Proof
This page carries the parts of the argument that are worth nothing unless they are verifiable: what ships and what does not, how the numbers are checked, what leaves the platform and in which format, and where we stand on language models. Nothing here asks to be taken on trust.
Where the line is
This audience checks. So here is the honest state of the product rather than a feature matrix with everything ticked.
Assisted analysis is deliberately not in this column. What runs, what we have committed to build and what comes after are set out in full above.
Numerical accountability
The experimental variogram, the four model types and the kriging system are asserted against independent reference implementations on every release, rotated anisotropy included. Compositing is checked for mass balance. The stages marked next are covered by the same suite as the stages that shipped.
Ask for the test suite during a technical review and we hand it over. We would rather do that than argue about it.
Reversibility
A small team supports this, and it answers. But the question behind the question is what happens if we stop.
That is not a contractual clause. It is what the export buttons do today.
.log or .jsonl.Assisted analysis
Every mining company is having this conversation right now. Our position is that the answer has to be architectural — a policy asking people not to paste a grade table into a chat window is not a control, and everyone in the room knows it.
Model-written Python executes on an isolated machine holding no credentials, on its own private network, one tenant at a time, with a run token minted for that machine alone. Provider keys stay on the server and never reach the browser. The worst case is code reaching data you uploaded yourself, and every run is recorded in the study's graph.
The assistant will work on the structure of a study, never its contents: hole names, coordinates, grades and variable names substituted before anything crosses the boundary, and the mapping never leaving your session. Stated here because a buyer deserves to know our position before the procurement call, not because it ships today.
Grounded in your own studies, routines and standards, with permissions following the data, and actions landing in the graph like any other step. Not a chat window that has read the internet and nothing about your deposit.
Straight answers
Ask for the test suite during a technical review. The experimental variogram, the variogram models and ordinary kriging are asserted against independent reference implementations on every release, rotated anisotropy included. We would rather hand that over than argue about it.
Safer here than in the arrangement you have now, which is people pasting into a chat window. Model-written Python runs on a machine with no credentials, on its own private network, one tenant at a time. The worst case is code reaching data you uploaded yourself. And it lands in the study's graph, so you can read what it did.
Be precise with us and we will be precise back. Part of the work runs on the engine, so the samples reach it; the interaction runs in your browser and reaches nobody. Where the engine lives is a deployment question, and on-premise is a normal conversation.
A small team that answers. Your variogram models leave in the formats your estimation package already reads, your geometry leaves as DXF, and your workflow leaves as a JSON graph. Nothing here is a hostage.
The shortest conversation we have
The test suite, the security model of the runner, the export of a study you bring us. All three are handed over in a technical review rather than described.