Frequently asked questions
The questions a diligence reader asks are the ones a homepage buries.
Ten questions, answered the way the rest of this site is written: what runs today, what is designed and not built, and what we will not claim. Send this page to your risk committee — that is what it is for.
The ten questions
Parts are running in production and parts are designed and not built, and this site marks which is which on every page. The unbuilt list, in full: the catastrophe financial chain; the dispatch seam between the orchestrator and the simulator; the formal-methods lane; drift detection; the A2A migration from v0.3.0 to v1.0.0; tiers three to five of the dispatch ladder; the folding-phone client; the per-jurisdiction emitters; and the lineage gates. Everything marked ◆ resolves to a repository path we will show you.
No. Never. It is architecturally prevented, not policy-prevented — the inference boundary is enforced in the platform, not in a document someone can override under pressure. Personality inference, emotion recognition and behavioural profiling do not reach an underwriting, pricing or claims decision, and the record can certify their absence for a given decision, which is a stronger statement than a promise. Consent-gated psychometric work exists on the human side of the product — coaching, tone, buying-committee reads — and never crosses into a risk decision.
No. It runs beside your policy admin and claims systems and reads from them. There is no rip-and-replace, and a pilot does not require one.
No. There is no free-text assistant at the centre of it. The unit of work is a decision that gets deliberated, gated and sealed — with a named human who signs it.
Nothing is released. A tier-five job that cannot get agreement between two independent models does not produce an output; it produces a refusal with a machine code, and the refusal is itself part of the record. That behaviour is designed and not yet built — tiers one and two run today.
In our own datacentre, in Europe. Every read, write and dispatch is scoped on three axes — your organisation, the individual owner, and optionally the business unit — and the predicate lives in the shared query layer every repository inherits rather than in something each route remembers to add. A surface that cannot resolve all three refuses rather than guessing.
Your organisation’s own provider pool. You bring your own accounts and your own billing; we hold no shared key behind your tenant. An organisation with no keys configured cannot serve AI at all — an honest empty state, not a silent fallback to ours.
Yes, in full, in an open format, including the hashes that make it checkable. Evidence you cannot remove is evidence you do not own.
Not yet, and we will not imply otherwise. We can show you how the record maps to the obligations, and that is a different claim from having been assessed against them.
Mostly you should not yet — which is why every projected figure on this site is marked as projected and carries what would falsify it. The numbers we do stand behind are the ones tagged as verified, with two independent sources, or observed, with a repository path. Ask us for either.