Home · Platform

One pipeline. Your hardware. No data leaves.

The interesting part of an AI system is rarely the model. It is everything around it: how data gets in, what happens when the model is unsure, who is allowed to approve what, and how you prove six months later why a decision was made. That is what we build.

01Architecture 02Deployment 03Security 04Integrations 05How we work 06Stack
01 · Architecture

Six stages, two rails, one loop back to the start.

Every deployment is the same shape. What changes is which perception models sit in stage three and which systems stage six is allowed to write to.

GOVERNANCE RBAC · PII/PHI redaction · policy engine · approval gates · immutable audit log · retention STAGE 01 Sources scanners · emailSFTP · REST API RTSP camerasdrones · PACS ERP exports STAGE 02 Ingest normalise · splitdeskew · dewarp de-duplicateredact at source queue · backpressure STAGE 03 Perceive OCR · handwritingdetect · segment track · re-identifyspeech · audio layout analysis STAGE 04 Structure schema bindingentity graph event timelinerelations · refs citations STAGE 05 Verify confidence gatescross-checks business ruleshuman queue side-by-side review STAGE 06 Act agents · toolsERP · MES writes tickets · emailline stop · gate webhooks human review below threshold only corrections + outcomes → training set OBSERVABILITY accuracy · drift · latency · throughput · queue depth · cost per document · model version pinning
Rail

Governance is not a feature

It wraps every stage. Redaction happens before storage, not after; permissions are enforced by the runtime, not by a prompt.

Loop

Corrections are the fuel

Every reviewer fix and every downstream outcome flows back as labelled data. The system gets measurably better at your work, not at a benchmark.

Gate

Unsure means stop

Below threshold, the pipeline does not guess. It routes to a person with the page or clip already open at the right region.

02 · Deployment

Four modes. You pick, not us.

We have deployed into a datacentre with no outbound internet at all, and onto a fanless box bolted to a machine frame. The software is the same; the packaging is not.

ModeWhere it runsEgressTypical hardwareBest for
On-premiseYour datacentre, your Kubernetesnone2 × L4 or A10 per 1M pages/moRegulated document workloads
Private cloud / VPCYour AWS, Azure or GCP accountvpc-internalg5/g6 or NC-series instancesElastic volume, existing cloud estate
EdgeBeside the camera or the linetelemetry onlyJetson Orin NX / AGX, industrial PCReal-time inspection, poor connectivity
Air-gappedIsolated network, offline updatesnoneCustomer-supplied GPU nodesDefence, critical infrastructure, health
Scale

Horizontal by stage

Perception, structuring and agents scale independently. The bottleneck is never the whole pipeline.

Resilience

Queue-first

Every stage is a durable queue. Nothing is lost when a node, a network or a camera drops.

Versioning

Pinned models

Model versions are pinned per workload and rolled forward deliberately, with a shadow period first.

Offline

Store and forward

Edge nodes keep working through outages and reconcile when the link returns.

03 · Security & governance

The questions your risk team is going to ask, answered up front.

We would rather have the uncomfortable conversation in week one than in month nine. Here is our default posture - all of it configurable tighter, none of it looser without a written decision from you.

  • Training: your data is never used to train a model any other customer touches
  • Residency: data stays in the jurisdiction and network you specify
  • Redaction: PII and PHI stripped at ingest, before storage and before inference
  • Access: role-scoped retrieval - an assistant can only see what its user may see
  • Audit: input hash, model version, output, actor and timestamp, immutable, seven years
  • Reversal: every automated write is logged with a defined undo path
  • Exit: your schemas, your extractions and your labelled data are exportable, always
policy · defaults
# applied at every stage, not bolted on
data:
  residency: "in-country"
  encryption: at-rest AES-256 · in-transit TLS 1.3
  raw_retention: configurable · default 0 days

identity:
  sso: SAML · OIDC
  rbac: per queue, per schema, per camera
  retrieval: permission-aware

models:
  weights: run inside your boundary
  third_party_llm: opt-in, per workload
  shared_training: never

audit:
  mode: append-only
  export: SIEM · syslog · S3
  covers: [reads, writes, approvals,
            overrides, model_changes]
04 · Integrations

It has to write into the system people already use.

An automation that ends in a CSV somebody has to import is not an automation. We connect to the systems of record directly, and where an API does not exist, we build the adapter.

ERP & finance
  • SAP (S/4HANA, ECC)
  • Oracle Fusion / EBS
  • Microsoft Dynamics
  • Tally, Zoho, QuickBooks
Plant & OT
  • OPC-UA, Modbus
  • MES / SCADA historians
  • PLC I/O for reject gates
  • RTSP / ONVIF cameras
Health
  • DICOM / PACS
  • HL7 v2 and FHIR
  • HIS / EMR adapters
  • Claims clearing houses
Data & workflow
  • S3, Azure Blob, GCS
  • Kafka, RabbitMQ
  • Snowflake, BigQuery, Postgres
  • ServiceNow, Jira, Slack, Teams
05 · How we work

Four steps, and we will tell you at step two if it will not work.

We would rather lose a deal early than deliver a pilot that quietly dies in month four. Roughly one in five scoping calls ends with us saying the problem is not ready for this yet - usually because the data does not exist, or the process it feeds is not agreed.

01WEEK 0

Scope on your actual data

A working session with the people who do the job today, not only the people who buy software. We want to see the worst documents, the poorest camera angle, the exception nobody has written down. We leave with a defined success metric and the honest failure modes.

success metric agreedfailure modes listedgo / no-go
02WEEK 1-2

Prototype, on your infrastructure

A real pipeline against a real sample - typically 500 to 5,000 documents, or a few hours of footage. You get numbers, not a slide: precision, recall, per-field accuracy, latency, and the list of cases it cannot yet handle.

measured baselineerror taxonomycost per unit
03WEEK 3-8

Pilot in production, shadow first

The system runs alongside the current process without touching anything, so you can compare its answers to your team's on live volume. Only when the numbers hold do the writes get switched on - usually one queue at a time.

shadow modereviewer queue livestaged write access
04ONGOING

Operate, measure, retrain

Accuracy, drift, throughput and queue depth on a dashboard your team owns. Reviewer corrections feed retraining on a schedule. When the world changes - a new vendor layout, a new part, a new camera - you hear it from the monitoring before you hear it from a complaint.

SLA-backed supportscheduled retrainingquarterly review
06 · Stack

What is actually under it.

We are pragmatic about models. Open weights where they are good enough and cheaper to run, frontier models where reasoning genuinely earns its cost, and our own training where your data is the advantage.

LayerApproachRuns where
OCR & layoutFine-tuned recognition and layout models, trained on your document familiesyour boundary
Detection & segmentationReal-time detector family, distilled and quantised for the target deviceedge / gpu node
Tracking & temporalMulti-object tracking with temporal action models over sliding windowsedge / gpu node
Reasoning & agentsFrontier LLMs where they earn it, with strict tool contracts and schema-constrained outputyour boundary or opt-in API
RetrievalHybrid lexical + dense retrieval, permission-aware, citation-enforcedyour boundary
OrchestrationDurable queues, idempotent stages, replayable pipelineskubernetes / docker
Review UISide-by-side evidence and correction interface, embeddable in your appsbrowser
MonitoringAccuracy, drift, latency, cost and queue metrics, exported to your stackprometheus / otel
Talk to us

Bring your architecture questions.

The first call is technical, not commercial. Bring the person who will have to run this, and the person who has to sign off on the risk.