Mighty
Why MightyCitadel
Use cases
LendingIncome files before you fundInsuranceAppraisals to claim photosClaimsPhotos and estimates at first noticeAll use cases
SecurityDocsLog in
See it on your files

Docs

Direct SaaS purchase is no longer offered

New commercial terms are enterprise or custom, scoped on a call.

See it on your files
Browse docs
Start Here
Citadel Docs5-Minute QuickstartMighty PlatformUse CasesFAQ
Core Concepts
How Citadel WorksModalities And AttacksModes And ToleranceChoose Scan SettingsGlossarySessions And Scan GroupsDriftBilling, SCU, And Limits
Integration Guides
Integration GuidesMultimodal SupportScan Text And OCR OutputScan File UploadsDamage Photo AI Fraud ReviewScan Model OutputAsync Deep ScansError Handling
Frameworks
Framework Integration MapVercel AI SDK Chat GuardrailNext.js Upload GuardrailBackend API HelpersDocument Processing PipelineLangChain + LangGraph Guardrail
Workflows
Workflow Playbooks
API Reference
POST /v1/scan
Use With AI
Use With AI
Start Here
Citadel Docs5-Minute QuickstartMighty PlatformUse CasesFAQ
Core Concepts
How Citadel WorksModalities And AttacksModes And ToleranceChoose Scan SettingsGlossarySessions And Scan GroupsDriftBilling, SCU, And Limits
Integration Guides
Integration GuidesMultimodal SupportScan Text And OCR OutputScan File UploadsDamage Photo AI Fraud ReviewScan Model OutputAsync Deep ScansError Handling
Frameworks
Framework Integration MapVercel AI SDK Chat GuardrailNext.js Upload GuardrailBackend API HelpersDocument Processing PipelineLangChain + LangGraph Guardrail
Workflows
Workflow Playbooks
API Reference
POST /v1/scan
Use With AI
Use With AI
Loading docs…
Mighty

Citadel is Mighty's product. It finds generated or AI-edited fakes in customer files.

See it on your files

Platform

  • For Lending
  • For Insurance
  • For Claims
  • Product
  • Use Cases
  • Contact
  • Docs

Company

  • Why Mighty
  • Blog

Trust

  • Security
  • Status
  • Privacy
  • Terms
© 2026 Nine Suns Inc. All rights reserved.Citadel, from Mighty

FAQ

What Citadel checks, what it does not claim, and where it sits before you fund, bind, or pay.

What does Citadel check?

The file a customer submitted: paystubs, W-2s, bank statements, applications, damage photos, estimates, invoices, and the text already read from those files.

It looks for generated or edited content, and for hidden instructions that try to steer the next system. It returns ALLOW, WARN, or BLOCK, plus the evidence.

Does Citadel say whether a claim is true?

No.

Citadel does not score truth, facts, or news. Your team still decides whether to fund, bind, or pay.

The product route is what stops the risk. Citadel returns three distinct fields:

  • action is one of ALLOW, WARN, or BLOCK. Switch on this for routing.
  • scan_status is one of pending, complete, or failed. Async lifecycle, separate from routing.
  • authenticity.verdict is one of likely_real, likely_ai_generated, ai_generated, or indeterminate. Forensics on the file itself, separate from routing.

Your app routes on action. indeterminate is a forensics verdict, not a routing action.

Citadel support operator explaining that Citadel routes altered files, hidden instructions, and suspicious evidence
Citadel flags risk on the file. Your team makes the decision.Use it before funding, bind, payout, storage, or a model call.

Does the model decide if the file is safe?

No. Your server calls Citadel first.

customer file -> Citadel scan -> route result -> underwriting, claims, or model

Only then pass routed material into the model, the reader, the agent, or the workflow.

Where should Citadel sit?

SurfacePut Citadel before
Paystub, W-2, bank statementFunding.
New-business applicationBind.
Damage photoClaim, repair, or payment decision.
Invoice or estimateApproval or payment.
Uploaded fileStorage, extraction, or indexing.
Text already read from a fileExtracted fields become workflow data.
Model outputUsers or downstream tools see it.
Agent tool outputTool output enters model context.
Chat promptModel call.

Does Citadel prove fraud?

No.

Citadel can flag a suspicious file, hidden instructions, unsafe output, or authenticity signals. Your team and product policy make the final business decision.

Use this wording:

  • Citadel flagged this for review.
  • Citadel blocked this route.
  • This result needs more evidence.
  • This result is indeterminate.

Do not say:

  • Citadel proved fraud.
  • Citadel proved the document is real.
  • Citadel proved the statement is true.

Does Citadel replace app security?

No.

Keep your normal controls: authentication, authorization, rate limits, file size limits, malware scanning when required, audit logs, and human review for high-risk decisions.

Citadel inspects the customer file before the workflow acts on it.

What file types does Citadel accept?

One scan contract across:

  • Text.
  • Images.
  • PDFs.
  • Documents.
  • Text already read from a file.
  • Model output.
  • Agent tool output.
  • Audio transcripts today. Audio file scanning is closed beta.

Use Multimodal Support to choose settings.

What should my app store?

Store these fields when returned:

  • scan_id
  • request_id
  • scan_group_id
  • session_id
  • action
  • risk_score
  • risk_level
  • threats
  • content_type_detected
  • redacted_output

This gives support, billing, review, and audit teams enough context to understand the route.

What should I give my AI coding agent?

Use this prompt.

AI-ready prompt
Explain Citadel correctly

Paste this into Cursor, Codex, Claude Code, or Windsurf.

Use Citadel, Mighty's product, to check customer-submitted files before funding, bind, or payout.

Do not implement Citadel as:
- a truth oracle
- a fact checker
- a misinformation classifier
- a source-of-truth system

Implement Citadel as:
- server-side scanning of the submitted file
- a second scan of extracted text or a model summary from that file
- multimodal scanning for text, images, PDFs, documents, extracted text, model output, and agent tool output
- routing on action (ALLOW, WARN, BLOCK), scan_status lifecycle (pending, complete, failed), and authenticity.verdict (likely_real, likely_ai_generated, ai_generated, indeterminate)

Risks to route:
- generated or edited income documents
- generated or edited claim photos, estimates, and invoices
- hidden instructions in the file
- data exfiltration attempts
- secret leakage
- extracted text that steers automation
- unsafe model output

Acceptance criteria:
- The file is scanned before funding, bind, payout, storage, or a model call.
- The app does not claim Citadel proves fraud or truth.
- The app stores scan_id, request_id, scan_group_id, session_id, action, and risk_score.
- Tests cover ALLOW, WARN, BLOCK, scan failure, and output scanning.
Next step

Ready to scan real traffic?

Book a working session on your files. Starting October 1, 2026, new commercial terms are enterprise or custom.

Run quickstartHow it works

On this page

What does Citadel check?Does Citadel say whether a claim is true?Does the model decide if the file is safe?Where should Citadel sit?Does Citadel prove fraud?Does Citadel replace app security?What file types does Citadel accept?What should my app store?What should I give my AI coding agent?