Files and vault
Read on the way in, sealed on request
Upload one document or forty. Say what you want looked at. The files are read as they arrive, and the answer comes back naming the page each figure sits on.
- Two documents that disagree, found on the way in
- A Form E and the pension scheme's own statement, put in together, come back with the transfer value each one gives, the date of separation each one gives, and the page for both.
- Connected to the whole file by default
- Everything read onto a matter you can see, Numo Bot can see. What you cannot see, it cannot see either, because the same permissions decide both.
- Except what you seal
- Lock a file to the vault and it is encrypted under that matter's own key. The assistant cannot read it at all, and says so, rather than answering around it.
Putting files in
One file, forty files, or straight from a drive
Choose from the computer, or bring a document in from a connected Drive or Google Docs without downloading it first. Type what you want looked at in the same breath, and the question travels with the files.
- The question goes in with them
- "Pull out every date and figure, and tell me where these disagree with the statement already on the file." The panel opens with the documents named, and the answer is about those documents rather than the matter at large.
- Read as they arrive
- Text is extracted on upload, so a question a week later does not wait for anything. PDFs and Word documents both. A scan with no text layer is reported as a scan, not guessed at.
- Five ways a file can fail, told apart
- A scan, a damaged file, an image, an old .doc and an unknown format each say what they are, because "could not read" tells a fee earner nothing about what to do next.

The vault
A vault the server cannot open
The vault is not a folder with a padlock icon. Each object has its own content key, wrapped by a vault key derived from a passphrase with Argon2id. The server holds ciphertext and nothing that opens it.
- Filenames live inside the encryption
- A list of sealed filenames is itself disclosure. They are stored inside the encrypted payload, not beside it, so the index gives nothing away either.
- Analysis needs a consent, recorded
- Unlocking the vault in a session is not the same as agreeing that a model may read something in it. Consent is given per object and written down.
- Files, photographs, matters, graphs
- Anything that can be attached can be sealed: a document, an image, a place you saved from the map, the exhibit a client sent. The vault is a state a thing can be in, not a separate cupboard.
- Recovery is shown once
- A recovery key is displayed at the moment the vault is created and never again. Nobody at Numo can produce it for you afterwards, which is the property that makes the rest of it true.

Before the model
A document that addresses an automated reader is withheld
Text inside a document is evidence about a matter. It is never an instruction. A file that contains one is quarantined before anything reads it, and then listed, so a person knows it exists and reads it themselves.
- Deterministic screening, not a judgement call
- The screen is a fixed set of patterns applied to extracted text. It runs before any model sees the document, so there is nothing to talk it out of.
- Untrusted text stays fenced
- Document text reaches the model inside a fence that marks it as material to be read about, with the instruction boundary outside it.
- Nothing enters the chronology by itself
- What the assistant finds becomes a proposal in a review queue. A person accepts it, and only then is it a fact on the matter.
Around the file
Locations, images and links belong to the matter too
A family matter is not only paper. Connect a place from the map with its Street View, a photograph, a link, or a person, to a matter, a person or the organisation, and the graph draws what is joined to what.
- Saved from the map, kept on the file
- Find a place by typing an address, save the view, and attach it to the matter, a person, the files list or the vault.
- Viewed without leaving
- Documents and images open in the application, at the page you were pointed to, rather than downloading to a laptop that then leaves the building.
- Every attachment is on the graph
- Press anything in the matter graph and it names everything joined to it, including the places and photographs.

The limits
Said as plainly as the claims
Scans are not read
A PDF with no text layer is reported as a scan. It is not run through a guess, and it is not silently skipped either.
A sealed file stays sealed
No support route, no administrator and no background job can read a vault object. If the passphrase and recovery key are both lost, the contents are gone.
Nothing is deleted quietly
Removing a file is an action with a name against it in the audit trail, like every other action on the matter.
No file leaves on its own
Sending a document anywhere is an action a person allows, one at a time, naming the recipient.
Asked before buying
- Can Numo Bot read everything on the matter?
- Yes, unless it is in the vault. That is the honest answer and the one firms want said out loud: by default it is connected to the whole file, bounded by what the person asking is allowed to see, and the vault is how you take something out of its reach.
- Where do the files actually sit?
- In private object storage in the EU, reached only through short-lived links minted after a permission check. Vault objects sit in the same place as ciphertext.
- What size and what formats?
- PDF and Word for text extraction, images as images, and anything at all for storage. Type and size are both checked on the way in rather than trusted from the browser.
See it on your own matters
Half an hour, your own file, and an honest answer about whether this fits how your firm already works.