An answer you cannot audit is an answer an institution cannot use. Designed for governed, auditable institutional workflows.
Separation is enforced by row-level security in the database, not by application filtering, and is tested by an adversarial suite that attempts the attacks across API, database, vector store, cache, export and guessed identifiers rather than assuming they fail.
Document identity is bound to document content before anything is classified. Synthetic material is a first-class, clearly-labelled status precisely so that nothing ever has to pretend to be a regulator's filing in order to exist.
Agents are principals with their own capability scopes, narrower than the humans who invoke them. Evidence a principal may not see never enters the working set, so prompt injection has nothing to reach for.
Arithmetic, permissions, entitlements and the immutable record are deterministic. Models read and reason; they never compute a number or grant access.
An immutable audit ledger on every action, and an append-only decision record. The prior state and the evidence behind it stay readable, an asset you can edit is not a record.
The record preserves what was known at the time. A resolution may only use evidence that existed at or after the resolution date, so a decision can never be graded against information that did not exist when it was made.
What we will not claim. A product whose premise is that every claim carries a receipt cannot overstate its own, so: