AI compliance platform · Lead product and AI engineer · Pre-launch
Designing controlled AI workflows for a regulated environment.
Pre-launch and under NDA. Details are limited to what's shown here.
1. Outcome
One controlled record of a firm's obligations, evidence and approvals, built privacy-first, with every finding traced to its source and every rule tested on history before release.
2. The problem
Agreed scope, fees, promised actions and approvals live in email. Drift shows up late, and the evidence is hard to produce when someone asks for it.
3. My responsibility
Lead product and AI engineer. I own the workflow design, the controls, the testing and the build.
4. Before and after
Before
- Scope, fees and promises live in email
- Drift is noticed late
- Evidence is hard to produce on request
After
- One record built from the signed agreement
- Checks that quote their source and show the arithmetic
- Overdue actions raised, evidence ready
5. What was built
- A pseudonymiser that codes people, organisations, places and contact details before any text leaves the machine.
- A project record built from the signed engagement agreement. Every field traces back to the words it came from, or is marked as not stated.
- Checks for out-of-scope requests, budget drift and fees against the agreement. Each finding quotes the sentence it came from and shows the arithmetic.
- An actions register that raises overdue and silent actions again, and a handover pack.
- Before releasing any risk flag, I replayed five candidates over a real 35-month email archive. One would have fired on about 1 in 6 outgoing messages, so it was redesigned before anyone saw it.
6. AI and controls
- Privacy first: names and contact details are coded before any text leaves the machine.
- Every finding is traceable to the sentence it came from.
- Rules are replayed on history before release.
- The AI layer is designed and next to build: Claude advises, the firm's own rules decide, and a person always approves.
- Nothing built so far sends client text to a model.
7. Evidence
- 10,896
real emails replayed before a single flag was released
Source: rehearsal run in the commit history, Sep 2026
- 0 leaks
across 200 real messages and 1.6 million characters through the pseudonymiser
Source: test run in the commit history, Sep 2026
- 147
checks passing across 5 suites, 19 of them deliberate-break tests
Source: test run, 1 Oct 2026
8. Technical implementation
Python, SQLite, Next.js, FastAPI, Supabase, Microsoft Graph (read-only)