neural-bridge.dev
active · since Aug 2026

Gemma GRC

A small, private compliance assistant on a Mac Mini. An open Gemma model is told to answer only from a governed library of my notes, course material and primary public regulatory texts, and to cite the passage behind every claim. A lab notebook measures whether any of it works.

Gemma GRC is a governance, risk and compliance assistant on a Mac Mini on my desk. Questions are answered locally, with no network connection. A small open Gemma model works from a library of my notes, course material and primary public regulatory texts. It is told to cite the passage behind every claim and to say so when the library does not cover the question. Those are prompt instructions rather than enforced checks; in one measurement it followed the citation instruction on 48 of 50 answers.

It is also a lab. Every change is a run with the hypothesis written down first, one variable at a time, scored against a frozen question set by a judge from a different model family.

The lab loop: write the hypothesis first and make one change, run the frozen question set, have a judge from another model family score it, read confidence intervals against the noise floor, then write the run note and the next hypothesis.
The lab loop · Open full size

How it works

Gemma GRC data flow. At build time, on the Mac with no model involved, my notes pass a fail-closed confidentiality gate; labelled, flagged or bannered notes are held back with the reason logged. Cleared notes are chunked and redacted, and join primary public regulatory sources, fetched with their licence recorded, in a stamped and fingerprinted index. At query time, with no network, the index is checked against its corpus and model, a hybrid dense and keyword search finds passages, and Gemma 3 4B answers only from them, citing each claim or naming what is missing.
Build time and query time · Open full size

My notes pass a scope check and a fail-closed confidentiality gate, then are chunked, redacted and stamped with a content-hash ID and a provenance class: public, own, or other (local only). Public regulatory texts come in on a separate lane that accepts only official hosts over https and records each text’s licence. The default library is 7,167 chunks: 1,178 from my notes and 5,989 from public texts.

At query time, hybrid search fuses BGE embeddings with BM25 and keeps the top eight passages. There is no reranker; one made results worse when I tried it. As many passages as fit a fixed budget go to Gemma 3 4B, running locally, which answers with a bracketed citation per claim or names what is missing.

What the lab found

Governance

The ingestion pipeline is fail-closed. A note never enters the corpus if it has any of these:

Line-ending or frontmatter quirks cannot open the gate. The provenance class decides where a chunk may go: only public text whose licence allows it, and my own published writing, may leave the machine or train a model that could. The search model tuned in August predates the gate and stays on this machine.

Chunk IDs are content hashes. The search index is stamped with the corpus and the model that built it, so it refuses to load against anything else.

My first gate read private flags but not classification labels. A self-audit found labelled notes in the local library and test set. None were published; the fail-closed gate is the fix.

Writing

What’s next

The public-text lane was finished on 2026-09-25: 58 official sources, including EU acts through CELLAR (EUR-Lex blocks scripts), UK legislation from legislation.gov.uk and NIST’s OSCAL catalogues. Still to do:

// Posts about this project