Governance

Governance that survives an examination.

Our wedge is not accuracy — accuracy is table stakes. It is that an operator, an auditor, or an autonomous agent can verify what we say without trusting us: replay it, hash it, open it, or receive an honest no.

Why this account is ranked first run 3b3dc851…
outcome bound · renewal_lost · out-of-time split
leak-guard · 2 columns quarantined, reasons recorded
top-decile lift · 2.96× · holdout, not in-sample
calibration · coefficient 1.01 · refit every cycle
action staged · awaiting approval
engine-verified · replayable byte-for-byte

Every claim on this page traces to a row like one of these. That’s the product.

Six commitments

What we hold ourselves to, mechanically.

determinism

Byte-identical replay.

A frozen, deterministic engine computes every fact. Identical inputs produce identical outputs to the byte — re-run any cycle and compare the core hash. The language model only phrases results; it never touches the math.

provenance

A fingerprint on every answer.

Every response carries the engine version and core hash. The governance export includes the data fingerprint and ordered run events, so any number can be traced to the exact engine and data that produced it.

honest-empty

We refuse rather than guess.

Below a validated lift of 1.5 on out-of-time holdout, you get a structured refusal with recorded reasons — never a weak ranking with caveats. Refused runs are never billed.

leak-guard

Leakage is quarantined and named.

Columns that encode the outcome after the fact are excluded automatically, and the exclusion — column and reason — appears in the response and the audit bundle.

faithfulness

Phrasing is validated against the numbers.

Every displayed figure is a persisted engine fact, byte-equal on render; factors are never invented or dropped by the phrasing layer, and a rejected phrasing is never silently retried.

human in the loop

Nothing acts without you.

Every action is staged in an approval outbox and recorded in an append-only ledger. You widen or narrow autonomy whenever you want; executed actions are measured against deterministic control groups.

Verify it yourself

Three checks anyone can run. No account manager required.

1 · Replay
Re-run any cycle on the same inputs and diff the envelopes — byte-identical, or we broke our core promise. The benchmark repo ships the harness.
2 · Reproduce
Clone The Analyst Test and re-derive every published number from seed-pinned artifacts — 19 protocol checks, independent verifier included.
3 · Audit
Export the governance bundle for any run — gate decisions with reasons, leak-guard exclusions, model quality, drift history, action ledger, bundle sha256.
Data handling

We don’t keep your data. We never train on it.

Data-minimization is architecture here, not policy. Raw data is processed for the run, then discarded; we retain derived facts and entity IDs only — an action can’t reach an account without its ID. Per-tenant isolation with no bulk export beyond your own entities; counterfactual access is per-tenant scoped and rate-capped.

Bundle contentsper run
gate decisions · with recorded reasons
leak-guard · exclusions + why
model quality · lift, calibration, drift
action ledger · append-only
data fingerprint · ordered run events
bundle · sha256
Get started

Send your auditor the file.

Governance · Hunter-Seeker