White papers

The hard problems — and how we’re solving them.

Each paper is tied to a product we’re running in production, or to a regulatory landscape our customers are operating inside. Citations linked. No gates, no marketing fluff — just the engineering reasoning behind what we’ve built.

Vendor-Agnostic Building Intelligence

50-year-old controls meet modern AI

The BMS market is locked behind controller vendors. AI extracts insight from any of them — WebCTRL, Niagara, Trane. The $14B→$34B opportunity nobody else is building for the MSP channel.

Read →

The Compliant AI Gateway

Multi-tenant LLM governance for regulated MSPs

Per-tenant virtual keys, budgets, audit logs, PII redaction. EU AI Act and HIPAA paths from day one. Why we built our own instead of buying off the shelf — and the cache-poisoning incident that proves the case.

Read →

Synthetic Identity Risk

Avatar & voice agents and the rise of consent-archived AI

Voice deepfake fraud up 680% YoY in 2025. EU AI Act Article 50 watermarking is fully applicable 2 August 2026. ELVIS Act and TRAIGA require consent ledgers. Why we banned Synthesia from our stack.

Read →

Continuous Audit as a Service

Monthly multi-repo scans, objective-aligned

Automated security, quality, UX, accessibility, dependency, IaC, and competitive-intel scans across every repo we ship. Findings classified against project objectives by an Anthropic Haiku classifier — reported without humans in the loop.

Read →

US AI Compliance for Regulated SMBs

CAIA, NIST AI RMF, SEC, FINRA, HIPAA, NYDFS, FTC. The audit pack regulators and insurers actually want.

Colorado AI Act delayed to June 2026 and paused in court. California AB 2013 in force. Texas TRAIGA $10K–$200K per violation. NYC Local Law 144 enforcement tightening. Cyber-insurance carriers added AI questionnaires in 2026 renewals. The stack of binding US AI obligations a 50–300-person SMB faces today, and the 90-day plan to ship the audit pack.

Read →