Source-to-report lineage on every reported figure.
Unauthorized data egress.
Data-residency incidents.
Human attestation on every submission.
Challenge
The institution modelled here spends more than $200M a year on compliance, roughly 40% of it on technology, which is over $80M annually. Both figures are our stated assumptions, replaced with the client's actuals in Phase 0. It still reconciles its regulatory returns by hand. That contradiction is the whole story, and it is not explained by a lack of vendors.
- The market is crowded and the institution has been pitched by all of it. Juniper Research forecasts regtech spend rising 124% between 2023 and 2028, from $83 billion to $207 billion.
- The data cannot go there. Reporting data is the institution's most regulated material: ledgers, risk positions, the finance corpus, and the returns built from them. A vendor cloud is a jurisdiction question the institution would rather not answer to a supervisor.
- So the pilot gets scoped to a sanitised copy. Which does not prove anything, and the project quietly ends.
- The lineage cannot be defended, which catches institutions late. A tool can produce a number. An examiner asks where it came from, through what transformations, from which source, and whether the same answer appears in two years.
- Faith is not an audit position. Lineage assembled outside the boundary, by a system the institution does not host and cannot fully inspect, is lineage the controllership defends on faith.
- Manual work has one property no tool matched. The institution can explain it, which is why the people keep doing it by hand however much the line costs.
- The gap was never automation. The institution knows how to automate. The gap is somewhere to run it that its regulator, its controllership, and its CISO all sign off on the first time.
Source to reported figure
- 01
Source systems
Reads Ledgers, risk positions, exposures, in the institution's own region
Held Raw figures, on paths allowlisted in the kernel
- 02
Aggregation and transformation
Reads One configured environment, executing every cycle identically
Held Each step logged and sequenced as it runs, not afterwards
- 03
Validation against the regime
Reads The institution's own rules and thresholds
Emits Exceptions surfaced, with the trail attached
- 04
The reported figure
Reads A complete source-to-report trail, tamper-evident
Emits A human review, signature and attestation on every submission
Solution
CreateOS is not a reporting tool the institution buys. It is an agent workforce running on infrastructure the institution hosts, with lineage built into the runtime rather than bolted on top of it.
Eighty million on technology
About 40% of a $200M-plus compliance budget, and returns still reconciled by hand.
100%source-to-report
Lineage native to the runtime
Written in sequence as each step executes, not generated on request.
- Lineage is the product, not a feature of it. Every reported figure traces to source through a logged, sequenced trail written as the work happens. A trail produced after the fact is a reconstruction, which is exactly what an examiner is trained to probe.
- Self-hosting is an architectural fact, not a contractual assurance. Control plane and storage run inside the institution's own region and jurisdiction, and regulated data never crosses the boundary. That is why the pilot ran on real reporting data instead of a sanitised copy, which is the only way a pilot proves anything.
- Egress is a path that does not exist. Agents reach approved internal systems and sanctioned regulator endpoints, nothing else. A control enforced in the kernel survives a compromised agent, a misconfigured service, and a bad prompt.
- Per-VM isolation by default. Every reporting run executes in its own guest kernel, so the blast radius of any single agent is one disposable machine and regimes and entities are cleanly walled.
- Reproducibility is a control the institution can evidence. One configured environment runs every cycle identically, so consistency is auditable and drift is a finding. The controllership asked about this before it asked about speed.
- Human attestation preserved by design. The agents assemble, validate, and draft. A human reviews, signs, and attests every submission, and nothing is filed autonomously. The report is the institution's word to its regulator, and it stays the institution's word.
- We own both layers. Most agent builders own the prompts and rent the runtime, which is the difference between making a data-residency promise and being able to keep one.
CreateOS is SOC 2 Type II and ISO 27001 certified. The platform that runs the institution's controls has its own controls evidence in place, which is the first question internal audit asks and the one most agent vendors cannot answer.
Outcome Derived
The security review became a step in the process rather than the end of it.
| Metric | Before | After |
|---|---|---|
| Where reporting data lives | Vendor cloud | Institution's own infrastructure, own jurisdiction |
| Data lineage | Assembled outside the boundary, partial | 100% source-to-report, written in-runtime, tamper-evident |
| Outbound data egress | Policy-enforced | Allowlisted in-kernel with eBPF, path does not exist |
| Isolation model | Shared tenancy | Per-VM kernel isolation, Firecracker micro-VM |
| Cycle-to-cycle consistency | Drifts | Identical templated runs, auditable |
| Filing authority | Varies | Human attestation on every submission, by design |
| Platform assurance | Varies | SOC 2 Type II, ISO 27001 |
| Pilot data | Sanitized copy | Real reporting data, inside the boundary |
The security review became a step in the process rather than the end of it, and this case carries no cost-out figure of its own on purpose. Inventing one would lose the room.
- It is what makes the other three bankable. The reporting cycle is worth $7.5M to $12.0M a year, change monitoring returns $2.2M to $4.0M, audit readiness takes out $1.5M to $2.4M. None is realisable by an institution that cannot get the system through its own security review, and none is defensible if the lineage was assembled in someone else's cloud.
- The $80M that has not fixed this. Technology is roughly 40% of a $200M-plus compliance budget, and the reconciliation is still manual. That reframes the CFO question from will this save money to why has the money you already spend not solved this.
- A promise versus an architecture. Every vendor says the data is safe. A policy forbidding exfiltration can be misconfigured, bypassed by a compromised process, or violated by a model doing something nobody anticipated. An egress path that does not exist in the kernel cannot be any of those.
- The lineage an examiner will actually accept. Source-to-report, sequenced and tamper-evident, written as each step runs. It is quietly better than the manual process produced, because a spreadsheet reconciled by someone who has since left has no lineage at all.
- The savings were never the missing piece. The institution has been shown them before. What it had never been shown is somewhere it could actually run them.
What We Would Prove, and How
Weeks 1 to 2, baseline. Establish the institution's current lineage coverage, its data-residency requirements by jurisdiction, its control framework, and the specific gates internal audit and information security will apply. The security review is designed into the engagement, not discovered at the end of it.
Weeks 2 to 6, build and integrate. Deploy self-hosted inside the institution's boundary. Integrate to source systems, ledgers, and reporting infrastructure along allowlisted paths. Encode the reporting rules, the controls, and the sign-off thresholds. Every outbound path is defined in the kernel and approved before it exists.
Weeks 6 to 9, parallel run. The agents produce returns alongside the current process without filing anything. Every figure is compared to the institution's own filed reports, and every figure's lineage is walked back to source. Proving the trail is right matters as much as proving the number is.
Week 9 onward, controlled adoption. Agent-produced returns adopted for the proven regimes, human attestation on every submission, scope expanding as the accuracy and lineage record builds.
Success criteria, agreed up front: 100% source-to-report lineage on every reported figure, zero unauthorized data egress, zero data-residency incidents, reporting accuracy at or above the current process, human attestation preserved on every submission, and information-security and internal-audit sign-off obtained before go-live rather than after.
Highlights
- Data lineage: 100% source-to-report on every reported figure, written in-runtime, tamper-evident.
- Unauthorized data egress: Zero. Allowlisted in-kernel with eBPF, the path does not exist.
- Data-residency incidents: Zero. Reporting data stays inside the institution's own infrastructure and jurisdiction.
- Human attestation preserved on every submission, by design.
- This case study does not carry its own cost-out figure. The value of lineage and residency is that they are the precondition for everything else.



