Alleadz
An operating system that turns a change in the world into a specific, evidence-linked commercial opportunity. It imports target accounts, resolves entities, watches for real signals, scores fit against a mandate twin with a deterministic rubric, drafts a nine-section thesis where every material claim is either cited to evidence or explicitly labeled a hypothesis — and prepares outreach that never sends without a human approval bound to a frozen content snapshot.
Signal → thesis → approved outreach.
Every stage is a hard gate; nothing skips evidence.
Multi-tenant, evidence-first
Organisations carry immutable twin versions (mandate, markets, capabilities). Claims are typed assertions — sourced fact, user claim, inference, disputed — and inferences demand a written rationale.
CSV in, originals kept forever
Preview → commit law: every row is retained raw with an error class and a research task for failures. Cross-tenant duplicates are flagged for a reviewer — the system never auto-merges.
Explainable scoring, no black box
Five rubric dimensions (fit, trigger, timing, budget, access) roll up to priority and coverage. Hard checks run first: mandate overlap, geography, capability match, disqualifiers, procurement eligibility. Unknowns block qualification.
Stage machine, server-enforced
identified → researching → thesis_ready → human_reviewed → qualifying → qualified → handed_off. Every transition is validated, audited, and gated on thesis quality — an unevidenced opportunity cannot reach qualified.
Bounded collection
Fetches are capped (2 MB, 15 s, 3 attempts, 10 URLs/run), SSRF-guarded, content-hash snapshotted, and stripped to an extraction allowlist — injected script content never survives into the reasoning layer.
Approve → bind → export. Never auto-send.
An approver binds a frozen recipient + content snapshot. Any edit revokes. Approval expires. Export only emits what a live approval covers — a human presses send, always.
Honesty is enforced, not aspirational.
The rules tests fail on.
Cite or label it a hypothesis
Thesis sections are validated: every material assertion either references a claim ID or begins with an explicit "Hypothesis:" frame. Uncited facts are rejected at write time (A05).
Published ≠ deliverable
Emails carry a class (person/company published, third-party reported, functional inbox, not found) separate from deliverability. Outreach to unknown contacts is structurally impossible (A09).
Deny by default, proven hostile
Postgres RLS with FORCE on every tenant table; transactions set tenant + user GUCs per statement. Tests prove a foreign tenant's token reads zero rows and cannot mutate (A01–A03). The test harness itself connects through a least-privilege role so superuser RLS bypass cannot mask failures.
Envelope with an allowlist
Handoffs emit a versioned envelope (event id, correlation, payload hash, disclosure scope) whose payload is field-allowlisted — nothing beyond target, sector, stage and scores ever leaves the building (A15).
Built like infrastructure.
Same engineering family as Sovereign Grid.
Express · Postgres · React 19
Modular-monolith server, zod-validated contracts, immutable thesis versions, append-only audit trail on every state change.
40 server + 3 client checks
Scratch-database test harness: real migrations, real RLS, per-file isolation, least-privilege app role — the isolation law is tested, not assumed.
Live on Render with a runbook
Auto-deploy on push, health-checked, shared-database schema isolation documented with backup and expiry procedures in the ops runbook.
Sector packs & portfolio depth
Packs (GPU rental, hardware, AI colocation, gov data infrastructure) are already configuration, not code. Next: portfolio analytics depth and discovery adapter growth behind the same caps.