Skip to main content

Technical architecture

This page describes how Revizo AI is put together: which components are included, where the boundaries between trust zones run, and how one chat request moves through the system. It assumes familiarity with Revizo’s general security architecture.


Design principle: the model is an adapter, not an authority​

The most important thing to understand is where decisions are made.

ResponsibilityWhoHow
Who the user is, and which organisationClerk session → RevizoRead server-side in withTenant. Never from the user’s text or the model’s reply.
Whether AI may be usedRevizoThe organisation’s AI settings, quotas, and rate limits are checked before the model is called.
Which tools existRevizoFixed catalogue defined in code. The model cannot add or change tools.
Which tool to use, and with which argumentsClaudeThe model’s task. The arguments are proposals.
Whether the tool may run, and on which dataRevizoEach tool handler receives tenantId and userId from the session and filters on them.
Whether something is sent out of the organisationThe userConfirmation cards in the interface.

Consequence: even if the model were manipulated into proposing a lookup on a foreign client ID, the lookup runs with the logged-in organisation’s ID as the filter and returns nothing.


Components and trust zones​

Zone 1 — Client​

The browser sends the message, the page the user is on, any active company and open task, and any screenshots (max 4 per message). The client has no access of its own to the model; everything goes via Revizo’s API.

Zone 2 — Identity​

Clerk issues the session. Revizo reads tenantId, userId, and role from it on the server. None of these values can be overridden from the client.

Zone 3 — Control plane​

The entire chat endpoint lives in Revizo’s Next.js application on Vercel (region fra1). All control points in the figure run here, in this order, before and after the model call. See Security controls for each one.

Zone 4 — Data plane​

Postgres at Supabase in Frankfurt. All lookups the tools make, and all storage of conversations, memories, and usage, happen here with tenant_id as the filter.

Zone 5 — AI sub-processors​

Anthropic receives system prompt, conversation, context, and tool catalogue for one request, and returns text and/or tool proposals. OpenAI receives the user’s question text for vectorisation against Revizo’s own help text; no accounting data is included in that call. Both are in the USA, under EU standard contractual clauses, and do not use API data for model training. See Data access.

Zone 6 — Outbound side effects​

Email to external contacts goes via Resend, and only after the user has confirmed on a card. Lovdata lookups are reading of public statutory text.


One request, step by step​


Models and parameters​

ParameterValue
Chat modelclaude-sonnet-4-6 (Anthropic)
Max tool rounds per request5
Max reply length1,024 tokens (2,048 for routine description)
Prompt cachingEphemeral, per request — no persistent cache at the provider
Embeddingstext-embedding-3-small (OpenAI), question text only
Voice modegpt-realtime (OpenAI), WebRTC, only when the organisation has enabled speech
Rate limit10 requests per minute per user
Monthly quotaConfigurable per organisation (tokens and number of chats)
Timeout60 seconds per request

AI entry points other than chat​

Chat is the most used entry point, but not the only one. All go through the same policy check and the same tool catalogue.

Entry pointModelTool accessTurned off with
Text chat (Smart Panel, AI page, task panel)ClaudeFull catalogue, filtered on the organisation’s accessesAI chat
Voice modeOpenAI RealtimeCurated subset (clients, tasks, reminders, navigation, Smart Match)Voice mode
Document analysis (extraction of task description from attachments)ClaudeNo tools — text-to-HTML only, sanitised server-sideAI document analysis
MCP server (external agents such as Claude Desktop, Cursor)The customer’s own agentSeparate tool catalogue, authenticated with an API key created by an administratorDelete the API key

The MCP server is documented separately: MCP server for AI agents.


What does not exist​

To avoid misunderstandings in architecture reviews:

  • No direct database access for the model. Claude never gets a connection, an SQL string, or an ORM object. It gets JSON results from named tools.
  • No AI infrastructure of our own at Revizo. We do not host models ourselves. Model calls go to Anthropic and OpenAI via their API.
  • No fine-tuning on customer data. The models are the provider’s standard models. Revizo does not train or fine-tune on conversations.
  • No persistent state at the provider. Prompt cache is tied to the individual request. Conversation history is stored at Revizo, in the organisation’s own tenant, and is sent again with each message.

Last updated: September 2026