Tie out MD&A figures
A workpaper that ties each MD&A figure to the table cell or calculation it came from, and flags the ones that do not match.
Built on: Numeric grounding, Grounding, Signed record
Loading the tool…
Use it your way
Use it from your codeThe hosted API with your key, and prompts to paste into a coding agent
Run it yourself, on request
- The same open models and app, on Any CPU for the tie-out; 1× RTX PRO 6000 (96 GB) or 1× RTX 5090 (32 GB) for Qwen3.8-27B if you want claims in words read.
- Data never leaves your machines, and there are no Decosa charges.
- One prompt for Claude Code or Codex assembles the whole stack.
- Early access: the container images are not public yet and the source needs access; the prompt says how to ask.
Get an API key
- Call the filing tie-out and md&a grounding API from your own code in minutes.
- Every model answer carries a signed receipt.
- Synthetic, public or test data only: real confidential data belongs on your own hardware.
Build with it
Paste one of these into Claude Code, Codex or another coding agent. The first wires your project to the hosted API with your DECOSA_API_KEY. The second pulls our containers and runs the same stack on your own GPU, with no Decosa charges.
- Base URL
- https://api.decosa.ai
- Auth
Authorization: Bearer $DECOSA_API_KEY(or a demo session token)- Tool id
- filing-tieout
Use the hosted API
# Decosa filing tie-out: use the hosted API (public filings only)
You are wiring Decosa's filing tie-out into this project. For a 10-K or 10-Q it ties every figure in the MD&A prose to
the filing's tagged statements and notes, in code: the cell it equals (fact id, table, period), or the change,
percentage change, margin or sum it is computed from, or a flag naming the cell it was compared with (a different value,
another period's figure, the wrong scale, the other direction, a Note reference to the wrong note, a fact shown with
two values). Figures the tables do not show come back `untraced` for a person. It returns a Markdown and CSV workpaper
and a signed record. Use only what is listed below. If you need something else, stop and ask me.
- Base URL: `https://api.decosa.ai`
- Health check: `GET https://api.decosa.ai/healthz`.
- **The hosted API ties public filings only.** Pre-release financial statements are material non-public information.
Use a bundled sample or an EDGAR accession; anything you paste (`html`, `tables`, a `draft`) must be public or
synthetic and needs `"public": true` (HTTP 400 otherwise). Drafts belong on a self-hosted box (see the self-host prompt).
- It is a preparer's and reviewer's aid, not an audit and never "compliant". Say so wherever you show results.
## Auth: API key (or a demo session)
1. Preferred: an API key (`dk_…`) from "Get an API key" on the tool page, kept in `DECOSA_API_KEY`, never in code.
Send `Authorization: Bearer $DECOSA_API_KEY`.
2. Without a key: `POST https://api.decosa.ai/demo/session` with `{"vertical": "filing-tieout"}` returns
`{"token", "expires_at", "budget"}`. Sessions per IP are limited (HTTP 429 with `Retry-After`).
3. Figures need no model and no budget. With `"judge_claims": true` (the default) up to 12 claims in words are read
by the model, about 260 generated tokens each; with too little budget the claims are skipped and a `warning` says so.
## Endpoints
- `GET /tieout/samples`, `GET /tieout/info` (no token): samples (AMD's 10-K with planted errors and as filed, Applied
Optoelectronics' 10-K, a synthetic company), statuses, limits and regulatory notes.
- `POST /tieout/check` (token). Body, exactly one source:
```json
{"sample": "amd-fy2025-planted", "judge_claims": true}
{"edgar": {"cik": "2488", "accession": "0000002488-26-000018"}, "judge_claims": false}
{"tables": [{"title": "Income", "scale": "millions", "csv": "Line,2025,2024\nNet sales,1248.6,1102.3\n"}],
"draft": "Net sales were $1,248.6 million in 2025.", "public": true}
```
Answer: `{status: mismatches|review|tied, counts, coverage: {figures, traced}, filing, sentences: [{sid, text, status,
figures: [{text, status, reason?, period, source?: {label, period, value, fact, table}, derivation?: {op, expr, value},
expected?, detail?, hint?}], direction, notes, claim}], cross_refs, trial_balance, receipts, workpaper_md,
workpaper_csv, report}`. Show every `mismatch` with its `detail`; show `untraced` as "check by hand", never as an
error. SSE with `Accept: text/event-stream`: `ready`, `sentence`, `receipt`, `warning`, `report`, `budget`, `done`.
- `POST /tieout/verify` (no token): `{report, workpaper_md?, workpaper_csv?}` returns `{valid_signature,
signed_by_this_server, workpaper_md_matches, workpaper_csv_matches}`. File the workpaper and the record together.
## Errors
400 bad input (the message says what: not public, no MD&A found (send `draft`), not inline XBRL, a bad accession,
an EDGAR error), 401/403 token, 409/429 busy (`Retry-After`), 413 body over 24 MB.
Run it yourself (containers)
On request. The container images and the compose file aren’t public yet. Ask for self-host access and Decosa sends the registry (DECOSA_REGISTRY) and the compose file’s URL (DECOSA_COMPOSE_URL) these steps use. They are the steps we tested end to end on a fresh machine.
# Decosa filing tie-out: run it yourself (containers)
You are setting up the Decosa filing tie-out on this machine, so drafts of financial statements never leave it. It
ties every figure in a 10-K or 10-Q's MD&A to the tagged statements and notes in code, flags the ones that do not tie
with the cell it compared them with, and writes a workpaper and a signed record. The tie-out needs only a CPU; the
model (Qwen3.8-27B) is optional and only reads claims in words. Nothing is sent to Decosa's hosted API. It is a
preparer's and reviewer's aid, not an audit.
Status: the container images (${DECOSA_REGISTRY}/decosa-*) and the compose file are on request while self-host is in early access (not on a public registry yet): ask at https://decosa.ai/contact?topic=self-host, and Decosa sends the registry as DECOSA_REGISTRY, the compose file URL as DECOSA_COMPOSE_URL, and pull access. If a pull fails with
"not found", "denied" or "unauthorized", stop and tell me. Do not substitute other images.
Ask me before any command that needs sudo, and show me the command first.
## Step 0: set up with a coding agent, rehearse on mock data, then go private
This prompt is for a coding agent running on the machine that will host the service. We recommend Claude Code with
Claude Opus 5.5; any capable coding agent works. Work in this order:
1. Set up on mock data only. During the whole setup you (the agent) work with the synthetic sample bundle below and
nothing else. Do not ask me for real data, and do not open, read, list or copy files that hold real data, even to
"test with something realistic".
2. Rehearse. When the steps below are done and the service is healthy, fetch the mock-data bundle for this tool,
https://decosa.ai/samples/filing-tieout.zip (3 KB, 16 checks, synthetic or openly licensed: see `licence` in expected.json),
show me what is in it, and run the rehearsal against the local API:
`docker compose exec api python scripts/rehearse.py filing-tieout` (the api image carries the same bundle under /app/rehearsal/filing-tieout/;
with no key set, the script asks the local API for a short demo token). From a decosa-api checkout instead:
`python scripts/rehearse.py filing-tieout --bundle filing-tieout.zip --base-url http://127.0.0.1:<PORT>`.
It sends the mock inputs to the local API and prints PASS or FAIL for each expected property (for example: "the synthetic draft does not tie", "the transposed 2024 net income is a value mismatch naming the table's figure", "the inventories accounts do not roll up to the balance sheet"). Show me
the full output. Every check must pass. If one fails, fix the install and run it again; never edit `expected.json`
to make a check pass.
3. Stop there. Once the rehearsal passes, tell me, and I will run my own data against the local API myself, on this
machine.
For the person running this: a coding agent that runs in the cloud sees everything in its context, including files it
reads, command output and anything pasted into the chat. Keep real data out of the chat and out of anything the agent
can read. Switch to your own data only after the rehearsal has passed and the agent's work is done.
## Steps
1. Docker: if `docker compose version` fails, install Docker Engine and the compose plugin using Docker's official
instructions for this distribution (docs.docker.com/engine/install). Only if I want claims read by the model:
install the NVIDIA container toolkit and check `docker run --rm --gpus all nvidia/cuda:12.8.0-base-ubuntu24.04 nvidia-smi`.
2. Fetch the compose file:
`mkdir -p ~/decosa && cd ~/decosa && curl -fsSL "${DECOSA_COMPOSE_URL}" -o compose.yaml`
Read it. Keep the `api` service, and the `llm` service only if I want claims read. For the `api` service set
`DECOSA_TIEOUT_PUBLIC_ONLY=0` (so this box accepts drafts), `DECOSA_CONTACT_EMAIL` to my address (EDGAR asks for
one in the User-Agent) or `DECOSA_TIEOUT_EDGAR=0` if the box must stay offline, and bind every port to 127.0.0.1.
With the model: `DECOSA_LLM_ROUTE=direct`, `DECOSA_LLM_URL=http://llm:8000/v1`, `DECOSA_LLM_MODEL=qwen3.8-27b`.
Never set the gateway route on this box: it would send draft text to the Decosa API.
3. Pull and start: `docker compose pull && docker compose up -d`.
4. Check: `curl -fsS http://127.0.0.1:<PORT>/tieout/info` shows `public_only: false`. `GET /attest/signing-key` shows
this box's public key; show it to me, it is what a reviewer pins.
5. Smoke test: get a token with `POST /demo/session {"vertical":"filing-tieout"}` and send
`{"sample":"amd-fy2025-planted","judge_claims":false}` to `POST /tieout/check`. Expect `status: "mismatches"`,
figure mismatches with reasons value, value, period and scale, one direction flag, one wrong Note number, one
`same_fact_two_values` cross-reference, and `coverage.traced` 44 of 57. Then `POST /tieout/verify` with
`{report, workpaper_md, workpaper_csv}`: all must be true. The rehearsal bundle
(`python scripts/rehearse.py filing-tieout`) runs the same checks and a synthetic company.
6. Report back: the public key, the counts and how long the check took.
Off by default. Joining as a provider serves other people's requests on this GPU; never do it on a box that holds
unreleased financial statements. If I ask for it later, follow the Provide page instead of improvising.
Run it on your own hardwareWhat it needs, and the prompt that sets it up
Run it on your own GPU
Same app, same pinned models, your hardware. Nothing goes to our servers and there are no Decosa charges.
Hardware check
Check your own hardware- CPU only, 64 GB RAMlite tierRuns with a smaller tier
The standard tier does not fit: Qwen3.8-27B (NVFP4) needs a GPU. The lite tier fits.
- GeForce RTX 4090standard tierRuns
The standard tier fits with changes: Replace Qwen3.8-27B (NVFP4) with A community 4-bit build of Qwen3.8-27B (AWQ or GGUF). This build is NVIDIA NVFP4, which needs a Blackwell GPU. (Memory is an estimate.)
- GeForce RTX 5090standard tierRuns
The standard tier fits with changes: Qwen3.8-27B (NVFP4): run it at its smallest setting (about 28 GB instead of 57.6 GB), with a shorter context and fewer parallel sessions.
- 2x GeForce RTX 5090standard tierRuns
The standard tier fits with changes: Split the language model across the GPUs with tensor parallelism (vLLM --tensor-parallel-size).
- L40Sstandard tierRuns
The standard tier fits with changes: Replace Qwen3.8-27B (NVFP4) with Qwen3.8-27B official FP8. This build is NVIDIA NVFP4, which needs a Blackwell GPU.
- H100 80 GB (SXM)standard tierRuns
The standard tier fits with changes: Replace Qwen3.8-27B (NVFP4) with Qwen3.8-27B official FP8. This build is NVIDIA NVFP4, which needs a Blackwell GPU.
- RTX PRO 6000 Blackwell 96 GBstandard tierRuns
The standard tier fits (57.6 of 96 GB).
- 2x RTX PRO 6000 Blackwell 96 GBstandard tierRuns
The standard tier fits (57.6 of 192 GB).
- Apple M3 Ultra (Mac Studio), 96 GBstandard tierRuns
The standard tier fits with changes: Replace Qwen3.8-27B (NVFP4) with Qwen3.8-27B MLX 4-bit. MLX build for Apple Silicon.
- Apple M5 Max, 64 GBstandard tierRuns
The standard tier fits with changes: Replace Qwen3.8-27B (NVFP4) with Qwen3.8-27B MLX 4-bit. MLX build for Apple Silicon.
Memory per component comes from measured footprints, the tool's stack.json, or an estimate from its parameter count, and each is labelled that way below. Only an RTX PRO 6000 and an M3 Ultra Mac Studio have actually been run.
On request. The container images and the compose file aren’t public yet. Ask for self-host access and Decosa sends the registry (DECOSA_REGISTRY) and the compose file’s URL (DECOSA_COMPOSE_URL) these steps use. They are the steps we tested end to end on a fresh machine.
- 1
Check the GPU, Docker and the NVIDIA Container Toolkit
The driver must see the GPU, and Docker must be able to pass it into a container.
nvidia-smi docker compose version docker run --rm --gpus all ubuntu nvidia-smi
- 2
Fetch the compose file
One file describes the API and the language model as services.
mkdir -p ~/decosa && cd ~/decosa curl -fsSL "${DECOSA_COMPOSE_URL}" -o compose.yaml - 3
Pull and start
The first start downloads pinned model weights, tens of gigabytes.
docker compose pull docker compose up -d
- 4
Check health
Wait until the API reports ok with the language model loaded. Then point your app at the local base URL.
curl -fsS http://localhost:<PORT>/healthz # {"ok": true, "llm": true, ...} curl -fsS -X POST http://localhost:<PORT>/demo/session \ -H 'Content-Type: application/json' -d '{"vertical":"filing-tieout"}'
Set up with a coding agent, rehearse on mock data, then go private
- Set up with a coding agent. Paste the self-host prompt into a coding agent on the machine that will run the service. We recommend Claude Code with Claude Opus 5.5; any capable coding agent works.
- Rehearse on mock data. The agent runs the tool on a bundle of synthetic inputs and checks each answer against the bundle's
expected.json. Every check must print PASS. - Go private. Only then do you run your own data against the local API, yourself, on that machine. Never give the agent real data during setup: a coding agent that runs in the cloud sees everything in its context, so keep real data out of the chat and out of the files it reads.
docker compose exec api python scripts/rehearse.py filing-tieout
Download the mock-data bundle (3 KB, 16 checks)expected.json
Two runs, for a self-hosted install (DECOSA_TIEOUT_PUBLIC_ONLY=0; on a public-only instance the pasted tables need "public": true, which the first step sends). First, a made-up company (Example Instruments Co.): its income statement and balance sheet as CSV in millions, a trial balance mapped to three balance-sheet lines, and a short MD&A draft in which 2024 net income is written as $64.2 million instead of $62.4 million. Second, AMD's filed FY2025 10-K (bundled with the API, public domain) with six errors planted in its MD&A text and one note table changed. Figures are tied in code with no model call (judge_claims false), so the rehearsal needs no GPU. Every planted error must come back as a mismatch naming the right cell, the rest must tie or compute, and the signed record must verify and catch a changed status.
What the rehearsal checks
- the synthetic draft does not tie
- the transposed 2024 net income is a value mismatch naming the table's figure
- the inventories accounts do not roll up to the balance sheet
- the cash accounts roll up exactly
- the planted AMD draft does not tie
- four planted figures are mismatches (value, value, period, scale)
- the scale error names the $577 million cell
- the swapped period is recognised as another year's figure
- the flipped direction is caught
- the wrong note number is caught
- the note table that disagrees with the income statement is caught
- most figures still tie or compute
- no model call was made (figures only)
- the signed record verifies with both workpapers
- the Markdown workpaper matches its hash
- a changed status breaks the signature
Licence: The synthetic company, its tables, trial balance and draft are made up (part of decosa-api, AGPL-3.0-or-later). The AMD 10-K is an SEC EDGAR filing, a US government work in the public domain (17 U.S.C. 105).
Prompt for your coding agent
# Decosa filing tie-out: run it yourself (containers)
You are setting up the Decosa filing tie-out on this machine, so drafts of financial statements never leave it. It
ties every figure in a 10-K or 10-Q's MD&A to the tagged statements and notes in code, flags the ones that do not tie
with the cell it compared them with, and writes a workpaper and a signed record. The tie-out needs only a CPU; the
model (Qwen3.8-27B) is optional and only reads claims in words. Nothing is sent to Decosa's hosted API. It is a
preparer's and reviewer's aid, not an audit.
Status: the container images (${DECOSA_REGISTRY}/decosa-*) and the compose file are on request while self-host is in early access (not on a public registry yet): ask at https://decosa.ai/contact?topic=self-host, and Decosa sends the registry as DECOSA_REGISTRY, the compose file URL as DECOSA_COMPOSE_URL, and pull access. If a pull fails with
"not found", "denied" or "unauthorized", stop and tell me. Do not substitute other images.
Ask me before any command that needs sudo, and show me the command first.
## Step 0: set up with a coding agent, rehearse on mock data, then go private
This prompt is for a coding agent running on the machine that will host the service. We recommend Claude Code with
Claude Opus 5.5; any capable coding agent works. Work in this order:
1. Set up on mock data only. During the whole setup you (the agent) work with the synthetic sample bundle below and
nothing else. Do not ask me for real data, and do not open, read, list or copy files that hold real data, even to
"test with something realistic".
2. Rehearse. When the steps below are done and the service is healthy, fetch the mock-data bundle for this tool,
https://decosa.ai/samples/filing-tieout.zip (3 KB, 16 checks, synthetic or openly licensed: see `licence` in expected.json),
show me what is in it, and run the rehearsal against the local API:
`docker compose exec api python scripts/rehearse.py filing-tieout` (the api image carries the same bundle under /app/rehearsal/filing-tieout/;
with no key set, the script asks the local API for a short demo token). From a decosa-api checkout instead:
`python scripts/rehearse.py filing-tieout --bundle filing-tieout.zip --base-url http://127.0.0.1:<PORT>`.
It sends the mock inputs to the local API and prints PASS or FAIL for each expected property (for example: "the synthetic draft does not tie", "the transposed 2024 net income is a value mismatch naming the table's figure", "the inventories accounts do not roll up to the balance sheet"). Show me
the full output. Every check must pass. If one fails, fix the install and run it again; never edit `expected.json`
to make a check pass.
3. Stop there. Once the rehearsal passes, tell me, and I will run my own data against the local API myself, on this
machine.
For the person running this: a coding agent that runs in the cloud sees everything in its context, including files it
reads, command output and anything pasted into the chat. Keep real data out of the chat and out of anything the agent
can read. Switch to your own data only after the rehearsal has passed and the agent's work is done.
## Steps
1. Docker: if `docker compose version` fails, install Docker Engine and the compose plugin using Docker's official
instructions for this distribution (docs.docker.com/engine/install). Only if I want claims read by the model:
install the NVIDIA container toolkit and check `docker run --rm --gpus all nvidia/cuda:12.8.0-base-ubuntu24.04 nvidia-smi`.
2. Fetch the compose file:
`mkdir -p ~/decosa && cd ~/decosa && curl -fsSL "${DECOSA_COMPOSE_URL}" -o compose.yaml`
Read it. Keep the `api` service, and the `llm` service only if I want claims read. For the `api` service set
`DECOSA_TIEOUT_PUBLIC_ONLY=0` (so this box accepts drafts), `DECOSA_CONTACT_EMAIL` to my address (EDGAR asks for
one in the User-Agent) or `DECOSA_TIEOUT_EDGAR=0` if the box must stay offline, and bind every port to 127.0.0.1.
With the model: `DECOSA_LLM_ROUTE=direct`, `DECOSA_LLM_URL=http://llm:8000/v1`, `DECOSA_LLM_MODEL=qwen3.8-27b`.
Never set the gateway route on this box: it would send draft text to the Decosa API.
3. Pull and start: `docker compose pull && docker compose up -d`.
4. Check: `curl -fsS http://127.0.0.1:<PORT>/tieout/info` shows `public_only: false`. `GET /attest/signing-key` shows
this box's public key; show it to me, it is what a reviewer pins.
5. Smoke test: get a token with `POST /demo/session {"vertical":"filing-tieout"}` and send
`{"sample":"amd-fy2025-planted","judge_claims":false}` to `POST /tieout/check`. Expect `status: "mismatches"`,
figure mismatches with reasons value, value, period and scale, one direction flag, one wrong Note number, one
`same_fact_two_values` cross-reference, and `coverage.traced` 44 of 57. Then `POST /tieout/verify` with
`{report, workpaper_md, workpaper_csv}`: all must be true. The rehearsal bundle
(`python scripts/rehearse.py filing-tieout`) runs the same checks and a synthetic company.
6. Report back: the public key, the counts and how long the check took.
Off by default. Joining as a provider serves other people's requests on this GPU; never do it on a box that holds
unreleased financial statements. If I ask for it later, follow the Provide page instead of improvising.
Help me customise for my hardware
Pick your GPU or Mac, or enter its memory. You get the tier that fits, the model swaps it needs, measured speed where we have it, and a setup prompt with those choices written in.
GeForce RTX 5090: 32 GB GDDR7, 1,792 GB/s, FP8 and NVFP4. NVIDIA product page
RunsFiling tie-out and MD&A grounding on GeForce RTX 5090: use the Standard · one GPU for claims in words (hosted demo) tier
The standard tier fits with changes: Qwen3.8-27B (NVFP4): run it at its smallest setting (about 28 GB instead of 57.6 GB), with a shorter context and fewer parallel sessions.
What this tool's stack says about this hardware:
- 1x RTX 5090 32 GB (fits): Estimate: Qwen3.8-27B NVFP4 needs about 20 GB of weights plus KV cache; not run for this use case.
Standard · one GPU for claims in words (hosted demo): what changesuses estimates
- Qwen3.8-27B (NVFP4): run it at its smallest setting (about 28 GB instead of 57.6 GB), with a shorter context and fewer parallel sessions.
Memory per component
- iXBRL parser, figure tie-out, period and scal...: decosa-api tie-out (decosa_api/verticals/tieout) with the numeric grounding block's table-cell matcher (decosa_api/verticals/numeric/cells.py). CPU. Runs on CPU (vram_gb 0 in stack.json).
- Claims in words: Qwen3.8-27B (NVFP4). ~57.6 GB (at least ~28 GB), weights 21.4 GB (from stack.json). Qwen3.8-27B NVFP4: Weights 19.9 GiB (21.4 GB), measured (field stack.json). The compose file gives the server 0.60 of a 96 GB card (57.6 GB) so the rest is FP8 KV cache for several sessions. The 28 GB minimum is an estimate: weights plus a short-context KV cache, which is why several stacks list a 32 GB RTX 5090 as 'estimate'. (stack.json lists 20 GB for this component.)
Expected speed
Not measured.
Not measured on this hardware. The only measured setups are an RTX PRO 6000 Blackwell and a Mac Studio M3 Ultra.
Setup prompt for this hardware
The self-host prompt for Filing tie-out and MD&A grounding, with a hardware plan for GeForce RTX 5090 added after Step 0. Loading the full prompt; until then it points your agent at the prompt's URL.
# Set up Filing tie-out and MD&A grounding on my hardware Fetch https://decosa.ai/prompts/filing-tieout-selfhost.md and follow it (including Step 0: rehearse on mock data first), with the hardware plan below applied. ## Hardware plan for this machine (from https://decosa.ai/self-host/hardware?use=filing-tieout) Target machine: GeForce RTX 5090 (32 GB of GPU memory; CUDA, FP8 and NVFP4). Quality tier: Standard · one GPU for claims in words (hosted demo) (standard). Fit check: runs with changes, about 28 GB of 32 GB used; some memory numbers are estimates, not measurements. First, check the machine: run `nvidia-smi` (or `rocm-smi`, or `sysctl hw.memsize` on a Mac) and confirm the GPUs and free memory match the line above. If they do not, stop and tell me before pulling anything. Use these components (the setup below describes the standard tier; change it to match): - iXBRL parser, figure tie-out, period and scal...: decosa-api tie-out (decosa_api/verticals/tieout) with the numeric grounding block's table-cell matcher (decosa_api/verticals/numeric/cells.py), CPU - Claims in words: Qwen3.8-27B (NVFP4) (nvidia/Qwen3.8-27B-NVFP4), 57.6 GB. Change: Qwen3.8-27B (NVFP4): run it at its smallest setting (about 28 GB instead of 57.6 GB), with a shorter context and fewer parallel sessions. GPU placement (set each service's device and its vLLM --gpu-memory-utilization to about the share shown): - GPU 0: Qwen3.8-27B (NVFP4) ~28 GB (88%); about 4 GB left During the rehearsal, watch GPU memory. If a model fails to load or runs out of memory, lower its --max-model-len and --max-num-seqs first, then its memory share, and tell me what you changed. The stack's own component list and compose layout: https://decosa.ai/prompts/filing-tieout-assemble.md
The proof
How we tested itEval results and end-to-end checks, hosted and self-hosted, with dates
Verified end to end
Hosted: verified 26 Sep 2026 · measured 26 Sep 2026: · p50 9.5 s · ~<$0.001 per run · 1 receipt
Loading the nightly status…
Self-host: verified 26 Sep 2026 · fresh clone, compose up, sample against local model servers
Measured cost to run: about $0.20 per 100 filings (hosted, 30 Sep 2026). Self-hosting is free: the code is open and the models are open-weight. You pay only for your own hardware and power.
A fresh clone of a decosa-api pre-release build (not yet merged), the api image built from it with DECOSA_TIEOUT_PUBLIC_ONLY=0, on the direct route to the running local Qwen3.8-27B. Re-run on commit 2562f1c with the rehearsal bundle (16 of 16 checks). The planted sample caught all seven plants in 0.21 s (0.61 s with one claim read), the clean sample had no flags, the record verified and a changed status failed, and an EDGAR fetch worked from the container.
Known limits (5)
- Only MD&A prose is tied; tables inside MD&A are not.
- Recall is low by design: most wrong figures in single-figure sentences come back untraced rather than flagged.
- Figures for segments, non-GAAP measures or narrower scopes that share a line's label can still be flagged against the consolidated line.
- Drafts must be iXBRL or pasted text with CSV tables; Word and PDF are not read.
- 10-Q quarter periods are handled but were not evaluated.
How it's builtThe steps, the models and what each one checks
Run it yourself, on request
- The same open models and app, on Any CPU for the tie-out; 1× RTX PRO 6000 (96 GB) or 1× RTX 5090 (32 GB) for Qwen3.8-27B if you want claims in words read.
- Data never leaves your machines, and there are no Decosa charges.
- One prompt for Claude Code or Codex assembles the whole stack.
- Early access: the container images are not public yet and the source needs access; the prompt says how to ask.
Get an API key
- Call the filing tie-out and md&a grounding API from your own code in minutes.
- Every model answer carries a signed receipt.
- Synthetic, public or test data only: real confidential data belongs on your own hardware.
Every figure in a 10-K or 10-Q's MD&A tied to the tagged statements and notes, in code, with a signed workpaper.
For SEC reporting teams, controllers and audit staff. Give it an inline XBRL 10-K or 10-Q (a draft from your disclosure tool, or a filed one from EDGAR), or tables pasted as CSV with a draft. Each figure in the MD&A prose is tied in code: to the cell it equals (fact id, table, period), or to the change, percentage change, margin or sum it is computed from, or it is flagged with the cell it was compared with: a different value, another period's figure, the wrong scale, the other direction, a note reference to the wrong note, or a note table that disagrees with a statement. Figures the tables do not show come back untraced for a person, not as errors. Optionally Qwen3.8-27B reads claims in words against the named lines. You get a Markdown and CSV workpaper and a signed record. A preparer's and reviewer's aid, not an audit.
- Deployment
- Self-host first
- Regulatory
- Checked 26 Sep 2026. Pre-release financial statements are material non-public information, so this is self-host first: the hosted demo ties public EDGAR filings, the bundled samples and text you declare public, and refuses the rest. MD&A content is set by SEC Regulation S-K Item 303 (eCFR, current text); the tie-out checks that the figures agree with the statements, not that the discussion is complete or its explanations right. Statements and notes are tagged in inline XBRL under Regulation S-T Rule 405; it reads the tags as filed and does not validate them. EDGAR requests follow SEC's fair-access policy (a declared User-Agent, well under 10 requests a second). PCAOB QC 1000 (a firm's system of quality control) is context for audit firms; we understand it to be effective 15 December 2026 after a postponement, but could not confirm the date on the PCAOB docket page (unverified). It is not an audit, gives no opinion and never says 'compliant'. Not legal or accounting advice. Model licence: Apache-2.0 (Qwen3.8-27B).
Text description
An inline XBRL 10-K or 10-Q (a draft, or a public filing fetched from EDGAR), or CSV tables with a draft, goes to the tie-out engine on the CPU. It parses the tagged statements and notes into lines with one value per period, finds the MD&A, and ties each figure: to a cell, to a change, percentage change, margin or sum computed in code, or flags it with the cell it was compared with. It checks direction words, Note references and facts shown twice. Optionally Qwen3.8-27B reads claims in words against the named lines, one receipted call each on the hosted route. Outputs: a Markdown and CSV workpaper and a signed record of hashes, statuses and fact ids. Self-hosted, everything stays on your machine; only EDGAR fetches you ask for leave it.
At a glance
- Data retention
- Nothing stored but a cache of public EDGAR documents you asked for. Drafts and tables live in memory for the request; the signed record holds hashes, statuses and fact ids, never text; logs carry counts only.
- What leaves the box
- Only an EDGAR request (CIK and accession number) when you ask for a public filing. Hosted: claim reads go through our gateway to the GPU serving Qwen3.8-27B. Self-hosted on the direct route with EDGAR off: nothing.
- What it will not do
- Audit, give an opinion or say 'compliant'. A clean result reads 'every figure tied to the tables (review still required)'; untraced figures are left for a person.
- Input formats
- An iXBRL 10-K or 10-Q up to 20 MB, a CIK and accession number, or up to 30 CSV tables with a draft of up to 120,000 characters; an optional trial balance CSV (account, name, balance, line).
- Typical run
- The figures are tied in code, a whole 10-K MD&A in about a second with no model. Each claim in words that is read is one gateway call, up to the run's claims cap, so a 10-K with many claims costs several times the planted sample; the cost per filing shown is measured on whole filed 10-Ks with their claims read.
Pick the tier for the quality you need
Same app at every tier. What changes is the models, the hardware they need, and whether receipts are signed. Scores are measured with the source named, or marked not measured.
- In the hosted demo
Lite
figures only, no GPU
Every figure, period, scale, direction and note reference tied in code; no model, no receipts. Runs on any CPU.
- Models
- decosa-api tie-out (decosa_api/verticals/tieout) with the numeric grounding block's table-cell matcher (decosa_api/verticals/numeric/cells.py)
- Hardware
- Any CPU
- Quality evidence
- False flags on untouched held-out 10-K MD&As (40 filings, frozen rules)11 in 6,039 figures (1.8 per 1,000); 2 more flags were real errorsdocs/evals/filing-tieout.md, 26 Sep 2026
- Planted errors caught, held-out: note table vs statement / scale / period / direction / % change / changed figure79/79 / 88/142 / 38/150 / 38/130 / 14/91 / 22/153docs/evals/filing-tieout.md, 26 Sep 2026
- MD&A figures tied or computed (held-out)34.6%docs/evals/filing-tieout.md, 26 Sep 2026
- Parser vs SEC's own extracted statement figures10,808 of 10,813docs/evals/filing-tieout.md, 26 Sep 2026
- Latency
- The code checks alone are quick on one core, with no model call; the measured time is in the eval files.
- Verification
- No proof yetNo model call, so no receipts; the tie-out is deterministic code.
- In the hosted demo
Standard
one GPU for claims in words (hosted demo)
The lite tier plus Qwen3.8-27B reading up to 12 claims in words ('gross margin improved') against the named lines' figures.
- Models
- decosa-api tie-out (decosa_api/verticals/tieout) with the numeric grounding block's table-cell matcher (decosa_api/verticals/numeric/cells.py)
- Qwen3.8-27B (NVFP4)
- Hardware
- 1x RTX PRO 6000 96 GB (measured) or 1x RTX 5090 32 GB (estimate)
- Quality evidence
- Flipped direction claims shown as mismatches (40 held-out sentences)20/40docs/evals/filing-tieout/claims-results-p1-1.json, 30 Sep 2026
- True sentences shown as mismatches (the same 40, unflipped)3/40docs/evals/filing-tieout/claims-results-p1-1.json, 30 Sep 2026
- Latency
- Each claim sentence adds one model call on the shared gateway, so filings with more claims take longer; the measured time is shown in the header.
- Verification
- Proof: strongEvery claim read is a separate gateway call with a gateway-signed receipt; the signed record lists them.
Also runs on
- MD&A tables and Word/PDF draftsA licence-clean table and document reader (not chosen)not builtTie the tables inside MD&A and read drafts from Word or PDF, not only iXBRL and pasted text. The reader is not chosen yet; it must be licence-clean. Hardware: 1x RTX PRO 6000 96 GB (estimate).
We host these ourselves when needed: small models get more of our own compute unless we detect a shortage, so they need no community providers.
Every model in the stack
| Model | Tiers | Params · VRAM | Verification | Details |
|---|---|---|---|---|
iXBRL parser, figure tie-out, period and scale rules, direction and cross-reference checks, workpaper and signed record (no model; CPU)decosa-api tie-out (decosa_api/verticals/tieout) with the numeric grounding block's table-cell matcher (decosa_api/verticals/numeric/cells.py) 0 GBProof: partial | LiteStandard | 0 GB | Proof: partial | |
| ||||
Claims in words (optional): the grounding judge reads a sentence against the named lines' figuresQwen3.8-27B (NVFP4)nvidia/Qwen3.8-27B-NVFP4 on Hugging Face (opens in a new tab) 27.8B · 20 GBProof: strongIn the hosted demo | Standard | 27.8B · 20 GB | Proof: strongIn the hosted demo | |
| ||||
Tables inside the MD&A, and Word or PDF drafts (alternate)A licence-clean table and document reader (not chosen) No proof yetSelf-host only | Alternate | n/a | No proof yetSelf-host only | |
| ||||
Tools, services and hardware
Tools
- SEC EDGAR (filings) and the Financial Statement and Notes data sets (opens in a new tab)US government work (public domain)
The demo filings, the eval's 140 10-Ks and the parser check against SEC's own extracted figures.
- SEC, Accessing EDGAR Data (fair access) (opens in a new tab)US government work (public domain)
User-Agent and rate rules the fetcher follows.
- Regulation S-K Item 303 (eCFR) (opens in a new tab)US regulation (public domain)
What MD&A must discuss.
- PCAOB Docket 046, QC 1000 (opens in a new tab)PCAOB publication
Quality-control context for audit firms (effective date unverified).
- scripts/eval_tieout.py and docs/evals/filing-tieout.mdApache-2.0
The filing sets, planted errors, clean-filing flags, the claim-judge eval and every result file.
- POST /tieout/verifyApache-2.0
Check a record's signature and the hashes of its Markdown and CSV workpapers.
Services
- decosa-api:8445
${DECOSA_REGISTRY}/decosa-api:<tag>GET /tieout/info, /tieout/samples; POST /tieout/check (SSE or JSON), /tieout/verify. Stores only a cache of public EDGAR documents.
- vLLM (model, standard tier):8114
vllm/vllm-openai@sha256:c2914767605584b6d8f45686b82de173ecc99e781897aa3d0a66dacd72c51ae1Qwen3.8-27B NVFP4 for claims in words, behind our gateway (hosted) or called directly (self-host).
Hardware
- CPU only Fits
Measured on our server: parse and tie of a whole 10-K takes a median 0.44-0.5 s on one core. This is the lite tier.
- 1x RTX PRO 6000 Blackwell 96 GB Fits
Measured on our server: the hosted demo's claim calls ran on this card through the shared gateway.
- 1x RTX 5090 32 GB Fits
Estimate: Qwen3.8-27B NVFP4 needs about 20 GB of weights plus KV cache; not run for this tool.
Latency per lane
- tie a whole 10-K (parse + figures + cross-references, no model)440 ms
Measuredmeasured on our server 2026-09-26: median over 40 held-out 10-Ks
- planted sample with claims in words, hosted gateway route9.4 s
Measuredmeasured on our server 2026-09-26: 3 smoke runs, 7.2-9.8 s, one claim call
- public 10-K fetched from EDGAR and tied (no claims)2.6 s
Measuredmeasured on our server 2026-09-26: Eastman Chemical, 2.4-2.8 s including two EDGAR requests
Notes
- On 40 held-out FY2025 10-Ks (frozen rules), the untouched MD&As produced 13 flags in 6,039 figures; 2 were real inconsistencies in the filings and 11 were false (1.8 per 1,000 figures). After fixing the bug classes that run showed, 6 flags, 2 real.
- Planted errors caught on that held-out set: a note table that disagrees with a statement 79/79, a wrong scale 88/142, another period's figure 38/150, a flipped direction 38/130, a wrong percentage change 14/91, a changed figure 22/153. Recall is low by design: a near miss is only called when the sentence is surely about that line.
- About a third of MD&A figures sit in tagged cells; the rest (non-GAAP measures, segment detail, deal terms, statistics) come back untraced for a person.
- Across 140 filed 10-Ks it found five real inconsistencies we checked by hand: an accumulated deficit in Applied Optoelectronics' MD&A that disagrees with its balance sheet, and stale note numbers in Vaxcyte, NETGEAR and Harmonic (two).
- The claim judge (re-measured 30 Sep, after a contradicted claim became a mismatch only when the judge is sure and compared a line the sentence names): 20 of 40 flipped direction claims shown as mismatches, 27 of 40 with the code's direction check, and 3 of 40 true sentences; the flips the judge was unsure of go to review.
Run this exact stack on your machine
Paste into Claude Code / Codex to assemble this stack locally. The prompt checks your GPU, pulls the pinned models, writes the compose file and runs a smoke test.
# Assemble the Decosa filing tie-out on this machine
You are setting up a tie-out aid for SEC reporting teams and auditors. Given a 10-K or 10-Q in inline XBRL (a draft
from your disclosure tool, or a filed one from EDGAR), or tables pasted as CSV with a draft, it ties every figure in
the MD&A prose to the tagged statements and notes: the cell it equals (fact id, table, period), or the change,
percentage change, margin or sum it was computed from, or why it does not tie (wrong value, another period's figure,
the wrong scale, the other direction, a note reference to the wrong note, a note table that disagrees with a
statement). It writes a workpaper (Markdown and CSV) and a JSON record signed by this box's own key. Work step by step,
show me each command before you run anything with `sudo`, and stop to ask if a check fails.
## Step 0: set up with a coding agent, rehearse on mock data, then go private
This prompt is for a coding agent running on the machine that will host the service. We recommend Claude Code with
Claude Opus 5.5; any capable coding agent works. Work in this order:
1. Set up on mock data only. During the whole setup you (the agent) work with the synthetic sample bundle below and
nothing else. Do not ask me for real data, and do not open, read, list or copy files that hold real data, even to
"test with something realistic".
2. Rehearse. When the steps below are done and the service is healthy, fetch the mock-data bundle for this tool,
https://decosa.ai/samples/filing-tieout.zip (3 KB, 16 checks, synthetic or openly licensed: see `licence` in expected.json),
show me what is in it, and run the rehearsal against the local API:
`docker compose exec api python scripts/rehearse.py filing-tieout` (the api image carries the same bundle under /app/rehearsal/filing-tieout/;
with no key set, the script asks the local API for a short demo token). From a decosa-api checkout instead:
`python scripts/rehearse.py filing-tieout --bundle filing-tieout.zip --base-url http://127.0.0.1:<PORT>`.
It sends the mock inputs to the local API and prints PASS or FAIL for each expected property (for example: "the synthetic draft does not tie", "the transposed 2024 net income is a value mismatch naming the table's figure", "the inventories accounts do not roll up to the balance sheet"). Show me
the full output. Every check must pass. If one fails, fix the install and run it again; never edit `expected.json`
to make a check pass.
3. Stop there. Once the rehearsal passes, tell me, and I will run my own data against the local API myself, on this
machine.
For the person running this: a coding agent that runs in the cloud sees everything in its context, including files it
reads, command output and anything pasted into the chat. Keep real data out of the chat and out of anything the agent
can read. Switch to your own data only after the rehearsal has passed and the agent's work is done.
## 0. Ground rules and licences
- decosa-api (AGPL-3.0-or-later) does the tie-out in plain Python on the CPU: no GPU and no model are needed for figures,
periods, scale, direction, note references or the record. That is the lite tier.
- Optional: Qwen3.8-27B (Apache-2.0) reads claims in words ("gross margin improved") against the named lines, at most
12 calls a run. That is the standard tier and needs a GPU.
- Drafts before release are material non-public information. Keep everything on this machine and bind every port to
127.0.0.1. The service stores nothing but a cache of public EDGAR documents; logs carry counts only. Keep it that way.
- It is a preparer's and reviewer's aid: not an audit, not an opinion, never "compliant". A person reviews every flag
and every untraced figure.
## 1. Check the machine
1. `docker --version` and `docker compose version`. If Docker is missing, install it from Docker's official
repository after asking me.
2. Lite tier: any x86-64 or arm64 machine, 2 GB RAM free. A 10-K parses and ties in about half a second on one core.
3. Standard tier only: `nvidia-smi` shows one GPU with at least 32 GB and driver 570+, and the NVIDIA container
toolkit works (`docker run --rm --gpus all nvidia/cuda:12.8.0-base-ubuntu24.04 nvidia-smi`). On a card without
NVFP4 use `Qwen/Qwen3.8-27B-FP8`.
## 2. Images and weights
- `${DECOSA_REGISTRY}/decosa-api:<tag>` (**publishing soon**). If the pull fails, build from source:
`git clone <decosa-api source: on request at https://decosa.ai/contact?topic=self-host>` (access required), check out the newest release tag that
contains `decosa_api/verticals/tieout/` (`main` until one does), and build `docker/api/Dockerfile`.
- Standard tier: `vllm/vllm-openai:v0.29.0` and `nvidia/Qwen3.8-27B-NVFP4` (revision
`482ca0f3832238542f8f5295dde86b5f22711d80`).
## 3. docker-compose.yml
Write this in `~/decosa/tieout/`. For the lite tier, delete the `llm` service and the `depends_on` block, and set
`judge_claims: false` in requests.
```yaml
services:
llm:
image: vllm/vllm-openai:v0.29.0
command: ["--model", "nvidia/Qwen3.8-27B-NVFP4", "--served-model-name", "qwen3.8-27b", "--max-model-len", "32768",
"--enable-prefix-caching"]
ports: ["127.0.0.1:8114:8000"]
volumes: ["~/.cache/huggingface:/root/.cache/huggingface"]
deploy: { resources: { reservations: { devices: [{ driver: nvidia, count: 1, capabilities: [gpu] }] } } }
healthcheck: { test: ["CMD", "curl", "-fs", "http://localhost:8000/v1/models"], interval: 30s, retries: 20 }
api:
image: ${DECOSA_REGISTRY}/decosa-api:<tag>
ports: ["127.0.0.1:8445:8445"]
environment:
DECOSA_HOST: 0.0.0.0
DECOSA_PORT: "8445"
DECOSA_DATA_DIR: /data
DECOSA_LLM_ROUTE: direct
DECOSA_LLM_URL: http://llm:8000/v1
DECOSA_LLM_MODEL: qwen3.8-27b
DECOSA_TIEOUT_PUBLIC_ONLY: "0"
DECOSA_TIEOUT_EDGAR: "1"
DECOSA_CONTACT_EMAIL: you@example.com
DECOSA_BUDGET_LLM_TOKENS: "60000"
volumes: ["decosa-data:/data"]
depends_on: { llm: { condition: service_healthy } }
healthcheck: { test: ["CMD", "python", "-c", "import urllib.request; urllib.request.urlopen('http://localhost:8445/tieout/info', timeout=4)"], interval: 30s, retries: 10 }
volumes:
decosa-data:
```
- `DECOSA_TIEOUT_PUBLIC_ONLY: "0"` lets this box take drafts; the hosted service refuses anything not declared public.
- `DECOSA_CONTACT_EMAIL` goes in the User-Agent of EDGAR requests (SEC's fair-access policy asks for one). Put a real
address, or set `DECOSA_TIEOUT_EDGAR: "0"` if this box must never reach the internet: drafts do not need EDGAR.
- The api keeps its state (keys, receipts, this box's signing key, the EDGAR cache) in the named volume `decosa-data`,
not a host folder: the image runs as uid 10001, and a host folder Docker creates is owned by root, which stops the api
with `PermissionError: [Errno 13] Permission denied: '/data/keys.sqlite'`.
Start it: `docker compose up -d`. On first start the api creates this box's Ed25519 key in `/data/attest/` (mode 0600).
Back it up with `docker compose cp api:/data/attest ./attest-backup`, keep that copy private, never print it. Model
calls on the direct route get receipts signed with that key (`attested`: an attestation by me, the operator, not a
proof). Never set `DECOSA_LLM_ROUTE=gateway` here: that would send draft text to the Decosa API.
## 4. Smoke test
1. `curl -s localhost:8445/tieout/info | jq '{public_only, edgar: .edgar.enabled, statuses: (.statuses | keys)}'` shows
`public_only: false` and the statuses `computed`, `mismatch`, `tied`, `untraced`.
2. Token: `T=$(curl -s -XPOST localhost:8445/demo/session -H 'content-type: application/json' -d '{"vertical":"filing-tieout"}' | jq -r .token)`.
3. The planted sample (AMD's filed MD&A with six planted errors, bundled in the image):
`curl -s -XPOST localhost:8445/tieout/check -H "authorization: Bearer $T" -H 'content-type: application/json' -d '{"sample":"amd-fy2025-planted","judge_claims":false}' > res.json`.
Expect `status: "mismatches"` and, under `sentences[].figures[]`, mismatches with `reason` value, value, period and
scale (the scale one says "$577 billion looks 1,000 times too large"); one `direction` flag ("says increased, but
Embedded went from ..."), one wrong `Note 6`, and in `cross_refs` one `same_fact_two_values` (Net revenue shown as
34,639 and 34,729). `coverage.traced` should be 44 of 57.
4. The clean case: the same with `"sample":"amd-fy2025"`: no mismatches.
5. `jq '{report, workpaper_md, workpaper_csv}' res.json | curl -s -XPOST localhost:8445/tieout/verify -H 'content-type: application/json' -d @-`
must show `valid_signature`, `signed_by_this_server`, `workpaper_md_matches` and `workpaper_csv_matches` true.
Change `status` in the report and verify again: it must fail.
6. Your own document: `jq -Rs '{html: ., judge_claims: false}' my-10k.htm | curl -s -XPOST localhost:8445/tieout/check -H "authorization: Bearer $T" -H 'content-type: application/json' -d @- > mine.json`
(a draft iXBRL export from your disclosure tool works the same way; to tie a revised MD&A against a filing's facts,
add `draft`). Then `jq -r .workpaper_md mine.json > workpaper.md`.
7. Standard tier: repeat step 3 with `"judge_claims": true` and check that each claim read has a `receipt_ids` entry.
8. Time it and tell me what you measure. On our machine the planted sample took 0.1 s without claims and 7-10 s with
one claim read through the shared gateway.
## 5. Point the app at the local API
Set `NEXT_PUBLIC_DECOSA_API=http://127.0.0.1:8445` in the site's `.env.local`, or call `POST /tieout/check` from your
close or disclosure checklist and file `workpaper_md`, `workpaper_csv` and the signed `report` with the draft. The
rehearsal bundle (`python scripts/rehearse.py filing-tieout`) runs a synthetic company and the planted sample against
this box. Contract: `API_CONTRACT.md`, section "Filing tie-out and MD&A grounding".
Off by default. Joining serves other people's requests on this GPU; never do it on a box that holds unreleased
financial statements. If I ask for it, follow the provider guide at `/provide` on the site, and only with my explicit yes.Rules and regulations it checks againstDated, linked to the primary source; not legal advice
Regulation watch
Loading the watch status…
5 laws, rules and guidance pages cited; 5 watched nightly at the primary source. A change marks this page for a human re-check; nothing is edited automatically. What we cite and how it is watched
Technical detailsModels, where it runs, labels
In short
Last reviewed
- What it is
- Every figure in a 10-K or 10-Q's MD&A tied to the tagged statements and notes, in code, with a signed workpaper.
- Who it's for
- SEC reporting teams, controllers and audit staff who tie out 10-K and 10-Q drafts.
- Where it runs
- Self-host for drafts (pre-release numbers are MNPI); the hosted demo ties public EDGAR filings
- Key numbers
- 11 in 6,039 figures (1.8 per 1,000) False flags on untouched held-out 10-K MD&As (frozen rules) (test split, n = 6039)
- 79/79 Note table that disagrees with a statement, caught (test split, n = 79)
- 88/142 (62%) Scale error (million/billion) caught (test split, n = 142)
- 9.5 s Median end-to-end run, hosted (QA sweep 2026-09-26)
- Models
- The tie-out is plain code; Qwen3.8-27B optionally reads claims in words
- Where
- Self-host for drafts (pre-release numbers are MNPI); the hosted demo ties public EDGAR filings
- Checks
- Every tie names a fact id; receipt per claim read; signed record over hashes, statuses and fact ids
- Industry
- Finance and insurance · Compliance and trust
- Runs
- Self-host
- Output
- Signed record or verdict · Structured data
- Data
- Confidential business data
- Hardware
- 1× 96 GB GPU
- Licence
- Permissive (Apache-2.0, MIT)
- Runs in
- Self-host
- Built from
- Numeric grounding · Grounding · Signed record
Questions people ask
What does it check?
Every figure in the MD&A prose against the filing's tagged statements and notes: the amount at its stated rounding, the period, the scale, changes and percentage changes worked out in code, direction words, Note references, and facts a note table shows with a different value than a statement.
How often does it flag a correct figure?
On 40 held-out filed 10-Ks with frozen rules, 11 false flags in 6,039 figures (1.8 per 1,000); two more flags were real inconsistencies in the filings. Recall is deliberately modest: many wrong figures come back untraced rather than flagged.
Can I send a draft before it is filed?
Not to the hosted demo, which takes public filings and text you declare public: pre-release numbers are material non-public information. Self-host it; the tie-out runs on a CPU and needs no model.
Is this an audit?
No. It is a preparer's and reviewer's aid that ties figures in code and leaves untraced ones for a person; it gives no opinion and never says a filing is compliant.
Did it find anything in real filings?
Yes, five inconsistencies in 140 filed 10-Ks, checked by hand: an accumulated deficit in one MD&A that disagrees with the balance sheet, and four Note references pointing at the wrong note.
Ask a question or leave feedbackWe read every message and publish useful answers
Ask about Filing tie-out and MD&A grounding
We read every message. Questions, comments and our answers show here once we have reviewed and approved them.
Loading questions…