The case file, with its guardrails built in
Case and document software for UK family practice. Three jurisdictions kept apart, every authority checked against the register, nothing served without a named person, and an assistant that shows you what it read.
Numo Bot
It asks before it touches your accounts
Connected is not the same as authorised: every send, every document, every diary entry is its own card.

What it refuses to do
Most of the work is in what it will not do
Software that will do anything you ask is no use on a file a court will read. These four are enforced in the product, not promised in a policy.
It will not serve anything
Service, filing and sending each need a named person's decision, recorded against the exact version.
It will not invent a figure
Every number is computed in integer pence with its workings. A model never produces one.
It will not mix jurisdictions
An outgoing draft carrying another system's vocabulary is blocked, not flagged.
It will not cite what it cannot find
Authorities are checked against the registers first. Anything unverified is marked as such.
The assistant
Numo Bot reads the file, and shows you what it read
Ask it anything from any page. It knows which matter you have open and which page you are looking at, so "summarise this" and "is this binding" have an answer without you explaining yourself first.
- Every answer carries its sources
- Under each reply is a strip of what it actually read: the file by name, the register with its own mark, the web page with its address. An answer that cannot show its sources is an opinion.
- It cannot send, serve or approve
- It prepares. A draft lands on the Documents tab, a fact lands in the review queue, and a person decides. Nothing it writes leaves the firm on its own.
- It asks before touching your accounts
- When it wants to send from your Gmail or make a Google Doc, a card appears with exactly what would happen. Nothing runs until you press Allow, and each action is asked for separately.
Files
Two documents that disagree, found on the way in
Drop a Form E and the pension scheme's own statement in together, say what you want looked at, and Numo Bot comes back with the figure each one gives and the page it is on.
- It can read every file on the matter
- Numo Bot is connected to the whole file by default: everything read onto a matter you can see, it can see. What you cannot see, it cannot see either, because the same permissions decide both.
- Except what you seal
- A file locked into the vault is encrypted under that matter's own key. Numo Bot cannot read it at all unless you have unlocked the vault in this session and recorded a consent to analyse it, and it says so plainly rather than guessing around it.
- Screened before the model sees them
- A document that tries to instruct an automated reader is quarantined and withheld, then listed so a person knows it exists and reads it themselves.
Intelligence
What the file knows that nobody has said out loud
Two documents disagreeing about a deposit is a fact about the documents, and finding it should not depend on one person remembering both. The engine compares dates, amounts, account numbers and names across every file on a matter.
- Found without a model
- The comparison is deterministic and anchored to two pages. A model is asked afterwards, and only about a pair the comparison has already found.
- The book, drawn and interrogable
- Press anything in the graph and it names everything joined to it: the matters a person appears in, the files read, the places and photographs attached to either.
- Never a finding about a person
- Two documents disagreeing is reported as exactly that. Whether somebody was untruthful is for a court.
Your own accounts
Connected one service at a time
Gmail without Drive. Docs without Chat. Each one is its own connection, held for one person, and the page tells you exactly what connecting it grants before you do.
- GmailSend from your own address
- Google DriveBring a document in
- Google DocsDraft on your template
- Google SheetsBuild a schedule
Google CalendarPut a hearing in the diary
Google MapsFind and keep a place- DropboxFiles into a matter
CalendlyAppointments on the file
Bring a document in from a drive, draft in Google Docs from your own template, build a schedule as a Sheet, put a date in the calendar, send from your address. Numo Bot asks before each one, in plain words, and you press Allow or Decline.
How it is built
Built so the awkward questions have answers
Not a policy page. These are properties of the software, and each one is visible in the product itself.
Read the detail- A vault the server cannot open
- Per-object keys wrapped by a vault key derived from a passphrase with Argon2id. Filenames live inside the encryption, not beside it.
- An audit trail that cannot be edited
- Every action is hash-chained to the one before it and verified on every load. It reads as English, because evidence is read by people who were not there.
- Your role decides what you see
- Counsel, a guardian and a client see different things on the same matter, enforced by the database and not by the screen.
- Untrusted content stays untrusted
- Text from a document is data, never instruction. A file that addresses an automated reader is quarantined before anything reads it.
- Nothing leaves without a person
- Service, filing and sending all require a named human decision recorded against the exact version.
- No secret in the applications
- Every key lives in a function's own secrets. The apps hold two public values and nothing else.
See it on your own matters
Half an hour, your own file, and an honest answer about whether this fits how your firm already works.