How it actually works

A look under the bonnet.

You have seen what it does. Here is how it is built: where your work is remembered, what it is allowed to do, and exactly where your data sits.

Written to be read two ways. Plain enough to follow without a technical background, and specific enough that, if you have one, you will know exactly what we mean.


i. One system

One system, not a toolbox.

Not a kit of tools we wire together at your place. One piece of software we built, that runs in your world, or one we run for you.

NotA platform you log into and figure out.
NotA toolbox we bolt onto your systems.
It isOne system we build, shape to you, and run with you.

We are not a platform you log into, and we are not a pile of third‑party tools we bolt on. We build one purpose‑made system, shaped to your business, and run it where you already keep your data. We stay alongside it as people, not a subscription.


ii. The brain

The model does the thinking. The journal does the remembering.

Most AI forgets everything the moment a task ends. Ours writes what it worked out into a permanent, sealed record, like a notebook kept in ink rather than pencil, and reads it back next time. So the second time it meets the same situation it is faster, surer, and already knows your preferences. Correct it once, and the correction holds.

Two clocks, not one.

You can ask what was true last Tuesday, and separately, what we knew last Tuesday. A careful business needs both.

For the technical reader An append‑only, cryptographically signed record is the system of memory. The model reasons; the record remembers. Entries are added, never overwritten or quietly altered, and held on two time axes, what was true and what was known, so history can be read either way.


iii. The harness

However clever it is, it only does the job you gave it.

Think of a capable new hire in their first week. There are things they can do, and things they must check first, however sharp they are.

There are things it can do, things it must ask about, and the rest it simply cannot do. That remit is written into the system, not a polite instruction it might drift from. When it is unsure, it asks rather than guesses.

Sure of itit proposes one move and waits for your nod.
Two good optionsit lays them out and lets you pick.
Genuinely unsureit says so, and stops. It would rather ask than guess.
#maintenance
MW
Margot Wren5:12 PM
Up to £150 a repair, approved contractors only. Anything over, or any emergency, still check with me first.

You set the line, in your own words. It never grants itself a thing, and you can move it or switch it off whenever. It earns the right to act on its own only after a clean run of work, and only inside limits you set and can take back.

For the technical reader Every action that touches the outside world passes through one controlled gate, enforced in code, not asked of the model in a prompt. Permissions are bound to a defined role and cannot be self‑granted. The decision policy is abstain‑biased: high confidence proposes a single action, medium offers ranked options, low abstains.


iv. Where your data sits

Where your data sits.

One self-contained kit. The very same kit runs on your own server, inside your own cloud account, or on a box we run for you.

Same system in all three. What changes is who runs the box.

The key to your AI account is yours. You can revoke it at any time, from your own account, wherever the system runs.

Your instance is yours alone. Your data is never pooled with another business, and it is never used to train shared AI.

For the technical reader One self‑contained unit, identical across your own server, your own cloud account, or a box we run for you. Single tenant, no shared store, no cross‑client pooling. When we run it, it is a dedicated instance under your control: secrets are encrypted at rest under a key you hold, and you can revoke our access at any time. Standard parts and portable data, so you are not locked in.


v. Right to erasure

To forget someone, we destroy the key.

A permanent record that can still forget a person, completely. Here is why that is not a contradiction.

Every person, property or account is locked under its own key. To erase them, we destroy that key, and their data becomes permanently unreadable, without disturbing the tamper‑evident record of what was done.

Step one · put the key beyond use
Tenant · Sophie

Reversible. The key is set aside. Nothing is lost yet, and this step can still be undone.

Step two · destroy the key

Irreversible, and a person has to confirm it by hand. The contents are gone for good.

The record that it happened remains. The contents do not.

Flagged personal data is stopped at the door, so much of it never reaches the record in the first place.

Ask us to erase someone's data and we run it for you, confirm it by hand, and tell you when it is gone.

For the technical reader Per‑subject envelope encryption. Destroying the key makes that subject's contents unrecoverable while the signed record stays intact and still verifies. Erasure runs in two phases, key‑beyond‑use then key‑destroyed, the second behind explicit human confirmation. Structured personal data, like emails and phone numbers, is caught at the write‑gate by deterministic detectors, so much of it never lands in the record.

A conversation, not a pitch

Now you know how it works.

If it is the kind of system you would want quietly running the work of your business, a short conversation is the best place to start.