Operating the platform.

It runs inside your own environment, and needs only a few named people from your side.

Deployed inside your perimeter.

It is installed in your own environment, in one piece. Your documents, your code, the schemas and the model itself stay there. Run an open-source model on your own hardware and nothing leaves at all. Choose a hosted provider instead and the reasoning call is the only thing that crosses, to a provider you approve, and switching that provider is a configuration change.

Your environment · the boundary
Coherence, one deployable unitInstalled inside

Our private cloud, your private cloud, or on-premise. Everything it reads and everything it builds stays here.

Your documents
Your code
Database schemas
The interfaces
The model itself
An open-source model you hostNothing leaves at all

The reasoning runs on your own hardware, inside the same boundary.

Or, if you prefer a hosted model
A provider you approveThe reasoning call, and nothing else
Anthropic
Google
Amazon
A model in your own region

Switching provider is a configuration change.

No credentials and no live access: it reads only what you export. Anything that later writes, whether a person or an agent, does it from your side, under your own permissions, and only after the gate.

Each step decides whether there is a next one.

The pilot runs a few weeks at a fixed price. Nothing commits you past the step you are on, and the first initiative is scoped once the pilot has shown what the model returns.

Pilot · a few weeks, fixed priceFirst initiative · a quarterThe model, kept true

Those three steps are the road on the landing page, at the scale you actually start: map one domain, then run one initiative on it, then keep it true.

Roles.

A few named people build it, and everyone else queries it. No steering committee, no workshops.

Your sponsorHolds the second gate: nothing changes a live system without their signature. About half an hour a week.
One owner per domainHolds the first gate, and gives verdicts only. The platform does the reading and the extraction, and brings them decisions to make.
A handful of contributors"I don't know" is a legitimate answer and gets recorded as one. One routed question at a time, answered in minutes, asynchronously.
Your IT, onceA one-time export. No credentials and no live access, and it reads only what you export.
Your end usersEveryone who queries the model once it is published. They ask in their own words, and every answer comes back with the document, schema line or code behind it.

The weekly rhythm.

Monday

The refresh lands. Anything that changed in your material gets re-read.

Through the week

Questions route to whoever actually knows. Minutes each, asynchronous, no meeting.

Twice a week

A verdict session, an hour or so, for decisions.

Friday

A written pulse: what moved, what is blocked, and what needs a name against it.

Who does the modelling changes with the plan. see the three.

The model is the only thing you tune.

No prompt to rewrite, no rules engine to configure, no retraining. When an answer has to change, you change the model, and every answer resting on it is flagged for review. Nothing quietly rewrites itself underneath a decision somebody has already made.

It stays current the same way. When work ships through the gates, the deployment writes the result back into the model: drift would require the delivery machinery to stop. And when your material changes outside that path, when someone edits a schema, rewrites a procedure or pushes new code, every element anchored to it flags itself for review.

Every one of those movements is recorded with who made it and why, so the model also tells you how the business worked when a decision was made, and who signed it.

01ModelAuthor the domain. No code, no query language.
02UseAnswers, deliverables, governed change.
03AdjustYou remodel, or accept the write-back it proposes.
04LiveThe new output, the same day.
Model, use, adjust, live, and back to model. One control, and it is the model itself.
Review queue · this week from the demo environment
Table changed · the promo calendar2 connections flaggedreceipt · table diffreview
Document updated · demand modelthe promo calculation asks for re-approvalreceipt · doc diffre-approve
Interface redeployed · weekly sales historyre-verified, queued for one-click confirmreceipt · job configqueued
small confirmations, weekly · from the gates and the anchors

When something moves, the model opens the review or closes it itself, and keeps the receipt either way.

The gates, and what stays yours.

The two gates

The publish boundary is held by a named person: a domain goes live only once published. The per-decision gate requires two signatures, from two different people, before anything changes reality. An AI can never sign its own work.

You keep everything

You keep the model, the exports and the proof. Stop whenever you like and it stays yours, in every way of working together.

See a worked example.

Three are open to explore, or start your own first domain with five documents.

This site uses cookies

We use essential cookies for the site to function and analytics cookies (Google Analytics) to understand how you use it. Analytics cookies are only activated with your consent. We do not track you across other websites. Your data is stored in the EU and processed in accordance with GDPR. Read our Privacy Policy