AIC
Intelligence
1.
Agree the question
One representative production case, handling scope, users and required outputs.
2.
See the real workflow
Synthetic requirement to approved release — including the negative cases.
3.
Validate your deployment
Disconnected, restart, restore and upgrade tests against your own criteria.
One connected workspace
From the question asked to the product delivered, nothing is separated from its origin.
Requirements
/
Source authority
/
Retained evidence
/
Entity relationships
/
Structured analysis
/
Product revisions
/
Controlled release
/
Explicit receipt
/
Recorded feedback
/
Evidence, connected
Examine an assessment against the evidence actually used.
01
Original file
The acquired byte sequence, retained with its hash and acquisition context. Quarantine and processing state are real.
02
Retained extraction
A parser output derived from those exact bytes, retained separately so the original is never replaced.
03
Exact citation
A precise retained passage or data cell, with the version and integrity detail needed to find the same material later.
Reprocessing a source does not change an older citation. Amending a report does not reuse approval for different content.
Deployment
On-premise, private cloud or public cloud.
CORTEX ships as a signed five-service node: ingress, web application, database, isolated parser and an optional local model. Run it on your own hardware, in your private cloud, or in an AIC-operated Microsoft Azure environment in the UK. Same application, same controls, whichever route you choose.
Disconnected
On-premise or air-gapped
Browser
Local CORTEX node
Application, storage and parser. Optional local model.
External capabilities are blocked before transport. An air-gapped profile ships with the node; physical isolation and disconnected acceptance are confirmed per installation.
Connected
Private or public cloud
Browser
Local CORTEX node
Application, storage and parser. Optional local model.
Approved feeds, map tiles and hosted model endpoints only, under your organisation’s policy. Hosted in Azure UK South with independent environments, or on cloud infrastructure you operate.
Secure by design
Authority is checked at every operation, never assumed from a role.
01
Fail-closed authority
Every content operation needs a current identity, an unexpired grant, workspace membership, a permitting role and the full handling scope, compartments and caveats included. Anything missing, malformed or expired fails closed.
02
Isolated processing
Uploaded files are treated as untrusted. Extraction runs in a separate non-root container with a read-only filesystem, capped memory and CPU, a hard deadline, and no access to database credentials or application keys.
03
Signed and recoverable
Release bundles are signed. Backups are encrypted without staging plaintext, carry a signed manifest, and restore into fresh storage only after signature, hash and image identity checks pass.
Handling labels run from OFFICIAL to TOP SECRET. Versions, actors, timestamps, reasons and integrity hashes are retained for every documented change.
AI, on your terms
Run a pinned local model on the node, or an approved endpoint you control.
01
Local model
A pinned, digest-verified model runs on your own hardware. No automatic download, no substitute model, no cloud fallback. Generation works in both Online and Offline modes.
02
Approved remote model
In Online mode, connect an OpenAI-compatible endpoint you have approved, with protected credentials and a handling ceiling. Tools, retrieval, remote storage and retries are switched off for this workflow.
03
Provenance you can inspect
Each assisted draft records the provider and model, prompt version, source and requirement versions, hashes and the first-draft fingerprint. The analyst reviews and edits before anything is saved.
Model assistance prepares an editable first draft from a bounded, authorised dataset. Review, approval and release stay with people.
Claim discipline
We publish what we can demonstrate. Not what sounds impressive.
Every statement on this page maps to a named, dated piece of project evidence with a stated boundary. Here is the line we hold, and the wording we refuse.
What we will say
Connects requirements, retained evidence, analysis, products and feedback.
Supports local operation without requiring cloud AI.
Retains exact revisions, citations and audit history.
Requires independent approval for exact release content and audience.
Records explicit acknowledgement of a package by a named recipient.
What we will not say
“The only complete intelligence platform.”
“No data can ever leave any deployment.”
“Tamper-proof legal chain of custody.”
“Accredited for any classification level.”
“Automatically produces verified intelligence from any source.”
Operational release acceptance is tracked separately for every deployment. Ask us which gates are still open — we will show you the list.
Recorded evidence, not marketing numbers.
1,646
Tests passed in the current unified pipeline run
105
Browser scenario executions across three configurations
121
Deployment contract checks, recorded separately
Zero
Browser errors or external requests in Offline runs
Each figure is attributed to named, dated evidence with a stated boundary. Totals from earlier baselines overlap and are not added together. Operational release acceptance — including the signed offline node, recovery, upgrade and image assurance — is assessed separately for each deployment.
The questions that decide it.
Direct answers, including where the honest answer is “not yet”.