AI your risk, finance and compliance teams can put their name on. Verified numbers for regulatory reporting, credit decisioning, disputes, financial crime and model risk.
industriesfinancial services
AI your risk, finance, and compliance teams can put their name on.
Your agents already answer questions about filings, credit decisions, disputes, and alerts. Xorq is the verification subagent they call before the answer goes anywhere: it runs the numbers as real queries on your governed data, records the lineage, and holds the result until a named person signs.
The same five jobs, in every institution. Each one ends with human approval.
The hard part is not getting an agent to answer. It is getting an answer a controller, an investigator, or a model validator will sign, and an examiner can reopen a year later. Each job below shows what that takes today and what it looks like as a Ledger entry.
01regulatory & financial reporting
“Is the number in the filing the same number treasury computed at close?”
controllerregulatory reportingtreasury
today
Figures are assembled from extracts and spreadsheets, reconciled by hand, and attested on the strength of tick marks. When a definition changes, last period cannot be recomputed on the new basis.
with xorq
Each reported figure is one expression run on the warehouse. Period-over-period variance uses the same definition. The controller signs the Ledger entry; the filing links to it, and any period reruns on demand.
“Show me how this decision was made, and give me the reason codes.”
chief credit officermodel riskfair lending
today
The decision log, the model version, and the feature snapshot live in three systems. Reason codes are reconstructed after the fact, and the reconstruction is what the examiner sees.
with xorq
The decision record carries the model version, the feature definitions, the input rows, and who promoted the model. Reason codes are derived from the same lineage, so the adverse action notice and the audit trail agree.
▸reason codes · derived from lineageDTI · utilization · tenure
03consumer disputes & data accuracy
“Is this tradeline accurate, and what exactly did we check?”
consumer operationscompliancefurnisher relations
today
Investigators pull from several furnisher feeds under a fixed deadline. The record of what was checked is a free-text note, and a reinvestigation starts from zero.
with xorq
The agent’s investigation runs as queries over furnisher data and file history. Every statement in the response letter links to the row and version it came from. The investigator signs, and a reinvestigation replays the same steps.
dispute · D-44821 · tradeline ····4471day 9 of 30
Claim: account reported 60 days delinquent in June; consumer states it was paid. Furnisher data as of 2026-09-01 shows the account current since 2026-05-281; the June delinquency was reported on 2026-06-04 and retracted by the furnisher on 2026-06-192. The retraction was not applied to the file3. Correction: remove June delinquency; 24-month history shows 0 late payments1.
1furnisher.feed · F-2201 · payment_history · version 2026-09-01ledger
2furnisher.corrections · 2026-06-19 · retraction record R-9931ledger
3file.apply_log · no entry for R-9931 · gap flagged to furnisher opsledger
“Why was this alert escalated, and what evidence supports the narrative?”
aml investigationsfraud operationsbsa officer
today
Agents draft narratives quickly, but every cited transaction has to be re-verified by hand before anything is filed. The speed gained in drafting is lost in checking.
with xorq
Each figure in the narrative traces to the transactions and KYC records it was computed from, at a version. The investigator signs once, and the narrative and its evidence are one filing-ready object.
case narrative · alert A-30917draft · awaiting sign
Between 2026-07-02 and 2026-08-15 the account received 14 inbound wires totaling $412,3001 from six counterparties in three jurisdictions2. Eleven were between $9,000 and $9,9001. Stated occupation at onboarding was retail employee, with expected monthly inflow under $6,0003. Funds left within 48 hours in each case1.
signpending · S. Rahman · financial crime investigatorledger
05model risk management
“Which models are in production, on what data, validated when, and by whom?”
model validationinternal auditsecond line
today
The inventory is a spreadsheet maintained beside the systems it describes. Validation evidence is scattered, and reproducing last year’s result depends on the original developer still being around.
with xorq
The inventory is the Ledger. Promotion, sign-off, and rollback are human commits with names attached, and any figure a model produced reruns from versioned inputs without the developer in the room.
model inventory · productionfrom the ledger, not beside it
Your agents keep their jobs. Xorq checks their work.
Xorq is not another agent framework. It is a subagent your existing agents call when an answer contains a number, and a Ledger that keeps what it finds. The controls your second line asks for are produced as a side effect of running.
01The agent asksAny agent, on any model behind your subscription, hands Xorq the question and the figures it intends to report.
02Xorq runs it for realThe figure is recomputed as a query on governed tables in your warehouse. Ungoverned sources fail at compile time with the source named. Query, versions, and result are written to the Ledger.
03A person signsThe result waits at a gate. The agent that computed it cannot release it. Approval is a commit tied to a named user through your SSO, and the signed entry is what the report, notice, or filing links to.
what the ledger gives your second line
attributable · named approver on every figurereproducible · rerun from versioned inputssegregation of duties · compute and release are separategoverned sources only · enforced at compile timemodel inventory · the ledger is the recordexam-ready · read-only lineage view
03 — inside your perimeter
Your VPC, your warehouse, your keys.
Nothing in the data path belongs to a vendor. Bulk rows never leave the warehouse; only the aggregates an answer needs move, and they move inside your network.
your vpc
warehouseSnowflake · Databricks · Postgres · filesQueries run here. Results are cached here. Bulk rows do not leave.
xorq · headless
Ledger · X-Engine · Verifier · GateDeployed in your account as a service your agents call. Logs land in your SIEM.
your agents · your modelsPrivate LLM endpoints · Claude Code · custom harnessesAny model behind your own subscription. No proxy, no token markup.
SSO · approvals tied to named users
Git server of record · promotion is a commit
Security review covers a deployment, not a third-party service
// a working session, not a demo
Bring a number your examiner asked about last cycle.
Pick one of the five jobs above and a figure your team already produces for it. In an hour we show it as a Ledger entry: who would sign it, where the lineage lands, and what an examiner would open.
01Your figure, as an expressionWe rebuild the number from your governed tables as one Xorq expression and run it on your warehouse.
02The sign-off pathWho approves it, what they see before they do, and how rollback works when a definition changes.
03The examiner viewLineage from the reported number to source rows, model version, and approver, in one read-only screen.
04Where it runsA deployment sketch for your VPC: warehouse, identity provider, model endpoints, logging.
60 minutes · your data stays in your environment · no install required for the session
SAY HELLO
Copy our address and paste it into whichever email client you use.
consent — cookies.txt
$
We use cookieless analytics to measure traffic. With your consent, we also enable product
analytics, session recording, and Google Ads conversion tracking, which store data in
your browser. Read our
Privacy Policy.