Honest answers. No sales talk.
Question not here? Email info@guardpilot.ai — you receive a personal answer within 24 hours.
An AI Pilot is not a tool that flags, but a living system that investigates on its own. GuardPilot reads every contract, invoice and ledger every night, builds evidence per finding and only then asks the right person a specific question — with an offer of help. Humans decide, AI informs. Always in that order.
Revenue you are contractually entitled to, but which never reaches the invoice or is billed too low. It arises from missed indexations, underbilling, duplicate or missing lines, forgotten escalation clauses and side letters that override the master agreement. Not fraud, usually not an incident — a structural pattern that only becomes visible on line-level comparison between contract, execution and invoice.
In contract-intensive services, structural leakage sits around 5.2% of annual revenue. On a €49.9M portfolio, GuardPilot found €2.6M in recoverable items in our own operation. The longer a contract runs without line-level control, the bigger the built-up backlog — indexations compound exponentially, and one missed side letter runs on for years.
Manually it is practically infeasible: one controller would spend months on one portfolio, and by definition work in samples. GuardPilot works line-by-line: 27 agents run every night through contract, execution and invoice. Every difference is investigated, backed with evidence and confirmed by two independent models before it passes as a signal to a human.
Personal data does not leave your network. Bulk processing runs locally on our own GPU; cloud analysis happens exclusively on anonymised data. No data exports outside the EU, no tracking, and every action is logged with actor and scope — traceability is a log line, not a promise.
No, and that is a firm design choice. Controllers shift from repetitive checking to reviewing and deciding. Your domain experts become part of the system: their answers become validated knowledge, and the system must never ask a question the organisation has already answered.
GuardPilot is available via a controlled waitlist; the first external pilots start in autumn 2026. The pilot structure is deliberately outcome-based: you pay based on what is actually flagged as recoverable revenue, not on seats or document volume. Concrete numbers are discussed in the intake, because portfolio characteristics determine the scope.
The first external pilots start in autumn 2026, controlled and one portfolio at a time. You can register via the waitlist; within 5 working days a short substantive conversation with the builder follows, to check together whether the match is right.
No — GuardPilot spans the entire company: administration, controlling, operations and commerce. HR records are read too, and every change is tested against laws and regulations, collective labour agreements and your own contractual arrangements. Every question that emerges is therefore tested on all those facets, not just one.
No. The system never makes autonomous decisions and never moves money. Every output is a question with an offer of help; only after your answer or approval does action follow — such as creating an additional-work number and preparing the invoice. Humans decide, technically enforced.
The model decides nothing — code decides whether a question is asked, about what and with which numbers; the model only supplies the wording. Every figure carries source, file and timestamp, two independent models cross-check each other (four-eyes principle), and if the model fails, the code itself constructs a fallback question. After every change, a fixed set of validated client cases runs as a test.
No — overload prevention is hard-enforced: a small maximum of questions per client per run, a repeat filter (the same question not repeated within seven days), materiality floors for micro-amounts, and ranking by financial impact. And the most important rule: healthy clients receive no question — over 90% remain provably silent every night.
The question doesn't disappear. First a controlled retry follows; if a response is structurally absent or the finding exceeds the mandate, an escalation proposal follows one level up the line — from location through region and district to the board. Escalation is always a proposal to a human, never an automatic decision.
Local-first: bulk analysis, OCR and embeddings run entirely on our own hardware — personal data does not leave the local network. Only the final synthesis runs on a frontier model, exclusively on anonymised data. Analysis always happens on a day-fresh copy, never on the source system itself.
Every finding passes four verification layers: figure-exact against the raw source, elimination (actively trying to explain it away via contract, cost type, duplicate or rhythm), a miss check and a maturity test. Hundreds of signals in one category are treated as a system error, not as hundreds of problems. What doesn't hold up disappears — with the reason logged.
Surprisingly little. The measurement layer, the contract understanding and the question logic are already in place. You arrange access to the source systems, and the owner and board answer the questions on which your organisation deviates from the standard — what should be included, who decides on what. The system does the rest.
About the context and history layer
The thirteen questions we get most often about working on an organisation's history. Feel free to share this page — this is the referral page.
No. A chatbot answers what you type. GuardPilot works on your organisation's history and context: it reads what exists, tests what is missing and reports where sources contradict each other — even when nobody asked.
No. Drafts are prepared in your own mail application, in your tone. You send them yourself. In fourteen days of production, fourteen drafts were prepared and zero sends were made by the system.
Yes, if available. What is not available is not guessed: a hard stop follows, stating which source is missing.
It stops. Missing data is a hard stop, not an assumption. In two weeks of production that happened four times — that is the intent, not a failure.
On your own equipment, locally, with private and business strictly separated. Local is a choice, not a technical detail: sensitive history does not belong outside the door.
Yes. In practice four simultaneous files were tracked without mixing them: each file keeps its own action list with party, date and waiting time.
Yes, and we show them. Four incidents from two weeks of production are listed with their measure on the context page. A system that hides its own misses cannot be checked.
A setup conversation, then reading in the history, then a first audit. No lengthy implementation up front: the first audit is the proof.
There is an orderly queue. We want to be further along before scaling up, so you join the waitlist and we get in touch once there is room. No sales pressure.
At the start, questions about what your company does differently from the rest, then yes, no or one word on the action list each round. In our experience, fifteen to twenty per cent of the context is your input.
Yes, that is exactly its strength: data from years back out of mail, chats, letters and bookkeeping, combined on today's question.
No. Questions are channelled: one situation, one question, answer a to d, phrased as help. No lists, no reckoning.
A system that forgets nothing and helps them do their work well, so mistakes are prevented and they keep time for what really matters.
The full evidence is on context and history.
Prefer a conversation over an FAQ?
30 minutes with the builder. No sales pitch.