Applications
One judgment shape, six places it decides money in home lending
Every surface below shares the same shape: documents in, rules applied, rationale written, exception routed, decision attested. The kernel is loan-type-agnostic — a first-mortgage purchase file, a refinance, a HELOC, or a home equity loan all sit in the same verification kernel, and so do the closing table's own artifacts: a title commitment, a settlement package, an escrow ledger. The kernel is subject-polymorphic from its first migration: a loan file is the first subject, not a hardcoded one. What changes per surface is content: which documents, which rules, whose queue. What never changes is the record: who judged, against which version of which rule, citing which page of which document — sealed so no one can quietly change the answer afterwards.
Post-close QC — the worked example
The mandate
Post-close quality control is not optional. Fannie Mae Selling Guide D1-3-01 requires a lender to select, for post-closing QC review, "a minimum of 10% of the loans that it originates or acquires using a random selection methodology" (quoted from the Selling Guide; verified 2026-08-17). That floor exists because human reperformance costs real money — whole departments or outsourced audit spend, file by file. The incumbent answers are mortgage QC software that manages the sample workflow and audit-services firms that supply the reviewers. Sampling itself is a cost compromise, not a method anyone would choose with free review.
The walk
What a governed QC reperformance looks like inside the kernel, step by step: a named actor claims the file; the kernel records every extraction with the exact document and page it read — the schema refuses an unanchored extraction; checks run against the guideline version live that day, and the seal captures that version, so "show me the rule as it read that day" has an answer; a distinct checker — not the maker — resolves findings, because the database refuses a maker sealing its own work; the sealed result appends to a tamper-evident chain.
The architecture's design basis is the full population — every file, not a sample, each with its own evidence pack. Stated exactly: we built the architecture for that; it is not a delivered customer result, and the AI review layer that would produce it at scale does not yet exist. The sealing architecture runs today; the AI judgment layer does not yet exist — see what runs today.
The sealed pack
the finding, and the rationale it rests onwho judged — and the distinct actor who approvedguideline identifier and the exact version live at judgment timedocument and page for every extraction citedderived by the kernel, never self-reportedappend-only entry; prior-entry hash carried forward