PRYSM
Deterministic core, LLM language layer.
- AI / Compliance
- Team Lead
- Team Ragnarok
- Current build
Context
PRYSM is a multi-tenant compliance platform, built by Team Ragnarok. It turns AI regulations into versioned controls and enforces them inline through an LLM gateway.
It began as a GST, ROC and statutory audit-intelligence platform: FastAPI, React, Groq with LLaMA 3.3, an 18-point deterministic compliance rule engine, ChromaDB and ReportLab. The current version is the operating system that grew from it.
Approach
Compliance cannot rest on a model's say-so, so the design rules are written down in 11 ADRs. LLM findings never close a control: a human has to confirm. Every obligation must cite exact source text, and code checks the citation. Tenant isolation is enforced twice, with Postgres RLS and in the application layer.
System
Versioned controls
AI regulations turned into controls, each citing exact source text
LLM gateway
Enforces controls inline on language-model calls
Human confirmation
An LLM finding never closes a control on its own
Hash-chained evidence trail
Tamper-evident and verifiable offline
Build
- M0 monorepo: pnpm and Turbo with uv, five services, Drizzle and SQL migrations, Valkey, OpenTelemetry
- CI gates for wording rules and TODO tracking
- LLM gateway and hash-chained evidence trail
- 11 ADRs recording the design rules
- First version: 18-point deterministic compliance rule engine on FastAPI, React, Groq/LLaMA 3.3, ChromaDB and ReportLab
Challenges
- Multi-tenant isolation that does not rest on one layer: Postgres RLS plus app-layer checks.
- Keeping LLM findings advisory. They never close a control without human confirmation.
- Making obligations checkable: each one must cite exact source text, and code verifies the citation.
- An evidence trail that can be verified offline, which is why it is hash-chained.
Result
The M0 foundation is built: a five-service monorepo with migrations, Valkey, OpenTelemetry and CI gates, governed by 11 ADRs. The platform itself is still being architected.
- 11
- 5
Learnings
Trust is an architecture decision. Deciding where the model may speak, and where it may not, comes first.