claim on this page traces to a row like one of these. That’s the product.
What we hold ourselves to, mechanically.
Byte-identical replay.
A frozen, deterministic engine computes every fact. Identical inputs produce identical outputs to the byte — re-run any cycle and compare the core hash. The language model only phrases results; it never touches the math.
A fingerprint on every answer.
Every response carries the engine version and core hash. The governance export includes the data fingerprint and ordered run events, so any number can be traced to the exact engine and data that produced it.
We refuse rather than guess.
Below a validated lift of 1.5 on out-of-time holdout, you get a structured refusal with recorded reasons — never a weak ranking with caveats. Refused runs are never billed.
Leakage is quarantined and named.
Columns that encode the outcome after the fact are excluded automatically, and the exclusion — column and reason — appears in the response and the audit bundle.
Phrasing is validated against the numbers.
Every displayed figure is a persisted engine fact, byte-equal on render; factors are never invented or dropped by the phrasing layer, and a rejected phrasing is never silently retried.
Nothing acts without you.
Every action is staged in an approval outbox and recorded in an append-only ledger. You widen or narrow autonomy whenever you want; executed actions are measured against deterministic control groups.
Three checks anyone can run. No account manager required.
We don’t keep your data. We never train on it.
Data-minimization is architecture here, not policy. Raw data is processed for the run, then discarded; we retain derived facts and entity IDs only — an action can’t reach an account without its ID. Per-tenant isolation with no bulk export beyond your own entities; counterfactual access is per-tenant scoped and rate-capped.
leak-guard · exclusions + why
model quality · lift, calibration, drift
action ledger · append-only
data fingerprint · ordered run events
bundle · sha256