For your work · Compliance-driven teams

Every read and every edit, on a record you can check.

Your documents stay in your own tenant. The assistant reaches them only with a token scoped to your business, and everything it does lands on a record you can export.

How the record works

One broken byte, one broken check.

Every action is hashed and linked to the one before it, so a skeptic can re-derive the head instead of taking our word. Signing and attestation are the local build's half of this, and are labeled that way.

01
Diff

every change captured exactly

Live today
02
Hash

content-addressed, byte for byte

Live today
03
Chain

linked to the event before it

Live today
04
Signature

Ed25519 · key never leaves the machine

Local build
05
Attestation

identity registered with Token Holder

Local build
Honest scope

Tamper-evident, trusted-operator forensics: an alteration is detectable and provable. It is not “cryptographically unalterable” — the value is that you can catch and prove a change, not that a change is impossible. And the hosted record is chained, not signed: an exported bundle proves the rows are consistent with their head, not that a key vouched for them.

Read the trust chain

Your team gets a chat assistant that answers from your own documents. It reaches them only through a token scoped to your tenant, and every read and write is written to a record that links each entry to the one before it. Export the window as JSON or CSV and hand it to whoever asks. One press re-checks the whole record.

Here is the line. The record is checkable, not signed: an auditor can confirm the rows are consistent with each other and with the head they were read under, not that a key vouched for them. Signed bundles for an outside auditor are on the roadmap, and we say so on this page rather than in the fine print.

Answers from your own documents

Live today

It lists your documents, opens the ones it needs, and answers from those, up to a bounded number of steps per turn.

listVault + readVaultFile, grant-gated

Reached only with your token

Live today

Every read or write goes through a token scoped to your tenant, enforced by Token Holder rather than our query layer. A turn with no token is refused, never downgraded. Shared hosting is what ships; a dedicated instance is the enterprise and regulated-vertical tier.

Fail-closed at the chat route · 403 from Token Holder

A record you can export and re-check

Live today

Each action lands on your tenant's record, linked to the one before it. Export it as JSON or CSV, and re-derive the head on demand.

The record names a person

Live today

Each person signs in with their own identity under your tenant, so a row names who did it, not a service account.

Signed bundles for an outside auditor

Roadmap

Per-event signatures and an openly fetchable trust root. Proven on the local agent host; not in the hosted product.

Map your operations

Live today

Before an assistant can take work off your team, somebody has to write down how the work moves today. MASS Lead Connect follows one job end to end and hands back every step, handoff and stall, marking the ones an assistant can carry. A paid engagement; the document is yours.

Delivered by MASS Lead Connect

Start an operations map
Honest scope

Hosting is shared for the standard tiers, and the boundary between businesses is Token Holder's to hold. Inside one business, a shared workspace is one vault every member can read; per-member scoping is on the roadmap.

Prove it yourself

The verifiability claim is always one click from a way to check it — no account, no trust required.

Verify a receipt