One system that does the work, keeps the record, and keeps itself running.
PureTensor deploys the system it runs its own company on: an autonomous layer that takes on an organisation's work, holds its complete institutional memory, and repairs its own faults. It is software that runs inside your boundary. It is not a service desk and it is not rented compute.
Three parts. One record. One system.
The parts are not three products with three logins. They share one memory and one approval policy, so what one learns the others know, and what you forbid one you have forbidden all of them.
The part that acts
Takes a task, chooses the seat and the model to run it, calls the tools it needs, checks the output, and reports back. Approval gates sit wherever you put them, and nothing in the approve class moves without a named person.
The part that keeps the record
The canonical institutional memory. Every decision, correction, document, and lesson is written once, with its source and its trust tier, and recalled by every part of the system. New staff and new seats inherit it on day one.
The part that keeps it running
Watches the estate the system runs on, triages its signals, applies the remedy it has seen work before, and escalates to a person only for the decisions you have reserved. Every incident it survives becomes a lesson kept.
Inside your boundary, on your terms.
Sovereignty is not a deployment option on a pricing table. It is how the system is built, because it is how the lab wanted its own system built.
Where your data lives
The system is deployed on hardware or cloud accounts you control. Nothing it collects or learns leaves that boundary unless you send it. There is no PureTensor tenancy in the path.
Models you can change
The reasoning seats are interchangeable. Run open models on your own hardware, a frontier model through your own account, or both. The record, the tools, and the approvals stay the same when the model changes.
A record you own
The canonical store is plain files in a repository you can read, audit, move, or delete. There is no export step because there is nothing to export from. Leaving takes a copy, not a negotiation.
It asks before it acts, wherever you tell it to.
Autonomy without a policy is a liability. The system ships with the gates, holds, and ledger the lab uses to run its own estate, and you set where the lines fall.
Approval gates
Every class of action is allowed, approved, or denied by a policy you set. Anything in the approve class waits for a named person, with a time limit, and the decision is logged whichever way it goes.
Hold states
When the system cannot cure something, it parks the problem, stops trying, and says so. It does not retry its way into a worse state, and it looks again only when the hold expires.
Attributable actions
Every action is written to the record with what prompted it, what was done, and what was verified afterwards. An auditor reads the same ledger the system does.
We run our company on it.
Every part of the system runs PureTensor's own operations today: it operates the lab's fleet, keeps its institutional record, and produces the service its clients pay for. The engineering record of each part is public, so the claim can be checked rather than trusted.
Argus, in production
The first service the system delivers to customers: verified written intelligence from open sources, in production for clients in the AI infrastructure sector since June 2026. Its engineering record is public.
An owned fleet, operated by the system
The lab designs and runs its own NVIDIA Blackwell fleet, and Sentinel keeps it running. Everything on this page was proven on an estate the lab cannot afford to have fail quietly.
Research in the open
The lab publishes what it measures: quantisation on workstation Blackwell, memory recall benchmarks, autonomous remediation. Read the research before you read the pitch.
Start with a conversation.
There is no pricing page and no form to fill in. An engagement begins with a conversation with the engineers who run the system, about the work you want to hand over and the boundary it must stay inside. From there it is scoped to one workflow, deployed inside your estate, and widened as the record grows.