Chatbots hallucinate citations
SEI's Stage 1 Guardian mechanically verifies every evidence ref — files exist, memory keys recall, API logs exist.
Tell us a goal in plain words. A team of specialist AI agents does the work, an independent checker verifies every answer against the evidence, and you get a clear, decision-ready report — with receipts. No guesses dressed up as facts.
No recovery, no fee. 20% of independently verified value. If we find nothing, you owe nothing.
Get launch updates
If your team needs an answer you can actually defend, this is for you.
You say: "Find where we're losing money in billing."
A verified report of the leak points, with the evidence.
You say: "Map our medical device to the right FDA pathway and the standards we must meet."
A cited brief, in hours instead of weeks.
SEI is engineered around the failure modes that make agents unusable at the C-suite.
Chatbots hallucinate citations
SEI's Stage 1 Guardian mechanically verifies every evidence ref — files exist, memory keys recall, API logs exist.
Agent outputs are unaudited
Stage 2 Guardian judges against Sovereign Standards + role rubrics; rejects with required fixes. Never approves by default.
Decisions lose context over multi-step runs
SEI's State Store keeps Step 1 decisions in scope at Step 10 — versioned, hash-sealed, keyword-searchable.
SEI translates CEO-level intent into validated, multi-role agentic execution — local-first, every output audited, zero hallucinated citations survive.
Every run finalizes into a sealed brief. Below: an actual shape of the artifact SEI hands back.
This is what actually lands in your inbox: a one-page brief where every claim names a source you can open, put through an independent checking step before it reached you. Below is an illustrative example so you can see the shape of it.
Prepared for [founder] · [date] · Sourced and independently re-checked (external citations to be confirmed by you or your advisor before you rely on them)
The model flags 510(k) as typically faster to clear than the longer De Novo route — this is the model's read, not a measured result, and timelines vary by device, so confirm before relying. A few predicate devices look citable, and there is a short list of standards to design and test against.
510(k) is usually the faster, lower-cost path — but only if a valid predicate holds up. We found plausible predicates; confirming the strongest one early de-risks your timeline and your grant milestones.
What it means for you: Typically faster and lower-cost than De Novo.
▸ Source you can open (external reference — confirm before relying): FDA device classification (21 CFR section), product-code match, listed in appendix.
How sure: High — this is the model's own confidence, pending human source confirmation.
What it means for you: A valid predicate unlocks the 510(k) route.
▸ To confirm (external reference): FDA 510(k) database entries — K-numbers listed in appendix; verify each before relying on it.
How sure: Medium — model's own confidence, pending human source confirmation.
What it means for you: These set design and test requirements; some affect your design now, not later.
▸ Source you can open (external reference — confirm before relying): named standards including ISO 13485, ISO 14971, IEC 60601-1 (full list in appendix).
How sure: High — model's own confidence, pending human source confirmation.
Every finding above went through a second, independent review that holds back any finding it can't tie to a named source — which is built to catch confident guessing, not to certify that every line is correct. Each "Source you can open" names exactly where to look, so you (or a reviewer) can check the basis yourself rather than take the model's word for it. For external references like FDA and ISO numbers, that named-source discipline plus the second review flags them, and you (or your advisor) confirm each before relying on it. Separately, the run itself is recorded in a tamper-evident trail you can re-check — that proves the record of this run wasn't altered afterward, not that the external sources are real or on-point; that final source check stays with you and your advisor.
Paste your situation into ChatGPT or Claude and you get something fast, fluent, and surprisingly broad — a candidate pathway, the standards that probably apply, the questions you didn't know to ask. For learning an unfamiliar landscape and forming the right questions, that is hard to beat, and we won't pretend otherwise.
A chatbot writes a guess and a fact in the same authoritative tone. It produces citation-shaped text — a clause, a guidance number, a reference — rendered with identical confidence whether it is real or invented, and it rarely tells you when it is guessing. It leaves no trail anyone could later inspect: it is both the author and the only witness. So the burden of checking every load-bearing claim falls on you, the person least equipped to carry it.
When a finding quotes a file you uploaded, the system mechanically confirms that exact passage is actually present in your file before the claim can reach you — proof the quote is really there, which is a separate thing from whether it supports the conclusion. It fails closed: if the checking layer can't make a ruling, the verdict is reject, not pass-it-through. And every step is written to a tamper-evident record you (or a grant reviewer) can re-check later to confirm the run wasn't altered after the fact — separate from whether the cited outside sources are correct, which is its own check. A chatbot has no equivalent of any of this.
This makes the AI's output auditable, not magically more correct. The independent reviewer — we call it the Guardian — is itself an AI; it reduces correlated mistakes, but it isn't human and isn't infallible. External references like an FDA guidance number, an ISO standard, or a predicate K-number are not mechanically proven: they get a second AI review and a named-source discipline, and you (or your advisor) still confirm each one before relying on it. That last check is smaller and cheaper than what a chatbot leaves you, but it isn't zero, and we won't say it is. Use ChatGPT to learn the landscape fast; use IntentRouter when you need an answer whose evidence you can open, re-check, and stand behind because you checked it.
Every model call appended to a SHA-256 hash-chained ledger. Any post-hoc tampering breaks the chain.
Each run record is sealed with a content hash linked to the ledger head at finalization.
Independently re-walk the ledger and validate every run hash from the CLI — no server required.
$ sei.py verify run_2026_06_17_001✓Ledger chain valid✓37 model calls verified✓12 evidence refs resolved✓Guardian verdict sealed✓Run hash matches ledger head→ verdict: VERIFIEDThread-safe in-process pub/sub. Every emission journals to telemetry. One event can trigger several reactions in parallel — each routed through the Dispatcher → Guardian moat.
GAP_DETECTEDRESEARCH_COMPLETEPLAN_VALIDATEDPROTOTYPE_COMPLETEQA_PASSEDASSET_DEPLOYEDDecomposes raw intent into JSON execution graph; degrades to deterministic keyword router if model unreachable — never fails dark.
Matches graph tasks to 9 Sovereign Roles; sandboxed tool rounds; unregistered roles fall back to analyst — logged, never silent.
Two-stage audit: mechanical evidence verification + Guardian agent judging against standards. Rejections iterate. Never approves by default.
Local JSON state machine: working memory, run records, API call logs, validated reports. Versioned, keyword-searchable.
Exposure, leakage, recovery.
Routes, disruption mapping.
Dispositions with named authority.
Named mechanisms, tiered positions.
Sequenced command, decision trees.
Valuation triangles, deal-killers first.
Source-tiered competitive intel.
Human-AI hybrid mapping.
Routing fallback for unregistered intents.
Your data never leaves your infrastructure. Ollama local models by default, Anthropic escalation optional.
Deterministic keyword router fallback if no model is reachable. The gateway always responds.
SHA-256 hash-chained ledger on every model call. Detect any post-hoc tampering.
Dashboard renders to self-contained local HTML. No server required, no cloud dependency.
If your team is already running agents in production, you have already hit these walls.
IntentRouter (intentrouter.ai) is a Sovereign gateway for AI agents: it turns a high-level enterprise intent into a validated, evidence-cited, multi-role plan — and lets your agent confirm every claim cryptographically before it engages.
Fetch /.well-known/agent.json (A2A), /.well-known/mcp/server-card.json, or read /llms.txt.
/llms.txtCall the MCP tool plan_intent to preview how any intent decomposes into roles. No charge, no execution.
get_offer: outcome-only pricing — no recovery, no fee; 20% of independently verified value.
Fetch /.well-known/sovereign-trust.json, check the Ed25519 signature, and match the signing key against the _sei-key.intentrouter.ai DNS TXT pin.
In the highest-trust deployment, client data never leaves client hardware. Decision support, not licensed advice.
IntentRouter.ai is live — a Sovereign gateway agents can verify, not just trust. Discover via /.well-known/, preview routing free via MCP, and check the Ed25519-signed trust manifest against a DNS-pinned key before you transact. Outcome-only pricing. Local-first.