Legal, Document intelligence

The clause that governs this claim is in a 2014 scan.
So is the answer you owe the regulator.

The wording, the endorsements, the claims file and the internal rule that governs them are all in the archive somewhere, mostly scanned, across systems never built to answer questions.

Oridex makes that archive answerable inside your own infrastructure: every answer carries the document, version, clause and page it came from, no document leaves your infrastructure, and the first workflow is in production in four weeks.

oridex
Illustrative, sample data
On-premise · Private cloud · Fully offline · Access-controlled retrieval · ISO/IEC 27001:2022
/ The moment

Tuesday, 10:40

A claims officer has a policyholder on the line.

The policy was underwritten in 2014. The wording sits in a scanned PDF. Two endorsements have amended it since, filed separately under a different reference. She needs the clause, the version in force on the date of loss, and some confidence that the colleague at the next desk would answer the same way.

She will get there. What she cannot produce is a record of how, and that gap is yours, not hers. It is the same gap that stretches every audit response. It lets two officers give two answers to one question, and stops the pilot at security review. One slow morning is a training issue. Ten thousand of them is an architecture decision, and it sits with you.

An answer you cannot cite is one your auditor cannot accept.

Every claim, every renewal, every review

/ What insurers hold

The archive is the hard part.

Not the model. Not the interface. The ten or twenty years of accumulated documents that every answer has to come from.

Volume that outgrew the tools

Large insurers can hold archives measured in tens or hundreds of terabytes. No context window holds it, and nobody is going to re-key it.

Every format the organisation ever used

Scans, photographed forms, faxes, PDFs of PDFs, Word and Excel. The documents outlive every system that stored them.

No single version of the truth

Wording withdrawn for new business still governs the book written under it. There is no correct answer to a coverage question, only the answer for this policyholder, on this date.

When audit asks why, you reconstruct

Decisions are defensible in substance but not traceable in record. Reviews can cost days, and the reasoning is rebuilt from memory.

/ Why the pilot stopped

Most insurers have already tried this once.

It stops in the same four places, and none of them are about the quality of the model.

01

The files have to leave

Uploading claim files to a third-party cloud is not a question compliance answers with yes.

02

The volume does not fit

An assistant that reads what you paste cannot read what you hold.

03

No reliable record of who read what

Access to policyholder records needs to be attributable to the user and the action taken. If the retrieval layer cannot produce that record, the control breaks before the answer reaches the screen.

04

No citation, no control

An answer with no source cannot be verified, so nobody downstream can act on it. The pilot demos well, then stops.

/ What we do

Three things, in this order.

01

Answers you can put in a file note.

Every answer is generated only from documents you registered, and shows the document, version, clause and page it came from. The system shortens the search; your officer still makes the decision, and when the file is reviewed later, the reasoning is in the record instead of in someone’s memory.

02

Nothing leaves your infrastructure.

Deployed on-premise or in your own cloud region, including fully offline, with the language models running inside your infrastructure. Documents are processed where they already sit. We build and own the platform, which is why running the whole of it inside your perimeter is a deployment option rather than a special project.

03

In production in four weeks.

One workflow, one document set, one outcome you can measure, agreed in writing before the build. Not a proof of concept that ends as a slide.

/ Which layer you need

Is your difficulty in the documents, or in the questions?

Two products, and the honest answer is that one usually has to come before the other. Worth settling before anyone builds anything.

Difficulty with the questions?

Start on this layer.

Difficulty with the documents?

Start on this layer.

Your claims and underwriting teams

Your policyholders

INSIDE YOUR INFRASTRUCTURE

ORIENE AI: THE ASSISTANTS PEOPLE TALK TO

Internal knowledge assistant

Policyholder-facing assistant

One AI-ready document base

cleaned, structured, versioned, access-mapped

Your other systems CRM / HRM

produces

ORIDEX: THE PLATFORM THAT MAKES THE ARCHIVE ANSWERABLE

Extract from PDF, scan, image, Word, Excel

Structure and version

Link what governs what

ingest as it is

YOUR ARCHIVE: AS IT IS TODAY

scanned matter files, advice memos, executed agreements, precedents, know-how: PDF, scan, image, Word, Excel

Two entry points, one stack, inside your infrastructure.

Illustrative architecture. Integrations scoped per firm.

The difficulty is in the documents

You need Oridex. A large archive, mostly scanned, many formats, accumulated over years across systems that no longer talk. The work is turning it into something that can be queried at all.

This is usually where the archive problem starts.

The difficulty is in the questions

You need Oriene AI. A defined, reasonably clean body of material, a precedent bank, a know-how library, a set of standard forms, and fee earners who need cited answers from it. When the material is already in good shape, Oriene runs on its own.

Smaller footprint, faster to stand up, and a sensible way to prove the approach on one practice group.

Both, eventually

Oridex prepares the archive for Oriene. When the archive is messy, Oridex gets the documents into a state Oriene can answer from; Oriene is the layer your lawyers actually use. Both can sit within the same deployment and access-control model.

Start with whichever half is blocking you. The other attaches later without rebuilding.
/ The platform underneath

What actually happens to a scanned matter file.

The claims officer’s 2014 policy, and what comes back once the archive has been ingested. Nothing is re-keyed, and the scan never leaves your infrastructure.

What you have

What Oridex hands back

The scan stays where it is. What comes back is the clause, version, page
and linked source information your team can verify.

Illustrative, constructed example

Three things the diagram does not show.

The shape is simple. These are the parts that decide whether it survives contact with a real firm archive.

One model does not read every document

A typed policy schedule, a photographed claim form and a thirty-page loss adjuster report do not yield to the same extraction. Document types are routed to the approach that handles them, and that routing is configured per archive, not assumed.

The language of the archive, not the model

For non-English archives we deploy recognition models for that language in place of general-purpose models tuned for English. We deployed this on the archive described below; it is not a locale setting.

Document access is on the record

Document read and write actions are recorded against a named user and retained to your policy. Retrieval respects the access rules mapped from your identity system, and the scope of that mapping is agreed per deployment.

/ In the work

The questions your teams actually ask.

Illustrative examples using sample data.

Claims

Was theft cover in force on the date of loss, at day 40 of unoccupancy?

Policy servicing

What do we need before a transfer endorsement can be issued?

Underwriting

Does our guideline allow cover for a warehouse with no sprinkler system?

Portfolio review

Which policies in this book carry the 2016 flood exclusion wording?

/ Where it runs

Run it where your data has to live.

Your security team will ask what a record contains before anything else.

ISO/IEC 27001:2022
CMMI Level 3
PDPA-ready

Your cloud

On-premise

Fully offline

Where it runs

Your AWS or Azure region

Your data centre

Your network, no internet

Your data leaves

No

No

No

Models run

In your region

Inside your infrastructure

Inside your infrastructure

Suits

Cloud-first insurers

Strict data residency

Air-gapped environments

Role-based access control, with access mapping agreed per deployment. Document read and write actions are logged. Encryption in transit and at rest.

audit log: one record
Illustrative format

Retention, key custody and support details are covered in the technical overview.

/ Delivered
East Asia
Insurance
Built and handed over by DEHA Global

A document intelligence platform,
then the assistants on top of it.

An insurance group in East Asia, holding more than ten years of policy, claims and legal records, several hundred terabytes, largely scanned, in a single non-English language, across PDF, scans and images, Word and Excel: product terms, claims procedures, internal rules, legal documents, and contracts negotiated individually with each policyholder.

They had already ruled out public cloud assistants, files could not leave, the volume did not fit, access could not be traced to a named employee, and without citations no answer could be relied on.

The group had no prior experience governing generative AI, and came to us asking for a chatbot. We advised against building one first. On that archive it would have failed the same way the public assistants had, so we built the document foundation underneath it instead.

Built to run fully offline inside the group’s own data centre, models, embeddings, database and processing, with no internet dependency

Recognition models for the archive’s own language deployed in place of general-purpose models tuned for English

Knowledge graph connecting product terms, claims procedures, internal rules, legal documents and individually negotiated contracts

Automatic document versioning and per-user access logging, built against the group’s obligations on personal data, information security, financial-advice standards, and human accountability for every answer

Two assistants specified on the same foundation: one for internal knowledge retrieval by staff, one for policyholder-facing Q&A, both designed to connect to the group’s CRM and HR systems

The output of that foundation is not a chatbot, it is a cleaned, AI-ready document base that other systems in the group can be built on. The two assistants were its first consumers, not the point of it.

DEHA Global built and handed over the platform and both assistant components against an agreed three-phase, six-month plan: a limited evaluation set with staff training first, then the internal assistant, then the policyholder-facing one. The customer is now rolling phases two and three out to its teams.

We do not publish performance figures for this deployment because we do not yet hold measured ones. The client and the delivery partner remain anonymous by agreement, the same discretion your own deployment would get. If you want a reference conversation, ask us and we will ask them.

/ The document your risk review wants

The technical overview, as a PDF. No meeting attached.

Architecture, deployment, access controls, data handling, integrations and model options, the detail a third-party risk team asks for before anyone talks about price. It arrives in your inbox, not your calendar.

One email with the PDF. One follow-up. No newsletter.

What is inside

Deployment options: on-premise, private cloud and fully offline, and what changes between them

The audit-log schema, retention, tamper-evidence and key custody

Data handling: sub-processors and DEHA Global access during delivery

Integration and model options: integration surface, AI-provider coverage and self-hosted models

Delivery model: scoping, support and the four-week implementation structure

/ Your alternatives

What you are comparing this against.

You are not choosing between us and nothing. Three other options are on your table, and each is the right answer for someone. Here is where each one wins, and where we do not.

A hyperscaler's
document AI

A large systems
integrator

Doing nothing yet

Oridex

What you get

Managed components for OCR, embeddings and retrieval in your cloud environment

A bespoke build, specified to your requirements

The current cost, unchanged

A platform that produces one versioned, permission-mapped document base

Where it wins

You already run that cloud, and your team can assemble the pieces

Deep process change beyond documents; a name your board recognises

The archive is not yet the constraint on anything expensive

The archive is the constraint, and the versioning between documents is the hard part

What it costs you

Your engineers own the assembly, the versioning logic and the maintenance

Typically 12–18 months and several times the licence cost; you own the result and its upkeep

Audit reconstruction, inconsistent answers, and the same blockers remain for the next pilot

A platform decision, and a smaller delivery organisation than a global SI

Language handling

Language support varies by service and model

Whatever the SI sources

-

Recognition models deployed for the archive's own language

Where we are the wrong choice: if your documents are already clean, structured and in one system, you do not need a document intelligence platform, you need an assistant, and Oriene AI on its own will be cheaper and faster. If your problem is process redesign rather than documents, call the systems integrator. We would rather say that now than in month three.

/ For systems integrators

If your insurance clients are asking for this, you can deliver it.

Some readers of this page are not insurers, they are integrators whose insurance clients have started asking for document AI, and who would rather deliver a platform than build one.

You hold the client relationship

You remain the prime contractor and the face of the engagement; we supply the platform and the engineering behind it. This is how the deployment described above reached its end customer, through a partner, not directly. Delivery scope and commercial terms are agreed before the engagement starts.

The platform is ours, so it can be shaped

Because Oridex is our own platform, not a resold API, its extraction, data model and deployment approach can be adapted to the client’s environment.

Including running entirely inside their environment where the client’s security review requires it.

Capacity under your badge

Integration is where your margin lives, and we are not looking to take it. A delivery centre of around 200 engineers, appraised at CMMI Level 3 and certified to ISO/IEC 27001:2022, can support delivery within your engagement. You choose which parts to hand over.

Partner contact

Brian Dang

CEO, DEHA Global
/ How it starts

From scoped practice group to production, in four weeks.

One workflow, one document set, one team, in production. 4 weeks A whole archive made answerable, at the scale described above. phased and scoped, not quoted from a website start week 4 month 3 month 6

We will tell you which of these two you are buying in the first conversation, not the third.

Week 1

Scope one workflow

One process, one document set, one measure of success, agreed in writing before the build. A mutual NDA is in place before any document is shared.

Weeks 2–3

Ground it

Your sources connected, indexed and permission-mapped. An evaluation set built from real questions your team actually asks, so success is measured against your work rather than a benchmark.

Week 4

In production

Live for one team, in the agreed deployment environment, monitored, with a retraining cadence and a support response commitment from day one.

After Week 4

Then it extends

More document sets, more teams, more assistants, on the same foundation, without a second platform decision.

And what we need from you.

Four weeks is four weeks of someone’s time, and some of it is yours.

One business owner who can sign off the measure of success

A few days of an application owner to get one document set out of the system holding it; for older systems this is often the longest dependency

A read-only copy of that set, and your access-control list in whatever state it is actually in

An early decision on whether a privacy impact assessment runs in parallel or in front, on its own, it can outlast the build

We'd prefer to lose a meeting over that last panel than discover it in week three.

/ FAQ

The questions that decide
whether this gets approved.

Can this run without any internet connection?

Yes. Models, embeddings, database and processing can all run inside your own data centre with no external dependency. The deployment described above was built to run this way. If you connect an external model provider instead, that is a configuration choice you make, and the boundary of what it receives is agreed during design.

No, that is the point of the platform. Scans and images are ingested as-is, with OCR and layout analysis, and different document types are routed to the extraction approach that best suits them.

You check it. Every answer shows the document, version, clause and page it came from, and it is generated only from the documents you registered. The system shortens the search; your officer still makes the decision. We do not publish an accuracy percentage because a number without a stated measurement method is not worth anything to your risk function.

Documents are versioned automatically as they change, and the knowledge graph links a policy to the endorsements and product terms that govern it. That is what makes date-of-loss questions answerable rather than approximate.

No. Your documents are used only within your own deployment, never to train models shared with other clients.

Your team, or ours, on your infrastructure, the deployment model is your choice and it can change later. Support carries a response commitment from day one.

There is no list price, because the archive determines the work. We scope against your sources, your channels and your deployment model, and quote against that.

See it on your own policy wording.

The technical overview answers most of what a security review asks, and it arrives without a conversation attached. When you want the conversation, it is with Brian Dang, CEO of DEHA Global, and the engineer who would run the deployment, bring one workflow and the questions your teams actually ask.


Delivering this to your own insurance clients? Say so when you write, partner terms are a separate conversation, held directly with Brian rather than through a sales process.