Skip to content
Ventralia

Platform

A signal platform, not a data platform.

The difference is architectural, not a marketing line. Raw data never leaves the company that produced it. What reaches the centre is derived, aggregated and irreversible.

The problem

Pooling everyone's data is the obvious design. It is also the one nobody will sign.

Every market intelligence product faces the same wall. The data is only valuable in aggregate, and no serious company will hand over its cost base, its suppliers and its margins so that a competitor can benefit from them. Promising confidentiality does not solve this, because a promise is a policy, and policies can change with an owner.

We resolved it by removing the possibility rather than prohibiting the behaviour. The centre never holds anything that could be traced back to a contributor — not because we choose not to look, but because the record was transformed before it ever arrived.

Architecture

Four layers. Only one of them is shared.

Data flows upward and narrows at every step. Decisions flow back down and widen again — carrying context that only the individual company has.

Ventralia platform architecture Four layers. Private company data stays isolated at the bottom. A shared product graph resolves identity. Anonymous signals are derived above a contributor threshold. A decision engine combines those signals with each company's private context and returns a decision to that company alone. Decision engine Shared signal + your cost, margin and cash position LAYER 04 private Anonymous signals Published only above a contributor threshold LAYER 03 k ≥ N Product graph One canonical identity per physical product LAYER 02 shared Company A PRIVATE Company B PRIVATE Company C PRIVATE Company D PRIVATE LAYER 01 · ISOLATED PER TENANT DERIVED DATA UP · NARROWS AT EVERY STEP DECISIONS DOWN · TO ONE COMPANY ONLY
Only the product graph is shared. Private data never leaves layer one, and a decision only ever returns to the company that asked for it.
Layer 01

Private data

Isolated per tenant

Inventory, purchase costs, supplier terms, customer records, margins. This layer belongs entirely to the company that produced it. It is not pooled, not sold, and not visible to us in aggregate. Every query against it is scoped to a single tenant at the database level, not by a filter someone could forget to apply.

  • Row-level tenant isolation
  • No cross-tenant reads
  • Customer owns and can export
Layer 02

Product graph

Shared and canonical

One identity per physical product, shared across every tenant. When four companies spell the same cartridge four different ways, the graph decides they are one thing. This is the layer nobody sees and everything depends on: get identity wrong and every price, index and recommendation downstream is quietly wrong too.

  • Entity resolution across spellings
  • Part-code and attribute matching
  • Structure only — never price, never ownership
Layer 03

Anonymous signals

Derived and irreversible

Private events become market signals only after they cross a contributor threshold and lose their origin. A single company's sale never becomes a visible data point. Below the threshold nothing is published — there is no override, because the aggregation happens before anything is stored.

  • k-anonymity threshold before publication
  • Irreversible aggregation
  • No path back to the contributing company
Layer 04

Decision engine

Private again

Shared signals meet private context: your cost base, your margin floor, your cash position, your capacity. A competitor can copy a market signal. They cannot copy a decision that depends on what you paid and what you need to earn. This is why the last layer is private again.

  • Mathematics produces the number
  • The language model only explains it
  • Low confidence returns a range, not false precision

Decision quality

The model explains. It does not decide.

Asking a language model to produce a price is how you get a confident, fluent, invented number. Ours never does. The figure comes from optimisation over observed transactions, bounded by hard constraints — cost floor, margin target, cash available. The model's only job is to put that result into a sentence a person can act on.

When the evidence is thin, the system says so and returns a range. A wrong number stated precisely is worse than an honest interval, because someone will trade on it.

Example output

List at 31,900 — expected sale in 6 days

Confidence: high · 34 comparable observations · expected margin +2,400

Feedback

Every recommendation is scored against what actually happened.

01

Recommend

A specific action with a target, a timeframe and an expected value.

02

Record

Taken or dismissed — both are logged. Ignoring advice is information too.

03

Reconcile

When the item sells, realised margin is compared to the forecast. The gap tunes the engine.

This closes the loop that most analytics products leave open. It also produces the only number that matters commercially: what the platform earned its customer this month.

Have a system that needs building — or one that stopped scaling?

Tell us what you are trying to decide. If we are not the right people for it, we will say so.

Start a conversation