On-prem BI copilot for finance & RevOps

Every number, independently verified — or refused.

Ask in plain English. We recompute the answer independently from your own data — we don’t detect-and-hope. If the number can’t be verified, it’s refused. You never paste a hallucinated figure into a board deck.

0 silently-wrong numbers across 1,258 benchmark cases · on-prem · data never leaves your VPC

sourceordersyour data · on-prem
path a · sql aggregate$223,360.81
path b · independent loop$223,360.81
PASSpaths agree · Δ = 0

illustrative method · same data as the live demorun the live engine →

0silently-wrong numbers across 1,258 cases in our benchmark · 4 real public domainson-prem / sovereignSOC 2 pathverified-or-refuse
Try the live demo — no login

Verify or refuse

An independent deterministic recompute confirms the number, or it’s refused. You get the figure and the proof — never a guess.

console.octonoc · live demo

Live engine temporarily offline — showing cached results.

Design partner program

Early access — build the verified engine with us.

We're working with a small group of teams who care about data they can prove. No commitment — just an honest conversation about what you need.

Apply for early access →
How it works

Connect, ask, verify — or refuse.

The verification spine is the product. Every answer passes a deterministic independent recompute — or refuses with a reason. No detect-and-hope, no silent pass.

sourceordersyour data · on-prem
resolvetotal_revenueSUM(units × unit_price)
recompute × 2223,360.81paths agree → PASS
Every metric stays connected to its source and its proof. Ask a number and follow the line back — to the exact data, the formula, and the independent check. That traceable lineage is what makes the answer trustworthy.
01

Connect

Point Octonoc at your data — on-prem, in your VPC. The tentacle induces the schema and double-verifies the logic against a held-out oracle.

02

Ask

Ask a KPI in plain English or Spanish. The semantic resolver grounds it to a governed metric definition — or refuses if it’s ambiguous.

03

Verify or refuse

An independent deterministic recompute confirms the number, or it’s refused. You get the figure and the proof — never a guess.

Why Octonoc

Verified analytics with no text-to-SQL hallucinations.

It will tell you when it doesn’t know — instead of guessing.

recompute · source rows · audit hash

Proof on every number

Click “show the derivation” on any figure: the recompute, the source rows, the audit hash — in mono, always inspectable.

row-level isolation · argon2id

On-prem, sovereign

Your data never leaves your servers. We can’t see it. Neither can the model vendor. Verified memory runs locally.

append-only · local

Ink — verified memory

It remembers your governed definitions, mappings and every refusal — a permanent, auditable record. Memory never is the number; the number is always recomputed.

Beyond the numbers

Now it verifies the code your AI writes.

One engine, three domains — your numbers, your security logs, and the code a frontier model just wrote. Same promise: independently proven with math, or refused with the exact input that breaks it. Never the model’s say-so.

execution-differential · property · smt

Proven, not trusted

Execution-differential against an independent oracle, property / metamorphic checks, and SMT where it’s decidable. The model’s output is evidence; the verdict is math.

counterexample · owned

It refuses — with a counterexample

When the code is wrong you get the concrete input that breaks it; when it can’t be proven, it refuses rather than bless. No silent pass.

one endpoint · mcp

Drop-in for coding agents

Any frontier agent calls one endpoint or MCP tool with code plus a spec and gets back a verdict it can defend — independent of the model that wrote the code.

The same verify-or-refuse engine also runs on your security logs — trustworthy counts and rates over real intrusion data, refusing what it can’t confirm. Verified security analytics →

What we built (2026)

One verify-or-refuse engine. Three production verticals.

The moat is deterministic verification, not generation — and it compounds with every verified win. Every claim below is real.

the moat · deterministic

Verify-or-refuse engine

Every number is independently re-derived from your own data and shown with proof. If it can't be verified, it refuses — no hallucination can pass. On-prem; data never leaves your VPC.

pattern · spec · correctness

OctoPattern — verified code that compounds

Not just verified BI — a verifier-gated pattern + autonomous-code engine. It researches state-of-the-art patterns, writes a machine-checkable spec, generates code, and keeps it only if it passes three deterministic gates: pattern-conformance, spec-conformance, correctness. What it can't prove, it refuses. Generation is commodity; the verifier and the compounding library are the moat.

research → spec → generate → verify → refuse-on-fail → compound

BI · accounting · insurance

Verticals on the engine

Verified analytics (BI) · accounting rule-pack · insurance rule-pack. Auditable, explainable decisions — EU AI Act tailwind. Same engine, three domains.

NVIDIA Inception Program memberNVIDIA Inception member · built to self-host on NIM

NVIDIA and the NVIDIA Inception Program are trademarks and/or registered trademarks of NVIDIA Corporation.

Security & sovereignty

Your data never leaves your VPC.

Row-level tenant isolation, a signed append-only audit ledger, argon2id + OAuth 2.1. We’re confident enough to run our own most sensitive numbers on it.

Stop shipping numbers you can’t prove.