AllClear

Agents investigate. Humans decide.

Track: Fortified Enterprise Fleet — live at allclear.neuralops.com


Inspiration

Every piece of marketing a broker-dealer publishes — a tweet, an email blast, a fund one-pager — is regulated by FINRA Rule 2210. Firms burn compliance hours reviewing it by hand, and still get fined (Merrill Lynch $5.8M, Wells Fargo $4M, M1 Finance $850K). Meanwhile FINRA itself proposed (July 2026) replacing mandatory pre-approval with a risk-based supervisory framework — which no vendor has shipped, because it isn't final. We built it.

What it does

AllClear runs the entire Rule 2210 workflow autonomously, with a human only where the rule demands one:

Agent Responsibility
Classifier Audience and category under 2210(a) — retail, correspondence, institutional
FINRA Agent (×3, parallel) Prohibited claims, disclosures, basis-for-claims
Enterprise Compliance Agent The firm's own uploaded policies (CPG-n)
State Agent State-level regulations (STATE-n)
Supervisor + Rewrite Agent Routing rationale and the compliant redraft with required legends
Policy Agent Watches principal decisions; drafts new firm policies for recurring gaps — humans keep the delete key

It reviews text, PDFs, audio, and video. Click a finding and the player seeks to the exact second the violation was spoken. Every case ends in write-once storage that even the project owner cannot delete.

What makes it different

AI ad-review tools exist (Saifr, Red Oak, Hadrius). They flag; a human does everything else. AllClear decides, routes, remediates, computes the filing obligation, and archives. Two guarantees are structural, not prompted:

  • No fabricated citations. A deterministic gate resolves every finding against rules/rule_2210_corpus.json and requires the quote to match the source verbatim; unresolvable findings are dropped before any human sees them.
  • Real immutability. Records land in a GCS bucket under a locked retention policy (Bucket Lock — the mechanism Cohasset assessed for SEC 17a-4(f)). gcloud storage rm as project owner returns 403.

Risk is scored by code, not model vibes — diminishing returns per finding, capped:

$$ risk = \min\left(0.99,\; 1 - 0.72^{\,n_{high}} \cdot 0.88^{\,n_{med}} \cdot 0.95^{\,n_{low}}\right) $$

and routing is an if-statement, not a prompt: retail communications never auto-approve, because 2210(b)(1) requires a principal's signature first.

How we built it

Gemini 3.5 Flash on Vertex AI. Google ADK — ParallelAgent fans out the three auditors with shared session state; SequentialAgent orders the pipeline. Cloud Run hosts three scale-to-zero services (intake, pipeline, Next.js console) behind Cloud Load Balancing with Google OAuth and 30-minute sessions. Firestore holds the case state machine and append-only event trail; Pub/Sub decouples intake from the fleet, idempotent on redelivery. Judgment is LLM; guardrails — citation gate, filing calculator, routing, state machine — are deterministic, unit-tested Python (17 tests).

Challenges

Google's frontend silently swallows Cloud Run paths ending in "z" — our /healthz endpoint 404'd at the edge with zero request logs while the service was Ready and healthy. An hour of phantom debugging later: renamed to /health. Gemini publisher models resolved only on Vertex's global endpoint for our project. And locking a bucket's retention policy is genuinely irreversible — we locked 24 hours, not 6 years, on purpose.

Accomplishments

Full pipeline live on GCP on day one of building. A red-team ad with a fake "SEC-endorsed" claim: caught, cited, remediated. A compliant institutional piece: zero findings, auto-approved, archived, untouched by humans. A real TV ad: transcribed with on-screen text read by Gemini, violations timestamped to the second.

What's next

Real AREF/FINRA Gateway filing packets, PMS integrations for RIA/BD hybrids, and the corpus pattern generalized to other rulebooks — the SEC Marketing Rule, HIPAA marketing.

Links

Built With

Share this project:

Updates