Ask your documents. Get everything you have access to.
One assistant for the whole organisation. Each answer draws on every document that person can open, and nobody has to check first.
Your documents, ready to ask about
Your single obligor limit is 20% of core capital for one borrower.Credit Policy 2026 · §4.2 · p12
Everest Cement's total exposure is 11.4% of core capital, so it sits inside the limit.Credit Memorandum — Everest Cement · exposure summary · p4
Guarantees count towards the same limit, and that figure already includes them.NRB Directive 3/2025 · §2 · p3
Each statement carries the paragraph it came from.
Every answer, with what it drew on
questions, follow-ups, and an answer in your words
each statement links to the paragraph it came from
the same rule the application uses, enforced where the data lives
your infrastructure, your models, your data
A question in plain language, an answer you can check.
Check any sentence against the passage it came from. Each answer is built from what you can open.
- Ask the way you would ask a colleague. Follow-ups keep their context, so "and the Trishuli one?" works.
- Each statement carries the document, section and page it came from.
- The same question from someone else comes back differently, on their own access.
- Every answer is written to a record, with its sources, as it is given.
Your single obligor limit is 20% of core capital for one borrower.Credit Policy 2026 · §4.2 · p12
Everest Cement's total exposure is 11.4% of core capital, so it sits inside the limit.Credit Memorandum — Everest Cement · exposure summary · p4
Guarantees count towards the same limit, and that figure already includes them.NRB Directive 3/2025 · §2 · p3
Each citation sits with the sentence it supports, not in a footnote at the end.
The access your people already have, applied to every answer.
Two things decide it. A clearance tier sets sensitivity; a grant opens the folder. Applied before the assistant reads anything.
- Written once. The application, the search and the database all use that same rule.
- It runs inside the search itself, so the assistant only ever sees what that person can open.
- Nothing beyond someone's access reaches the model, so no clever prompt can talk it into more.
- Tests run on every change to prove browse, search and ask all agree.
Identical clearance, opposite outcome. Clearance is a ceiling, never a key.
How the assistant finds the right paragraph.
Meaning, keywords and exact wording, searched together. Nobody picks a mode — you can still search it yourself.
- Finds the paragraph, with its section and page, not just the file.
- Wording you half-remember still finds it. Type it with four typos and it comes back first.
- Text read from a scan says so, and names its page.
- Results tell you how many more documents cover the topic, so you know what to ask access for.
Type it with four typos and it still comes back first.
Every answer keeps its own evidence.
Who asked, what they could see, and every source the answer drew on — written as it happens, not reconstructed.
Every read and every answer, written down.
- Reads, downloads, searches, questions, permission changes, emergency access — every kind of event.
- Nothing is ever edited or removed. People with history are suspended, not deleted.
- Filter to refusals and "who looked at this" takes seconds.
Runs on your infrastructure, with your models.
Each model role points at its own endpoint. Where the thinking happens is a setting.
- Roles: chat, fast, planner, vision, embedding. vLLM, Ollama, LiteLLM, OpenRouter or your own.
- Move the answering model in-house first. Changing the index model means a rebuild, and a mismatch is refused.
- PostgreSQL. Argon2id passwords, and sessions you can revoke instantly.
- In production it refuses to start rather than run insecurely.
Deployed on your infrastructure. Not a subscription service.
Each role is set separately. Only the embedding role costs a rebuild.
The document side is the simple part.
Upload a file and it is ready to ask about in minutes.
Clearance confidential · member
33 of 82 documents
Every screen your team works in.
Twelve screens. Your menu shows the ones your role uses.
Library
Folders you can open. Each document shows its classification.
Search
Search everything you can open, and see how many more documents cover the topic.
Ask KhojAI
Ask in plain language. Each answer is drawn from what you can open.
Upload
Every stage runs in the open. A person confirms the proposed classification.
Administrators only
People & Access
Clearance tiers and folder grants in one place, with the access requests they produce.
Invitations
Invite somebody with a clearance and their grants. No mail relay? The link comes back to you.
Administrators only
Audit Log
Every kind of event, with who did it and when.
Answer Records
Every answer leaves a record you can cite.
Retention
The schedule proposes, a separate person approves. Legal hold outranks both.
Administrators only
Recertification
Proof that access is still right, folder by folder.
Attestations
Proof that a policy was read, person by person.
Settings
Mail and security for the installation. Changes apply on the next request.
System administrators only
What happens when you upload a document.
Every stage is shown live, and every stage leaves a record. No overnight batch.
Text out of the file
PDF, Word, Excel, PowerPoint, CSV, Markdown, images.
Pictures described
A scan with no text is read by a vision model, not skipped.
Classification proposed
The model proposes a tier. An administrator confirms it.
By meaning, keyword, full text and spelling — so wording you half-remember still finds it.
Old versions stay searchable but leave everyday results. A revised figure never competes with the one it replaced.
Checking the rules is a job of its own.
KhojAI Niyam applies your compliance rules to every record and returns a result per rule.
- Rules are written as plain sentences by the people who own them.
- Every result carries the rows it was reached from.
- Licensed as an add-on, for organisations that need it.
Niyam never closes a record. A person decides.
Common questions about KhojAI.
Where the system stands today, answered in plain terms.
Does it do SSO or MFA?
Can it run as more than one replica?
How does it handle bulk ingestion?
Can we change the classification tiers?
Could someone prompt-inject past the access rule?
What happens when someone leaves or changes department?
Bring us a real set of documents.
A working session, not a slide deck. Tell us what your people need to find, and we will show you them finding it.
A 45-minute working session · a deployment shape on paper · a pilot against your own documents, under NDA.