AI where it earns its place
Fast models, prompt caching and one cost-mode dial across WaveAI and internal tooling. Honest boundaries on data, spend and judgement, without ethics waffle.
One dial. Four tiers. No runaway bills.
Every Claude call honours ai.mode across Books, WaveAI and internal tooling. Lower tiers return null silently so features degrade to rules without breaking pages.
Active tier
Minimal
Rules only. Zero model spend.
- Deterministic matching and categorisation rules
- WaveAI retrieval without live model calls where configured
- Full audit trail with no API traffic
Active tier
Flow
Background AI that pays for itself.
- Transaction categorisation via Claude Haiku
- Receipt OCR cleanup with vision
- Nightly batch work with prompt caching
Active tier
Rise
On-demand explain and help.
- AI toolbar Explain and Help buttons
- WaveAI live chat with grounded answers
- Cached responses so repeat clicks do not re-bill
Active tier
Surge
Richest tier, still capped.
- Summarise this Page on demand
- Higher token budgets for complex drafts
- Monthly hard cap prevents runaway spend
Where AI runs vs where rules run
Models accelerate judgement-heavy work. Deterministic code owns anything that must be exact, auditable or legally binding.
Probabilistic
AI assists
-
WaveAI visitor Q&A
Grounded answers from your knowledge base, with handoff when context is thin.
-
Categorisation hints
Claude suggests chart-of-accounts labels. Rules still win when confidence is low.
-
Receipt OCR cleanup
Vision reads uploads, then a light model pass tidies merchant names for matching.
-
Internal drafting
Brainstorming, boilerplate and research speed-ups, always reviewed before anything client-facing ships.
-
Lead capture on your site
WaveAI can answer questions and pass a name and number to your team when a visitor is ready.
Deterministic
Rules enforce
-
Money and journals
Minor-unit arithmetic, double-entry posting and period locks stay in deterministic services.
-
Auth and access
Gate, password, PIN, TOTP and role checks never delegate to a model.
-
Abuse and rate limits
Honeypots, visitor/IP throttles and burst blocks fire before a model is called.
-
Invoice numbering
Sequences, rollovers and PDF queue drains follow fixed rules, not probabilistic guesses.
-
Upload validation
Mime checks, size caps and authenticated serving paths stay in PHP, not prompts.
Human checks without fear-mongering
We ship fast tooling, then layer calm guard rails: named humans, ticket escalation and abuse controls that work even when models are off.
Humans stay named
Decisions that affect your brand, legal position or customers stay with people you can reach on support, not a black box.
Escalation by design
WaveAI collects the right details and opens a ticket when a visitor needs a person. Thin retrieval triggers honest "I do not know" replies.
Abuse guard
Honeypot fields, blocklists, per-visitor cooldowns and duplicate-message bursts are slowed or blocked before they waste your quota.
Generated code passes the same bar as hand-written code.
Review, tests and security mindset apply before anything client-facing ships.
Claude, caching, caps
Anthropic Messages API behind a hardened client. Lightning-fast defaults, spend telemetry you can audit, and Sonnet available when the task earns it.
Haiku 4
Default model
High-volume, low-latency tasks
~80%
Cache savings
Ephemeral prompt caching on system prompts
20s
API timeout
Hard ceiling per Anthropic call
£5/mo cap
Spend guard
Daily and monthly USD-cent limits
0 bodies
Logged payloads
Token counts only, never request text
Prompt caching
System prompts carry ephemeral cache markers so repeat categorisation batches pay mostly for message deltas, not the full instruction stack every time.
Graceful degradation
When mode, caps or sanitisation block a call, callers get null and fall back to rules. No stack traces, no mystery 500s on production pages.
What we never automate
Cutting-edge models sit behind these red lines. If a feature crosses them, it stays human or deterministic.
Money movements
Payments, journals, tax lines and write-offs post through audited services, not model output.
Credentials
Passwords, PINs, TOTP secrets and API keys are never parsed or generated by AI workflows.
Legal judgment
Contract interpretation, regulatory calls and client commitments stay with qualified humans.
Unreviewed sends
Client email queues through cancellation windows. AI may draft, humans approve.
Period overrides
Closed accounting periods cannot be reopened by a model suggestion or chat command.
Access grants
Roles, invites and portal permissions change only through authenticated admin actions.
Specifics you can verify
Questions about subprocessors, retention or DPIAs belong in Privacy and in direct conversation. Here is how the platform behaves day to day.
Structured logging
Every call records mode tier, token counts and redacted summaries in ai_usage_daily. Enough to audit spend, never enough to leak content.
Inference only
We use provider APIs in inference mode. Your conversations are not fed back into public model training.
UK team
Tidalux Ltd is UK-based and ICO-registered (ZC091301). Subprocessors and retention are listed in our privacy materials.
Plain limits
When retrieval is thin, WaveAI says so. When a feature is a thin wrapper, we say that too. Specifics beat manifestos.
Want WaveAI for your brand?
Hosted assistant, knowledge grounding, abuse guard and UK support, scoped to what you actually need.