Decided by the system
High-volume, low-ambiguity, fully evidenced. Runs unattended, fully logged, sampled for quality on a schedule you set.
Governance & assurance
A policy document cannot stop a model inventing a number. A programmatic gate can. Every control on this page is enforced in the runtime of the systems we build — and demonstrable to your auditor.
Why agentic systems are different
A chatbot that is wrong produces a bad sentence. An agent that is wrong files a claim, quotes a price, or sends a document to a regulator.
That difference is the whole of our engineering practice. We assume the model will be confidently wrong some proportion of the time, and we design the system so that when it is, the failure is caught, routed and logged rather than shipped. The controls below are not aspirational — they are the ones running in the engagements on our work page.
The control set
Not every engagement needs all eight. Every engagement gets a written decision on each one — which are in scope, which are not, and why. That record is part of your handover pack.
On regulated topics, a response without a cited source is blocked programmatically before it reaches the user. Not discouraged by a prompt — blocked by code. Running today in a payments compliance assistant.
Structured extraction runs against strict JSON schemas where every uncertain field is explicitly nullable. A field the model cannot evidence comes back null, never as a plausible guess.
Each extracted field carries a confidence score. Values below the agreed threshold route to a human queue automatically. You set the threshold; we show you the trade-off curve between review load and error rate before you do.
Where two sources disagree, the system surfaces both and flags the conflict. It does not pick a winner. Silent reconciliation is how a wrong number becomes an audited number.
Defined points where output cannot proceed without a person approving it. In one legal engagement, that gate covers 100% of drafts before anything is sent externally.
Written conditions under which the agent stops and hands control back — out-of-scope topics, low confidence, conflicting sources, anything touching a regulated determination. Agreed with you at design, not discovered in production.
Identity, scopes and per-user permissions are carried through to the model boundary rather than bypassed at it. An agent acting for a user can reach exactly what that user could reach, and nothing further.
Prompt, tool call, retrieval, citation and final decision are logged to a standard that survives an audit. When someone asks in eighteen months why the system said what it said, the answer is retrievable.
Assurance
Unit tests tell you a function returns what it returned last week. They tell you nothing about whether an agent will hallucinate a policy clause under an unusual prompt. So we evaluate the behaviour.
Human oversight
“The AI decided” is not an answer your regulator will accept, and it is not one we will let a system produce. Every autonomous decision path terminates in a named human owner.
High-volume, low-ambiguity, fully evidenced. Runs unattended, fully logged, sampled for quality on a schedule you set.
The system prepares and evidences; a person approves before anything moves. The default for anything client-facing or externally binding.
Regulated determinations, low confidence, conflicting sources. The agent stops, states why, and routes to the named owner for that decision class.
Which decisions sit in which band is your call, not ours. We bring a recommendation and the evidence behind it. You sign the map, and it becomes part of the acceptance criteria the build is tested against.
Regulated & public sector
Most of our delivered work sits in regulated industries — financial services, insurance, payments and professional services. The requirements below are the ones that come up, and where on this site each is answered.
| Requirement | How it is met | Detail |
|---|---|---|
| Data sovereignty | Singapore by default, AWS ap-southeast-1 — or any region you nominate. Data does not leave the region you choose. | Residency |
| No training on your data | Zero Data Retention where your Anthropic agreement provides it. Prompts and completions are not retained once served, and never used to train a model. | Retention |
| Personal data protection | PDPA compliant, Data Protection Officer appointed, client data processed only for the contracted purpose. | Trust |
| Auditability | Prompt, tool call, retrieval, citation and decision logged. Retrievable long after the fact. | Control 08 above |
| Human accountability | Every decision path terminates in a named human owner. Review gates enforced in code, not policy. | Oversight model above |
| Vendor and sub-processor risk | Named sub-processors with purpose and region. Any addition is disclosed before use. | Sub-processors |
| Source code and IP | Client-accessible repositories from day one. All work product assigns to you on final payment. | IP ownership |
| Exit and continuity | Named backup lead on every engagement. Repositories are already yours, so exit is not a migration. | Exit |
Deploying inside your own boundary. Where your security posture requires it, the application runs in your AWS account, under your controls, inside the environment your organisation has already accredited — we build and operate it there rather than asking you to extend trust to ours.
Ask us for the register. Policy set, insurance certificates, the certification register with holder names and renewal dates, and referees from delivered engagements — all available to your risk function before you commit.
Common questions
If your questionnaire has something not covered here, send it — we complete them ourselves rather than returning a brochure.
Policy set
Next steps
We would rather your compliance function reads it before the commercial conversation than after it. Bring their questions to the discovery call.