Analysis & evidence
This section covers how FACE turns a customer’s operational data into findings,
evidence documents and recommended actions. It also covers what each output does
not establish. It is written for evaluators who need to decide whether those
outputs can be trusted, so every statement here is taken from the backend code and
its protobuf contract (semantics.v1), and names the RPC, field or variable it
describes.
Two rules that shape everything here
Sovereign inference only. Every text, vision and embedding call goes to an OpenAI-compatible model plane served inside the customer’s own cluster. FACE never calls a third-party LLM API, and it ships no model server of its own. If the plane is not configured, FACE refuses to start instead of running with nothing behind it. See Sovereign models.
Determination is separate from expression. Any output that a third party might act on, such as an evidence document or a remediation order, is built in two layers:
- Determination is fixed arithmetic over cited records. No model is involved.
- Expression is optional prose that a model may draft, but only after the determination is frozen.
The contract states it in one line: the model never decides what is true; it only phrases what was decided. See Evidence documents.
The pipeline at a glance
flowchart LR
A[Connected sources] -->|allowlisted reads| B[Extract & profile]
B --> C[Cluster & EDA<br/>HDBSCAN · Prophet/ARIMA]
C --> D[Phase 1<br/>posture + rules]
D --> E[Phase 2<br/>hypothesis swarm]
E --> F[Phase 3<br/>twins decision]
F --> G[Judging ladder]
G --> H[Action cards +<br/>evidence documents]
H --> I{Operator<br/>approve / reject}
I -->|approve| J[Seal chained into<br/>append-only lineage log]
K[(Tenant corpus<br/>Comet)] -.grounding.-> D & E & F
Pages in this section
How to read the limits
Every page ends with a What this does not establish note. Throughout the contract,
FACE puts the difference between “measured zero” and “not measured” on the wire, not in
prose. You’ll see this in fields such as EvaluationMetrics.unmeasured_reason,
FetchAnalysisResult.hypothesis_swarm_ran, AbsentFigure.reason,
IngestSurveillanceFeedResponse.detection_note and
AnalyzeEstateCausalResponse.answered. A client that shows a number should read its
companion field first.
Connecting sources is covered in Data sources. Transport, identity and at-rest encryption are covered in Security. Full message definitions are in the API reference.