Skip to content
OHMby YantrAI
ENFR
Log in Book a demo Start free
OHM · Security
Security

You're handing us vendor invoices.
Here is the whole stack,
bottom to top.

OHM is built on PRISM-ES — seven layers, each with one job. It is worth reading from the bottom, because the bottom is the part most people actually want to know about.

An agent can only see and do what the signed-in user could see and do themselves.Access is scoped before the intelligence layer acts. The AI does not have its own permissions, its own login, or its own reach into your data. It inherits yours, and nothing more.

The seven layers

Read bottom-up. Master data is the foundation; Engineering and Scalability span every layer above it.

P

Platform — the access layer

One system reachable from every device the team uses, with the same data, approvals and permissions on every channel.

iOSAndroidWindowsChromeOS
R

Roles & permissions

Every user, approval and view is scoped by role before anything deeper is reached. Maker-checker is enforced here — entered, checked, approved, posted — with named-user override logging against limits and tolerances you define.

OIDC / JWTRBACMFANamed-user sessions — no shared logins
I

Intelligence — AI in tandem with the stack

Agents reason and act through defined tools and guardrails, never around them. Every model touchpoint is defined, guarded and reviewable: PII redaction and prompt-injection screening before anything reaches a model, retrieval scoped to your namespace, grounded answers with citations, and output filtered, validated and redacted on the way back.

Input securityPer-customer vector namespaceOutput guardrailsCitations
S

Shield — the privacy layer

Row-level security isolates each customer's books, giving you a private cloud within the platform. Enforced in the database, not just in application code, so an application-layer mistake fails closed. What the system learns from your data stays in your deployment — it is never used to train shared models.

Row-level securityEncrypted in transit & at restNever trains shared models
M

Master data — the system of record

SQL, object storage and the vector database sit at the bottom. Your ERP holds the authoritative books. OHM reads from it and posts back to it; it does not become the place your accounts live.

SQLObject storageVector DBYour ERP stays authoritative

E · Engineering

A modern, proven stack end to end — HTML on the front end, Node.js and C# across back-end services, .NET and Python behind the frameworks and algorithms, and Windows agent apps running beside on-premise systems.

S · Scalability

Multi-entity and multi-site from day one, integrating with the ERPs and CRMs already in place rather than requiring a move onto one platform.

The four questions we actually get asked

01

Where does the data sit?

In your deployment, isolated at the row level in the database. Encrypted in transit over TLS and encrypted at rest. Your ERP remains the authoritative record throughout.

02

Who can see it?

Only your authenticated users, each in a named session scoped by role. No shared logins. Agents inherit the signed-in user's scope and cannot exceed it.

03

What is retained?

What you post and what the agents write, with an immutable audit trail against it — what was checked, what was found, who released it. Exportable or deletable on request.

04

Does any of it train a model?

No. Nothing from your deployment is used to train shared models. Names, account numbers and identifiers are redacted before any model call, and nothing is retained by the model once the answer returns.

Why the ordering matters

Most questions about AI and finance data are really questions about reach — what can this thing get to, and who decided that. Putting roles and permissions above intelligence in the stack is the answer: the scope is resolved before an agent runs, by the same access control that governs a person.

Start with an export. No connector, no access to your systems.

The savings check runs on a file your team already produces. Nothing needs to be connected to find out whether this is worth a longer conversation.

$Check your savings→