Mighty
Why MightyCitadel
Use cases
LendingIncome files before you fundInsuranceAppraisals to claim photosClaimsPhotos and estimates at first noticeAll use cases
SecurityDocsLog in
See it on your files

Docs

Direct SaaS purchase is no longer offered

New commercial terms are enterprise or custom, scoped on a call.

See it on your files
Browse docs
Start Here
Citadel Docs5-Minute QuickstartMighty PlatformUse CasesFAQ
Core Concepts
How Citadel WorksModalities And AttacksModes And ToleranceChoose Scan SettingsGlossarySessions And Scan GroupsDriftBilling, SCU, And Limits
Integration Guides
Integration GuidesMultimodal SupportScan Text And OCR OutputScan File UploadsDamage Photo AI Fraud ReviewScan Model OutputAsync Deep ScansError Handling
Frameworks
Framework Integration MapVercel AI SDK Chat GuardrailNext.js Upload GuardrailBackend API HelpersDocument Processing PipelineLangChain + LangGraph Guardrail
Workflows
Workflow Playbooks
API Reference
POST /v1/scan
Use With AI
Use With AI
Start Here
Citadel Docs5-Minute QuickstartMighty PlatformUse CasesFAQ
Core Concepts
How Citadel WorksModalities And AttacksModes And ToleranceChoose Scan SettingsGlossarySessions And Scan GroupsDriftBilling, SCU, And Limits
Integration Guides
Integration GuidesMultimodal SupportScan Text And OCR OutputScan File UploadsDamage Photo AI Fraud ReviewScan Model OutputAsync Deep ScansError Handling
Frameworks
Framework Integration MapVercel AI SDK Chat GuardrailNext.js Upload GuardrailBackend API HelpersDocument Processing PipelineLangChain + LangGraph Guardrail
Workflows
Workflow Playbooks
API Reference
POST /v1/scan
Use With AI
Use With AI
Loading docs…
Mighty

Citadel is Mighty's product. It finds generated or AI-edited fakes in customer files.

See it on your files

Platform

  • For Lending
  • For Insurance
  • For Claims
  • Product
  • Use Cases
  • Contact
  • Docs

Company

  • Why Mighty
  • Blog

Trust

  • Security
  • Status
  • Privacy
  • Terms
© 2026 Nine Suns Inc. All rights reserved.Citadel, from Mighty

Framework Integration Map

Choose the right Citadel pattern for chat, uploads, backend APIs, serverless routes, and agent frameworks.

Every framework integration is the same idea: scan on the server before trust.

The framework only changes where you put the helper.

Core concept

Scan the file before the workflow acts on it.

Customer filePaystub, photo, PDF, extracted text, model output
Citadel scanPOST /v1/scan returns action, risk, IDs, and signals
Your routingContinue, review, redact, or block before automation acts
Citadel does not prove fraud. It flags risk on the file before funding, bind, payout, storage, or a model call.

Choose Your Pattern

StackPut Citadel hereUse this guide
Vercel AI SDK chatInside app/api/chat/route.ts, before streamText, and before strict output returns.Vercel AI SDK
Next.js uploadsInside the upload Route Handler before storage, OCR, or extraction.Next.js file upload
Backend APIIn a server helper or middleware before the handler calls AI, OCR, storage, or tools.Backend API helpers
OpenAI SDKScan prompt before model call. Scan output before public display or automation.Backend API helpers
LangChainScan user input before chain invocation. Scan retrieved docs and tool output before adding them to context.Backend API helpers
LlamaIndexScan query input, retrieved nodes, extracted text, and final response before trust.Backend API helpers
Async reviewSubmit mode=comprehensive, async=true, then poll or handle webhooks.Async scans

Integration Rules

  • Keep MIGHTY_API_KEY on the server.
  • Scan before the model, OCR, storage, workflow automation, payment, or agent action.
  • Use scan_phase=input for submitted material.
  • Use scan_phase=output for generated, extracted, summarized, or agent-created material.
  • Reuse scan_group_id for related input, file, OCR, output, and review scans.
  • Use session_id for the wider chat, claim, case, batch, or agent run.
  • Route ALLOW, WARN, BLOCK, indeterminate, and async pending.
  • Use safe fallback behavior when Citadel cannot be reached.

Framework Traps

TrapFix
Calling Citadel from browser codeMove scan calls to a server route.
Scanning only the initial promptScan model output, tool output, OCR output, and extracted fields too.
Returning JSON from a useChat route that expects a UI message streamFor Vercel AI SDK streaming routes, return toUIMessageStreamResponse or createUIMessageStreamResponse.
Losing scan_group_id between upload and OCRPersist it on the item, not only in logs.
Treating framework errors as safeFail closed or use review fallback for high-risk workflows.
Next step

Ready to scan real traffic?

Book a working session on your files. Starting October 1, 2026, new commercial terms are enterprise or custom.

Vercel AI SDKNode and Python

AI-Agent Prompt

AI-ready prompt
Choose the Citadel framework pattern

Paste this into Cursor, Codex, Claude Code, or Windsurf.

Choose the correct Citadel framework integration pattern.

Rules:
- Use server-side scan calls only.
- Put POST /v1/scan before AI, OCR, storage, workflow automation, payment, and agent action.
- Use the Vercel AI SDK route pattern for app/api/chat/route.ts.
- Use the Next.js upload route pattern for browser file uploads.
- Use the backend API helper for Node, Python, Express, FastAPI, Flask, Django, workers, queues, and custom APIs.
- For LangChain and LlamaIndex, scan before chain invocation, before retrieved content enters context, before tool output is reused, and before final output is shown.
- Preserve scan_id, request_id, scan_group_id, session_id, action, and risk_score.

Acceptance criteria:
- API key never reaches client code.
- Existing framework response shape is preserved.
- Tests cover ALLOW, WARN, BLOCK, and scan failure.

On this page

Choose Your PatternIntegration RulesFramework TrapsAI-Agent Prompt