A professional reviewing a document beside an office window at dusk

Your Data. Your AI. Your Audit Trail.

Regulated firms are told to pick two: control of the data, capability that is actually useful, or evidence that stands up afterwards. We think you should have all three, and we can show you a firm that already does.

There is a meeting that kills most AI projects in regulated businesses. It is not the one where someone asks whether the technology works. That meeting goes well, because by then somebody has run a demo and everyone is impressed.

It is the meeting afterwards. Compliance asks where the client files go. Someone from risk asks what happens when the regulator wants to know how a number was arrived at. The IT lead asks which third party ends up holding the data, and under whose contract. Nobody in the room can answer properly, so the project becomes a pilot, and the pilot becomes a document, and the document becomes nothing.

We built Odokai around the three answers that stop that meeting from ending badly.

The three things, and why most tools give you two

A regulated small or mid-sized firm needs all three of these at once. Take any one away and the compliance veto comes back.

  1. Sovereignty. The system runs where your data already lives, on models you have approved.
  2. Provenance. Every output can show how it was produced, in enough detail to defend.
  3. Proof. It is doing real regulated work today, not in a roadmap.

Plenty of platforms will sell you one or two. Consumer AI tools are capable and give you neither sovereignty nor provenance. Self-hosted open-source stacks give you sovereignty and leave the governance as an exercise for the reader. Governance and observability vendors give you logging, then assume you have an engineering team to wire it into something that does actual work. Enterprise platforms will give you the lot, at enterprise prices, on an enterprise timeline, which is no use to a forty-person firm.

The interesting part is not any single capability. It is the conjunction, held together in one system, in production.

Sovereignty: it runs on your infrastructure

Odokai deploys as your own instance: your cloud account, your datacentre, or an air-gapped environment, depending on what your jurisdiction and your risk appetite require. Your documents, your index, your workflow logic, and your audit trail sit inside that boundary and stay there.

We should be precise about the one part everyone glosses over, because your compliance team will ask about it and they should. At the point of reasoning, a request has to reach a model. Where a step can run on a smaller open-weight model hosted inside your environment, we route it locally and nothing leaves at all. Where you want a frontier model, that call goes out under a zero-retention, no-training agreement, hosted in-region — the same standard your firm already accepts for other cloud services. And if you would rather hold that relationship yourself, we set it up so the contract, the data processing agreement, and the invoice are all yours.

Any model. Any infrastructure. The choice stays yours, and it stays reversible.

That last word matters more than it looks. Model choice is not really about today's benchmark leader. It is about not being trapped when the leader changes, when a provider's terms change, or when your regulator takes a view on a particular vendor. A model-agnostic platform is an insurance policy against decisions you have not had to make yet.

Provenance: every output shows its working

This is the part that is genuinely different, and it is worth being exact about what we mean, because "audit trail" has been used loosely enough to stop meaning much.

Most systems log the conversation. You get a transcript: here is what was asked, here is what the agent said. That is a record of what the agent said, not a record of what it did, and for a regulated file it is close to useless. A transcript cannot tell you which document a figure came from, whether the check that should have caught an error actually ran, or whether the person who approved it saw the same evidence you are looking at now.

A provenance trail is a different object. It attaches to the output rather than the session, and it goes down to the field. Here is the shape of it on a document-heavy client file:

  • A figure in the finished output traces back to the exact page of the exact source document it was read from, with the extraction preserved.
  • That figure was cross-checked against a second document on file, and the result is recorded whether the check passed or failed.
  • Any calculation applied to it records the rule that was used, and the version of the policy that defined that rule.
  • The external criteria the file was assessed against are named, with the version in force on the date it ran.
  • A named human approved it at a recorded time, having seen that evidence.
  • The whole chain can be replayed. Same inputs, same model, same policy version, same result.

So when a counterparty queries a figure eight months later, or a regulator samples a file, or a client's solicitor asks a pointed question, nobody has to reconstruct what happened from memory and a folder of PDFs. The answer is attached to the output.

There is a reason to care about this beyond the immediate convenience. The EU AI Act's obligations for high-risk systems — automatic logging, record-keeping, post-market monitoring — reach full application this month. Firms that already produce this evidence as a by-product of doing the work are in a very different position from firms that will need to go and build it.

Proof: it is already doing regulated work

All of the above is the kind of thing anyone can put on a website. So here is the part that is harder to copy.

Odokai runs in regulated production today. Live cases, external counterparties, decisions that carry consequences. It saves more than two hours on each case handled, and every output it produces carries the provenance trail described above.

That is not a sandbox and not a proof of concept. It is a regulated business doing regulated work on the platform, with the compliance conversation already had and already survived.

"Isn't this just another agent harness?"

We get asked this, and it is a fair question given how many frameworks have shipped in the last two years. The answer is short.

Harnesses are frameworks developers use to build agents. Odokai is a governed workplace: your infrastructure, your model, your audit trail, running live in regulated production. Frameworks don't do regulated work — we already do, in production, against live counterparties. Show me another agent platform that can say that.

A framework hands your developers a set of parts. If you have an AI engineering team and eighteen months, that is a reasonable place to start. Most mid-sized regulated firms have neither, and the gap between a working agent and a governed, evidenced, defensible workflow is where those projects quietly die.

Why this is worth your attention now

Capability is becoming the cheap part. Every quarter, the models get better and the gap between vendors on raw capability narrows. What does not commoditise is the ability to prove what a system did, why it did it, and who is accountable for the outcome.

That view is not only ours. Writing in Forbes this month, Omega Venture Partners' Gaurav Tewari argued that accountability could become vertical AI's biggest moat: technical capability earns you a pilot, but accountability is what earns you scale, and industries with binding compliance requirements hit that wall first. We would treat that as a well-argued prediction rather than a settled fact — but it matches what we see in every procurement conversation we have.

If it is right, the firms that win in regulated markets will not be the ones with the cleverest demo. They will be the ones who can hand over the file.

Where to start

Bring a handful of your own documents to a 45-minute call. We build a workflow live, on your data, and show you the provenance trail it produces. You come away either with written acceptance criteria and a fixed fee for the build, or with a much clearer picture of what is actually worth automating in your firm.

Both outcomes are worth the 45 minutes. Talk to us.

Your data. Your AI. Your audit trail.

See it running on your own documents, with the provenance trail attached, in 45 minutes.