Demonstration dataA demonstration portfolio. Every property and every reading was authored to exercise the product. No hotel supplied any of it and no company is described.
Select any layer to see what it holds, what it produces, which version governs it, and what it is structurally incapable of doing. The constraints are the product: an engine that could be argued into a different answer would be worth nothing to a partner who has to defend it internally.
Solid layers are operational in this build. Dashed layers do not exist yet, and selecting one says what it is waiting on. Nothing is drawn as working that is not.
Governed by ontology 1
One sentence, and everything above is a consequence of it.
The deterministic system is the truth. AI is interpretation. That relationship is never reversed.
A model may one day explain a ParaVida score in a guest’s language. It may never decide one. The same rule governs the evidence layer: a model may propose a reading about a property, and that proposal is retained in full — with its source and its rationale — and excluded from the arithmetic until a person confirms it.
A policy is a promise about how carefully a model will be prompted. This is different: the scoring engine takes a weight vector and an entity and nothing else. There is no argument it could be passed that would carry a preference, no configuration that could weight a partner up, and no code path from a model’s output to a score. The proposal exclusion happens when a property is projected, before any surface sees it. You cannot forget to apply a rule that has no opt-out.
Counted from the same capability list every surface in this product gates on.
The deterministic compatibility, weighting, confidence and evidence engines run on every surface in this product. Nothing here is precomputed copy.
Findings, twins, shortfall, coverage and refusals are computed from the loaded portfolio at request time.
A live read endpoint scores a property against a guest archetype and returns the engine's own refusal when coverage is short.
One portfolio is served from source control. There is no per-tenant isolation, so no second partner could be onboarded without building it.
Depends onTenant model in Postgres, row-level security on partner tables, and a partner identity separate from the consumer auth system.
The compatibility endpoint is unauthenticated and read-only against synthetic inventory. It is not a production integration surface.
Depends onAPI key issuance, scoping, rotation and per-tenant rate limiting.
The verification queue is computed and reviewable. Confirming a reading from the browser would change what the engine scores, so it is not wired up.
Depends onPartner-scoped write path with an audit trail, reviewer identity, and a re-assessment pipeline triggered on evidence change.
There are no enterprise seats, roles or directory integration.
Depends onSAML/OIDC integration and a role model on the tenant.
No usage is recorded against an account and nothing is billable.
Depends onMetered request logging per tenant and a billing integration.
Copilot answers from deterministic evidence. There is no model in the product, by design — and no API key configured for one.
Depends onA model provider credential, plus a tool interface that lets the model read engine output without ever writing a score.
Produced underscoring 1 · weights 4 · ontology 1 · climate model 1 · engagement 1 · min coverage 0.5