AI vision document extraction — docs → org's vision provider → VerifiedFact(OCR)

FeatureSecurityService
Shipped
July 10, 2026 at 7:45 PM UTC
Author
Kamo
Commit
d61e5e5

The first producer of VerifiedFactSource.OCR: POST **************** reads a vault document (bank **************** ID) with the ORG'S OWN configured vision provider (MlosAiClient, MEDIUM tier) via a short-lived HMAC-signed public URL (VaultDocUrlSigner keyed off internal.auth.secret; VaultDocPublicController re-verifies org+vault assoc, no-store) and records每 extracted field as an evidence-backed VerifiedFact with per-field confidence. Party + confused-deputy + app-party authz; best-effort by contract (no provider/unreadable → status, never 5xx). Reconcile then applies facts to the URLA. The AI reads — it never decides.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing