Pre-checks
Injection scan. Ambiguity score. Sensitive topic flag. Multi-question detection. Your message gets read before any model sees it.
What happens between your message and the response.
This is the normal checked-chat path. Raw mode and specialist endpoints can take a different route. The response shows which checks ran, and the depth depends on the plan and request.
Injection scan. Ambiguity score. Sensitive topic flag. Multi-question detection. Your message gets read before any model sees it.
Intent recovery. Filler strip. Multi-question numbering. Context injection. Your prompt becomes precise before it goes out.
Smart routing selects from the engine families available to the plan. When independent verification runs, one lineage-separated verifier can review the result. The record names what actually served the request.
The model runs. Streaming or non-streaming. Your direction set loaded as system prompt. Tier-gated model selection.
Synchronous post-checks run on the normal path unless raw mode is selected. Deeper drift, second-opinion, and silent-drop checks can finish after the answer and join the audit record.
Account records, credentials, and hot cache have separate jobs. The public page describes those jobs; deployment region, backup schedule, and failure recovery need operational evidence, not a marketing promise.
Account data and minted receipts use the DreamerOS system of record. Queries are scoped to the authenticated account where the route enforces that boundary. Public proof exposes signed fields only; signed-in accounts can see their own private context. Public verification of deployment region remains In Beta 2.0.
Credential storage and application-data storage use separate code paths. Encryption depends on the configured vault key. Backup schedule and restore proof are operational controls and remain In Beta 2.0 on this public surface until the current evidence is published.
The hot cache supports speed and rate-limit enforcement; it is not the system of record. On a cache miss, the normal path can reload from storage. Receipt minting is attempted separately, so a mint failure leaves the answer without receipt fields. Recovery during a real cache outage remains an operational test, not a public guarantee.
The pipeline
Your input goes in. The route shows which shaping, generation, and checks actually ran before and after the answer.