Technology & Architecture

Workflow automation built on the newest AI, deployed the old-fashioned way — on your servers.

Every Cortexeon product is a decision-support system, not an autonomous one: current-generation language and vision models draft, classify, and cite — a named human always signs, reviews, or approves before anything is filed, sent, or pushed. That pattern, and the security architecture underneath it, is the same across both of Cortexeon's products.

How Cortexeon Builds AI

The model drafts. A named person decides.

Cortexeon builds for professions where a wrong answer has a real cost — a missed disclosure, a mis-stated materiality, a blown filing deadline. That shapes every AI feature shipped, across every product.

Decision support, never autonomous filing

AuditWP AI drafts an explanation or a disclosure note — a preparer reviews and saves it. TaxPulse AI drafts a return position, a withholding statement, or a client email — nothing files itself, and a Tax Senior signs off before anything goes out. The pattern is deliberate and identical everywhere: the model proposes, a named person decides.

Grounded, cited answers — not fluent guessing

TaxPulse AI's "Ask Your Engagement" cites the invoice, deadline, or filing behind every answer, and says "no record of that" instead of inventing one. AuditWP AI's disclosure checklist shows the matched terms behind every confidence score. Every AI claim in Cortexeon's products traces back to a record you can point to.

The right model for the task, not one model for everything

Routine, repeated classification work runs on efficient, self-hosted open-weight models so throughput scales without a per-call bill or a data-residency question. Tasks that benefit from frontier reasoning or vision — drafting a nuanced notice response, reading a scanned NTN certificate — call a current-generation frontier model for that specific step, scoped to that request. Neither approach is used where the other fits better; each product picks per capability.

Semantic memory, so the model doesn't repeat itself

AuditWP AI indexes every evidence file and working paper with vector embeddings, so a manager can search an entire engagement in plain language and find the right document without knowing which working paper it lives in.

Architecture

Self-hosted by default. Modern under the hood.

Cortexeon deploys on infrastructure you control, not a shared multi-tenant cloud you have to trust blindly. Underneath, it's the same engineering stack a modern SaaS product would use — you just run it yourself.

Clean Architecture, self-hosted

Built with Clean Architecture and CQRS principles, deployed by Docker Compose on a single server or Kubernetes across your data centre — no vendor-hosted control plane in the loop.

One database for data and AI

A single relational database holds both engagement data and AI embeddings — one system to back up, secure, and reason about, not a separate vector store with its own access model.

Local-first LLM inference

Core AI features run against models hosted on your own infrastructure — no API key and no cloud dependency required to use the product day to day.

Database-enforced tenant isolation

Row-level security is enforced at the database layer, not just checked in application code — a second, independent line of defense between one client's data and another's.

Guided, auditable integrations

Trial balance and ledger connectors (TallyPrime, QuickBooks, Xero, Zoho Books, SAP Business One), regulator connectors (FBR IRIS, SECP eServices), and a native OAuth handoff where a platform supports it — configured through a labelled form, not hand-edited JSON.

Deploys where your data already lives

Air-gapped deployment is fully supported across the product line. Where a product offers an optional cloud model call for a specific capability, it's opt-in — never a requirement to run the core product.

Data Security & Privacy

Zero data egress by design, not by policy promise.

"Your data doesn't leave your servers" is an architectural fact in a self-hosted deployment, not a clause in a vendor's privacy policy. The controls below are implemented in the product and verifiable, not just claimed.

  • Immutable, hash-chained audit trails. Every login, sign-off, materiality approval, sample draw, and AI-generated draft is written to a SHA-256 hash-chained log. Any tampering breaks the chain and is detectable on inspection — this is how Cortexeon's audit and tax products are designed to meet QCR and QAB review requirements.
  • Encryption at rest and in transit. Secrets — TOTP seeds, connector credentials, API keys — are encrypted with AES-256-GCM. Evidence files are SHA-256 integrity-hashed at upload, so a modified file is detectable even if the storage layer itself is compromised.
  • Modern authentication, by default. TOTP multi-factor authentication, Active Directory / LDAP single sign-on for enterprise firms, automatic lockout after repeated failed logins, forced password rotation after an admin reset, and rotating JWT refresh tokens with theft detection — reusing a superseded token revokes the entire session family.
  • Role-based access, structurally enforced. Four-tier separation (e.g. Trainee, Manager, Engagement Partner, System Administrator) with explicit per-engagement staff assignment — a junior only sees the files they're staffed on, and administrators can run the platform but structurally cannot sign audit or tax work.
  • Air-gapped deployment, fully supported. Where a product's AI features run against a local model, the product functions with no outbound internet access at all — a genuine option for firms bound by strict confidentiality or client-data rules, not a checkbox that quietly still phones home.
  • No shadow copy of your data. Cortexeon doesn't operate a hosted multi-tenant version of these products that retains your data on its own infrastructure. Deployment is on your servers or your cloud account — Cortexeon doesn't hold a copy by default.

Compliance Alignment

Built for the frameworks your team is audited against.

Each product targets the specific standards its users actually answer to — implemented in the product, not asserted in a data sheet.

Audit & assurance

ISA 320 materiality, ISA 530 reproducible sampling, and the ICAP Quality Control Review sign-off matrix, enforced structurally in AuditWP AI.

Tax & statutory filing

Companies Act 2017 disclosure requirements and FBR / PRA / SRB / KPRA / BRA filing rules, built into AuditWP AI and TaxPulse AI's compliance calendars and checklists.

For the full breakdown of frameworks, data-handling commitments, and deployment options, see Cortexeon's compliance documentation.

See the architecture running your own workflow, not a slide deck.

Book a demo to see how this applies to your engagement file or your ledger.