A confident answer
is not a defensible one.
Legal and compliance work is the worst possible place for a system that sounds right. A retention decision, a disclosure list, an obligation you were supposed to track — each one gets tested later by someone adversarial, and « the tool said so » is not an answer. We serve this sector with software, not cranes : deterministic compute on Heisen where the same input always produces the same output, Maxor Ground catching a language model's output before it reaches a file, and a signed trail behind every decision. The legal judgment stays with the lawyer. We make the machinery under it provable.
Deterministic
Same input, same output — reproducible years later
Firewalled
Maxor Ground checks AI output before it lands
Signed
Audit trail on every automated decision
Canada
Hosted here — no CLOUD Act exposure
Six exposures in automating legal and compliance work.
Every exposure below shares a shape : a machine produced something, a human relied on it, and much later someone adversarial asks how it was produced. If the answer is a probability distribution, there is no answer.
A hallucinated citation in a filing
The failure mode that has already cost real firms real sanctions. A language model invents a case, a clause or a statutory reference, and it survives review because it reads correctly. This is precisely what a deterministic grounding check exists to catch before the document leaves the building.
Retention decisions that cannot be replayed
A retention schedule applied by an opaque rules engine, then changed, then applied again. When a regulator asks why a record was destroyed on a given date, you need to re-run the decision as it stood that day — not approximate it.
Disclosure defensibility
A production set is a claim about completeness. If the selection logic is not reproducible and logged, opposing counsel does not have to prove you got it wrong — they only have to show you cannot demonstrate you got it right.
Obligations that fall between owners
Regulatory obligations spread across contracts, jurisdictions and internal policies, each with a different owner and renewal date. What gets missed is rarely the hard one — it is the one nobody knew they held.
Privilege and confidentiality in a shared model
Sending privileged material to a third-party model that trains on it, or logs it, or stores it in another jurisdiction, is a category of mistake that cannot be walked back. Deployment posture is the control, not a vendor promise.
Cross-border data exposure
Loi 25, PIPEDA and internal residency policy all point the same way, and a US-hosted platform carries CLOUD Act exposure regardless of its terms. Anything we host for this sector stays in Canada.
Six workflows where determinism actually changes the outcome.
These are the workflows where a probabilistic answer is a liability rather than a convenience. Each one is compute we can make reproducible, logged, and re-runnable as it stood on any past date.
Hallucination firewall on AI-assisted drafting
Maxor Ground checks a model's output against its sources before a human ever sees it — three independent deterministic checks, not an ML classifier that drifts. A claim with no support does not reach the draft.
Replayable retention and disposition
Retention rules as deterministic compute with versioned policy, so « why was this destroyed on that date » is answered by re-running the schedule as it stood, not by reconstructing it from memory.
Reproducible selection and production sets
Selection logic that produces the identical set on re-run, with the criteria and the version recorded alongside. Completeness becomes something you demonstrate rather than assert.
Obligation register across contracts and regimes
Every obligation with its source clause, owner, trigger and deadline in one register — surfaced ahead of the date rather than discovered after it.
Policy attestation and evidence collection
Attestation cycles with the evidence attached at the moment of signing, so an audit reads a complete file instead of chasing screenshots six months later.
Breach and incident reporting clocks
Statutory reporting windows tracked from the moment of detection, with the decision trail intact — Loi 25 and PIPEDA obligations do not wait for a committee.
The standards we work to.
The compute and the record are our scope, so the standards we cite are privacy, security and evidence-integrity standards — executed inside the firm's or the function's own governance. The legal position, the privilege call and the regulatory interpretation belong to counsel, not to us.
Quebec private-sector privacy law
Referenced as the posture for personal information handled by any system we build or host for a Quebec organization — including the breach-notification clock and the residency expectation.
Federal privacy legislation
The federal counterpart, referenced where data crosses provincial lines or the organization operates nationally.
Trust services criteria
Referenced as the control framing for security, availability and confidentiality of what we host. The organization's own attestation remains its own.
Information security management
Referenced as the posture for how matter data, evidence and deliverables are stored and exchanged on our side of the engagement.
Data integrity principles
Attributable, legible, contemporaneous, original, accurate — plus complete, consistent, enduring, available. The integrity vocabulary we apply to an evidence trail.
Our own non-negotiable
Every engine we ship in this sector is pure, bounded and documented : same input, same output, no hidden state. It is the property that makes a decision replayable years later, and we treat it as a standard rather than a feature.
One capability line of four. We say so plainly.
Three of our four pillars are lifting and rigging capabilities, and they have nothing to do with a legal function. We do not stretch them to fit. The software line carries this sector entirely.
Sealed plans + emergency response
Not applicableNot applicable. There is no crane in a legal or compliance engagement. Lift planning is real engineering work and it is simply not what this sector needs from us.
Distribution + training + implementation
Not applicableNot applicable. CRANEbee® simulates multi-crane operations. No crane, no simulation.
Distribution + advisory + training
Not applicableNot applicable. Murlink® is Dyneema® lifting chain for heavy rigging. Nothing here gets lifted.
Deterministic engineering platform
This is the whole engagement. Deterministic compute on Heisen for retention, disclosure and obligation workflows ; Maxor Ground as the hallucination firewall on any AI-assisted drafting ; Maxor Audit for the signed record ; Maxor Connect where the function needs matter and deadline operations. Hosted in Canada, on infrastructure you can name.
Beyond the four pillars — software built for your operation.
Compliance obligations are shaped by your contracts, your regimes and your risk appetite — no off-the-shelf tool holds that shape. We build the one that does, in Canada, and we make it reproducible.
Heisen — our deterministic intelligence layer — is optional on any build: embed it or not, your call. Either way it plugs into a fresh custom app or your existing third-party software via API.
Obligation graph
Contracts and regimes parsed into obligations with owner, trigger, deadline and source clause — one register that surfaces what is coming rather than what was missed.
Grounded drafting workspace
AI-assisted drafting with Maxor Ground between the model and the document : every claim carries its support, and an unsupported one is blocked rather than flagged.
Replayable decision log
Every automated decision stored with its inputs and its policy version, so it can be re-run exactly as it stood on any past date — the difference between explaining a decision and proving it.
Make the machinery provable.
Tell us the workflow that has to survive an adversarial review. We will scope the deterministic compute under it — and tell you plainly where our scope stops and counsel's begins.


