02 / 05 · AI / Compliance

PRYSM

Through-lineDeterministic core, LLM language layer.

Category
AI / Compliance
Role
Team Lead
Team
Team Ragnarok
Status
Current build

01 / 07Context

01Context

PRYSM is a multi-tenant compliance platform, built by Team Ragnarok. It turns AI regulations into versioned controls and enforces them inline through an LLM gateway.

It began as a GST, ROC and statutory audit-intelligence platform: FastAPI, React, Groq with LLaMA 3.3, an 18-point deterministic compliance rule engine, ChromaDB and ReportLab. The current version is the operating system that grew from it.

02Approach

Compliance cannot rest on a model's say-so, so the design rules are written down in 11 ADRs. LLM findings never close a control: a human has to confirm. Every obligation must cite exact source text, and code checks the citation. Tenant isolation is enforced twice, with Postgres RLS and in the application layer.

03System

Diagram · How a control is enforced
  1. 01

    Versioned controls

    AI regulations turned into controls, each citing exact source text

  2. 02

    LLM gateway

    Enforces controls inline on language-model calls

  3. 03

    Human confirmation

    An LLM finding never closes a control on its own

  4. 04

    Hash-chained evidence trail

    Tamper-evident and verifiable offline

Deterministic coreLLM language layer

04Build

  • M0 monorepo: pnpm and Turbo with uv, five services, Drizzle and SQL migrations, Valkey, OpenTelemetry
  • CI gates for wording rules and TODO tracking
  • LLM gateway and hash-chained evidence trail
  • 11 ADRs recording the design rules
  • First version: 18-point deterministic compliance rule engine on FastAPI, React, Groq/LLaMA 3.3, ChromaDB and ReportLab

05Challenges

  • Multi-tenant isolation that does not rest on one layer: Postgres RLS plus app-layer checks.
  • Keeping LLM findings advisory. They never close a control without human confirmation.
  • Making obligations checkable: each one must cite exact source text, and code verifies the citation.
  • An evidence trail that can be verified offline, which is why it is hash-chained.

06Result

The M0 foundation is built: a five-service monorepo with migrations, Valkey, OpenTelemetry and CI gates, governed by 11 ADRs. The platform itself is still being architected.

11
Architecture decision records
5
Services in the M0 monorepo

07Learnings

Trust is an architecture decision. Deciding where the model may speak, and where it may not, comes first.

AI / SYSTEMS / PRODUCT ENGINEERING
SHREEKUMAR.B000