Home/Sectors/Legal
Sector · Legal & Regulatory

Dinanu

Dinanu — the Legal implementation of Nabu, the trusted investigation & discovery platform. Evidence-grade AI, for work where the bar is not “useful” but defensible — every answer traceable to its sources, every derivation replayable, every step on a signed record that survives an auditor, a regulator, or a court.

Not a number someone typed. A number a named, verifiable process produced.

Legal
9 / 9
Trust components, NIST-mapped
Every claim
Cited to source — or rejected
Zero egress
Sealed, on-premise inference
Human
Sign-off before any release
The implementation

"Where did this come from, and why should I believe it?"

Legal, regulatory, and audit work has a question generic AI cannot answer. Enkidu systems are built so that question always has a complete answer: every trust claim is an assurance case — claim, argument, evidence — bound to a policy with an explicit threshold; every evidence item carries a citation resolvable to a specific document; and every inference is recorded in a signed, hash-linked chain of custody that makes tampering visible and every result reproducible.

The central rule: determinism where it matters, reasoning where it helps. Scores, thresholds, and rubrics are code-enforced ground truth. The language model interprets, extracts, and drafts — it never assigns the verdict.

    What it delivers
  • Citation-enforced outputs — uncited claims are rejected
  • Signed, tamper-evident chain of custody
  • Replayable runs — any historical result reproducible
  • On-premise, sealed from the internet — data sovereignty
  • Human review before anything is released
The work

What Dinanu does

Dinanu reads, organises, and cross-references the material of a matter — documents, records, and data — at a scale no team can, and returns findings a legal professional can verify: each one cited to sealed source material, reproducible, and carried in a chain of custody from first byte to final claim.

Every trust claim is an assurance case — claim, argument, evidence — bound to a policy with an explicit threshold; every evidence item carries a citation resolvable to a specific document; and every inference is recorded in a signed, hash-linked chain of custody that makes tampering visible and every result reproducible. The central rule: determinism where it matters, reasoning where it helps. Scores, thresholds, and rubrics are code-enforced ground truth. The language model interprets, extracts, and drafts — it never assigns the verdict.

The finished work product carries a certification of that entire chain. Verification never requires trusting the machine; it requires checking the record.

Citation-enforced outputs

Uncited claims are rejected.

Signed chain of custody

Tamper-evident, end to end.

Replayable runs

Any historical result reproducible.

Sealed on-premise

No egress — data sovereignty.

Human review

Before anything is released.

Diagram of Dinanu's seven planes, from access and presentation down to provenance and custody, with an invariant spine running the full height. Diagram of Dinanu's seven planes, from access and presentation down to provenance and custody, with an invariant spine running the full height.
scroll →
Fig. — Seven planes, one spine
Long description

Seven horizontal planes, top to bottom, against a single vertical spine — the spine is invariant, behaviour is configuration. P0, access and presentation: workspaces, notifications, gateway. P1, ingestion and fusion: multi-modal acquisition, normalised and policy-checked from the first byte. P2, knowledge and data: case-partitioned stores, facts, registries, the provenance ledger. P3, the deterministic logic layer: the only committers; the only paths to data. P4, the agent layer: agents propose; they never commit. P5, trust and policy control: the reference monitor; fails closed. P6, provenance and custody: append-only, tamper-evident, exportable.

Proven in production · Case study

Environment and Climate Change Canada

A multi-agent system that assesses business-capability maturity and assembles branch Digital Roadmaps from a large body of internal documentation — interview transcripts, process documents, incident reports, audit findings — delivered January to June 2026, running entirely on local infrastructure.

01 · Separation of duties

Seven agents, one verdict path

The agent that extracts evidence is not the agent that scores, which is not the agent that writes the narrative — and an independent critique agent can force a rescore. No component both proposes and commits.

02 · Anshar zones

Handoffs as contracts

The roadmap pipeline is a continuum of bounded zones, each with explicit entry and exit conditions and a coverage gate. Failures are designed-in error zones with a structured route back — never silent drops.

03 · Trust harness

Zero-trust, every step

Nothing an agent produces is trusted by default. Ingress sanitisation, per-agent tool allow-lists and budgets in flight, and schema, citation, groundedness, and PII checks before a word reaches the report. High-stakes checks fail closed.

In the client's words
"The system maintained a complete chain of custody over the source material it analyzed and generated a provenance record for every inference… this emphasis on evidence traceability and auditability was unusually rigorous for a proof of concept and gave us confidence in the integrity of the system's outputs."
Ellis Perryman A/Director, Environment and Climate Change Canada

"…the proof of concept met the objectives we set for it. I am glad to recommend him."

The line that never moves

Not a number someone typed.
A number a named, verifiable process produced.

The goal is not maximal trust but calibrated trust — reliance matched to demonstrated trustworthiness, because over-reliance and under-reliance are both failures. Every output is decision support: the final report is reviewed and released by an accountable human, and the question "who granted this agent the power it used?" is always answerable from the trace.

Externally defensible by design
AI risk managementNIST AI RMF · ISO/IEC 42001
Zero-trust architectureNIST SP 800-207
Provenance modelW3C PROV
Data sovereigntyOn-premise · no egress
Release authorityHuman-in-the-loop

This line holds in every Enkidu sector — see Trust.

Lineage

Part of Nabu

Dinanu is Nabu, tuned for legal work: the same platform, carrying privilege-aware models, legal policy packs, and the handling posture privileged material demands. What Nabu guarantees everywhere — a source behind every statement, a tamper-evident record of every step — Dinanu guarantees for the matter file.

The foundation

Built on Ekur

Every stage of a matter runs on the same shared stack — one layer for where things may happen, one for whether they may. Anshar makes each analytical stage a bounded zone with explicit entry and exit conditions and contractual handoffs; Kittu binds every claim to a policy threshold and captures the chain of custody behind it. The full detail lives on the platform page.

Enkidu

Put your analysis on the record

Book a walkthrough of the ECCC case study and see a committed result traced, claim by claim, back to its evidence.

Customisation services

Dinanu is staffed and tooled through Enkidu’s services. Ummânu — the Enterprise AI Workforce Instrument — supplies Tier 16 personas whose outputs are privileged drafts for a supervising avocat, fenced by a no-override gate. Kulla — the Governed Skill Production Instrument — supplies regulated-practice gates such as mise-en-demeure-lint, which checks form, not substance, and says so. A firm’s own filing conventions become promoted skills with fixtures, a registry entry and an approver.

Persona LibrarySkill Library
Ongoing research and investigation

Enkidu is evaluating NVIDIA ModelExpress for medium and large implementations of Dinanu — the Legal implementation of Nabu — where scale-out, failure recovery, rolling model updates, and surge ingestion all wait on model weight movement. Six integration patterns under evaluation keep one rule absolute: ModelExpress moves the bytes; the registry and the trust gate decide what may serve.

Evaluation and prototyping activity; no availability or performance claims.

NVIDIA ModelExpress