
Paddock · Knowledge Modules
Knowledge you can govern like records
The Principle
Your AI should not memorise your data
Paddock is built on the opposite principle: the model stays stateless, your facts live in Knowledge Modules, and the model bound on top only reads them.
The model brings the reasoning. The modules bring the knowledge. Because the two never mix, every fact in the system keeps an address: which module it sits in, who can reach that module, which dates it covers, and when it must go.
That single design decision turns the hardest questions in AI governance into ordinary records management. The right to be forgotten stops being a research problem and becomes a delete operation. Need-to-know stops being a prompt instruction and becomes an access rule the query physically cannot cross.
A filter can leak. A separate index cannot return what it does not contain.

| Fact in the weights | Fact in a module | |
|---|---|---|
| Delete it | Retrain the model | one operation |
| Permission it | Cannot | per-module rule |
| Date it | Cannot | as-of query |
| Show it is gone | Cannot | erasure log |
The Mechanism
Every module is its own index
One module per individual
One module per client or matter
One module per domain
One module per period
One module set per customer
Modules within modules
Lifecycle
Four operations your auditor will love
- 01
Permission it
Access is granted module by module, to roles you define. A clinician sees their care team's patients. A deal team sees its own data room. The wall is structural: a query from outside the grant has no index to search, so there is nothing to leak. - 02
Freeze it
Lock a module at a moment that matters: the day the policy renewed, the day the report shipped, the day the incident occurred. Frozen modules answer as-of questions and are tamper-evident, which is exactly what a dispute, a legal hold, or an investigation needs. - 03
Hand it back
A module is portable. When a client leaves, give them their index, complete, and keep nothing. When a contract requires data to come home at the end, the end is an export, not an argument. - 04
Delete it
A patient withdraws consent. An employee departs. A retention clock runs out. Remove the module and everything Paddock holds on that person, documents, index, and every derived structure, is deleted in one logged operation. There is no shared store for fragments to hide in. Copies in your source systems and backups follow your own retention policy; Paddock's share of the obligation is done, and the log shows when.
Where This Lands
Draw the module around the obligation
A module per patient
A module per matter
A module per deal, a wall per desk
A module per compartment
A module per revision
A module set per client
A module per deal room
A module per employee
A module per licence
No Trade-Off
Governance that costs you no accuracy
On our benchmarks, retrieval across modules matches the whole-library baseline.
A question is routed to the modules that bear on it, and the answers that come back are as good as if the entire library had been one index. Isolation between modules held in the same tests: a query granted one module returned nothing from any other, every time. Separation is not a mode, it is the architecture.
So the choice between an AI you can govern and an AI that answers well is not a choice. You draw the modules your obligations require, and the answer quality your teams rely on carries through.
| Answer quality, across modules vs one index | matched, measured |
|---|---|
| Cross-module leakage under test | zero |
| Routing | A query only touches the modules that matter |
| Scale behaviour | Adding a module never disturbs the others |
These are measurements, not positioning. Ask and we will walk you through them, then rerun the same tests on your data before you commit.
Run It Your Way
On your metal, in your cloud, or on ours


Your VPC, as code

Managed, still isolated
We Use It Daily
Our own research runs on it
Paddock's first production tenant was us. Our research programme keeps years of experiments, findings, and literature in a Paddock library split into modules that our team and our AI agents query before any new work begins.















