Platform · Private AI
AI Analyst
A private AI that answers only from records the person asking is allowed to see, and cites every claim.
01
It cannot exceed you
The AI holds no database credentials and issues no SQL. It reaches data through a fixed set of read-only tools, and each one re-checks your permissions at the service that owns the data. There is no tool to close a case, change a record, export data, or reach the network.
The asking user’s permissions
AI tool scope · read-only
- search records
- read record
- traverse graph
- read timeline
- close case
- change record
- export data
- reach network
No such tools exist — not disabled, absent
02
Citations are structural
Citations are built from what the tools returned, not from the model's output. An answer with no supporting records carries no citations and says so, rather than composing something plausible.
› why was ACC-2201 flagged this week?
The account funded TXN-88412, 9.6× its 90-day average, to a counterparty incorporated seven weeks ago.
⌁ Core Banking · TXN-88412⌁ KYC · COM-3308⌁ Monitoring · ALR-0233
No supporting records → no citations → the answer says so
03
Documents are data, never instructions
Text extracted from an uploaded document is analysed, never obeyed. Which tools run is decided by rules, not by the model, so a document containing instructions cannot widen what the AI touches.
04
Your data stays inside your deployment
The default runtime is a model running inside your perimeter. External providers are disabled by default; enabling one is an explicit, audited operator decision.
See it on your data’s shape — not a slide deck.
A pilot runs on synthetic or masked data first, inside your perimeter.