ENCSRequest code access

Systems

Systems

Two working systems, built around the same idea: the dangerous decisions — who may see what, what counts as evidence, what may leave the company — are made by code that can be tested, not by the model. Both are private; the code is shared by invitation — request access.

Knowledge base →

Permission-scoped answers over a company's own documents. Access is decided in SQL before the model sees anything — for vectors, words, word statistics and the typo vocabulary alike, with no exception for the owner. Retrieval is hybrid (vector + lemma / stem keys, fused by RRF); without evidence the answer is “not in the knowledge base” and the model is not called; only cited documents are shown as sources.

Python · FastAPI · Postgres + pgvector · local embeddings · tested against a real Postgres, with a forced-fail gate in CI. Decisions: 0001, 0003, 0006.

Governance runtime →

A policy engine over a vector store that sits between AI tools and a company. It finds the rules that apply to a piece of text and its context, runs their checks and returns a verdict — ok, warn, block or insufficient_data — with the steps to fix it. Rules are YAML playbooks with three levels (advise / warn / block); sessions carry a drift anchor; outbound actions pass a gate that derives severity from typed data and writes an audit record.

Python · FastAPI · Postgres + pgvector · sentence-transformers · schema per tenant.