Every read and every edit, on a record you can check.
Your documents stay in your own tenant. The assistant reaches them only with a token scoped to your business, and everything it does lands on a record you can export.
One broken byte, one broken check.
Every action is hashed and linked to the one before it, so a skeptic can re-derive the head instead of taking our word. Signing and attestation are the local build's half of this, and are labeled that way.
every change captured exactly
Live todaycontent-addressed, byte for byte
Live todaylinked to the event before it
Live todayEd25519 · key never leaves the machine
Local buildidentity registered with Token Holder
Local buildTamper-evident, trusted-operator forensics: an alteration is detectable and provable. It is not “cryptographically unalterable” — the value is that you can catch and prove a change, not that a change is impossible. And the hosted record is chained, not signed: an exported bundle proves the rows are consistent with their head, not that a key vouched for them.
Your team gets a chat assistant that answers from your own documents. It reaches them only through a token scoped to your tenant, and every read and write is written to a record that links each entry to the one before it. Export the window as JSON or CSV and hand it to whoever asks. One press re-checks the whole record.
Here is the line. The record is checkable, not signed: an auditor can confirm the rows are consistent with each other and with the head they were read under, not that a key vouched for them. Signed bundles for an outside auditor are on the roadmap, and we say so on this page rather than in the fine print.
Answers from your own documents
Live todayIt lists your documents, opens the ones it needs, and answers from those, up to a bounded number of steps per turn.
listVault + readVaultFile, grant-gated
Reached only with your token
Live todayEvery read or write goes through a token scoped to your tenant, enforced by Token Holder rather than our query layer. A turn with no token is refused, never downgraded. Shared hosting is what ships; a dedicated instance is the enterprise and regulated-vertical tier.
Fail-closed at the chat route · 403 from Token Holder
A record you can export and re-check
Live todayEach action lands on your tenant's record, linked to the one before it. Export it as JSON or CSV, and re-derive the head on demand.
The record names a person
Live todayEach person signs in with their own identity under your tenant, so a row names who did it, not a service account.
Signed bundles for an outside auditor
RoadmapPer-event signatures and an openly fetchable trust root. Proven on the local agent host; not in the hosted product.
Map your operations
Live todayBefore an assistant can take work off your team, somebody has to write down how the work moves today. MASS Lead Connect follows one job end to end and hands back every step, handoff and stall, marking the ones an assistant can carry. A paid engagement; the document is yours.
Delivered by MASS Lead Connect
Start an operations mapHosting is shared for the standard tiers, and the boundary between businesses is Token Holder's to hold. Inside one business, a shared workspace is one vault every member can read; per-member scoping is on the roadmap.
The verifiability claim is always one click from a way to check it — no account, no trust required.