Regulated & compliance-grade systems
For health data, age-restricted goods and advertising-claim law, the compliance walls are built into the system — not bolted on after.
A live platform holding special-category health data under UK GDPR.
Consent capture, data-minimisation, an isolated Firebase project, an audit log, and data-subject export — running today, not designed and shelved.

Machine-enforced claims-lint on a live regulated catalogue
A pre-commit lexicon guard checks changed product copy against a claims blocklist, with its known gaps written into the guard itself.
Age gates and claims walls for restricted-product storefronts
A fail-closed age/consent gate and a categorical content wall, built for a research-use products storefront — nothing regulated ships without them cleared first.
Handling data or claims the law is strict about? Let's talk it through.
Start a conversationLLM proposes, deterministic code commits, a human on every payment.
The discipline behind any money-adjacent build: an LLM may draft or flag, but it never fires a payment or a trade. That step is deterministic code, or a person.
Proven on a live-money system
A live-money automated trading system ran this split in production: no LLM in the execution path, multi-stage refusal gates, and exactly-once safety before anything fired.
Expense-claim automation, in discovery
For a timber-group finance process: nominal-code assignment with a confidence gate and duplicate-receipt detection — designed, not yet built.
- 01
Discovery
Map the data, the rules that bind it, and where a human must stay in the loop.
- 02
Build
Consent, isolation and gating built in from the first commit, not added at the end.
- 03
Handover
Audit trail and export paths proven working before go-live.
- 04
Maintain
Light ongoing care as rules or the catalogue change.
What kind of “regulated” does this cover?
Special-category health data under UK GDPR, age-restricted or advertising-claim-bound catalogues, and any money path where a payment must never be LLM-triggered.
Do you handle the legal side too?
No — MAST builds the system to the rules you or your solicitor set. The consent flows, isolation, audit log and gates are engineered to hold that line technically.
Is the money-discipline pattern only for trading systems?
No — it applies anywhere a payment or a financial commit is in scope: the proven pattern is LLM-propose, deterministic-commit, human-in-loop.
Tell MAST which piece of work consumes your week. Half an hour is enough to see whether an agentic system is worth building.
Start a conversation