Everything the system does, and how much of it runs today.

Sentanis runs today against a real book of nearly 80,000 auto claims. 7 of its 14 capabilities ship now; the rest are labeled plainly on the roadmap. Pick any capability to see what it does, watch the mechanics run on fictional files, and read the controls by name.

The system

One system, from first notice to final decision.

Sentanis runs today against a real book of nearly 80,000 auto claims — the console linked from this page is that software, not a drawing of it. 7 of the 14 capabilities below ship now; the rest are labeled plainly on the roadmap. Pick any capability to see what it does, why it matters, and who has to sign before anything leaves.

The life of a claim Running today Partly built Next

Intake

the file arrives

Watch

the clock starts

Adjuster and counsel decide the response

Read

what the other side sent

SIU and adjusters set the track

Answer

what goes back out

Counsel edits, signs, and files

Resolve

settle or defend

The adjuster records the decision

Across every stage

Running todayTLD Sentinel

TLD Sentinel

Never miss a time-limited demand

Reads every inbound attorney letter and answers one question: is this a time-limited policy-limits demand, explicit or disguised? It reads the expiration terms out of the demand documents themselves, runs the countdown, and puts the file at the top of the queue with the response the file needs next.

A mishandled demand is how a small policy becomes a seven-figure judgment — in Harvey v. GEICO, a $100K policy became $9.2M in liability. On a 30/60 book the same trap is set on every serious claim. The Sentinel can raise a demand and calendar it; it is structurally incapable of rejecting one.

Human gate: Adjuster and counsel decide; the Sentinel can never reject

Watch it work →

Interactive product demos

Four parts of claim work. One source record.

Choose a workflow and inspect the evidence, deadlines, prepared work, and named human review boundary. Every file shown is fictional.

Loading capability demo

Safeguards

The AI never decides. That’s the design, not a disclaimer.

A claims professional reviewing an AI-drafted document at their desk
The human gate — where every decision lives

The system never

  • Denies a claim
  • Rejects a demand
  • Contacts a claimant
  • Files with a court
  • Releases a document
  • Signs anything

The gates are wiring, not policy

Every settlement or tender decision goes to a licensed adjuster. Everything filed with a court or sent to opposing counsel is reviewed, edited, and signed by licensed counsel — that's Sean's side of the house. In the running system these are enforced below the interface: named permissions, gate-specific authority, and row-level security in the database decide who may record a decision, and the browser hiding a button changes nothing.

Source documents are evidence, never instructions

A demand package is an adversarial document written by someone who would very much like your system to do what it says. Imported text and attachments are treated as untrusted evidence throughout — the model reads them, and never takes orders from them. That distinction is architectural, and it is the one most AI claim tools get wrong.

An independent audit with no power to release

More than 1,500 court decisions now involve fabricated AI citations. Sentanis runs a separate audit agent over every drafted response: it inventories each matter of law and each explicit authority, resolves them against claim-free legal sources, and binds numbered findings to that exact revision. Edit the letter and the proof is void. A passing audit is evidence for the person signing — it never releases anything itself.

Written for the jury that may read it

Courts have already compelled insurers to hand over their AI's claim evaluations. So decisions are append-only, evidence is recorded alongside the judgment a reviewer saw, feedback and later evaluation stay attached to the file, and a derived assertion carries the source line that produced it. Cheap to build in from the start, expensive to retrofit under a market-conduct exam.

The mechanisms, by name

Shipped controls in the running system — the things a security review or a market-conduct exam actually asks about.

Private deployment
Runs on the carrier's own infrastructure; claim data never leaves it
Row-level security
Postgres RLS plus named permissions and explicit per-claim grants — the database enforces access even if the UI doesn't
Append-only audit
Every decision is recorded against an authenticated person, and the access trail is append-only — enforced by a database trigger
Field-level encryption
Names, contacts, source records, and document text encrypted at the field level in the system of record
Untrusted-evidence rule
Imported documents are evidence, never instructions — a demand letter cannot steer the model that reads it
Redaction before egress
PII redaction runs before any external model call sees claim text
Login admission control
Account and aggregate rate limits on password work throttle credential attacks at the door
Audited analysis access
Analyst and agent data access runs read-only, permission-scoped, and audited — content-free logs, bounded queries

How evaluation works

Run it on the files you already closed.

Every engagement starts with a shadow evaluation: the system runs as one supervised pipeline against your historical claims. It observes and scores — it sends nothing, decides nothing, touches no live file. Then we lay it side by side with what actually happened. Zero live-fire risk; real evidence on your own data.

Caught in time

The one that blew up

A clean-liability file the system flags for early tender 18 days before the demand was due. In reality it sat in a queue and tried to a ~$210K excess judgment.

Caught before payment

The buildup ring

Three 'separate' minor-impact claims the fraud flag ties to one clinic-and-attorney cluster at intake — before a dollar goes out the door.

Correctly left alone

The routine file

A claim the system recommends handling routinely — and that's exactly what happened. A triage tool that flags everything is useless; this is the precision side.

The adjuster’s view

This is what your team would actually see.

A working console in the application’s own shell, not a slideshow: the pre-suit worklist, each claim’s recommended track and score, the calendared deadlines with their dual-key check, the fraud and coverage flags, the full audit trail, and the backtest scorecard. Every recommendation ends at a human gate — Sentanis recommends, your licensed adjuster decides.

Request a demo
WorklistShadow mode · advisory
BR-2025-04417Fast-tender

R. Aguilar · Demand deadline 03/18 · dual-key ✓

BR-2025-07732Investigate

D. Okafor · Clinic cluster overlaps two open files

BR-2025-09105Routine

L. Tran · Low causation risk · monitor only

Illustrative files and figures are fictional, for demonstration only. In an evaluation these run against your real closed pre-suit files, against pre-agreed outcome labels, with strict temporal discipline. Any dollar figure is a modeled estimate, never a measured result.

Deployment

Twenty weeks to full deployment. Not two years.

Twenty weeks is credible because the foundation is not on the schedule: the claims workspace, document intelligence, the Sentinel, demand deconstruction, citation QA, and fraud triage are already built and running against a claim book. What remains is tuning to your book, litigation drafting, and the operational surround — and every phase gates on measured accuracy, not the calendar. If the shadow evaluation says the Sentinel isn’t catching every demand yet, live claims wait until it does.

Typical enterprise rollout~24 months
Sentanis — already running, gate-checked20 weeks

Shadow pilot on closed files

Replay your history

You give us 50–100 closed litigated files. We run the system against history: every demand the Sentinel would have caught and how many days earlier; every file triage would have flagged before it blew up; drafted responses blind-graded by attorneys against what was actually sent; valuation calls scored against actual outcomes. The pipeline this runs on is the software behind the demos on this page, not a prototype built for the evaluation.

What you get

A dashboard of your own files, scored — the ROI math on this page recomputed with your data instead of vendor claims. Zero live risk. Zero regulatory exposure.

Honest fine print: speed comes from starting with running software — never from skipping a gate. Every document still passes through licensed counsel; every settlement decision still belongs to your adjusters.

Every demo above runs on your closed files instead.

A shadow evaluation replays 50 to 100 closed litigated files through the same pipeline and scores it against what actually happened. Three weeks, no live claims.

Request a demo