Beat 4 · Ontology & Architecture

A governed core. Best-of-breed, swappable infrastructure.

We build the parts that carry your compliance guarantees, and use proven, swappable infrastructure for the rest. The result: no model lock-in, no data lock-in — and nothing that touches client data ever leaves the compliance boundary.

The shape

One governed system, three planes

Your existing systems stay exactly where they are. CloudLink adds a thin, governed layer on top — and concentrates the things that matter for compliance into one place we control and you can audit.

Public architecture ceiling

The simplified public architecture (governed core + best-of-breed engines + compliance envelope) is the deepest published diagram. Past that: "The full component map is shared under NDA during a readiness engagement — here's the invariant it enforces instead." Invariants travel; diagrams leak.

Your systems, as one ontology

Microsoft 365, your CRM, custodian/portfolio, and planning tools — connected, never replaced, and expressed as the RIA Ontology: typed objects, governed relationships, and the actions each allows. It ships as a versioned, CI-verified artifact — AI prompts carry it version-pinned, runs record the version they executed under, and the relationship graph is directly queryable. GraphQuery answers concentration and review-evidence questions as typed graph walks, cited record by record. Your firm remains the system of record.

The governed core

A single control point meters, applies policy, redacts, and logs every AI action — the one place an examiner or auditor can verify the controls are real. Instance health keeps freshness, completeness, and obligation coverage visible before workflows run.

Model-agnostic inference

Any frontier or open-source model, chosen per task, reached only through the governed core — with a safety-vetted default.

What we build, buy, and wrap

Build the moat. Buy the commodity. Wrap the rest.

A simple, honest rule decides every component — and it's the rule that keeps you un-locked-in and keeps us outside your regulated perimeter.

Build · our IP

The governed core

The parts that carry your compliance guarantees — so they're ours, not a third party's.

  • The AI gateway — meters, redacts, logs, and routes every model call
  • The policy & guardrail engine
  • Your firm's unified data model + connectors
  • Human approval & the immutable audit trail
  • The automation runtime and our compliance evaluations
Wrap · swappable

Governed engines

Best-in-class engines, used behind our own interfaces — so any one can be swapped without changing your platform.

  • The AI models — frontier and open-source
  • Redaction & grounding checks
  • Quality evaluations
  • Workflow orchestration & scheduling
Buy · proven infra

Commodity infrastructure

Undifferentiated plumbing from established providers — running inside your compliance boundary.

  • Encrypted storage & key management
  • Search index & records storage
  • Monitoring & observability
  • Identity (your existing SSO) & billing

Under the hood, the regulated plane runs on AWS with Claude on Amazon Bedrock as the safety-vetted default; any provider that processes client data is a disclosed sub-processor under your agreement.

The Ownership Line

The models are rented. The operating asset is owned.

Every year the models get better, and every year some of the software around your firm gets replaced. The Ownership Line is how we build for that: the models are rented — routed through one gateway, chosen per task, swapped when a better one ships. Everything above the line is owned, by you: the versioned map of your firm, the workflow definitions, every approval your people ever made, the evidence of what the system actually did, and the controls an examiner would test. A model upgrade is a routing change. A vendor change is an integration project. Neither touches what you own — and what you own is what compounds.

Owned

the ontology of your firm · workflow definitions · approval & audit history · the evidence ledger · the compliance envelope

Rented

models · vendor software · infrastructure

Model routing

Every AI call flows through one gateway, so the model is a setting — not a rewrite.

Workflow-as-data

Your workflows, approvals, and evidence stay above the line even when vendors change below it.

Versioned map

The firm model and pinned runs create diligence-able history, not a pile of disconnected prompts.

Evidence receipts

Every draft, approval, and exception is inspection-ready.

Portable exit

The twin is not your system of record; your authoritative books and records stay in the systems you already run.

Stays-human floors

Capability churn cannot become liability churn.

The compliance envelope

Everything that touches non-public client information — your data, the search index, the AI calls, the models, the redaction and audit — runs inside one boundary: in-region, under contract, with no training on your data, and a tamper-evident, examiner-ready log of every action. "Any model" never means your data leaves that boundary. The control plane outside it holds only configuration and metadata — never client data.

See it for your firm

Architecture you can take to your CCO.

Honest under diligence, built compliance-first, and free of the lock-in that traps firms later.