For tax & legal teams

The grunt work systematised. The judgment kept.

You lived through cycle one: collecting numbers out of subsidiary accounts, interpretations nobody wanted to own, and a work product that cannot be reused. This is the system built by someone who understood exactly where that hurt — and who never asks you to trust an AI with a number.

review queue · group FY2024sign-off locked · 2 flags open
SEAnnual report · Group ABverified ✓p. 47
DEJahresabschluss · GmbHverified ✓p. 63
IEAnnual report · Ltdflagged — readings disagreep. 12
NLJaarrekening · B.V.verified ✓p. 55
FITilinpäätös · Oyverified ✓p. 31
GBAnnual accounts · Ltdverified ✓p. 78
CHGeschäftsbericht · AGflagged — fill fiscal yearscan
JP有価証券報告書 · K.K.verified ✓p. 104
DKÅrsrapport · A/Sverified ✓p. 29
NOÅrsregnskap · ASin review…
14 jurisdictions · 11 verified · 2 flagged · 1 in reviewnothing proceeds until the flags are cleared
How it works

Five acts. The AI reads. It never counts.

  1. 01

    Read — disagreement is the signal.

    Drop your annual reports in the window, one PDF per jurisdiction. The system identifies company, jurisdiction and fiscal year itself — and stops rather than guesses when it cannot. Every extracted figure is then read three times, by three genuinely different techniques: an AI reads the document, deterministic code verifies every value against the document itself, and a third, independent reading settles any disagreement — including on scanned documents. Two independent readings agree: verified. They don’t: flagged. Never a silent majority vote.

  2. 02

    Review — nothing is ever silently assumed.

    Every document — including the clean-looking ones — passes a human review queue. Each figure is shown with its value, confidence and verification verdict, and one click renders the actual page of your PDF with the value highlighted where it was read. Missing data points are flagged loudly and filled by hand; corrections become visible, dated premises and re-run through the engine. Sign-off is technically locked until every flag is resolved. There is no clicking past a warning.

  3. 03

    Calculate — same inputs, same filing, every time.

    From here down, no AI touches a number. Per jurisdiction, the deterministic engine runs financial net income → GloBE Income → Covered Taxes → ETR → top-up where the rate falls below 15%, with currency-aware de minimis testing. For every top-up, an honest indication of where it is likely collected: locally via QDMTT, or flowing to parent-level IIR. Every line of the calculation carries its OECD article. The whole chain is auditable — and the engine is verified against OECD’s published worked examples.

  4. 04

    Take a position — every judgment call, three ways.

    Only where a top-up is triggered: a guided walk through that jurisdiction’s grey zones, one question at a time, each ticked off as an active decision. Each question carries a slider from conservative to assertive with the practice-based recommendation marked, three parallel perspectives on the same point — the tax counsel, the consultant, the CFO — and the connected case law. Move the slider and the engine actually recomputes: the position is calculation input, not decoration. The result is not “the system calculated”. It is every grey zone deliberately decided by a qualified person, with the reasoning documented. And where the judgment is a price between your own companies, the walk continues into the arm’s-length layer below — both countries’ rules at once.

  5. 05

    File — a filing that validates, and defends itself.

    The GIR-XML is generated and validated against OECD’s official schema — real schema validation, with the outcome shown honestly. Your calibration reasoning travels as a separate risk annex, outside the GIR file itself, which carries only OECD’s own elements.

Intra-group flows

Arm’s length, seen from both ends at once.

Your factory in Poland sells to your distributor in Germany. Two tax authorities, two rulebooks, one price. The system lights up the defensible range with both countries’ reviewed transfer-pricing rules — while your amounts never leave your browser.

Step 1

Describe the flow

From-country, to-country, transaction type — goods, services, IP licence or financing — amount and declared price. The rows live only in your browser and export to your own file. Each row is two-sided: revenue at the seller is cost at the buyer, shown at both ends. Change a row, and every approval that relied on it falls back into the review queue.

Step 2

Light up the range

One click sends exactly three neutral parameters — the two countries and the transaction type. Never amounts, never prices; the API signature is locked by test, so a “practical” amount parameter can never creep in. Back comes the crossing of both profiles: accepted methods, range mechanics, audit posture, documentation thresholds, advance-pricing routes, and whether the pair’s treaty carries MLI.

Step 3

Pair analysis, fenced in

A further click lets an AI synthesise the pair’s full analysis under one hard rule: it may use only the two countries’ reviewed profiles. No model knowledge of the countries, no invented figures — gaps in the base are carried openly, and the pair’s specific treaty text is flagged for deep analysis instead of guessed. Six fixed sections, from how each side sees the flow to the risk picture both ways.

Why this cannot be one country’s memo: Hungary adjusts to the median if you price outside the range — and its US treaty is terminated. Vietnam accepts only percentile 35–75, so a lower-quartile price defensible almost everywhere else falls outside. Malaysia runs the narrowest range in the base (37.5–62.5) and may adjust even within it. South Africa’s secondary adjustment can never be treaty-relieved. New Zealand has legislated high inbound loan rates away. Six countries publish authority-set safe-harbour rates — carried in the profiles with current figures.

The profiles carry the countries’ rules and range mechanics — not benchmarking studies, not local files, not advice. The range is illuminated qualitatively: which side presses where, where the risk zones begin, which rates the countries themselves publish. Your position is always yours to set — including outside the illuminated range, clearly marked.

Architecture, not promises

Built to be doubted — and to hold.

Every objection you have about AI in tax is an objection we designed against. Not with claims — with structure.

The AI never touches a number

It reads documents. The engine is deterministic code. The two are never mixed — not in the product, and not in this sentence.

Its reading is never taken at its word

Two independent non-AI readings cross-examine everything the AI extracts. Agreement verifies; disagreement flags.

Uncertainty is never silent

Missing, unreadable, implausible or contested — every one becomes a flag that blocks sign-off until a human resolves it. The system refuses to approve what it cannot vouch for.

Judgment is shifted, not replaced

Your own tax people — the most qualified in the world on your numbers — own every decision. The system does the heavy lifting and shows exactly where it is unsure.

Confidential by design

Your risk profile — the positions you chose — is never persisted with us. It lives in your session and saves to a local file on your machine, version-anchored so a changed legal position flags the moment you load it. The same holds for intra-group flows: the rows live in your browser, and only country pair and transaction type ever reach the server. Architecture, not policy.

Everything is versioned

Every knowledge cell carries a content hash. If a cell changes, its reviewed status falls automatically until it has been reviewed again — and saved positions that relied on it are flagged.

Where the AI actually is

A smaller AI footprint than you’d guess — on purpose.

Your infosec team will ask. Here is the honest ledger.

AI is used for
  • Reading your documents. Extraction only, running on Google’s Gemini via Vertex AI in an EU region — and never taken at its word: cross-examined by two non-AI readings, then approved by a human against the source page. What it reads is annual reports: figures already published or filed with authorities. Where a group has its own hosting requirements, that is agreed per licence.
  • Building the knowledge base. The grey-zone material and the three lenses are researched and drafted with AI assistance — then adversarially reviewed by humans, version-hashed, and frozen. What you read at runtime is reviewed content, not live model output.
  • Synthesising the pair analysis — fenced in. On request, for intra-group flows: the AI may use only the two countries’ reviewed profiles, never its own knowledge of the countries. Gaps in the base are carried openly in the analysis instead of papered over. The call itself carries our two reviewed profiles and your three neutral parameters — no client data — and each run is keyed to the exact profile versions and model that produced it, so any analysis can be traced back to precisely what it was given.
  • Watching the law move. Continuous monitoring of new guidance and case law across the 58 jurisdictions. Every detected change flows through the same adversarial review before it reaches a cell — and your saved positions are flagged.
AI is never used for
  • The calculation. Deterministic code, verified against OECD’s worked examples. Same inputs, same filing, every time.
  • Your positions. The judgment is yours; the reasoning you rely on is pre-reviewed material with sources — no model improvises law at runtime.
  • Your risk profile. It never reaches a model, because it never leaves your machine.
  • Your intra-group amounts. Only country pair and transaction type ever cross the wire — the flow rows live in your browser and your own file.
The knowledge base

58 jurisdictions. Every cell adversarially reviewed.

Not scraped. Not generated. Researched against primary sources — statute, case law, administrative guidance, in the local language where it mattered — then attacked by an independent reviewer whose only job was to break it.

The elasticity in Pillar Two is real, but it sits in different places in every country: in classification, timing, method choices and documentation — almost never in old aggressive structures. No group can map that alone. Today that knowledge lives in expensive advisory hours, scattered and undocumented. Here it is a product: per country, per grey zone, with the sources visible.

58jurisdictions — EU/EEA complete, JP·KR·CA·AU, the Asian hubs, the low-tax centres, LatAm — and the US side-by-side as its own chapter
325grey-zone cells, each one adversarially reviewed against primary sources
~975reasoned perspectives — tax counsel, consultant and CFO, per cell
57transfer-pricing profiles — four transaction types per country: methods, ranges, safe harbours, documentation thresholds, treaty networks with MLI status
~870claims in the TP profiles adversarially tested against primary sources in two phases — reference drift and three treaty-count errors found and fixed; four genuine source contradictions carried openly
250+verified legal source references — no hallucinated cases found in review, anywhere in the base

The discipline is the moat: each cell is version-hashed, its reviewed status bound to the exact version that was reviewed. When the law moves, the change flows in under the same review — and every saved client position that touched that grey zone is flagged automatically.

grey-zone cell1 of 325 · reviewed ✓ · v-hash 8f3a…
the statute — and where the vagueness sits
conservative ↔ assertive position
practice-based recommendation
residual risk · amount leverage
tax counsel
consultant practice
the CFO
connected case law — what it actually says
licensed content — the structure is public, the substance is not

Dividend exclusions · arm’s length adjustments · QRTC classification of tax credits · deferred tax · SBIE substance · transitional safe harbour traps · de minimis · Art. 7.3 elections

In development — on the same rails that keep the base fresh

File before the ruling. Timing is a position too.

30 June is a deadline, not a date — a GIR can be filed months earlier. That matters, because the law under your positions moves by court ruling more often than by statute. Court calendars are public: the system is being extended to watch pending litigation across your group’s jurisdictions, flag when an expected ruling could move the ground under one of your positions, and put early filing on the table — filed in good faith on the law as it stands, before the ruling lands. Decision support with sources, as always: whether to file early is a judgment your counsel makes. We just make sure you are never the group that finds out about the ruling in July.

Fair questions

Asked by people who’ve been through cycle one.

We already have Big4 on this.

Keep them. The system doesn’t replace advice — it gives you the control and the underlying material, and lets your advisors review output instead of billing for the grunt work. Prevailing advisory practice is built in as a benchmark perspective on every grey zone.

AI can’t be trusted with tax law.

Correct. That is why the AI never touches the calculation or the law: it reads documents, it is cross-examined by two non-AI readings, and the law comes from a human-reviewed knowledge base with statute and case law behind every position.

Can we trust the extraction?

Three independent readings per figure, and you approve every number against its source page — highlighted in your own document — before anything is calculated. Errors are caught and flagged: three readings, plausibility gates, blocked sign-off.

What happens when the rules change?

The knowledge base is versioned with content hashes. When the legal position moves, the change flows in under the same adversarial review — and any saved position of yours that touched the affected grey zone is flagged automatically, even in old profiles.

What does it cost?

Licensed annually per group — a base fee plus a per-jurisdiction rate, so the price scales with your actual footprint. A single-jurisdiction group starts at €47,500 a year; a typical fourteen-jurisdiction group lands around €150,000. Every licence includes independent local counsel review of each jurisdiction’s knowledge base, contractual update SLAs, source and knowledge-base escrow, and unlimited users. Founding member terms are available for the first groups. Or compute your exact number yourself →

What happens if the supplier disappears?

Your positions are already a local file in your hands, and escrow is offered per contract — the full answer, including the security posture, lives on the procurement page.

We’re a US-parented group.

Then Pillar Two may genuinely not be your problem — the side-by-side arrangement carves most US-parented groups out, and the system identifies and tells you so honestly at upload. We would rather flag that than sell you a licence.