- Weights hash (SHA-256)
- In Sealed mode, the receipt records the hash of the weights that ran
- Where it runs
- Sealed: inside AMD SEV-SNP confidential virtual machines (NexQloud Sealed). Standard: NexQloud cloud, plus an outside AI provider if one is used
- Third-party AI providers
- Sealed: none. Standard: may be used, on terms that bar training
- Trained on client documents
- Never
- Output limits
- Fixed forms only (schema-constrained output)
- Tools it can call
- Document reader, tariff and Chapter 99 tables, duty-split calculator, matching solver, CAPE check. None can send data out of the run
- Intended use
- Read customs and trade documents, propose matches, draft claim lines with evidence and explain exceptions, all for a licensed broker's review
- Not for
- Tariff classification decisions, filing, legal advice, or CUI-marked files, drawings and export-controlled technical data, in either mode
- Known limits
- Documents are untrusted input (section 4)
How the agent works
An AI drawback agent that shows its work
The agent reads your records, matches exports to imports and drafts each claim line with its evidence. Plain code does every calculation, and your broker decides.†
About 3 minutes on a sample file. Your email and name open it. We never ask for your ACE login or bank details.
- Every line names its source
- Sealed on AMD SEV-SNP
- CBP 7501 · page 1Entry 716-2042014-4, line 1HTS 8108.90.3060 · 220 pieces · duty $46,860.00
- Commercial invoiceTitanium alloy forgingsUK supplier · 220 pieces
- Export recordOne export shipment120 of the 220 pieces
- Claim lineRegular duty on the 120 exported pieces99% of it, plus the line's share of the merchandise processing fee
- Broker approvalApprovedReviewer and time logged
The pipeline
What does the agent do, step by step?
Seven steps. Each leaves an artifact you can open.
The example line, from the demonstration file
Entry 716-2042014-4, line 1: titanium alloy forgings from a UK supplier, 220 pieces, HTS 8108.90.3060, duty at 15%: $46,860.00. The same entry also carries an IEEPA line: 9903.01.25 at 10%, $31,240.00.
-
Step 1. Plan
It lists what is missing in plain words and asks for it. When the set is complete, it tells you, and the 24-hour clock* starts.
The completeness checklist
What happens: The agent checks what you uploaded against what each drawback type needs.
The example: 73 of 73 documents: 12 entry summaries, 12 commercial invoices, 12 packing lists, 12 transport documents, 18 export records, 1 bill of materials, and 6 duty payment and broker statements. Package complete.
-
Step 2. Read
The model reads each document into a fixed form. Every field keeps a pointer to the document and page it came from.
The extracted fields, each with its source
What happens: The model identifies each document's type, then reads it into a fixed form for that type: entry and line numbers, HTS number, quantity, value, duty, dates and parties. It can only answer in that form.
The example: Entry 716-2042014-4 · line 1 · HTS 8108.90.3060 · 220 pieces · duty $46,860.00 · source: entry summary (CBP 7501), page 1.
-
Step 3. Classify
Code sorts each duty line by program. Classification decisions belong to a licensed broker.
A program tag on every duty line
What happens: Code sorts each duty line by program: regular duty, Section 301, Section 122, Section 232, Section 338 or IEEPA, using the Chapter 99 numbers on the entry. The agent does not choose tariff classifications. It reads the ones already on your entries.
The example: 8108.90.3060 → regular duty. 9903.01.25 → IEEPA.
-
Step 4. Match
A matching solver links each export to the import it came from, and applies the time limits and the 99% cap.
The match table
What happens: A matching solver links each export to the import it came from, by part number and quantity (direct identification) or under the 8-digit tariff rule (substitution). When two documents describe a part differently, the model may suggest a link, and a person confirms it.
The example: 120 of the 220 pieces matched to one export shipment.
-
Step 5. Split by program
For each matched line, code computes the duty that can come back under each program. It checks every IEEPA line for CAPE first.
The duty split, line by line
The example: The regular duty on the 120 exported pieces can be claimed: 99% of it, plus the line's share of the merchandise processing fee. The IEEPA line is flagged for CAPE. CAPE excludes entries that are the subject of a drawback claim, and CBP recommends filing CAPE first.[2] So this entry's drawback line waits until its CAPE question is settled.
CAPE and Section 232, in one place.
Most IEEPA refunds go through CAPE. We check every entry for CAPE first. No entry goes into a drawback claim package while its CAPE question is open. CAPE is filed by the importer of record or its filing broker; refund firms work through one of them. Drawback on Section 232 duties depends on the program.[3]
-
Step 6. Check
Code re-adds every line to the totals on each 7501, to the cent, and flags any field the model was unsure of.
The check log
The example: The entry re-foots to its 7501 total of $78,734.62: duty $46,860.00, IEEPA duty $31,240.00 and merchandise processing fee $634.62. Quantities agree on the invoice, packing list and 7501: 220 pieces.
-
Step 7. Package
Code builds the claim package: a claim summary, a line-level CSV you can re-foot in Excel, and the evidence trail for every line.
What the package holds
What happens: Sealed runs add a receipt.
The example: One claim line, with pointers to the 7501 page, the invoice, the packing list and the export record.
The demo builds a sample package on synthetic data: a claim summary, the claim lines as CSV, an explanation of every line and, in Sealed mode, a receipt.
*When the 24 hours start
*24 hours from a complete package: entry summaries (CBP 7501), commercial invoices, packing lists, transport documents and export records for the period, plus the bill of materials and production records for manufacturing claims. We tell you the moment your package is complete, and the clock starts then. CBP rulings, waivers and approvals are separate from this clock.
AI or code
Which parts use AI, and which are plain code?
The model reads documents and may suggest links; a person confirms. Every calculation, match and cap is ordinary code.
Task by task: AI, code or a person
| Task | Who does it |
|---|---|
| Recognize each document's type | AIModel |
| Read fields into a fixed form | AIModel (it can only output that form) |
| Plan the work and list what is missing | AICodeAgent: the model plus fixed rules |
| Suggest a link when two documents describe a part differently | AIPersonModel; a person confirms |
| Explain an exception in plain words | AIModel |
| Sort duty by program | CodeCode (table lookup) |
| Match exports to imports; apply time limits and the 99% cap | CodeCode (matching solver) |
| Every calculation, re-footing and the CAPE check | CodeCode |
| Build the claim package and CSV | CodeCode |
| Tariff classification decisions | PersonA licensed broker |
| Approve each claim line and file in ACE | PersonA licensed broker |
| Supply documents and answer exceptions | PersonYou, with your broker |
Why we call it an agent
A workflow follows fixed code paths. An agent directs its own steps and tool use. That is the distinction Anthropic draws in its published guidance on building agents.[4] Ours plans the work, picks which tool to run next and handles exceptions. Those are the only parts we call agentic. Everything that adds, multiplies, matches or caps is ordinary code that gives the same answer every time.
Self-checks
How does it catch its own mistakes?
Code checks the model's work before any person sees it:
- Every line re-foots to its 7501 total, to the cent.
- Quantities must agree across invoice, packing list and 7501.
- No duty dollar can sit in both CAPE and drawback.
- No line can exceed the 99% cap or break a time limit.
- Every field must fit its fixed form.
- Any field the model was unsure of is flagged.
A licensed customs broker, ours or yours, reviews every line, approves or rejects it, and files the claim in ACE as entry type 47.[5]
Exceptions go to a person
Anything that fails a check goes to a person, with a reason code, such as a quantity mismatch or a missing proof of export. In Sealed mode, that person is only you or your broker. In Standard mode, it is you, your broker or named NexQloud staff.
Documents are untrusted input
A document can carry hidden instructions meant for an AI. That risk is well documented.[6][7] The model can only fill fixed forms. It has no tool that can send data out. And a licensed broker decides before anything is filed. Those steps limit what a hostile document can do. They do not make the agent immune, and we do not say they do.
Your broker decides, and every line keeps its record
Each approval is logged with the reviewer's name and the time. That log is the broker's supervision record. CBP has held that preparing entry data for others is customs business, and that the actual decision on classification, or any other information needed to make entry, "must be made by a duly licensed customs broker".[8]
Each claim line keeps its trail: document, page, field, claim line, approval. False drawback claims carry penalties (19 U.S.C. 1593a),[9] so the record is built for an audit, not for a demo.
Each agent claim, and how to check it
| Claim | Backed by | How you check | Limits |
|---|---|---|---|
| Every claim line names its entry, its export and its source document | Evidence pointers in the CSV and claim summary | In the demo's sample package, follow any line to its source | A pointer shows where a value came from, not that the source document is right |
| The math is plain code | The calculation code and the check log | Re-foot the sample CSV in Excel; totals tie to each 7501 | Code can have bugs |
| A licensed broker approves every line before filing | The approval log, with reviewer and time | Your broker's own log | The log shows approval, not how carefully a line was reviewed |
| No duty dollar is claimed in both CAPE and drawback | The sequencing check | The CAPE flags in the sample claim summary | Only as good as the CAPE status data you or your broker upload |
Trust boundaries
What sits inside each trust boundary?
A trust boundary marks what you have to trust.
Sealed
- Encrypts files before upload
- Checks the AMD report before releasing your key
- Encrypted
- Your key Checks pass
Host: outside the boundary
Sealed boundary
AMD SEV-SNP confidential virtual machine
- The measured image, started from published code
- No SSH, no console, debug off
- The model and the calculation code
- Your documents, readable only here, in memory AMD encrypts
- The run's keys, destroyed at the end
- Host operating system
- Hypervisor
- Our servers
- Cloud storage: encrypted data only
- Logs
- NexQloud operators and staff
- Physical access
- Claim package and CSVYour brokerEncrypted to them
- Claim totalsBilling
- ReceiptYou
- Inside the boundary: what you trust. AMD, our published code, and the verifier you choose.
- Outside: everything else, including us.
Sealed: protected by hardware, checkable by receipt. Read the limits
Read the diagram as steps
- Diagram of a Sealed run in seven steps.
- Your browser encrypts each file.
- A sealed machine on AMD SEV-SNP hardware starts from published code, and your key is released only after its checks pass.
- Inside the solid Sealed boundary there is no login or console.
- Only files encrypted to you and your broker, claim totals and your receipt leave, and the working copy is erased at the end.
- Our servers, storage, logs, staff and the host sit outside the boundary.
Standard
- Encrypted in transit
NexQloud cloud
- Upload service
- Encrypted storage
- Processing: the open-weight model and the calculation code
- Workspace
- Claim package and CSVYour broker
- Claim totalsBilling
Standard: protected by our controls. Named staff can open documents for exception review and support, and every access is logged.
Read the diagram as steps
- Standard architecture.
- You and your broker sit outside a dashed boundary labeled NexQloud cloud.
- Inside it: the upload service, encrypted storage, processing with the open-weight model and calculation code, the workspace, and named staff for exception review and support, with every access logged.
- Third-party AI providers sit outside; one may process your documents, only on terms that bar training.
Who you trust in each mode
| Question | Sealed | Standard |
|---|---|---|
| You trust | AMD's chips, firmware and keys. Our published code. The verifier you choose | NexQloud: our cloud, our staff controls and our logs. Our hosting provider. The model code. Any outside AI provider we use, and its terms |
| You do not need to trust | Our staff, our servers, the host, the hypervisor and storage (the Sealed limits apply) | No hardware boundary. You trust the parties above. |
| How you check | A receipt for every run | Our policies, audits and trust center |
What we borrowed from larger systems
What we borrowed from larger systems, and what waits
Large platforms that run private AI have published how they make their claims checkable. We took the parts that work at our size:
- Apple's Private Cloud Compute logs every production build in a public, append-only log, and devices send data only to logged nodes.[10] Our version: a public log of every release, and your browser releases your key only to a logged release.
- Microsoft Azure has relying parties check code measurements against published values and build provenance.[11] Our version: published measurements and build provenance for every release.
- Google's Confidential Space runs a hardened image with no SSH and a verified read-only disk.[12] Our version: no SSH, no console, and a verified read-only disk in the measured image.
What waits until we are larger: a research environment like Apple's, and bounties like its awards of up to $1,000,000. None of these companies has reviewed or endorsed NexQloud Drawback.
Get started
See the agent build a claim.
Run the demo on a sample file. About three minutes.
-
01
Upload one quarter.
Entry summaries, invoices and export records.
WhoYou
-
02
AI drafts your claim.
It ties each export to its import, to the cent.
WhoThe agent
-
03
Your broker files. CBP pays you.
The refund goes directly to your bank account.
WhoA licensed broker
Your email and name open the demo. We never ask for your ACE login or bank details.
Ready now? Start a claimThe model
Which model reads your documents?
An open-weight model. In Standard, an outside AI provider may process your documents, only on terms that bar training.
In both modes, your documents are never used to train any model.
How the model is used
In Sealed mode, you can check it yourself: the receipt shows which weights ran, and the sealed machine sends out only encrypted files to you and your broker, claim totals and the receipt. In Standard mode, our terms commit to it and our controls enforce it, and an outside AI provider may process your documents only on terms that bar training.
Status
What has been audited?
SOC 2 Type 2. The report is available under NDA on request.
Words we avoid
Which claims will you never see from us?
Some words sell AI. We do not use them, because they are not true of this product or cannot be checked.
The words, and what we say instead
| We will not say | Why | What we say instead |
|---|---|---|
| "Autonomous," "no humans needed," "fully automated" | A licensed broker reviews every line. Federal prosecutors and the SEC have charged a founder whose "automation" was hidden human work[13] | "The agent drafts the claim package for your broker's review" |
| "Our AI files your claim," "AI broker" | A software tool is not a licensed person[8] | "A licensed customs broker, ours or yours, reviews every line and files" |
| "Finds X% more," "every dollar," "100% accurate" | Accuracy claims need testing at the time they are made. The FTC has acted against AI accuracy claims without that support[14] | No accuracy figure without a published test set and date |
| "Agentic" for fixed steps | Calling a fixed workflow an agent is what Gartner calls "agent washing"[15] | "Agent" for planning and exceptions; "code" for the math |
| "Immune to prompt injection" | Documents are untrusted input, and published tests show these defenses can be beaten[6][7] | The limits we put on the model, described as practice |
| "Unhackable," "zero risk," "military-grade," "no one can ever access" | Researchers have published attacks on SEV-SNP | "In Sealed mode, no one sees your documents without your consent," with the limits linked |
| "The only" or "the first" | We cannot check every provider in the world | Nothing |
| "CMMC, ITAR or FedRAMP compliant" | Sealed is not a compliance certification | "Keep CUI-marked files, drawings and export-controlled technical data out of both modes. Drawback doesn't need them." |
| "Instant," "in minutes," "you qualify" | They promise what cannot be known before your entries are read, and they echo the pressure CBP's fraud warning tells importers to watch for[16] | "Claim package within 24 hours*"; "your entries decide" |
| "Patented" | Not unless a patent is granted | Nothing, until one is |

