Of claims grounded and traceable at source.
MNPI or data-leakage incidents.
Source-and-step audit coverage, replayable.
Data egress allowlisted with eBPF; research never leaves the boundary.
Challenge
The output was good enough. Both pilots died at the compliance review, for reasons the vendors could not fix, because the reasons were architectural. The firm was not short of research tools. It was short of somewhere to run one.
- The data could not leave. Using any evaluated tool properly meant sending internal research, analyst notes, models, and most damaging of all the list of names under work to a vendor cloud. A tool that quietly tells a third party which sectors the fund is building a position in has leaked the thesis, not improved the research.
- The CCO's position was simple and correct. We do not send our book to somebody else's infrastructure so they can help us think about it.
- Approved for public data only, adoption collapsed in a quarter. Which is the version of the problem where you own a research assistant not allowed to read your research. The analysts went back to doing it by hand and the firm concluded, wrongly, that the technology was not ready.
- One invented number is a fiduciary event. A model that fabricates a revenue figure, or attaches a real number to the wrong citation, moves the checking burden and poisons the decision downstream. The standard was that every figure be traceable to the page it came from, and no evaluated tool held it under load.
- The information barrier could not rest on policy. The firm runs a private side and a public side, and regulators expect an adviser to demonstrate its policies account for MNPI vectors. We told the tool not to is not a demonstration.
- No structural boundary is a violation waiting for a bad week. A research system that ingests material across both sides with nothing separating them is exactly that.
What the compliance review decides
Approved for public data only
- Adoption collapsed in a quarterA research assistant not allowed to read the research.
- The barrier rests on policyWhich is a violation waiting for a bad week.
Running inside the walls
- Nowhere for the data to goEgress is a route absent from the kernel, not a policy.
- The barrier is the hypervisorPrivate side and public side are separate guest kernels.
Solution
CreateOS built the research agent crew and, more importantly, deployed it inside the firm's own boundary on infrastructure the firm hosts. The controls are not settings. They are the architecture.
A research assistant that cannot read your research
Approved for public data only, because internal notes would broadcast the thesis.
100%grounded and logged
Pointed at the real data
Control plane inside the firm's boundary, with the barrier held at the hypervisor.
- The data does not leave, because there is nowhere for it to go. Control plane and storage run inside the firm's own infrastructure, and research, notes, models, positions, and the identity of the names under review never cross the boundary.
- Egress is a route absent from the kernel, not a policy. Gathering agents reach approved data providers and nothing else, so the firm's research cannot be exfiltrated by a compromised agent, a misconfigured prompt, or a curious vendor.
- Every claim is grounded, or it does not enter the memo. Ungrounded generation on factual and numerical content is not permitted. The analyst does not receive a memo and then check it: each figure arrives carrying the page it came from.
- The information barrier is enforced at the hypervisor. Every research workstream runs in its own guest kernel, so the private side and the public side are walled by the machine rather than the prompt. Separate mandates and deal teams are separate machines.
- MNPI is screened on corpus and draft. Against the firm's own policies, inline, with anything that should not be there flagged.
- A misbehaving agent is suspended instantly. Through the VM lifecycle, not a support ticket.
- The trail exists before anyone asks for it. Every source, model, and step is logged, so the memo is reproduced rather than re-derived. That serves the investment committee wanting to know why and the regulator wanting to know how.
CreateOS is SOC 2 Type II and ISO 27001 certified. Most agent builders own the prompts and rent the runtime, which is why their answer to the CCO is a paragraph in a security questionnaire. We own both layers, and the answer is a deployment diagram.
Outcome Derived
The value here is not a percentage. It is that the project happened at all.
| Metric | Before | After |
|---|---|---|
| Research, notes, and names under review | Sent to vendor cloud, or tool unused | Never leave the firm's boundary |
| Data egress | Vendor policy and trust | Allowlisted in-kernel with eBPF |
| Claim grounding | Analyst checks the model's work | 100% cited and traceable at source |
| Information barrier | Enforced by policy and instruction | Enforced at the hypervisor, per workstream |
| MNPI screening | Manual, after the fact | Inline, on corpus and draft |
| Audit trail | Partial, reconstructed on request | 100% of sources and steps, replayable |
| MNPI or data-leakage incidents | Open risk | Zero |
| Certifications | Vendor-dependent | SOC 2 Type II, ISO 27001 |
- Self-hosting is the precondition, not a concession. Every efficiency number in the other three cases, the memo down to under eight hours, the 35% of capacity coming back, coverage rising on the same headcount, is only available to a firm that can point the agents at its real data.
- A tool restricted to public material delivers a fraction. Which is why the firm's first two pilots produced polite interest and no adoption.
- The CCO's three questions were answerable with architecture. Where does our data go: nowhere, and here is the kernel-level route table. How do we know the memo is true: every figure carries its source. How is the barrier held: at the hypervisor, one micro-VM per workstream, logged end to end.
- The analyst remains the control of record. Grounding reduces the risk of a fabricated figure to as close to zero as the architecture allows, and the citation trail makes an error visible rather than buried. No system removes the analyst, and any vendor who says otherwise has told the CCO everything they need to know.
What We Would Prove, and How
Weeks 1 to 2, baseline. Establish the firm's current controls, information-barrier policy, and the specific data classes in scope. Agree what the system will and will not be permitted to reach.
Weeks 2 to 6, build and integrate. Stand up the agent crew, integrate to data providers, document stores, and internal research along allowlisted paths, encode the firm's information-barrier policies, deploy self-hosted inside the boundary.
Weeks 6 to 9, augmented run. Analysts produce memos with the agents alongside the normal process. Confirm that every claim is grounded, that the MNPI controls hold, and that egress behaves exactly as specified. Proving accuracy and confidentiality is the entire purpose of this phase.
Week 9 onward, controlled rollout. Expand across coverage areas, strategies, and eventually the private side, as the grounding and control record builds.
Success criteria, agreed up front: 100% of claims grounded and traceable, zero MNPI or data-leakage incidents, 100% source-and-step audit coverage, and an egress record that matches the allowlist exactly.
Highlights
- 100% of claims grounded and traceable at source; ungrounded generation on factual and numerical content is not permitted.
- Zero MNPI or data-leakage incidents; research, notes, and names under review never leave the firm's boundary.
- 100% source-and-step audit coverage, replayable; egress allowlisted in-kernel with eBPF.
- Information barrier enforced at the hypervisor, per workstream, not by policy and instruction alone.
- Success criteria agreed up front: 100% grounding, zero leakage incidents, 100% audit coverage, egress record matches the allowlist exactly.



