Technical architecture
This page describes how Revizo AI is put together: which components are included, where the boundaries between trust zones run, and how one chat request moves through the system. It assumes familiarity with Revizo’s general security architecture.
Design principle: the model is an adapter, not an authority
The most important thing to understand is where decisions are made.
| Responsibility | Who | How |
|---|---|---|
| Who the user is, and which organisation | Clerk session → Revizo | Read server-side in withTenant. Never from the user’s text or the model’s reply. |
| Whether AI may be used | Revizo | The organisation’s AI settings, quotas, and rate limits are checked before the model is called. |
| Which tools exist | Revizo | Fixed catalogue defined in code. The model cannot add or change tools. |
| Which tool to use, and with which arguments | Claude | The model’s task. The arguments are proposals. |
| Whether the tool may run, and on which data | Revizo | Each tool handler receives tenantId and userId from the session and filters on them. |
| Whether something is sent out of the organisation | The user | Confirmation cards in the interface. |
Consequence: even if the model were manipulated into proposing a lookup on a foreign client ID, the lookup runs with the logged-in organisation’s ID as the filter and returns nothing.
Components and trust zones
Zone 1 — Client
The browser sends the message, the page the user is on, any active company and open task, and any screenshots (max 4 per message). The client has no access of its own to the model; everything goes via Revizo’s API.
Zone 2 — Identity
Clerk issues the session. Revizo reads tenantId, userId, and role from it on the server. None of these values can be overridden from the client.
Zone 3 — Control plane
The entire chat endpoint lives in Revizo’s Next.js application on Vercel (region fra1). All control points in the figure run here, in this order, before and after the model call. See Security controls for each one.
Zone 4 — Data plane
Postgres at Supabase in Frankfurt. All lookups the tools make, and all storage of conversations, memories, and usage, happen here with tenant_id as the filter.
Zone 5 — AI sub-processors
Anthropic receives system prompt, conversation, context, and tool catalogue for one request, and returns text and/or tool proposals. OpenAI receives the user’s question text for vectorisation against Revizo’s own help text; no accounting data is included in that call. Both are in the USA, under EU standard contractual clauses, and do not use API data for model training. See Data access.
Zone 6 — Outbound side effects
Email to external contacts goes via Resend, and only after the user has confirmed on a card. Lovdata lookups are reading of public statutory text.
One request, step by step
Models and parameters
| Parameter | Value |
|---|---|
| Chat model | claude-sonnet-4-6 (Anthropic) |
| Max tool rounds per request | 5 |
| Max reply length | 1,024 tokens (2,048 for routine description) |
| Prompt caching | Ephemeral, per request — no persistent cache at the provider |
| Embeddings | text-embedding-3-small (OpenAI), question text only |
| Voice mode | gpt-realtime (OpenAI), WebRTC, only when the organisation has enabled speech |
| Rate limit | 10 requests per minute per user |
| Monthly quota | Configurable per organisation (tokens and number of chats) |
| Timeout | 60 seconds per request |
AI entry points other than chat
Chat is the most used entry point, but not the only one. All go through the same policy check and the same tool catalogue.
| Entry point | Model | Tool access | Turned off with |
|---|---|---|---|
| Text chat (Smart Panel, AI page, task panel) | Claude | Full catalogue, filtered on the organisation’s accesses | AI chat |
| Voice mode | OpenAI Realtime | Curated subset (clients, tasks, reminders, navigation, Smart Match) | Voice mode |
| Document analysis (extraction of task description from attachments) | Claude | No tools — text-to-HTML only, sanitised server-side | AI document analysis |
| MCP server (external agents such as Claude Desktop, Cursor) | The customer’s own agent | Separate tool catalogue, authenticated with an API key created by an administrator | Delete the API key |
The MCP server is documented separately: MCP server for AI agents.
What does not exist
To avoid misunderstandings in architecture reviews:
- No direct database access for the model. Claude never gets a connection, an SQL string, or an ORM object. It gets JSON results from named tools.
- No AI infrastructure of our own at Revizo. We do not host models ourselves. Model calls go to Anthropic and OpenAI via their API.
- No fine-tuning on customer data. The models are the provider’s standard models. Revizo does not train or fine-tune on conversations.
- No persistent state at the provider. Prompt cache is tied to the individual request. Conversation history is stored at Revizo, in the organisation’s own tenant, and is sent again with each message.
Last updated: September 2026