Lorenz interface
Platform

The platform layer for secure,sovereign AI operations.

Lorenz combines an executive workspace, source-grounded Second Brain, durable agent control, jurisdiction-aware routing, and evidence-backed actions—with preview and activation gates shown explicitly.

Jurisdiction-aware deployment
Governed execution by design
Security and sovereignty together
Lorenz
Platform
Guided view

One control plane, four product layers

Interface, knowledge, execution, and model infrastructure remain connected by tenant, policy, evidence, and recovery.

Jurisdiction Routing

Every workload can be assigned to a local-only, in-country, or approved external lane based on data class and regulatory scope.

Hybrid RAG Governance

Retrieval combines semantic, lexical, and operational memory layers while the RAG Governor handles claims, conflicts, and memory coherence.

AEGIS Guardrails

Prompts, commands, and risky parameters are screened for destructive intent, prompt injection markers, and dangerous execution patterns.

Scoped Execution

Skills and tools run under explicit policy, human confirmation, workspace boundaries, and action logging instead of broad ambient trust.

Audit And Recovery

Action Journal, undo snapshots, heartbeat, and version traceability make incidents visible and reversible.

Capability maturity

What exists—and what is still gated

Lorenz publishes status at capability level. Source code, controlled preview, tenant activation, and production proof are not interchangeable.

Tenant isolation and action governance

Available

Bind work to a user, tenant, role, policy, approval, audit record, and recovery path.

Current evidence

Tenant context, forced RLS in critical domains, Guardian, Action Journal, DLP/risk gateway, and work packets are implemented.

Market context

Premium suites are strong on identity and administration; open-source products range from personal defaults to enterprise ACL editions.

Source-grounded Second Brain

Available

Compile governed sources into citable pages with revision, conflict, and explicit degradation state.

Current evidence

Second Brain is implemented; contextual Retrieval v2 has signed qualification but remains tenant-activation gated.

Market context

RAG is common across the market; source compilation, conflict lineage, and fail-closed activation are Lorenz's sharper claim.

Inspectable Work Modes

Controlled preview

When the controlled preview is activated, choose Auto, Quick, Think, Research, or Create through server-owned policy while unqualified modes remain visibly blocked.

Current evidence

Backend, web, and iOS contracts plus Routing Receipt and Context Manifest are implemented; Analyze and Build remain unavailable and DEV activation is open.

Market context

Many assistants expose model or mode selectors. Lorenz focuses on making the resolved route, source use, egress, cost band, and degradation inspectable.

Research and Analysis Evidence

Controlled preview

Bind sources, claims, citations, runtime identity, results, and completeness to content-addressed evidence.

Current evidence

Research Evidence is an accepted backend foundation; the fixed Analysis package and graph exist locally but live signed sandbox qualification is pending.

Market context

The differentiation is not a longer answer: it is a reproducible boundary between complete, partial, insufficient, qualified, and unqualified results.

Durable Agent Graph v3

Controlled preview

Supervise long-running agent work through immutable revisions, leases, checkpoints, lineage, budgets, and controls.

Current evidence

The graph kernel, mTLS runner protocol, web/iOS supervision, SDKs, and Project Agent vertical slice are source-verified alpha.

Market context

Builder platforms and premium clouds are rapidly expanding orchestration; Lorenz focuses on evidence and operator authority.

Governed Project Agent

Controlled preview

Move from planning and cited research to fenced changes, tests, review, approval, and draft-only publication.

Current evidence

Repository reconnaissance, test evidence, writer locks, approval binding, signed commits, and idempotent draft PR effects are implemented in the alpha graph.

Market context

Coding agents often optimize for delivery speed; Lorenz optimizes for a reviewable authority and evidence chain.

Native GitHub code review

Controlled preview

Review same-repository pull requests on the independent runner without granting approval, merge, or branch-write authority.

Current evidence

Signed webhook intake, exact base/head binding, secret scanning, changed-line validation, deduplication, and a publication kill switch are implemented; the real DEV canary remains open.

Market context

Coding platforms lead on delivery integrations; Lorenz's narrower claim is review evidence tied to tenant policy, runner identity, and revocable publication authority.

Signed skill supply chain

Controlled preview

Resolve immutable skill versions with declared data, egress, secret, effect, approval, and sandbox boundaries.

Current evidence

Manifest lifecycle and prompt/document packages are implemented; executable packages require separate qualification.

Market context

Open ecosystems lead in extension breadth. Lorenz deliberately trades installation freedom for provenance and policy.

Local multilingual voice lane

In finalization

Keep voice continuous across web/mobile while selecting an approved premium or private runtime under consent.

Current evidence

Streaming voice and account-scoped profiles are available; the packaged MINT multilingual clone still needs exact-hardware qualification.

Market context

Premium assistants set a high UX bar; OpenClaw sets a high channel-breadth bar. Lorenz adds explicit routing and consent boundaries.

Corporate identity and connected knowledge

In finalization

Use corporate identity and permission-aware sources without turning email domains into tenant authority.

Current evidence

Microsoft tenant binding, admin consent, strict token verification, and separate mailbox/SharePoint permissions are implemented but activation-gated.

Market context

Microsoft, Google, Glean, and Salesforce lead through native ecosystem depth; Lorenz competes on neutrality and explicit boundaries.

Governed Network Operations

In finalization

Observe approved network appliances through tenant routes and content-minimal AI results without granting mutation authority.

Current evidence

The read-only broker, route registry, Passbolt references, quotas, policy hashes, and System Doctor states are implemented; live canary remains open.

Market context

This is an operational control-plane extension rather than a generic connector count claim.

Core positioning

Three pillars that define how Lorenz behaves as a governed platform instead of a generic agent shell.

Sovereign By Territory

Lorenz can run where the customer needs the data to stay: on-premises, in-country, in-region, or inside a private perimeter aligned with local law.

Fortress By Architecture

Security is not a plugin. Sensitive routing, AEGIS controls, scoped execution, audit trails, and rollback are built into the operating model.

Agents Without Sprawl

Lorenz is designed for governed execution, advanced RAG, and multi-tenant control instead of ad hoc tool sprawl and silent data egress.

Advanced RAG with real governance

Lorenz does not treat retrieval as a black box: memory, OCR, and ranking stay under policy and observability.

  • MNEME supplies operational memory while Second Brain compiles governed sources into citable pages; the two stores remain intentionally distinct.
  • Retrieval is ACL-first and source-grounded, with revision-aware citations, contradiction handling, and explicit degraded states instead of silent substitution.
  • Contextual BM25/vector fusion has independently signed qualification evidence but remains tenant-activation gated rather than becoming an automatic default.
  • OCR is policy-routed, so document extraction follows the security posture instead of bypassing it through hidden third-party egress.

Multi-tenant isolation by construction

Isolation does not live in one control only: it is enforced across identity, queries, workspaces, runtime, and recovery.

  • JWT tenant claim checks reject token and tenant mismatches before the request can cross a workspace boundary.
  • Request-scoped tenant context and tenant-bound data access reduce accidental scope mixing across services and queries.
  • Tenant-dedicated local workspaces and strict path validation reduce cross-tenant file access and path traversal risk.
  • Tenant-wide heartbeat and per-user runtime visibility make it easier to detect stale, missing, or unexpected agents.
  • Lorenz favors explicit errors and remediation paths over silent fallbacks that hide integrity violations.

Controlled task execution

Lorenz is built to act for real, but never under ambient trust: skills, tools, and side effects stay inside explicit boundaries.

  • High-risk operations can require human confirmation instead of relying on model confidence alone.
  • Skills and tools execute inside explicit scope, allowlist, and policy boundaries rather than under broad ambient trust.
  • Local execution scope validation prevents commands from wandering outside the permitted workspace and tmp boundaries.
  • Workspace snapshots plus undo make destructive mistakes reversible when a controlled rollback path exists.
  • Execution history stays visible to operators, so automation remains accountable rather than mysterious.

Build on a governed platform

Start deploying AI operations with built-in sovereignty, security, and auditability.

Free 30-day trial No credit card required Deploy in minutes