ASL Help Engine — Source library
Public documentation snapshot: 2026-09-08
A wrong answer costs more than no answer
In-product help that answers only from your reviewed sources, cites every claim, and stays silent otherwise.
A wrong answer costs more than no answer
Built for: A support lead whose team answers the same forty questions by email every week and cannot risk an assistant inventing the forty-first · A product owner in a regulated field - therapy, corrections, benefits, compliance - where a made-up answer becomes someone's real decision · A software team that needs one help assistant across several applications without each one getting its own half-maintained copy · An operations manager whose staff see different procedures depending on their role, and who cannot have a help box flatten those boundaries
ASL Help Engine exists because of this.
You put a help assistant in your product because the support queue was drowning. Then someone asked it about refunds, or about who is allowed to close a case, and it answered - confidently, fluently, and wrong. Nobody noticed until a customer acted on it. Now you are the one on the phone explaining that your own software told them something untrue, and the trust you were trying to build is the thing you spent. The usual response is to smother the assistant. You bury it under disclaimers, or you switch it off and go back to email. Neither actually fixes anything. Your team still retypes the same answers, your written procedures still sit in a folder nobody opens, and the person who needed help at 9pm still gets nothing. The problem was never that an assistant is a bad idea. The problem is that a system which cannot tell the difference between knowing and guessing will always guess, because guessing looks like helpfulness right up until it does not. And if your help content is not uniformly public, the risk gets sharper. A scheduler should not read the billing manager's procedure. One store's answer should not surface in another store's window. A restricted operating guide should not be reachable by anyone who happens to find the help box. Most help tools treat access as a display problem - hide the article in the sidebar - when it is really a retrieval problem. If the wrong passage can be retrieved at all, it can be quoted back to the wrong person in a sentence that never names the article it came from.
ASL Help Engine exists because of this.
Refusal is designed in and protected by the release gate - the reviewed question set includes questions the engine must decline, so cite-or-stay-silent cannot quietly regress
ASL Help Engine exists because of this.
Entitlement is enforced before retrieval, so a passage the reader may not see is never a candidate for a paraphrase
ASL Help Engine exists because of this.
Authorization claims inside a request body - role, tenant, visibility, purpose, subject, even the collection name - are rejected rather than trusted
ASL Help Engine exists because of this.
Questions never leave for an outside AI service and the engine does no live internet search when an answer is produced
ASL Help Engine exists because of this.
The last safety check on the open public collection is one-way: it can withhold a shaky answer but has no ability to create one, invent a citation, or upgrade a refusal into confidence
ASL Help Engine exists because of this.
Every answer carries an explicit verdict label from a fixed set, including a request to narrow a question rather than a guess at what it meant
ASL Help Engine exists because of this.
Every answer is checkable by the reader - document, section, exact excerpt, authority, version, and the original source link
How ASL Help Engine works, start to finish.
The ASL Help Engine is the shared answering service behind help in Auto Secure Login products. You give it help content that a named owner has actually reviewed. When someone asks a question, it finds the passages in that content that genuinely bear on the question, and answers using the reviewed wording - with a citation attached to every claim. If the reviewed content does not support an answer, it says so and returns nothing else. There is no fallback to general knowledge, no improvising around a gap, and no quiet paraphrase of something adjacent. That refusal is the product, not a failure mode. Every answer comes back in the same shape, so your interface can be honest instead of decorative. Each reply carries an explicit verdict label rather than a uniform confident tone. The labels are a fixed set: a direct answer, a supported answer drawn from reviewed wording, a conditional answer with stated caveats, an answer corroborated across more than one source, a potential conflict where reviewed sources disagree, a request to narrow a question that is too vague to place, and insufficient evidence. A live check on 2026-09-02 returned supported for a reviewed help question, conditional for a public-law excerpt, and insufficient with zero citations for an off-topic one. Each claim carries its citations - the document, the section or page, the exact excerpt used, the authority behind it, the version, and a link to the original source - plus any limitations the reader should know before acting. A reader can check the answer without trusting the answerer, which is the only kind of checking that counts. Content is organised into separate governed collections, each with its own accountable owner, data classification, languages, and audience. Your application tells the engine who is asking, and the engine intersects what that application is allowed to reach with what that collection is allowed to release, before it retrieves anything. Restricted collections fail closed: if entitlement cannot be established, the answer does not happen. An anonymous visitor can reach public collections only. Nobody widens their own access by claiming a role in the question - authorization fields placed in the request itself are rejected outright, and a public request that tries to name its own collection comes back as a refusal, not a partial answer. Six governed collections run today, from a fully public help set to a restricted staff collection with ten roles and six separately granted capabilities inside it. Getting content in is a reviewed pipeline, not an upload button. Owners can submit plain text, Markdown, CSV, or structured files; the engine converts them into the article shape, validates them, and holds them as staged drafts. Nothing publishes itself. A staged draft can be listed, retrieved, retired, and recovered, and it is checked against the live collection - version parity, English and Spanish parity, existing question behaviour - before a human owner decides. The engine will not index, publish, activate, or learn from a draft on its own, and it has no path that lets an uploaded file quietly become a live answer. Around all of that sits ordinary operational discipline. A fixed set of forty-eight reviewed questions with expected citations runs before and after a release, so an accuracy regression stops the release rather than reaching a customer. Approved source links are checked for reachability, and the running service publishes the dated result of its last check. Readers can mark an answer helpful or not, tied to that exact answer, and comments that look like an email address or account number are rejected rather than stored. The activity record keeps what is needed to investigate - which collection, which evidence, what verdict, which content version - and deliberately never keeps the raw question or the conversation.
Everything in the current release.
Each of these is built and working today. Nothing on this list is a roadmap item.
It cites, or it says nothing
Every claim in an answer carries the exact passage it came from, the document and section, the authority behind it, the version, and a link to the original. When the reviewed content does not support an answer, the reply is an explicit statement of insufficient evidence with zero citations attached, plus a short note on what would make the question answerable. There is no in-between state where the wording sounds sourced but is not.
An explicit verdict on every answer, not one confident voice
Every reply is labelled from a fixed set: direct, supported, conditional, corroborated across more than one source, potential conflict, a request to narrow the question, or insufficient. Your interface can show that label rather than hiding uncertainty behind a friendly tone. When two reviewed sources genuinely disagree the engine flags the disagreement instead of silently picking a winner, and when a question is too vague to place it asks which source, jurisdiction or section you mean rather than guessing at one.
English and Spanish, both actually reviewed
Collections carry independently reviewed English and Spanish articles that share the same identity and version. The release gate compares the two languages for article counts, versions, visibility, audience, source location, and actual answer behaviour, so one language cannot drift ahead of the other. The reply follows the language your application states for that reader rather than the language the question happens to be typed in - a live check returned the reviewed Spanish passage and the identical citation once Spanish was stated. If only one language has been reviewed, the other is not presented as supported.
Access decided before retrieval, not after
Collection, audience, role, tenant, language, visibility, and content lifecycle are all applied before anything is ranked or quoted. A passage the reader is not entitled to is never a candidate, so it cannot leak through a paraphrase. Restricted collections fail closed when entitlement cannot be established.
Identity comes from your application, never from the question
Your application already knows who is signed in and what they may see; it passes that through in a request-bound signed form the engine verifies and a browser cannot produce. Role, tenant, visibility, purpose, and subject fields placed in the request body are rejected rather than honoured - a public request that tries to name its own collection is refused outright. Nobody talks their way into a restricted collection by describing themselves as an administrator.
Your questions are not sent to an outside AI service
Answering happens inside the service on the reviewed content you supplied. There is no call out to a third-party model when an answer is produced, and no live search of the open internet. What you publish into a collection is the entire universe the answer can be drawn from.
A one-way safety gate on the open public collection
On the collection anyone can query without signing in, a last check scores whether the question belongs to that body of knowledge at all before a proposed answer is released. It can turn a shaky answer into an honest refusal, and that is the only direction it can move - it cannot add an answer, invent a citation, choose a route, or upgrade a refusal into confidence. Be clear about its reach: it guards that one public collection today. The others rest on the entitlement filter, the citation validator, and the reviewed question set, which apply everywhere.
Misspellings handled without guessing at meaning
Common typos in English requests are corrected on the way into retrieval, and the correction is disclosed to the reader alongside the answer. A real-word confusion - such as wave where waive was meant - is drawn from a small fixed list and applied only when the corrected wording actually turns up official evidence that clearly outscores the original. A genuine use of the original word is left alone, the displayed question and citations are never rewritten, and Spanish wording is not touched.
Well-rounded evidence rather than five copies of one passage
Evidence selection scores each candidate for the parts of the question nothing has covered yet, so a reader gets a rounded set of citations instead of the same paragraph quoted five times. Ranking weighs exact identifiers, headings, phrases, and editorial signals, not just keyword overlap. This is what lets an answer about one specific rule cite that rule rather than its neighbours.
Content intake with a review gate that cannot be skipped
Owners can submit plain text, Markdown, CSV, or structured files and get back a validated draft in the correct article shape. Drafts stay in a protected staging area where they can be listed, fetched, retired, and recovered without ever touching live answers. Publishing is a separate, deliberate, owner-approved release.
A proposed change is tried against the live one before it ships
Before content is integrated, the engine runs the proposed version and the current version side by side through the real answering path. It replays the reviewed question set, probes the specific articles that changed, checks that near-miss questions in both languages still refuse, repeats runs to confirm the same answer every time, and reports the difference. An owner reads that report and decides.
Accuracy checks run before and after a release
A fixed set of forty-eight reviewed questions with expected citations and expected refusals - covering every collection in both languages - runs as part of a release, both before the switch and again on the live service afterwards. A regression stops the release rather than reaching a reader. The running service publishes its most recent result together with the date it was produced, so you can see exactly what was checked and when.
Feedback bound to the exact answer it is about
A reader can mark an answer helpful or not helpful and pick up to four reasons from a fixed list: incorrect, missing information, wrong source, outdated, unclear, or other. A short optional comment is capped at 500 characters. Feedback is tied by a short-lived token to the specific answer that produced it, so it cannot be aimed at someone else's session or another organisation's content, and comments containing an email address, phone number, or account-number pattern are rejected instead of stored.
Records that keep the audit and drop the person
The activity record keeps what an investigation needs - which collection, which evidence, which verdict, which content version - and deliberately never keeps the raw question or conversation. Names, email addresses, phone numbers, raw user identifiers, credentials, and source excerpts are all excluded; a one-way fingerprint stands in for identity. The default retention for those minimized records is ninety days and can be shortened.
Numbers we can stand behind.
Every figure below comes from the product's own release record or test suite, not from a marketing estimate.
Numbers we can stand behind.
English and Spanish are held to parity by the release gate, not by hoping the translation kept up
Numbers we can stand behind.
Uploaded content cannot become a live answer on its own; staging, comparison against the live collection, and owner approval are separate steps
Numbers we can stand behind.
Each governed body of content is its own collection with a named owner, data classification, and audience - not one shared bucket with filters bolted on
Numbers we can stand behind.
Answer accuracy, source-link health, and the current content fingerprint are all published by the running service with their dates, so nobody has to take a release note's word for it
Surfaces and status.
Status as of 2026-09-02. Checked live on 2026-09-02. The running service reports version 0.10.10, six governed collections each with a published content fingerprint, and its most recent reviewed-question run passing 48 of 48, dated 2026-08-29. Behaviour checks in that same session: an English question returned a supported answer citing the exact reviewed section with its source link; the same question returned the reviewed Spanish passage and the identical citation once the request stated Spanish, and returned the English passage when no language was stated; an off-topic question returned an explicit insufficient-evidence reply with zero citations and a note on what would make it answerable; a request that tried to name its own collection or role was rejected outright, because those fields are set by the service and not by the caller; anonymous requests to both restricted collections were refused; and a public-law question, once addressed to the public-law collection, returned a cited excerpt from a published appellate opinion with its rule identifier, legal-status label, page reference and official source link. Two things the site copy must not overstate: that public-law question is refused if it is sent to the product help collection instead, and the repository's dated production activation records run only through 0.10.9 on 2026-08-29 - the 0.10.10 record still lists activation as pending, so the running service is the evidence for that version rather than the repository.
Worth more together.
Products on this platform share one sign-in, one support queue, and one engineering standard. These pair naturally with ASL Help Engine.
Policy Lens
The public face of the engine. Policy Lens is where anyone can see the behaviour first-hand without signing in: ask about a rule, get a cited excerpt with its authority label, legal status and official link, or get an honest refusal when the indexed sources do not cover it.
ASL Therapy
The largest restricted collection runs here - staff help where a scheduler, a biller and a supervisor each see only the procedures their role and delegated capabilities cover. Ten roles and six separately granted capabilities in one collection make it the working proof that audience boundaries hold before retrieval, not after.
ShopFit
Merchant help for installation, audit results, approval limits, integrations, billing status and privacy, in English and Spanish, behind sign-in. It shows the engine answering commercial operating questions without ever touching customer or order data.
ASL Intake
Public setup and go-live guidance for firms taking in new matters, answered in both languages from the same reviewed articles the product already publishes on its own help pages.
HomelessHelper
A public service help collection - verified live returning cited answers on how to search by state and county, and who to call in a crisis, each linking back to its reviewed source. The people asking are often on a phone, in a hurry, and cannot afford a confident wrong answer about eligibility or where to go.
ASL Tickets
Where an unanswerable question is meant to go next. The hand-off from an unresolved answer session to support, as a short summary carrying no personal data, is built and has been exercised end to end - but it is deliberately switched off, and the running service reports it as not configured.
Recent progress.
This product ships often. The most recent verified changes, newest first.
Recent progress.
2026-08-25 a full-policy search collection went live alongside a single reliable path for one regulator's rules.
Recent progress.
2026-08-26 corrected the statewide bilingual bridge. Between.
Recent progress.
2026-08-28 multi-authority public-law references went live - covering statutes, enacted session laws, rulemaking records, judicial rule changes, published appellate opinions, attorney-general opinions, municipal sources and department guidance, each keeping its own authority label - followed on.
Recent progress.
2026-08-28 by exact-identifier decomposition, a refusal envelope that tells the reader how to fix their request, and an English spelling and word-confusion guard that only corrects when the corrected wording actually produces better official evidence. On.
Recent progress.
2026-08-29 a regression that let a capability question be answered with the wrong reviewed article was repaired and shipped, and the one-way domain-margin gate over the open public help collection was confirmed on a held-back set the engine had never seen and activated in production, cutting incorrect confident answers from four to two across 7,837 cases while introducing none. On.
Recent progress.
2026-09-01 citations began carrying the direct policy identifier, so a reader sees which rule matched without opening the source document to find out; a live check on.
Recent progress.
2026-09-02 confirmed that field arriving in a real public-law citation, on a service reporting version 0.10.10 with 48 of 48 reviewed questions passing.
Recent progress.
Pricing for ASL Help Engine is quoted after a short conversation about your situation, because the right scope differs from one team to the next. There is no charge for that conversation.
We already have a help centre and a search box. Why add this?
Keep the help centre - this reads from it rather than replacing it. The difference is what happens when someone asks a question your search box answers with ten blue links or nothing at all. This returns the specific passage that answers it, with the section, the version, and the link, or it tells them plainly that the reviewed material does not cover it. Your articles stay the source of truth; this is a better way to reach into them.
We already tried a general AI chatbot on our documents. What is different here?
The usual arrangement will always produce an answer, because producing answers is what it is for. This one is built to stop. Refusal is part of the reviewed question set that runs with a release, so an answer that starts appearing where it should not appear breaks the release instead of reaching a reader. It also enforces who may see which content before it retrieves anything, and it does not send your questions to an outside AI service.
What does it cost?
Pricing is not published. It runs today as shared infrastructure behind several Auto Secure Login products rather than as a separately priced product, and the honest answer is that the cost depends on how many collections you need, how much content review they need, and whether support escalation is in scope. Ask and you will get a real number rather than a tier chart.
How much work is it to move our content in?
The mechanical part is short: plain text, Markdown, CSV, or structured files go in and come back as validated drafts in the right shape, with staging, retrieval, retirement, and recovery all available before anything is live. The real work is editorial - deciding who owns each collection, what classification it carries, who may read it, and writing the reviewed questions it must answer plus the near-miss questions it must refuse. Expect the review to take longer than the import, and treat that as the point rather than an obstacle.
Is our data safe, and what exactly gets stored?
The activity record keeps which collection was asked, which evidence was used, which verdict came back, and which content version was live. It deliberately does not keep the raw question or the conversation, and it excludes names, email addresses, phone numbers, raw user identifiers, credentials, and source excerpts - a one-way fingerprint stands in for identity. Those minimized records are kept for ninety days by default and can be shortened. Feedback comments that look like an email address or account number are rejected instead of stored.
Can one customer, or one staff role, end up seeing another's content?
Access is decided before anything is retrieved, so material outside a reader's entitlement is never even a candidate to be quoted. Restricted collections fail closed when entitlement cannot be established, and role, tenant, or permission claims written into the question itself are rejected rather than believed - a public request that names its own collection is refused outright. A feedback token issued for one organisation's answer cannot be used to act on another's.
Is it actually ready, or is this a roadmap?
It is running now, and you can check it yourself without asking us: the service publishes its running version, its collections with content fingerprints, and the dated result of its last reviewed-question run, which currently reads 48 of 48. What is genuinely not finished is stated plainly: support-ticket escalation is built but switched off, running multiple copies side by side is not supported, and external merchant availability still needs a named human approval.
How would we know if it quietly got worse?
You would see it in the published numbers rather than hearing it from us. The forty-eight reviewed questions include cases the engine must refuse as well as cases it must answer with a named citation, and that run is part of a release both before the switch and again on the live service afterwards. The running service reports the result and the date it was produced, and the link-health check reports the same way, so a stale or failing check is visible instead of hidden in a release note.
What happens to our content and our answers if we stop?
Your content is yours. It lives as reviewed article files with stable identifiers, version records, and source references, and it can be handed back in that form - there is no proprietary shape you would have to reverse-engineer. Nothing about your published help depends on the engine continuing to run; your own help pages stay exactly where they are. What stops is the answering, the citations, and the refusals.
Will it just answer in whatever language the question is written in?
It answers in the language your application states for that reader. That is deliberate - the reviewed English and Spanish articles are held to parity by the release gate, so the engine serves the reviewed passage for a stated language rather than guessing a language from the wording and possibly serving an unreviewed pairing. In practice you pass the reader's language the same way you already pass who they are. Send nothing and you get English, with the same citation.
What should I know before I rely on it?
We would rather you hear this from us than discover it later. As of 2026-09-02:
What should I know before I rely on it?
It only knows what you have reviewed and published into a collection. It will not answer from a folder of unreviewed documents, and there is no setting that makes it improvise around a gap.
What should I know before I rely on it?
Handing an unanswered question to a support ticket is built and tried end to end, but it stays switched off until delivery, failure handling, privacy, and duplicate-ticket evidence are attached to a release. Today the running service reports it as not enabled.
What should I know before I rely on it?
The service runs as one copy. Running several copies side by side needs shared replay and queue state added first, and that work is listed as deliberately not done.
What should I know before I rely on it?
The link check confirms an approved source still resolves to an approved location, and its published result is a dated snapshot rather than a live reading - it can lag the intended daily cadence. It also does not prove the content behind the link is still correct; a named owner still has to re-read the source on a schedule, ninety days for security, privacy, incident and billing material.
What should I know before I rely on it?
Merchant help is not yet opened to outside merchants. Automated bilingual and security review is recorded, but a named human owner still has to approve the rendered pages before external availability.
What should I know before I rely on it?
It is not legal, clinical, financial, or compliance advice, and it does not make a decision for anyone. Public-law results in particular are short search excerpts with their authority and status labels attached; the official source must be opened to confirm full text, currentness, and exceptions.
What should I know before I rely on it?
The large public-law and policy corpus is owned and searched by Policy Lens. The Help Engine is the evidence-selection and citation boundary over it, and when that upstream service cannot state its exact contract the engine drops to a plainer quote-only path or refuses rather than guessing.
What should I know before I rely on it?
The typo and word-confusion guard covers English requests and a small fixed list of confusions. Spanish wording is deliberately left untouched.
What should I know before I rely on it?
Adding a new product collection is real work, not a switch: reviewed articles, a named owner, a data classification, an approved source location, role and audience decisions, and its own reviewed question set including questions it must refuse.
What should I know before I rely on it?
The one-way safety gate that can only withhold an answer runs today on the collection anyone can query without signing in, not on every collection. Everywhere else the protection is entitlement filtering before retrieval, citation validation, and the reviewed question set with its required refusals.
A wrong answer costs more than no answer
Prefer email? contact@autosecurelogin.com