Paddock · Search
Your documentsanswerable, citedand measured
Paddock Search is the retrieval engine inside the Knowledge Plane of the Bounded AI Architecture (BAA). Point it at your manuals, policies and records and it answers from them, with the page cited, refusing what it cannot support. Then it measures itself on your content and hands you the certificate. Run it on hardware you control, or start on our SaaS and move later.
Principle
The index is the source of truth
The model reads. It does not remember. Everything else here follows from that one decision.
- 01
Why the model must not know things
What a model absorbed in pre-training cannot be traced to a source, updated when your documents change, or erased when a customer asks. In a system whose job is answering from your content, that knowledge is a liability, so we pick the smallest reader that comprehends, and certify how reliably it defers to the page in front of it. - 02
Wrong answers get fixed in the data
A repaired chunk, an alias for the phrase your staff actually use, a re-ingest. Every one of those is traceable and reversible. We used to build a patch that edited facts into the model itself; we no longer do, on principle: it puts knowledge back in the one place you cannot audit. - 03
Retrieval needs no model at all
Building an index and finding the right passage uses no language model. Only writing the prose answer does. The reasoning model is bound at the last step, where you can swap it for a better one, shrink it, or run it on hardware you control, and nothing in the index changes.
Self-audit
It audits itself, on your content
Retrieval settings do not transfer between document sets. This is the single most common way these systems decay quietly, and the product is built around it.
The case that changed the product
A retrieval blend tuned on a bank’s website and an airline’s flight manual was assumed to transfer. On an aircraft maintenance manual it did not: a technician’s verb (“service”) is a noun in that manual’s own checklists, and the keyword channel evicted the correct task from the shortlist entirely.So it re-measures, and repairs
The console generates questions from your own pages in two registers (how a specialist types, and how everyone else does), sweeps the retrieval settings through the real answer path, and applies a change only when the improvement is statistically clean. Then it re-runs to prove the change took effect.A real repair, dated
On a live index this September the loop lifted the correct page reaching the reader from 73% to 92%, applied it, and verified it. Not a benchmark: a production index, repairing itself, with the before and after on the record.
BEFORE SELF-REPAIR · LIVE INDEX
73%
AFTER SELF-REPAIR · SAME INDEX
92%
Retrieval accuracy on generated test questions, September 2026.
Once enough real questions have been asked, it audits against those instead: the distribution it is actually serving. A deployment in use for a month is configured for your site and your vocabulary, without a consultant or a change request.
Identifiers
Some answers must be exact
A part number is not a topic. Asking a language model to paraphrase one is a category error.

MS21042-08
- 01
Identifiers get their own path
Semantic search is blind to bare identifiers, and standard keyword tokenizers splitMS21042-08into fragments that match the wrong things. Part numbers, SKUs, CVEs and invoice numbers are answered from a deterministic catalogue instead. - 02
What that buys
On a 200-question audit against an illustrated parts catalogue, the correct figure came back 192 times out of 200, in a median 18 milliseconds, with no language model involved in almost every answer. - 03
And the eight it missed
Seven were parts carried only in a temporary revision the index did not yet hold. One we cannot explain. Both facts are in the certificate, because a number without its failures is not evidence.
Tenancy
One tenant, one module, one deletion
Each body of content is its own Knowledge Module: a physically separate index, not a filtered view of a shared database.
Accuracy that survives scale
When many customers ask structurally similar questions (“what’s my balance”, “what’s my plan”) a pooled index gets worse as you add tenants, because everyone’s records look alike. Separate modules do not degrade.Erasure you can demonstrate
When a contract ends, removing that customer is a file deletion: sub-millisecond, and the data is physically gone. A shared index offers a tombstone and a filter, with the content still resident until a rebuild. One of those can be shown to an auditor.The cost of doing it this way
About 40 MB of memory per thousand indexes. Cheap enough that the argument for pooling turns out to be a habit rather than a constraint.
A separate module is a structural guarantee: it cannot return what it does not contain. It is not a substitute for access control, which Watchman applies at the module boundary.
Deployment
Where it runs
On hardware you control, in your cloud, or on our managed SaaS. Private is the shape we specialise in, and your modules move with you if you change your mind.
On a Mac, on a server, in a container
One command on Apple silicon, or a container on CPU or NVIDIA. It starts factory-empty and a guided wizard builds your first index in minutes.
Air-gapped, genuinely
An offline bundle carries its own interpreter and every dependency; a portable build ships the console, the models and a pre-built index in a single image that boots with no network at all. That image is tested from an empty volume, offline, before release.
Measured at real scale
We have built and audited indexes over aviation maintenance manuals and parts catalogues (a hundred thousand pages and forty thousand part numbers) plus banking support content in English and Turkish.


