Skip to content

Artificial intelligence that does not take your documents away

Most systems advertising artificial intelligence today solve the problem by sending your documents to someone else’s server. For a public body holding restricted information, that is not a feature: it is a leak.

Orpyca does the opposite. The model can run inside your own infrastructure, without a single byte leaving the institution. And if you choose an external provider for material that is not sensitive, the system enforces a boundary that cannot be switched off.

Search by meaning, not by exact wording

You ask “what did we answer about the village street lighting” and the system finds the records dealing with the matter, even if none of them uses those words. The index feeds itself: every time a document is registered it enters the search without anyone having to reindex anything.

Precedents with the citation attached

Before answering a right-of-petition request, the system shows what the institution has answered before on the same matter, with the registration number and date of each precedent. It is not a summary you must take on trust: it is a list of sources you can open.

An assistant that acts with your permissions, not its own

The conversational assistant has no privileged account. It works with the token of the user talking to it, and every operation it attempts goes through role and clearance checks again. If you cannot see a case file, neither can the assistant, and no amount of persuasion changes that.

The whole system, available to agents

Orpyca exposes its operations as tools for artificial intelligence agents: register a document, look up a record, search, open a case file, view its index, list the retention schedule, review the processing inbox and consult the inventory. Each user only sees the tools their permissions allow.

The sovereignty boundary

This is the part worth reading carefully, because it is the difference between a system you can use in a public body and one you cannot.

Restricted material never leaves

Material classified as restricted or above is never sent to an external provider. It is not a configuration checkbox a distracted administrator could untick: the checkbox does not exist. If the context of a question includes restricted material, that material is excluded and the answer degrades to plain retrieval, saying so.

Permissions apply before the model

Clearance filtering happens server-side, before anything reaches the model. The model never receives documents the user could not open themselves, so it cannot leak them by accident.

There is a record of who processed what

Every generation records the provider and the model that produced it, in separate columns and with its entry in the audit trail. Six months later you can state precisely which provider received a given query.

No invention when it cannot answer

If the artificial intelligence provider is not configured or does not respond, the system returns an explicit error. It never fabricates a plausible answer to disguise an unavailable feature.

You choose where the model runs

The artificial intelligence layer is pluggable. The default configuration is the sovereign one: everything inside your infrastructure.

Local, on your own server

The semantic representation model runs inside the container itself and the generative model on a model server you host. No data leaves the institution. This is the default.

No generative model

Semantic search and cited precedents only, without automatic drafting. It is the lightest option and the one demanding the least hardware.

External provider

For public material, if the institution so decides. The classification boundary still applies and admits no exceptions.

How much does the artificial intelligence in Orpyca cost?

Nothing. It is included in the software, which is free and open source.

All you need is the hardware to run it on, and the figure is worth stating plainly: search by meaning and cited precedents work on the minimum server, with no graphics card. The conversational assistant does need one — from 8 GB of video memory for the default model, and 24 GB if you want a model that drafts regulatory language well.

It is a one-off investment and the equipment is yours. Set against a per-user monthly subscription, a card pays for itself in months and is still there the following year.