How we build

Enterprise-grade is not a sticker. It is a set of decisions you can inspect.

Isolation

One client, one instance.

Every client runs on their own database, their own authentication, and their own API keys. There is no shared tenant, which means there is no scenario where a bug or a misconfigured query exposes one client's data to another. It is the most expensive way to build and the only one we will stand behind.

Your instance lives on your infrastructure under your accounts, or on ours under an agreement that says how and when it transfers to you.

Autonomy

Nothing writes without a human.

The assistant drafts, proposes, and prioritizes. It does not send, does not delete, and does not change a record on its own. Every write action waits in a queue for a person to confirm, and every confirmation is attributable to the person who made it.

As a workflow proves itself, you can raise the autonomy on that specific step. You choose which ones, and you can lower it again. The default is always confirm.

What we do not build on

We do not run your business on somebody else's roadmap.

Most of what gets sold as a platform is a seat-based product with your processes bent to fit it, priced per head, with the parts you actually need behind the next tier. We build the thing that fits, and you stop paying for the ninety percent you never used.

The stack

Modern, boring, and inspectable.

Typed application code in a monorepo with reviewed changes and a full history. Managed Postgres with row-level security. Server-side rendering so nothing sensitive reaches the browser. Frontier models called from the server, never from the client, with keys that never leave the environment. Deploys are atomic and every one of them can be rolled back.

You get the repository. If we disappear tomorrow, your team or any competent engineer can pick it up on Monday.

Data handling

Your data trains nothing.

We do not use client data to train models, we do not pool it across clients, and we do not sell or share it. Model providers are used under agreements that carry the same terms. Retention is what you set, and export is a first-class feature, not a support ticket.

If it ends

You keep everything.

The code, the data, the documentation, and the ability to run it without us. That is written into the engagement, not promised on a website.

Thirty minutes. No deck.

We will tell you what we would look at first and whether we are the right team to do it. If we are not, we will say so on the call.

Book a call

We don't sell retainers. We sell capability. Every engagement has a defined end and your team owns everything we build.