Model abstraction
A model-adapter layer keeps the platform model-neutral: open-weight defaults or a customer-provided endpoint. Swapping models is a governed change, not a rebuild.
Evaluation before use
Versioned, checksummed golden sets measure grounding, citation coverage and refusal recall before a configuration is approved for operational use.
Regression after change
Model, embedding or knowledge updates trigger re-evaluation. A configuration that regresses does not activate.
Human oversight
Output is advisory and labelled with confidence and risk indicators. The system refuses when approved knowledge is insufficient and never executes operational actions.
Known limitations, stated plainly
- Injection resistance is measured in evaluation; no claim of perfect protection or zero hallucinations is made.
These are architecture and control descriptions, not audit results. Current assurance status — implemented, tested, planned — is summarised in the Security & Trust Centre, and deeper material is available through the security architecture pack.