Deterministic local processing, a customer-contained model for raw and sensitive context, an approved external model over a constructed release package, and the explicitly authorized raw route. No silent fallback between them.
Updated July 2026
Reconciling a requirement list, reading a K-1 and drafting the follow-up are different tasks with different risk, and Proxara routes each to the place it belongs. The route is chosen by the firm's approved definition, never by the model.
| Route | What it handles | What it receives |
|---|---|---|
| Deterministic customer-local | Exact matching, extraction, validation, calculation, threshold checks, binding and readback | The firm's real material |
| Customer-contained model | Document and tax classification, layout interpretation, sensitive cross-source reasoning, private drafting | The firm's real material |
| Approved external model-safe | Drafting, organizing, sequencing, explaining, selecting from approved actions | A constructed release package |
| Explicitly authorized raw external | One purpose, processor, data class and destination the firm has separately configured a basis for | What that authorization names |
The fourth route is configured deliberately or not at all. It is never a fallback for a compilation that failed.
The model does not receive the firm's documents with the sensitive parts removed. It receives a payload assembled only from claims the firm's policy authorized, and anything the system cannot account for never leaves.
Removing what a scanner recognizes leaves behind whatever it did not. Building the payload from admitted claims leaves nothing behind, because unaccounted material was never a candidate. Coverage is verified structurally, prohibited classes are checked for, and a residual read of the package is one verification step among several rather than the mechanism.
Exact computation stays local while an external model organizes or phrases an approved result. A variance is calculated in the firm's environment; the model receives that a threshold was crossed and drafts the sentence explaining it.
Numbers are classified by the role they play: identifier, return figure, amount, period, form or line reference, threshold, locally computed result, or public constant. An external model may receive symbolic variables, typed relationships, thresholds crossed, or conclusions computed locally. Random perturbation and generalized bucketing are not used where they could alter tax logic, a filing, a reconciliation, or the preparer's understanding.
A managed model endpoint reached over a private network link is still a managed external processor. Network privacy and customer-contained inference are different properties, and one does not substitute for the other. Any argument about where raw material is processed has to name which of the four routes is in use.
When classification is uncertain, coverage is incomplete, or the destination has accumulated too much, the work stays local, omits that source and states the omission, asks the preparer one clarification, opens a fresh destination, or stops. There is no silent fallback from a customer-contained route to an external one, and no route widens because a dependency was slow.
| To understand | Read |
|---|---|
| What decides the route for a given job | Approved work |
| What the external model actually receives | What the model sees |
| Where the preparer sees the clear result | The private workspace |
| Who controls the environment each lane runs in | The private environment |