Conclusion: the accelerator is the team’s command over the substrate; and no decision here is taste: the choice is written down, with what was discarded and why. The pyramid below is the map; the gap stays outside it, stated.
What SazAI is
Engines, components and documentation, mastered by whoever built them
SazAI is the platform: the intelligence and proof substrate the products are built on. Multi-tenancy, authentication, lineage, orchestration, agent layer, exact metering, and versioned decisions, built once. SazAI Corpus, the vault, and the design system are the products that have already come out of it, and each one uses the same engine instead of rebuilding it.
The panels descend by anchor strength, and each one closes with its references in an expandable block, for whoever wants to check. Citations follow the ABNT NBR 6023 standard, 2018.
It is not plug and play for someone arriving from outside. The accelerator is not the substrate; it is the team’s command over it. Whoever knows the engines, the components and the documentation builds a new SaaS product from what already exists, and the rest of this page is the measure of how much that shortens the path.
The frame for this idea is not new, and not from this page: it is the eighth of the nine pillars SazAI describes itself with, platform before product. What follows is its evidence.
The engine depends on format standards to exist
Step 1 · execution dependency, the strongest anchor there is
If the standard were wrong in the code, the engine would not run. The reference is not mentioned; it is depended on, and determinism comes out of that.
Data and facts:
- OOXML namespace in the engine: 237 occurrences across 37 distinct forms (2026-09-01).
- Dublin Core as a dependency: 22 namespaces. ISO 8601: the most cited standard in the database, 60 occurrences.
- The checkable chain: published clause → DDL column comment → data map → column. Paraphrase forbidden by written rule; DDL and map carry the same clause, verbatim.
And the next format costs less
The first format was PowerPoint, and it cost the whole engine: reading, measuring, translating, writing back, comparing, all for the first time. The second, the Word document, cost one order of magnitude less. The third, the spreadsheet, one more. And the fourth, PDF, cost the same as the third: the curve stabilized. It is not a list of achievements; it is a curve, and the curve is the argument.
The PDF is the first substrate that is not Office: a binary graph of objects instead of zip plus XML. If the engine had only gotten good at PowerPoint, the fourth format would have cost like the first. It cost like the third. The engine did not get faster at PowerPoint; it became format-agnostic, and the four formats run today on the same architecture, each with its own declared guarantee. That is why the fifth will cost what the fourth cost, and that is what this page calls acceleration.
Where this is recorded, stated before you ask. In git, not in the institutional diary: the curve rests on dated decisions and commits, which are the right source for an interval, and that is what gets checked in an evaluation. The absolute times for each format live in the technical document, with the command that derives them next to it.
References and recorded decisions
What is written, and what was discarded
- Read each format by the standard, clause by clause; the heuristic was discarded because it does not survive an audit.
- Dates in ISO 8601 across the whole system; metadata by Dublin Core.
- PDF accepted as the first non-Office substrate, cited by its own standard.
References (ABNT NBR 6023:2018)
- ECMA INTERNATIONAL. ECMA-376: Office Open XML File Formats. Available at: https://ecma-international.org/publications-and-standards/standards/ecma-376/.
- ISO/IEC. ISO/IEC 29500: Office Open XML File Formats.
- ISO. ISO 32000-1: Portable Document Format. · ISO. ISO 19005: PDF/A.
- ISO. ISO 15836-1: Dublin Core. · ISO. ISO 8601: Date and time.
- IETF. RFC 5646: Tags for Identifying Languages.
- MICROSOFT. MS-PPTX · MS-DOCX · MS-OE376 · MS-ODRAWXML · MS-OFFCRYPTO: implementation notes.
- UNICODE CONSORTIUM. Unicode CMap specifications.
The body of knowledge
Everything we decided, measured, and wrote, linked, and navigable by the team and by agents
The team’s command over the substrate has a place where it lives: an Obsidian vault that mirrors the repository. Decisions, the data map, agent contracts, personas, strategy, working sessions: each note links to the others, and hubs are the doors a person or an agent enters through. It is the same graph the product delivers to the customer in their own vault, used first on ourselves. Below, ours, in motion; hover a hub to see what it links, and click to open it in full.
How far the map reaches, measured, and it is the part worth most. The vault graph reaches 55 of the 158 data-map tables and one of the five format maps; the repository reaches 158 of 158. A figure that showed everything connected would be this page's only claim with no receipt behind it, on a page whose whole subject is that our claims carry receipts. What is validated is not that everything connects: it is that we know exactly what connects and what does not. Where the map is silent, the repository answers.
Data protection is design, and design gets audited
Step 2 · the law became schema, and the schema is checkable
What the law asks for in writing, the database fulfills through structure. Verification is not reading our policy; it is auditing the schema.
Data and facts:
- Permanent storage carries no document content; content lives in a separate database, sensitive and erasable.
- Isolation by tenant as a column, not as a promise: slices never cross tenants.
- Certification today: none. Controls designed to serve as evidence when it is sought.
References and recorded decisions
What is written, and what was discarded
- Privacy by design and by default as architecture; a compliance layer over a shared database was discarded.
- Removal is called withdrawal, not deletion: the stronger word was discarded because it promised a reach that backups do not sustain.
References (ABNT NBR 6023:2018)
- EUROPEAN UNION. Regulation (EU) 2016/679 (GDPR), art. 25.
- BRAZIL. Law No. 13,709, of August 14, 2018 (LGPD).
- CAVOUKIAN, Ann. Privacy by Design: the 7 foundational principles. Toronto: IPC, 2009.
- ISO/IEC. ISO/IEC 27001. · OWASP FOUNDATION. Available at: https://owasp.org/.
Accessibility is measured, not declared
Step 3 · a cited standard is compliance; a measured number is design
The criterion lives in the component, with the number next to the code, and contrast is measured before a color enters the system.
Data and facts:
- WCAG 2.2 AA across 51 design-system files, with criteria cited by number (1.4.1, 3.1) (2026-09-01).
- Contrast measured per token:
--hue-lineageat 4.00 with the note guide, never text written inside the token itself;--text-faintfailed for measuring 2.56 on white, and the failure recorded. - Color blindness measured: the purple evaluated under deuteranopia, color distance ΔE 29.1.
- Zero architecture decisions record WCAG; the house’s strongest accessibility anchor is invisible in the decision record, and recording it is work still to do.
The design system is a product, built on an open standard
Step 4 · the accelerator for the other surfaces, in W3C standard
The design system is a SazAI product by ratification (2026-08-26), with the function of accelerating the others: the components that serve marketing, the vault and the showcase are the same ones, and they are open standard, not a proprietary framework.
Data and facts:
- Components built on W3C Custom Elements and CSS Custom Properties; no framework dependency.
- One library, three surfaces served; light and dark themes and white-label skins through the same token mechanism.
- The tokens carry their own measurements and usage notes (step 3), so the rule travels with the color.
References and recorded decisions
What is written, and what was discarded
- Criterion by number in the component that fulfills it; the central policy page was discarded.
- Word out of design: text in HTML, geometry in SVG.
References (ABNT NBR 6023:2018)
- W3C. WCAG 2.2: Web Content Accessibility Guidelines, level AA. Recommendation, 2023. Available at: https://www.w3.org/TR/WCAG22/.
What is written, and what was discarded
- Standard Web Components; the proprietary framework was discarded so white label would not depend on a license of ours.
- Held to the same standard as any surface: a suite that runs, guards that refuse at build.
References (ABNT NBR 6023:2018)
- W3C. Custom Elements (HTML Living Standard). · W3C. CSS Custom Properties for Cascading Variables.
Channels are capability: API and MCP change what the product can be
Step 5 · open standards at the door, and what they enable
Open API and MCP are not plumbing: they are what allows other interfaces and connections to be built on the same substrate, without us in the room. A third-party agent, a dashboard of your own, a workflow integration: the product becomes able to be those things because the channels exist.
Data and facts:
- The agent channel is a standard OAuth resource server: 401 with no credential, discovery published.
- Parity as contract: MCP ⊆ OpenAPI, everything MCP exposes exists in the open API. One substrate, several readers.
- Orchestration by a durable workflow execution tool, adopted for what it guarantees, and the guarantee is measured: dead work leaves no partial state; overload degrades into a queue, it does not break; nothing fails silently.
References and recorded decisions
What is written, and what was discarded
- Authentication and discovery by the RFCs; a custom convention was discarded.
- A new channel does not invent a new surface: the parity rule keeps MCP from becoming a second API.
References (ABNT NBR 6023:2018)
- IETF. RFC 8414: OAuth 2.0 Authorization Server Metadata. 2018.
- IETF. RFC 9728: OAuth 2.0 Protected Resource Metadata. 2025.
- IETF. RFC 8707: Resource Indicators for OAuth 2.0. 2020.
- OPENAPI INITIATIVE. OpenAPI Specification. Available at: https://spec.openapis.org/.
- ANTHROPIC. Model Context Protocol (MCP). Available at: https://modelcontextprotocol.io/.
How we validate
Tests that refuse, audit with method, and defects published next to what passed
Validation has four layers, and the order matters. Tests: 505 test files in the repository, with the design-system suite running on every build. Guards: checks that refuse at build time in place of only reporting; a build that violates a rule does not ship. Load: the test of 2026-07-20, on a faithful production replica, with 50 concurrent reads answered in 0.77 s, a heavy job peaking at 4.71 GiB against a ceiling of 5, and waves of five and ten jobs with zero failures, zero memory overruns, zero corruption. Under overload the system enters a queue; it does not break. Internal audit: dated stress, destruction, and security reports, with a verdict per item.
We are not SOC2 or ISO certified. What we have is documented internal audit, with a declared method and with the defects it found published next to the ones it passed. One of our reports carries, as its own sections, defects found, a false positive I almost published, and what I could not establish. A seal is a third party's word; a declared method, the technical reader judges alone. And the written decisions are designed to serve as control evidence when certification is sought.
What this page cites and what it does not cite. Here is the existence of the reports and their method. The item-by-item verdicts live in the technical document that accompanies an evaluation, because publishing the probe list with results at the top of the funnel hands a map to whoever should not have one. The phrase the load test does not authorize: fifty concurrent. It is fifty seats and one heavy job at a time; confusing the two is the error this page exists not to make.
References and recorded decisions
External methodology declared for the testing axis: none. Strong practice, guards that refuse at build, dated reports; the source of method is internal, and saying so is part of the method.
How we decide
Written, dated decisions, and a supersession that strikes two sentences and nothing else
Every SazAI architecture decision is a dated document, with the context, the rejected alternative and the reason. There are 61 as of this page’s date, and the number enters dated because it grows; the command that derives it is in this panel’s references. What makes this a receipt and not a dead file is the supersession: when a new decision contradicts an old one, it states exactly which sentence of the old one stops holding, and the old one gets the mark in its own body, on the sentence, and not on the title.
The most recent example is from yesterday. Decision 023 fixed, among other things, the vocabulary the user names the product’s capabilities with. Decision 061 superseded two sentences of it, both about vocabulary, and left everything about the engine intact, including the clause believed violated that was not. Three competent readers had read that clause the same wrong way, and the decision records all three names, because a decision that keeps only the conclusion loses the reason three people got it wrong together.
A number this page does not publish. How many of these decisions are accepted depends on which words the counter admits into the state field, and five competent counters reached five different numbers this week. Nobody was wrong: the field never declared its own vocabulary. We publish the dated count, with the command next to it; the accepted count only goes public when it comes with the command that produces it next to it, the way the 158 tables already do.
And how we write: an internal contract, one step down for honesty
Step 6 · recorded internal coherence, one step below external standard
Writing style, naming, and house conventions live in a versioned contract that agents cite. Its anchor is internal coherence with a recorded decision, not a numbered external standard; that is one step below the previous ones, and stepping down proves this page’s hierarchy applies even when it costs something.
Data and facts:
- A single writing standard, versioned by revision, cited by decisions and by agents as contract.
- Naming and name conventions uniform across the whole system; a cited standard is never paraphrased.
- Formatting, lint, and secret scanning automated, declared in the standard with the source next to them.
References and recorded decisions
What is written, and what was discarded
- The count:
ls docs/corpus/pptx/tech_specs/ADR | grep -c '^ADR-'returns 61 on 2026-09-01. The number grows; the command does not. - The naming alternatives were rejected by convergence across three surfaces, and the rejection is recorded with the reason.
References
the internal contract (`code_standards`, versioned) names its own sources; this page does not paraphrase it.
The internal contract (code_standards, versioned) names its own sources; this page does not paraphrase it.
What is a receipt, and what is still practice
Four capabilities with evidence; three declared, with no verb in the present tense
Every capability on this platform was put through three questions: is there a written decision that governs it? is there a measurement? or does it just work, with nobody having written why? What passes the first two we call receipt. The rest is practice, and it stays declared as direction, the same way the roadmap below declares what does not exist yet. A page that presents seven capabilities where three are receipts is weaker than one that presents four.
Receipt
Declared practice
The four on the left have somewhere to be checked, and the following chapters say where. The three on the right are where the platform is going, and none of their verbs is in the present tense.
And the market: studies with the caveats attached
Step 7 · anchors where we play, not how we build
This step supports positioning, not engineering, and that is why it is last: it is the weakest anchor on the page, and it is labeled as such.
Data and facts:
- Seven houses: Gartner, BCG, McKinsey, Deloitte, Menlo Ventures, MIT NANDA, Stanford HAI.
- Caveats built into the entries themselves: preliminary called preliminary (MIT NANDA, n=52); republished called republished (Stanford/McKinsey); a regional slice called regional (Deloitte, EMEA).
- BCG’s 79% proves the obstacle, ungoverned unstructured data; it does not prove the bridge.
- Executive survey research is perception, not audited financials.
References and recorded decisions
What is written, and what was discarded
- Platform before product; buy before build.
- On Shadow AI, only the citable form: reduction through a governed corporate path. "SazAI solves Shadow AI" was discarded for having no measurement to support it.
References
the full entries in ABNT NBR 6023:2018 form are in this page's blocks; of the 25 in the inventory, the ones consulted online carry Accessed on, as the standard requires, and the rest do not, as the standard permits.
Roadmap: what we are building
The roadmap holds the big directions, the ones the platform points toward and has not built yet. When a piece leaves here, it disappears from this list and appears on the page for the matching capability, with the date. A roadmap that moves is the only proof of pace that cannot be written with an adjective. Nothing below has shipped, and no item here should weigh on your decision today. Nothing on this page has shipped. No item here should weigh on your decision today, and nobody on our team should present any of them in the present tense. What has shipped is in the product walk, with what it guarantees, and the limits of what exists are in trust.
Redline and negotiation intelligence
Comparing a draft against the parties’ revisions, showing what each side changed, where the risk shifted, and what intent the text reveals. The comparison engine that underlies this already exists and runs today over document versions. What is missing is the legal layer: understanding that an altered clause is not just a different paragraph.
Why it is on the roadmap and not on the road: it is the direction with the greatest potential to create its own category, and that is exactly why it is the easiest to sell too early. It does not exist.
Specialized agents over your corpus
Agents with their own scope, built on the knowledge already in your vault: a tutor that teaches from your company’s real material, an adoption companion for a new process, an evaluator that checks competence while citing the source it used.
What already stands underneath: the corpus, lineage, the conversational agent, and source citation. What is missing: task-level specialization, with its own limits and rules per agent.
Substrate for a fleet of governed agents
The next step from the previous one, and the widest-reaching. Each part of the company feeds the vault with its own documents, and the agents that part already uses consult that vault at runtime, by file or by protocol, for any question about the company. One governed source underneath an entire fleet, instead of loose AI tools that nobody audits.
Why this is roadmap and not a vague promise: the adoption mechanism is concrete and already exists in part, because the vault is portable and consumable from outside. What is missing is fleet governance, and it is not built.
Things that exist and that we still cannot show you
These are evidence gaps, not missing features. The capability is there; the public proof is not, and until it is we would rather list the gap than talk around it.
- Demonstrated vault export. The vault exists and is plain text with links; what is missing is a published demonstration that anyone can reproduce without talking to us. Until then, it is a due-diligence conversation, not a page item.
- Sufficiency of the record for formal audit. The record exists and serves as control evidence. Whether it closes a specific audit requirement in your sector is a question we answer case by case, not a page claim.
- Scale above what we measured. Volumes in the hundreds of thousands or millions of documents have not been exercised. That is a sizing project before it is a purchase.
Things that do not exist yet
These are missing features, and filing them anywhere softer would tell you they are there and we just cannot show them. They are not there.
- Faithful visual verification. The system measures structure and counts elements; it does not look at the final page. A visual checker inside the product does not exist.
- Deletion that reaches backup copies. Today deletion is complete in live systems and does not reach backups within the retention window. The technical path is defined and not yet built. The exact scope is in privacy and sovereignty.
- Remove the content and deactivate the account, in one action through the interface. Today document deletion exists and takes derivatives with it; doing this all at once does not exist yet, and closure is handled on request. The name is deliberate: it erases the content and deactivates the account, because the trail of who accessed the system remains.
How this page is maintained
An item leaves here when it exists and has been measured, not when it is almost ready. When it leaves, it enters the capability page with what it guarantees and where it stops. If you follow SazAI for a while, this page is where the pace shows.
Where the boundary passes
Three limits a technical reader tests first, stated before the test
The provider boundary. Lineage follows each piece of text until it leaves for the language model and picks up again when it returns. None of our tables records what happened on the other side; whoever asks prove what they did with my text inside the model receives the retention terms of the provider they contracted, and in an installation of your own the provider is your choice. The page on sovereignty says where that stops.
The copyleft license exclusion. No AGPL library enters the engine, and that is written in the dependency file as a documented project decision. It is a comment, not a gate: nothing breaks the build if someone ignores it. Saying so is stronger than pretending it is a gate, because whoever opens the file sees it in ten seconds.
The agents. This system is built by a team of agents with declared scope and a review chain, and the communication between them is practice, not receipt: there is no written decision that governs the channel, and its failure modes were measured by us this week. It sits on the right side of the ledger, and that is where it is going.
Everything this page states has a command or a document behind it, and what does not is stated as direction. If something here cannot be reproduced in your own evaluation, that is a defect of ours and we want to know before you do. The product that came out of this platform first is what you see when a document comes in.
What this pyramid does not hold up
An honest pyramid says what stays outside it.
Data and facts:
- Five doctrine references in zero engineering artifacts: W3C PROV · ZAHARIA et al., compound AI systems (BAIR, 2024) · XU et al., GraphRAG (SIGIR, 2024) · model routing literature · CommonMark/GFM. They shaped the thinking; no recorded decision came out of them.
- Tests: strong practice, guards that refuse at build, dated reports; external methodology declared: none. Said in those words, with no plausible neighbor.
- And the finding that holds up the whole conclusion, measured across the decisions with an alternative in the header: in eleven of eleven, what decided was an engineering principle, not an external reference. The standard supports; the choice is ours, and it is written down.
Figures measured on 2026-09-01 over sets that grow: whoever repeats the measurement tomorrow should expect larger numbers, not the same ones.