Skip to main content
trust · in plain english

proof, not promises

What we can show today. What we are not yet. Nothing in between.

mana receipts

the receipt is the proof. every run gets one.

A Mana Receipt is the legible record of one thing an agent did: the sources it used, the assumptions it made, who reviewed it, and a hash that seals the trail. It is the document your board, auditor, client or insurer can actually read.

where answers come from

aprimary sources

NZ legislation, gazette notices and official government guidance, ingested on a schedule. When an answer turns on the law, agents cite current NZ legislation with the retrieval date on the citation.

bknowledge base

Sector guidance and assembl-maintained playbooks — versioned, sourced, and shown as citations so you can see where a draft came from.

cworkspace data

What you bring to your own workspace, plus clearly-labelled demo data in pilots. Always marked so it can never be mistaken for a primary source.

Citations in agent replies carry their tier, so a statute and a playbook never look like the same kind of evidence. Where retrieval is not wired for an agent yet, it says so — it never invents a source.

privacy act 2020 · ipp 3a

IPP 3A came into force on 1 May 2026: when personal information is collected indirectly, people must still know. assembl is designed to align with it — agents are disclosed as agents, indirect collection is flagged, and the receipt records the trail. Alignment is a design posture we can show, not a certificate we hold.

  • aligned with the Privacy Act 2020, including IPP 3A (in force 1 May 2026).
  • every output is a draft a named person reviews before it ships.
  • data hosted in Sydney (AWS ap-southeast-2, Supabase) — an NZ option is the goal; until then, Sydney is the honest answer.
  • not SOC 2 certified. We will pursue SOC 2 Type II when the enterprise pipeline justifies it — posture at /trust/soc2.
  • not ISO 27001 certified. Same reasoning, same honesty.
  • not HIPAA certified — HIPAA is a US framework; we run under the NZ Health Information Privacy Code.

The detailed posture, sub-processors and change log live on /trust/soc2 and /mana-receipts. Te Tiriti statement: /te-tiriti.

request the security pack

The audit pack — architecture, data flows, sub-processors and the current posture — for teams doing due diligence.

Less admin. More mahi.