Demos

Watch Subsidia at work

Each use, played on sample data with the real screens. Click a step to jump to it. Nothing is stored, nothing is sent.

Understand

How an answer is made

Shield, routing, search in your documents, model, certificate: one step, one sentence.

The engine, live
How an answer is made

Animated diagram: a question goes through eight stations. The shield swaps emails, IBANs and phone numbers for placeholders if the question has to leave; routing keeps the sensitive on your machine and counts the cost; Cortex finds the passages in your documents; the model writes from those passages; references without a real passage are removed; a signed, chained certificate is saved; the real values come back in the answer, each with its source.

The difference

Same question, two answers

A consumer assistant answers with confidence. Subsidia cites its sources, says what it can't find, and lets nothing out.

Security and compliance
The same question, two answers

The same question is asked twice, with a client's real data: a €5,400 invoice, a €2,160 deposit and the client's email address. On the left, a general-purpose assistant: the text leaves as is, email included, for a third-party server abroad. The answer is fluent and confident, but the 12% late-payment rate is made up, with no source, and nothing is recorded on your side. On the right, Subsidia: the question is judged sensitive and handled by a local model, nothing leaves the machine. The answer comes from the documents in the file: €5,400 and €2,160 are highlighted in green with their document. The late-payment rate is in no document: Subsidia says so instead of inventing it. The answer gets a signed proof and a line in the Register. A three-row table then compares sources, data and traceability. Closing line: the same question, an answer you can stand behind.

Use · your team's AI

Take back control of your team's AI

The tools your teams already use go through a single address: sensitive work stays in-house, every call is metered and logged.

The full use case (in French)
Take back control of your team's AI

Four AI tools used across the organisation (Claude Code, Cursor, n8n, an internal assistant) each call their own cloud provider with their own key: nobody knows who sends what. They are then all pointed at a single address, the Subsidia Gateway. A sensitive request, addressed pulse-sensitive, is handled by a local model and never leaves the building. A simple request, addressed pulse-auto, goes to a cloud provider after the email and IBAN are masked. The Console counts the calls of each key, team by team, and the share of calls that stayed local or went external. Every call becomes a row in the AI usage registry, with the model, the data, the date and the person. One address for all your tools. Everything accounted for.

Use · your product

Change one line, every call is proven

Your code keeps its OpenAI or Anthropic SDK; only the base URL changes. Every answer comes back with a signed certificate you can verify offline.

Developer page
Gateway: change one line

In an editor, an OpenAI SDK client changes a single line: baseURL goes from api.openai.com to api.subsidia.protypa.fr, and the key becomes SUBSIDIA_API_KEY. The model becomes the address pulse-auto+cortex and the message holds a made-up name, email and IBAN. The answer comes back as HTTP 200 with the headers x-pulse-proof, x-pulse-provider and x-pulse-pii-masked (2 values masked before leaving for the provider), then the answer text. A proof certificate appears: id, model route, chain position and previous hash, document hash and Ed25519 signature. It is verified offline: hash recomputed, signature valid, chain link in place. One line changed. Every call proven.

Use · your clients

Ship AI to several clients, walled off

One workspace per client, with its documents, agent, key and ceiling. You run it all from one place; nothing crosses between clients.

Become an integrator
Integrators

An integrator deploys AI for two hair salons. Their console lists their client firms: each one is an isolated workspace with its own documents, its own front-desk agent and its own API key. The same question, "Are you open on Saturday?", asked with the first salon's key gets an answer drawn from its opening hours, 8:30 to 17:00; with the second salon's key, an answer drawn from its own hours, 9:00 to 13:00. With the first salon's key, asking for the certificate of one of the second salon's answers returns 404: not found. The second salon's key has a monthly ceiling of 20 questions: at 85 % the gauge turns orange and the integrator gets an alert email; at the ceiling the API answers 402 API_KEY_BUDGET_EXCEEDED. The integrator's overview gathers both firms, their questions this month and the unpaid month. Your clients, each in their own place.

Use · your RAG

Check the RAG you already have

Keep your pipeline. Send the answer and its sources: every claim gets a verdict, with a certificate. No model involved.

The full use case (in French)
Verifier — your RAG, with proof

A developer already runs their own RAG: a retriever (for example Qdrant) and a model that writes an answer from the retrieved passages. They do not replace it. They send the answer and those passages to POST /v1/verify in one call. The Verifier returns a verdict for each claim: verified, unsupported, contradicted or unverifiable. Here the 30-day notice period is contradicted by the passage, which says 90 days, with the quote; no percentage. The response also carries a signed, hash-chained certificate, computed with zero model calls, counted as a control and not as a question. Their application then displays the answer with the result of the check. Keep your RAG, add the proof.

Use · your documents

Your documents, sourced answers, checked texts

Cortex answers from your documents only, and every value points to its source. The Verifier checks any text against those same documents.

The full use case (in French)
Cortex · The Verifier

Three documents of the Dupont lease file are dropped into Cortex: each is read, split into passages and indexed, on the local machine. We ask for the rent, the deposit, the notice period and the building insurance. Cortex searches by exact words and by meaning, then answers: each value is highlighted in green and tied to its passage (lease, amendment). Insurance is in none of the documents: the answer says so and does not assert it. Then the Verifier checks a text written by another AI tool, with no model: one claim is verified, one is contradicted by the amendment (18,600 and not 19,200), one is unsupported (indexation on the ILC), one is unverifiable (an opinion, which is not a defect). No score, no rewrite. Closing line: your documents have the last word.

Use · repetitive work

Roles that work on their own, nothing leaves without you

An agent has a job description and its sources. An automation triggers it; every outgoing message waits for your approval, word for word.

The full use case (in French)
Roles and Reflex

A job-role agent called "Accueil" (front desk) states its mission, the folders it may read, its skills and what it will never do, including sending an email without approval. A client writes to ask the amount of the year-end accounts fee. The automation fires: the email is read, Cortex is searched, the agent drafts the reply and cites the 2026 engagement letter for the amount of 1,450 euros excluding tax. The run stops at the "Approve the reply" step: the exact email waits for a person. After a click on "Approve and send" the reply goes out and the approval is logged in the audit trail: who, when, and the fingerprint of the exact email. Your agents work. Nothing leaves without you.

Understand

Where your data goes

What stays in-house, what leaves masked, what comes back with its proof.

Security and compliance
Where your data goes

Animated diagram: a boundary separates your premises (team, documents, Subsidia, local machine, proof) from the outside (an external AI provider). Journey 1: a sensitive request is handled entirely in-house, nothing crosses the boundary. Journey 2: a simple request leaves with the email masked, comes back, and the real value is put back in-house; the certificate stays in-house. Journey 3: documents, their passages and the index are always stored in-house; by default the vectors are computed on your machine. If you chose an external provider for indexing, passages leave masked and only numbers come back. Certificates and register stay in-house. You always know what leaves, and what doesn't.

Use · on your premises

Run AI on your own machines

A second machine shows up on its own; you admit it and the load spreads. Nothing leaves the building.

The full use case (in French)
Console · Machines

One machine runs Subsidia with a local model; requests pile up in a queue. A second machine plugged into the same network shows up on its own as a candidate (mDNS discovery). An administrator admits it. From then on each whole request goes to the least busy machine, never split across two machines, and the queue empties. When one goes down, its requests move to the other. Nothing leaves the building.