Every tier ships these. They gate scale and premium AI — never safety. This is the consistency contract the whole platform honors.
One commitment register keyed by ClientEntity × Fund × Vintage drives everything downstream. No parallel spreadsheets, no reconciliation of the reconciliation.
Every booked cash flow links back to its source PDF and extracted fields — immutable, timestamped, and traceable from figure to approver.
Capital calls carry funding dates; late funding is a default event. SLA clocks run on the metering engine and escalate before the breach, not after.
Extraction and booking are automated; release of cash is gated by approval. Dual-control is mandatory on wires over $5M. Nothing is straight-through.
Cash, positions, and unfunded reconcile to custodian and GP statements every cycle — T+0, not just at quarter-end.
Each rule maps to a runtime control — an SLA-clock metering engine, a dual-control approval FSM, a hash-chained event store. Policy text is the description; the architecture is the enforcement.
The Sentinel Auth Worker is a deny-by-default policy decision point. It consumes a verified principal and authorizes per request, scoping every database read to the caller's tenant and client entities. Money authority and data-administration authority are deliberately disjoint — no single role can concentrate privilege.
Every read, export, correction, approval, and wire release emits an audit event into an append-only, hash-chained ledger event store. Each event hashes the previous event's hash, so any retroactive edit is detectable. Periodic digests are sealed to write-once secure storage (WORM) as tamper-evident checkpoints.
TLS 1.3 protects every connection to the edge; mTLS client certs secure custodian and bank adapters. The cloud platform encrypts the database, cache, and secure storage at rest by default — and on top of that, Sovereign ZX app-level-encrypts the most sensitive fields before they touch the database.
Each client entity carries a residency region; its documents, events, register rows, and NAV live only in that region's data plane. The global control plane holds routing and policy metadata only — never client financials.
When an inbound notice changes any bank detail against the GP standing instructions on file, the per-call SLA-clock Durable Object enters its HardStop state and the wire-release path becomes unreachable. It stays unreachable until an independent callback — to a known number, never one from the notice — verifies the change. Wires can only ever target a verified SSI.
The same audit substrate that runs the product produces the control evidence. Attestations are continuous outputs of the architecture, not a once-a-year scramble.
Control evidence drawn from the ledger audit-event stream and the analytics pipeline — security, availability, confidentiality, processing integrity.
A live ISMS with a maintained risk register and Annex A control mapping.
Hash-chained books & records with write-once secure storage; every figure traceable to its source document and approver.
Regional residency, signed DPAs, data-subject tooling, and least-privilege access throughout.
Deny-by-default authority, immutable provenance, region-pinned data, and a fraud hard-stop enforced in state. See it on your own book.