
Paddock · The Knowledge Plane for AI
The Knowledge Plane for AI
BOUNDED AI ARCHITECTURE
Three layers, each bound to something you control
Paddock is the Knowledge Plane of the Bounded AI Architecture (BAA). Three layers, each with one job: the knowledge never moves, the model can, and the log covers both.
- 01 · The reasoning layer
Ram
A frontier model compressed to the size you name, reasoning kept and certified, bound to the plane. Swap it as models improve.
How Ram works - 02 · The Knowledge Plane
Paddock
Your knowledge bound to Knowledge Modules: one per topic, period, person, permission or tenant. Permission, freeze, hand back or delete each one on its own.
How modules work - 03 · The governance layer
Watchman
Every module permission, every bind and every model's provenance bound to one log. Five certificates before anything goes live.
What Watchman governs
A wrong answer from a document assistant is worse than no answer, because someone acts on it. Paddock is built for the questions where the number has to be right.
Answers you can stand behind
What Paddock Does
Every answer cites its page

Every answer cites its page
Table-precise, not table-adjacent

Table-precise, not table-adjacent
Grounded, or it tells you

Grounded, or it tells you
Diagrams answer too

Diagrams answer too
Knowledge Modules
Knowledge Modules, permissioned one by one
One module per domain
Ask as of a date
One module per individual
Walls a query cannot cross
One deployment, strict walls
Every module is its own index
The Reasoning Layer
Bind the model you choose. Swap it later
Start on a cloud model, or keep the whole thing private. Same plane, your decision.
Run it on-premise. When the data cannot leave, Paddock runs a Ram model on hardware you control, air-gapped, with nothing going out. A Mac appliance that runs everything on one machine, in a hangar, a branch, a ship, a bank. This is the shape we specialise in.
Run it in your cloud. Containers your platform team drops into its own stack as infrastructure as code. Your cloud account, your region, your keys. Your library and indexes live on volumes you own, and can sit in whatever residency the rules require.
Or let us run it. On our managed SaaS you get the same plane with the same modules, one isolated module set per tenant, and you are answering questions in days. Because modules are portable, starting on SaaS never locks you in: move on-premise later and take your modules with you.
| On-premise | Mac appliance or your servers · air-gapped · 0 outbound |
|---|---|
| Your cloud | Containers, infrastructure as code, your VPC and keys |
| SaaS | Managed by us, one isolated module set per tenant |
| The reasoning layer | Ram on your hardware, a cloud endpoint, or your own model. Swappable |
| Portability | Modules move with you, SaaS to cloud to metal |
SaaS gets you started. Private keeps the data in. We build for the second one, and we will tell you which your case needs.
Ingest
Feed it what you already have
| Source | What it handles |
|---|---|
| Manuals and reports, including dense technical tables | |
| Websites | Support portals and docs sites, crawled and re-synced on a schedule |
| HTML / Markdown / text | Knowledge bases and internal notes |
| CSV / JSON | Structured records and exports |
| You get back | |
|---|---|
| Exact value | The figure from the table, with its page |
| Grounded prose | An answer built from your passages, cited |
| Figure | The diagram itself, as a clickable thumbnail |
| Honest miss | "Not in these documents," when it isn't |
Beyond Answers
Turn your knowledge into decisions
Ask across everything at once
Put one question to every module you are allowed to see. Paddock gathers the relevant passages from every source that bears on it and lays out what they actually say, so an analyst starts from the evidence instead of hunting for it.Evidence, not opinion
Every claim carries the citation it came from. A recommendation traces back to the exact page that justified it, so the people who sign off can see the ground it stands on.The reasoning stays home
The analysis runs where your data lives. Your knowledge is never shipped to someone else's model to be reasoned over, unless you decide it should be. The intelligence comes to your data, not the other way round.
Data Sovereignty
One module per person, when you need it

- Isolation
Separated by construction
Each person's data sits in its own module. A query inside one can never reach another, so there is no shared index quietly mixing records that should never meet. - Erasure
Right to be forgotten, cleanly
A patient withdraws consent, an employee departs, a retention clock runs out. Delete that individual's module and their data is gone in one operation, with nothing left bleeding into a shared store. The erasure is complete because the separation was real to begin with. - Residency
Point at where it lives
Keep each module on the hardware, in the region, or under the tenant the rules require. Data residency stops being a promise and becomes an address you can show an auditor.
Scale
Built to hold your whole organisation


Patent-pending binary search

Fast at any size
Architecture








