Controlled AI matching
Tessera
AI matching for regulated firms. Identity stays pseudonymized throughout the match, rehydrated only in one controlled step, every match carries a written explanation, and bias is measured before a model ever ranks a real case.
The opportunity
A matching engine you can show a regulator
Candidate to role, portfolio to mandate, applicant to programme: any A to B match carries personal data the moment it reaches a model. Tessera separates the match from the identity, so your compliance, legal, and data protection teams get a system built around their questions from the first pilot.
The matching layer works on tokens, not names. The real record sits in a separate encrypted store the matching layer cannot read, rehydrated only in a controlled, one-shot step when a result needs a name attached. The model behind the match is Swiss and EU hosted, and swappable as your evaluation of providers evolves, with residency held to Switzerland and the EU by default; any change of provider is a controlled, customer-approved step.
How it works
Pseudonymize, match, explain, audit
Four steps, each one visible to the team running the match, not hidden inside a model call.
01
Pseudonymize
Names, contact details, and other identifiers are tokenized before anything reaches an external model. The real identity lives in a separate encrypted store the matching layer cannot read.
02
Review and send
The exact pseudonymized prompt appears on screen before it goes anywhere. Your team sends it, or aborts it, with the full text in view every time.
03
Match and explain
Local embeddings score each candidate pair on its own axes, skills, seniority, mandate fit, whatever the domain calls for, with a written, per-axis rationale for every result.
04
Audit
Every prompt, score, and decision lands in an append-only, tamper-evident trail your compliance team can open at any time, with cost tracked per match.
Step 02 in practice: the prompt your team sees before it sends
SYSTEM: Score candidate TOKEN-7F3A against role RQ-2291 on five axes: skills_fit, seniority_fit, mandate_fit, availability_fit, location_fit. Return a 0-100 score and a one-sentence rationale per axis. CANDIDATE (pseudonymized): TOKEN-7F3A skills: [python, portfolio-analytics, client-reporting] years_experience: 6 location_code: CH-ZH-03 ROLE: RQ-2291 required_skills: [python, portfolio-analytics, financial-modelling] seniority_band: mid-senior location_code: CH-ZH-03 No name, contact detail, or identifying field is present above. Rehydration to the real candidate record happens only inside the encrypted identity store, after this response returns.
Illustrative example. In a live Tessera workspace, both buttons are active and every send is logged to the audit trail.
Why Tessera
Residency, explainability, measured bias, controlled AI
Four properties your risk and compliance stakeholders will ask about first, built into the product from the first pilot.
Swiss and EU residency
Identity data stays in Switzerland and the EU. Only pseudonymized tokens reach the matching model, with rehydration back to identity handled in one controlled step inside the encrypted store.
Per-axis explainability
Every match carries a human-readable rationale, broken out by scoring axis, so your team reads the reasoning behind every result.
Measured bias
Matching models go through twin-CV and golden-matrix testing before release, producing a documented bias evaluation your team can review on a fixed retest cycle.
Controlled AI
Cost is visible per match, the model endpoint is swappable, and the full flow supports your FADP and GDPR obligations, audit-ready by design.
Infrastructure
Built on proven controlled-AI infrastructure
Tessera runs on the same architecture we use for controlled-AI financial workflows: pseudonymization ahead of every external call, authenticated and logged requests, and a decision trail your auditors can read end to end.
Authenticated, logged, authorised
Every request carries authentication, authorisation, and logging as a default property of the platform, not an add-on module.
Ahead of the direction of travel
The architecture is designed to support high-risk AI obligations as they take shape across the EU and Switzerland, giving your team a head start on the evidence a regulator or client audit will ask for.
Conformity-supporting by construction
Tokenisation, explanation, and audit trail are built into the matching flow itself, so the evidence pack for a review already exists when the review is requested.
Bring Tessera into your matching workflow
Early access starts with a short scoping conversation: your data classes, your matching axes, your rollout timeline. Reach out and we set up the first working session.
Tessera runs on synthetic and pilot data during early access. Production rollout with live identity data follows a scoping review with your compliance team.