Enterprise solutions
AI document workflows that fit the process you already run
Packaged workflows for document-heavy operations, delivered on a closed-source workflow substrate with published retention, deletion and sub-processor terms. Requirement confirmed, delivered fast, kept secure.
Requirement confirmed
Fast delivery
Continuous security
Packaged solutions
Three verticals, one substrate
All three run on the same substrate; only the workflow differs. So the security and integration terms you verify for one of them already apply to the other two.
- Manufacturing
Quality inspection reports and shipping document packs
Handwritten inspection records, gauge output and photos become the report your customer's template asks for. Measured values are transcribed, never rewritten; out-of-spec items and unreadable entries are flagged for a person.
- Logistics
Pre-clearance review packets
Scattered email threads, invoices, packing lists and bills of lading become one review-ready packet. Conflicts surfaced, missing documents listed, every field carrying a source page.
- Commerce
Supplier catalogues to platform-ready listings
Supplier PDFs and photos become a CSV the marketplace importer accepts first time. Currency split out, units normalised, variants resolved against your own template.
How adoption works
Three phases, each ending in something you can sign off
An adoption project fails on scope, not on models. Each phase below closes with a written artefact, so the next one starts from an agreement rather than an assumption.
Requirement confirmed
We inventory the documents and systems already in use, agree which fields matter and how each is read, and draw the line where a person reviews rather than the workflow decides.
Output of this phaseA written scope note naming every field, every reading rule, and every human checkpoint.
Fast delivery
The workflow is assembled from generic platform tools rather than built for one customer. Real sample documents run first, and volume follows once the sample set is clean.
Output of this phaseA running workflow on real sample documents, with the cost per run measured before scale-up.
Continuous security
Every run leaves a tool-invocation record. Retention windows, deletion behaviour and the sub-processor list are published pages that a security reviewer can check without asking us.
Output of this phaseAn audit trail per run, and a documented retention, deletion and sub-processor position.
System integration
Build once, call the same workflow from the web, the API or an SDK
A workflow is built once in Builder. All three call surfaces point at that one workflow, not three copies to keep in step.
In
- Direct upload
- Google Drive
- Dropbox
- URL import
- Dedicated inbox
Workflow substrate
- Excel
- Word
- JSON
Out
Call surfaces
Web interface, REST · Python SDK · TypeScript SDK. Agent workflows stream events over WebSocket; deterministic conversion is polled.
Where it runs
Workflows run in the cloud. Ainalyn for desktop (beta) handles image, PDF and OCR conversion on the machine; convilyn.local converts offline with no key and no network.
Your own tools
You can host a tool server and have the platform call into it. Every outbound request carries a HMAC-SHA256 signature and a timestamp, so you can verify it came from us.
URL import accepts https only, does not follow redirects, refuses addresses that resolve to internal ranges, and has a size limit. Download links are short-lived presigned URLs and can be reissued.
Why Convilyn
The substrate is ours, and the guarantees are checkable
Document automation projects stall at security review. Every item in this section can be checked before you talk to us.
Decision boundary
Eight gates decide in code, against fixed thresholds, in a fixed order. A model cannot skip one, and cannot argue a threshold up.
- RedactionSensitive content is masked before it reaches a model.
- Budget ceilingA per-request spend cap. Work stops at the limit.
- Retry policyFixed backoff, so a rate limit never becomes a stampede.
- Phase legalityA tool runs only in the phase the workflow allows.
- Cycle detectionThe same call repeated in a row aborts the run.
- Output reject limitThree rejected outputs and the run stops retrying.
- Tool permissionWriting to an outside system needs granted authority.
- Code rescue admissionWhether a code rescue may run is configuration, not a judgement.
Extraction is held to the same kind of rule: a field the source does not contain is left empty. A grounded blank is the correct answer; an invented value is not.
Privacy is the default, not a setting to find
Model providers do not train on your content. Runs started with an API key are excluded from Convilyn's own model work in code, and fail closed — a refusal by default, not a policy statement.
Integration flexibility, because the constraint is usually on your side
The interfaces are listed above. The other half of that commitment is this: if a requirement is beyond us, we say so during the assessment rather than at go-live.
Model training
Inputs and outputs sent through AWS Bedrock are not used to train Anthropic's models (see Bedrock's data protection terms). Runs started with an API key are excluded from Convilyn's training data, enforced in code.
Deletion
Files can be deleted immediately through the API, by the uploader only. A file attached to a running workflow is protected until that run reaches a terminal state.
Encryption and isolation
TLS in transit, encrypted at rest. Storage paths are isolated per account and every read and delete checks ownership — guessing an identifier does not reach another account's file.
Redaction
Rules match on field name and value shape, so content inside fields like resume_text is caught too. It does not rely on a model to judge what is sensitive.
Sub-processors and DPA
Every sub-processor handling customer content is listed publicly. Enterprise customers can sign a DPA, are notified when a sub-processor changes, and can object.
Retention
- 1 hourSource files and download links
- 7 daysWorkflow run state
- 30 daysDeliverables
The cleanup pass runs every 15 minutes, which is why the shortest horizon is about an hour rather than exactly one. A file still attached to a running workflow is kept until that run finishes. Any file can be deleted immediately through the API.
Processing regions are fixed today: file storage and workflow execution in Tokyo (ap-northeast-1), model inference in us-east-1, and OCR in Singapore (ap-southeast-1). The region cannot be selected per request. Raise a data-residency requirement during the assessment and we will say plainly what is and is not possible.
Start with the requirement, not the demo
Tell us which documents pile up and which system they have to reach. The first conversation is about scope and constraints, and it costs nothing.
Book an adoption assessment