org.tech / Products / The gateway Glass box. Second product

Your people already work inside an AI assistant. The only open question is whether your documents reach it under your rules or under nobody's.

Your files, governed, for the assistant your people already use.

A private server, in a cloud account you own, that lets the AI assistant your people already use search, read and work with your own documents and operational data. It runs no language model of its own. It retrieves, scopes, computes, scaffolds and records, and it reports what is missing rather than filling the gap.

Two products, one decision.

THE CHOICE · BEFORE ANYTHING ELSE

We build two things, and they answer the same question in opposite directions: where does the model sit relative to your data? Everything else follows from that answer, so it belongs at the top of the page rather than buried in a comparison grid. If the first cell describes your constraint, the rest of this section is not for you, and ninety seconds is the right amount of time to find that out.

Running in one real build
Built, thinly exercised
Not built, not claimed
01

orgOS keeps the model inside your account.

The whole environment runs in a cloud account you own: chat over frontier models, an optional knowledge base, a content policy made mandatory by cloud identity policy, and business modules on their own isolated origins. No third-party assistant vendor is in the path at all. If your security owner needs content never to reach one, this is the product.

orgOS · the platform
02 This page

The gateway leaves the model where your people already are.

Your staff keep the assistant they use today. The gateway brings that assistant to your files under your rules: your sign-in, your access policy, your confirmed facts, your calculations. In exchange, what a tool returns travels to your assistant's vendor. That is the trade, and it is the whole trade.

The gatewayTool results leave
Which one is yours

The deciding question is not budget or size. It is whether a third party may see document content at all. If the answer is no, you need the platform, and leading with the gateway in that room is the wrong move. We wrote the decision out in full, including the cases where we would talk you out of this product: platform or gateway, an honest way to choose.

The work is already going on. Ungoverned.

THE PROBLEM · ALREADY HAPPENING

The alternative this product actually competes with is not another vendor. It is the thing your people are doing right now: pasting confidential files into an assistant one at a time, with no access rules, no citations and no record. Measured against that, a governed connector is strictly better.

A connector, backed by four things a connector normally lacks.

WHAT IT IS · FOUR PARTS

In the vendors' sense of the word, this is a connector: your assistant discovers it, signs in to it and calls its tools. The difference is everything sitting behind it. It is not a knowledge graph, not a chatbot, and not a module of the platform.

01

A mirror and index in your account.

Approved content copied one way out of your document libraries into storage you own, parsed, embedded and indexed there.

02

A policy on the server.

Which tools, records and classes of data a person reaches is decided server-side on every call, not in the assistant.

03

Facts a person signed off.

Confirmed facts, kept apart from whatever the documents merely say, each attributed to the person who confirmed it.

04

Tools that compute and refuse.

Canonical tables, answers in SQL over every row, workflow gates on entry criteria, and refusal rather than estimation.

The mirror is read-only, granted one library at a time, and revocable by you in one action. How it works takes each of these apart.

Three rules matter more than any single tool.

THREE RULES · THE SHAPE OF IT
Server-enforced · not advisory

The server is deliberately the boring half.

The tools are grouped in families, and they change as a client's process changes. These three rules do not.

  • 01
    The server calls no language model. Nothing in it reasons, summarizes or estimates. It reads, retrieves, computes, records and refuses. The assistant does the reading and the writing.
  • 02
    Every call passes a tool gate, then a scope check. The caller's own arguments can only narrow what they reach, never widen it. A denied scope short-circuits before retrieval runs.
  • 03
    Absence is reported, never filled. A missing fact comes back as a visible gap. A missing table comes back as a named refusal. A missing format comes back as a note saying what to do about it.
gateway · tool call trace
SERVER-SIDE
call analysis.revenue_by_customer(record: "R-4417")
[gate] role may call analysis family
Requested scope✓ narrowed to 1 record
Widening attemptnone in arguments
Integrity checks✓ 6 of 6 passed
Rows readall 41,208
Supplier cost column△ absent in source
✕ gross_margin refused: not derivable from this source
answer returned with query attached · no model called
Illustrative output1 refusal
A refusal is an answer·Gross margin needs a column this source does not hold

Who this is for, and who it is not.

FIT · AND THE DISQUALIFIER

This suits an established, document-heavy organization whose people already use a commercial AI assistant. The buyer is usually the owner-operator or the operations lead who wants more throughput from the same team. The prerequisites are real, and a project that starts without them stalls in the first fortnight. They are checked in the assessment rather than assumed.

PrerequisiteWhat it actually meansWhat happens without it
An owner for the source contentOne named person who can say what belongs in a library and what does not.Nobody can approve a library, so nothing gets indexed.
A folder taxonomy, or the will to make oneThe mirror preserves your tree exactly, so a file's address in the mirror is its path in the library.Classification leans on folder conventions, so scoping becomes unreliable.
Named rolesWho reaches which tools, records and classes of data, written down before anyone connects.There is no default role by design, so an unrecognized person gets nothing.
An approved assistantOne your organization has sanctioned, on a plan that supports authenticated custom connectors.There is nothing to connect the gateway to.
Business rules explicit enough to testA calculation or a gate stated precisely enough that code can refuse when it is not met.Deterministic tools cannot be written, and you are back to asking a model.

Judgment, not measurement: these are the conditions the one real build needed, generalised.

The disqualifier, stated plainly

An organization that has banned external AI assistants, or whose security owner needs data never to reach a third party, is not a buyer for this product. It needs the platform instead, and we will say so in the first meeting. See also where AI does not belong, the same discipline applied to the work rather than the architecture.

Said once, plainly

Everything at rest stays in your account. Tool results do not.

This product cannot win an argument about the data boundary, so it does not try. What it wins on is action, your own rules, and numbers that reconcile.

  • 01
    In your account. The mirror, the index, the confirmed facts, the canonical tables and every generated artifact live in a cloud account you own and pay for directly. We host none of it.
  • 02
    At your assistant's vendor. What a tool returns, a passage, a table, a scaffold, travels to the assistant so it can be read. That is governed by your agreement with that vendor, and we will put it in writing before you sign.

The five questions that come up every time.

QUESTIONS · ASKED FIRST
01Where does our data actually go?

Everything at rest stays in your account: the mirror of the approved libraries, the index, the confirmed facts, the canonical tables and anything generated. What a tool returns travels to your assistant's vendor, because that is where the assistant reads it, and that traffic is governed by your existing agreement with that vendor.

The full breakdown, line by line, is on access and the data boundary. We make no residency claim for this product at all.

02Is this another application for our people to adopt?

No. Your document libraries stay the front door for filing, and the assistant is the one your people already use. A person adds a connector once, signs in with their corporate account, then asks questions in plain language. Nobody types a tool name. If you later change assistant, the protocol is an open standard, so that is a reconnection rather than a migration.

03Will it make things up?

The server invents nothing. Outward-facing artifacts accept confirmed facts only, computed figures come from SQL over complete data with the query attached, and anything missing appears as a gap. What your assistant then writes in prose is outside our control, which is why every passage carries a citation. We offer no faithfulness or groundedness guarantee, because the server never sees the answer.

04What does it cost to run?

Tens of dollars a month on your own cloud bill in the one build so far, and nothing per seat, because the answering model is not in that account. Cost tracks document churn rather than how much your people use it. The engagement is scoped in the strategic assessment; there is no published price for this product.

Read it in order, or jump.

THE GATEWAY · IN FULL

Six pages, written to be read by a sceptic. Take them in order, or start with the one that answers your own question first.

⎯⎯ Book the strategic assessment ⎯⎯

Your files, inside your control ·

A bounded piece of work that decides which of the two products fits, what it would govern, and what it would cost to run. You keep the deliverable whether or not you proceed.