Five sectors. Chosen because we have shipped in them, not because the list looks better long.
A new firm claiming depth across twelve industries is claiming depth in none. These are the five where the founders have production experience and where we can name the constraint before you explain it to us.
- sectors
- 5, deliberately
- first question
- Never technical
- outside these
- We'll say so
In every sector, the binding constraint is a rule, not a technology.
The architecture falls out of the constraint once you have named it correctly. Getting that first step wrong is what produces systems that are technically sound and legally unusable.
Healthcare
PHI cannot leave systems you can audit.
Clinical and billing systems integrated over fifteen years, where the interface engine is often the only thing holding the record together and nobody currently employed configured it.
- HIPAA
- HITECH
- 42 CFR Part 2
- HL7 / FHIR
Which systems touch PHI, and which of those are covered by a current business associate agreement?
Systems we expect to find
- EHR (Epic, Cerner, athena)
- Interface engines (Mirth, Rhapsody)
- Practice management
- Imaging / PACS
What we do differently here
- BAAs executed before any vendor touches PHI, including model providers — and confirmed in writing, not assumed from a marketing page
- Retrieval scoped to the requesting clinician's existing chart permissions, carried per-query rather than granted to a service account
- Interface engine inventory completed before any migration is scheduled, because the HL7 feeds are what break
- Audit logs written somewhere that survives the vendor relationship ending
Finance & Fintech
Every change needs an auditable approval trail.
Core banking and payment paths where the binding constraint is not uptime — it is proving, months later, who approved what and when, to somebody who was not there.
- SOX
- PCI DSS
- GLBA
- FFIEC
- SOC 2
When an examiner asks who approved the last production change, where does that evidence come from?
Systems we expect to find
- Core banking platforms
- Payment gateways
- Loan origination
- Data warehouse / reporting
What we do differently here
- Change management wired into CI so the audit evidence is a build artifact rather than a screenshot someone remembers to take
- Cardholder data environment scoped down with tokenization before money is spent hardening it
- Model outputs logged alongside their inputs and prompt version, so adverse-action decisions stay explainable
- Segregation of duties enforced in IAM, not asserted in a policy document nobody reads
Legal
A retrieval must never cross a matter boundary.
Document sets where a single passage leaking between matters is a malpractice exposure and a client notification, not a bug report.
- Attorney-client privilege
- ABA Model Rule 1.6
- Client outside counsel guidelines
Are your ethical walls enforced by the document system, or by everyone remembering where they apply?
Systems we expect to find
- Document management (iManage, NetDocuments)
- Practice management
- eDiscovery platforms
- Time and billing
What we do differently here
- Ethical walls enforced at the index level, so a wall cannot be bypassed by phrasing a prompt differently
- Matter-scoped retrieval with the requesting user's identity carried end to end
- Privilege review workflows that keep a human on the final call, with the model narrowing rather than deciding
- Retention schedules applied to embeddings and derived indexes, not only to the source documents
Retail & E-commerce
The year is decided by six weeks of traffic.
Storefronts and fulfilment paths that must absorb a 20× spike without a re-architecture scheduled two weeks before it arrives.
- PCI DSS
- CCPA / state privacy
- ADA / WCAG storefront
What broke last peak, and has anything changed since other than hoping it won't recur?
Systems we expect to find
- Commerce platform
- OMS / WMS
- Payment and fraud
- Marketplace integrations
What we do differently here
- Load modelling against last season's real traffic curve, including the spike shape rather than the daily average
- Checkout path isolated so a catalogue or search incident cannot take payments down with it
- Payment scope reduced through tokenization before hardening spend is committed
- Freeze windows and rollback rehearsed ahead of peak, not improvised during it
Manufacturing
The plant network was never meant to meet the internet.
Shop-floor systems where an hour of downtime carries a known dollar figure and the controls predate the security model now being wrapped around them.
- IEC 62443
- NIST 800-82
- CMMC (defense supply chain)
What is an hour of unplanned line downtime worth, and who currently decides when the plant network changes?
Systems we expect to find
- SCADA / HMI
- PLCs and historians
- ERP (shop floor integration)
- MES
What we do differently here
- OT/IT segmentation designed with the controls engineer in the room, not inferred from a network diagram
- Read-only telemetry paths off the plant floor established and proven before any write path is discussed
- Predictive maintenance validated against your own recorded failure history, or declined if that history does not exist
- Patch windows planned around the production schedule, never the other way round
Most of what we do is sector-agnostic. Say which one you are in and we will tell you honestly whether it matters.
Cloud migration, modernization, and day-two operations look broadly the same in professional services, education, or non-profits. Where a specific regulator or a specific class of system is central — clinical trials, defense contracting, gaming — domain experience matters a great deal, and we will tell you if we do not have it rather than learning on your budget.
Bring the constraint. We will bring the architecture.
The assessment starts with your regulatory and operational limits, not with a technology recommendation. It is the only order that produces a plan you can actually deploy.