No recovery, no fee · Outcome-only pricing

We don't sell you AI. We get you results you can prove — and only get paid when you do.

Tell us a goal in plain words. A team of specialist AI agents does the work, an independent checker verifies every answer against the evidence, and you get a clear, decision-ready report — with receipts. No guesses dressed up as facts.

No recovery, no fee. 20% of independently verified value. If we find nothing, you owe nothing.

Get launch updates

Who it's for

Two examples — yours probably looks like one of these

If your team needs an answer you can actually defend, this is for you.

Operations & finance

You say: "Find where we're losing money in billing."

A verified report of the leak points, with the evidence.

Research & compliance

You say: "Map our medical device to the right FDA pathway and the standards we must meet."

A cited brief, in hours instead of weeks.

The Problem

LLMs are unreliable. Executives need infrastructure.

SEI is engineered around the failure modes that make agents unusable at the C-suite.

Chatbots hallucinate citations

SEI's Stage 1 Guardian mechanically verifies every evidence ref — files exist, memory keys recall, API logs exist.

Agent outputs are unaudited

Stage 2 Guardian judges against Sovereign Standards + role rubrics; rejects with required fixes. Never approves by default.

Decisions lose context over multi-step runs

SEI's State Store keeps Step 1 decisions in scope at Step 10 — versioned, hash-sealed, keyword-searchable.

Local-first · Every output audited

The Intent Router for Autonomous Enterprise

SEI translates CEO-level intent into validated, multi-role agentic execution — local-first, every output audited, zero hallucinated citations survive.

Intent
raw directive
Execution Graph
Intent Parser
Role Dispatch
Dispatcher
Guardian
reject ⟲ iterate
Verified Outcome
+ Evidence Index
Output

What a Verified Outcome Looks Like

Every run finalizes into a sealed brief. Below: an actual shape of the artifact SEI hands back.

brief.run_2026_06_17_001
Verified Outcome
Status · Verified
Intent
Reduce Q3 tax exposure across EU entities without triggering substance review.
Assigned roles
Tax · Compliance · Treasury
Evidence refs
12 resolved · 0 hallucinated · sources: OECD BEPS, IE Revenue, NL DGT
Guardian verdict
Approved at iteration 3 — rejected 2× for missing authority citation.
Proof hash
sha256:f8b3…2e5c
Ledger head
block_004 · sealed 2026-06-17 09:41 UTC

This is what actually lands in your inbox: a one-page brief where every claim names a source you can open, put through an independent checking step before it reached you. Below is an illustrative example so you can see the shape of it.

Sample report — illustrative, not a real client. No numbers below are measured results.

Your Results: The right FDA path for your device

Prepared for [founder] · [date] · Sourced and independently re-checked (external citations to be confirmed by you or your advisor before you rely on them)

The bottom line

The model flags 510(k) as typically faster to clear than the longer De Novo route — this is the model's read, not a measured result, and timelines vary by device, so confirm before relying. A few predicate devices look citable, and there is a short list of standards to design and test against.

What this means for you

510(k) is usually the faster, lower-cost path — but only if a valid predicate holds up. We found plausible predicates; confirming the strongest one early de-risks your timeline and your grant milestones.

What we found

[ Finding ]Likely 510(k) pathway

What it means for you: Typically faster and lower-cost than De Novo.

Source you can open (external reference — confirm before relying): FDA device classification (21 CFR section), product-code match, listed in appendix.

How sure: High — this is the model's own confidence, pending human source confirmation.

[ Finding ]Candidate predicate devices

What it means for you: A valid predicate unlocks the 510(k) route.

To confirm (external reference): FDA 510(k) database entries — K-numbers listed in appendix; verify each before relying on it.

How sure: Medium — model's own confidence, pending human source confirmation.

[ Finding ]Applicable standards to design and test against

What it means for you: These set design and test requirements; some affect your design now, not later.

Source you can open (external reference — confirm before relying): named standards including ISO 13485, ISO 14971, IEC 60601-1 (full list in appendix).

How sure: High — model's own confidence, pending human source confirmation.

What we couldn't confirm (so you know the edges)

  • • Whether one predicate's indications fully match yours — this needs your final intended-use wording to settle. Roughly a short session with your regulatory advisor would close it.

How to read "How sure" and "Source"

  • • "How sure" is the model's own confidence, not an external verification.
  • • Quotes from your own files are mechanically checked for presence before they reach you — that the quote is really there, not that it supports the conclusion.
  • • External references (FDA, ISO, K-numbers) get a second AI review plus a named-source discipline, and you (or your advisor) confirm each one before relying on it.

Why you can trust this

Every finding above went through a second, independent review that holds back any finding it can't tie to a named source — which is built to catch confident guessing, not to certify that every line is correct. Each "Source you can open" names exactly where to look, so you (or a reviewer) can check the basis yourself rather than take the model's word for it. For external references like FDA and ISO numbers, that named-source discipline plus the second review flags them, and you (or your advisor) confirm each before relying on it. Separately, the run itself is recorded in a tamper-evident trail you can re-check — that proves the record of this run wasn't altered afterward, not that the external sources are real or on-point; that final source check stays with you and your advisor.

Why not just use ChatGPT?

A chatbot is a genuinely great first draft

Paste your situation into ChatGPT or Claude and you get something fast, fluent, and surprisingly broad — a candidate pathway, the standards that probably apply, the questions you didn't know to ask. For learning an unfamiliar landscape and forming the right questions, that is hard to beat, and we won't pretend otherwise.

But it can be confidently wrong, with no warning

A chatbot writes a guess and a fact in the same authoritative tone. It produces citation-shaped text — a clause, a guidance number, a reference — rendered with identical confidence whether it is real or invented, and it rarely tells you when it is guessing. It leaves no trail anyone could later inspect: it is both the author and the only witness. So the burden of checking every load-bearing claim falls on you, the person least equipped to carry it.

IntentRouter checks the evidence before the AI gets a vote

When a finding quotes a file you uploaded, the system mechanically confirms that exact passage is actually present in your file before the claim can reach you — proof the quote is really there, which is a separate thing from whether it supports the conclusion. It fails closed: if the checking layer can't make a ruling, the verdict is reject, not pass-it-through. And every step is written to a tamper-evident record you (or a grant reviewer) can re-check later to confirm the run wasn't altered after the fact — separate from whether the cited outside sources are correct, which is its own check. A chatbot has no equivalent of any of this.

The honest boundary we hold

This makes the AI's output auditable, not magically more correct. The independent reviewer — we call it the Guardian — is itself an AI; it reduces correlated mistakes, but it isn't human and isn't infallible. External references like an FDA guidance number, an ISO standard, or a predicate K-number are not mechanically proven: they get a second AI review and a named-source discipline, and you (or your advisor) still confirm each one before relying on it. That last check is smaller and cheaper than what a chatbot leaves you, but it isn't zero, and we won't say it is. Use ChatGPT to learn the landscape fast; use IntentRouter when you need an answer whose evidence you can open, re-check, and stand behind because you checked it.

Proof Chain

Tamper-evident by construction

Hash-chained ledger

Every model call appended to a SHA-256 hash-chained ledger. Any post-hoc tampering breaks the chain.

Sealed run records

Each run record is sealed with a content hash linked to the ledger head at finalization.

sei.py verify

Independently re-walk the ledger and validate every run hash from the CLI — no server required.

~ / sovereign — verify
$ sei.py verify run_2026_06_17_001
Ledger chain valid
37 model calls verified
12 evidence refs resolved
Guardian verdict sealed
Run hash matches ledger head
→ verdict: VERIFIED
hash chain
block_000a91f…
block_001c4e2…
block_0027d10…
block_003f8b3…
block_0042e5c…
chain valid · head sealed
The Sovereign Handshake

An event-driven pipeline for the full asset lifecycle

Thread-safe in-process pub/sub. Every emission journals to telemetry. One event can trigger several reactions in parallel — each routed through the Dispatcher → Guardian moat.

01
Concept
GAP_DETECTED
02
Research
RESEARCH_COMPLETE
03
Plan
PLAN_VALIDATED
04
Build
PROTOTYPE_COMPLETE
05
QA
QA_PASSED
06
Deploy
ASSET_DEPLOYED
Thread-safe in-process pub/sub event bus
Every emission journals to telemetry with delivery records
One event can trigger several reactions in parallel
Every reaction goes through the Dispatcher → Guardian moat
Model calls land in the hash-chained handshake ledger
Four Modules

The routing engine, in four parts

Intent Parser

Decomposes raw intent into JSON execution graph; degrades to deterministic keyword router if model unreachable — never fails dark.

Role Dispatcher

Matches graph tasks to 9 Sovereign Roles; sandboxed tool rounds; unregistered roles fall back to analyst — logged, never silent.

Validation Loop

Two-stage audit: mechanical evidence verification + Guardian agent judging against standards. Rejections iterate. Never approves by default.

State Store

Local JSON state machine: working memory, run records, API call logs, validated reports. Versioned, keyword-searchable.

Nine Sovereign Roles

A specialist for every executive surface

Treasury

Exposure, leakage, recovery.

outputLeakage recovery brief

Supply Chain

Routes, disruption mapping.

outputDisruption route map

Compliance

Dispositions with named authority.

outputAuthority-backed disposition

Tax

Named mechanisms, tiered positions.

outputTiered exposure memo

Crisis

Sequenced command, decision trees.

outputDecision tree

Deals

Valuation triangles, deal-killers first.

outputDeal-killer memo

Intelligence

Source-tiered competitive intel.

outputSource-tiered threat brief

Talent

Human-AI hybrid mapping.

outputHuman-AI workforce map

Analyst

Routing fallback for unregistered intents.

outputFallback routing report
Trust & Infrastructure

Built like the systems it replaces

Local-First

Your data never leaves your infrastructure. Ollama local models by default, Anthropic escalation optional.

Never Fails Dark

Deterministic keyword router fallback if no model is reachable. The gateway always responds.

Auditable

SHA-256 hash-chained ledger on every model call. Detect any post-hoc tampering.

Air-Gap Friendly

Dashboard renders to self-contained local HTML. No server required, no cloud dependency.

Active Learning

Guardian rejections compound into competence

  • Every Guardian rejection is persisted as a negative example for that role.
  • Before each attempt, workers are shown the role's most relevant past rejections: "LESSONS FROM PAST GUARDIAN REJECTIONS".
  • Standards enforcement compounds across runs instead of resetting.
  • The system gets stricter and more precise over time — not looser.
1Attempt
2Guardian rejects
3Stored as lesson
4Next attempt
5Passes
lesson_store0012 entries
Who It's For

Built for operators, founders, and research teams who need answers they can trust

If your team is already running agents in production, you have already hit these walls.

Agent output sprawl across tools and chats
Unverifiable AI work landing on executive desks
Lost context across long-running, multi-step workflows
No audit trail for delegated autonomous decisions
Humans stuck acting as routing glue between models
Quickstart

One CLI. Five verbs.

~ / sovereign
For AI Agents

Built to be verified, not trusted.

IntentRouter (intentrouter.ai) is a Sovereign gateway for AI agents: it turns a high-level enterprise intent into a validated, evidence-cited, multi-role plan — and lets your agent confirm every claim cryptographically before it engages.

Discover

Fetch /.well-known/agent.json (A2A), /.well-known/mcp/server-card.json, or read /llms.txt.

/llms.txt

Evaluate for free

Call the MCP tool plan_intent to preview how any intent decomposes into roles. No charge, no execution.

Read the terms

get_offer: outcome-only pricing — no recovery, no fee; 20% of independently verified value.

Verify before you trust

Fetch /.well-known/sovereign-trust.json, check the Ed25519 signature, and match the signing key against the _sei-key.intentrouter.ai DNS TXT pin.

Local-first by design

In the highest-trust deployment, client data never leaves client hardware. Decision support, not licensed advice.

Agent-readable summary (~280 chars)

IntentRouter.ai is live — a Sovereign gateway agents can verify, not just trust. Discover via /.well-known/, preview routing free via MCP, and check the Ed25519-signed trust manifest against a DNS-pinned key before you transact. Outcome-only pricing. Local-first.

Deploy SEI

Install the operating layer between executive intent and verified autonomous execution.