Your facts. Your hardware.
A signed answer — or an honest I don’t know.
Photon answers from your own verified sources, flags a near-miss, or tells you it doesn’t know — built to abstain rather than invent (0 fabricated / 147-battery). The grounded engine runs on your own machine: grounded answers and honest abstains are computed there and never leave. Every answer is designed to carry a cryptographic receipt anyone can re-verify.
The grounded core runs where your data already lives.
The grounding engine, the fact registry, and the receipt signer run on one machine you control. When the engine answers from your records or abstains, your documents, your queries, and your answers stay on that box. You hold the signing key and publish only the public half — so anyone can verify a receipt without ever seeing the data behind it.
We turn your ground truth into a record the engine answers from — or abstains — instead of guessing.
A pack is your own domain facts — a product catalog, an SOP or compliance ruleset, an approved-vendor list, a parts database, a drug formulary, a legal-citation corpus, an internal wiki — turned into a grounded registry. Every entity is bound to a source record you designate as ground truth. When someone asks about your facts, the engine answers from that record, flags a near-miss (“did you mean…”), or abstains. It’s the same machinery that grounds public genes, CVEs, RFCs, chemistry and clinical-trial records on our live demo.
Every answer is designed to sign itself.
Each answer carries an ed25519 receipt — the question, the answer, and the sources — signed by a key you control. Anyone you share it with can re-verify it against your published public key — with one small verifier file, offline, no callback to us or to you, and any tampering is rejected, because the signature is bound to the exact answer. It’s an audit trail for what your AI said and why, without exposing the data underneath. You can watch this exact mechanism run on our public demo today →, where the receipt loop is verified live end-to-end.
Built for the rooms where being wrong has a cost.
Teams that need an AI to answer about their own facts — support, compliance, clinical, legal, procurement, engineering — and can’t put it in the loop until every answer is checkable after the fact. If your data can’t leave your walls, or every answer needs to be defensible after the fact, this is the shape that fits.
Four steps, one domain at a time.
We scope your facts
You bring the ground-truth source — a catalog, a ruleset, a corpus. We map what a grounded record looks like for your domain.
We build the pack
Your facts become a grounded registry with near-miss and out-of-registry detection, validated against held-out examples from your own data — so the engine answers from source or abstains.
You deploy on your hardware
The grounded core runs on one machine you control — the registry, the receipt signer, and a mid-brain model. We scope the hardware with you, and you generate the signing key.
Every answer is receipted
Answers ship with a signed, re-verifiable receipt against your published key — a checkable trail for every response.