Cross-cutting guarantees
1
In-boundary & sovereign. Runs in the firm's cloud, tenancy, data centre or air-gapped enclave; three editions, no raw data leaves. §1a
2
Governed at every layer. Access, policy, approval and immutable audit enforced at source, on every action; RBAC + ABAC. §3a · §3c
3
Grounded, not generative. Answers assembled from evidence, each line traceable to source; abstains where grounding is absent. §4b
4
Reproducible. Replay the exact evidence, historical data state, rule versions and execution path that produced a result. §3c
5
Model- & cloud-agnostic. Bring your own model, including open-weight hosted locally; the platform compounds as models improve. §1b · §1d
The stack
6
Users & surfaces. Role-based, entitlement-scoped access; agencies act under the acting user's entitlements. §3a
7
Agentic layer. Agencies, no-code Rule Studio, BPM flows, the autonomy dial and the deterministic validation gate. §5a · §5b · §5c
8
Governance & observability. Policy/guardrails, model gateway, grounding, monitoring, immutable audit and lineage — spanning every layer. §1b · §3 · §4
9
Resolved knowledge graph. One graph on active metadata — entities, relationships, lineage; a projection over live sources, not an ingested copy. §2a · §6c(i)
10
Knowledge Fabric. Unify in place, auto-discovery, sensitive-field tagging, schema/ontology derivation, entity resolution, field-level lineage. §2a · §2b · §4a
11
The estate. Systems of record resolved in place — databases, ERP/HR, CRM/SaaS, warehouses, streams, documents/DMS, APIs; raw records never egress. §1a · §2a
Deployment & boundary
12
Control plane. Works only on metadata and configuration — schedules, policies, definitions; never documents or prompt content. §1a · §1b
13
Data plane. Reads, resolves and indexes entirely in-boundary; the graph store sits in the firm's chosen region. §1a · §2a
14
The boundary. Default-deny, fail-closed egress; raw records never cross — by construction. §1a
15
Named enforcement points (C1–C5). Every crossing inspectable, logged and provable — a boundary a CISO can verify line by line. §1a · §3c
16
Keys. The firm's KMS/HSM; in the sovereign edition, inside the firm's enclave, tamper-evident. §1a