Use Cases
Where Citadel sits before a mortgage funds, or an insurer binds or pays.
Start with the file the customer sent. Ask where that file becomes a funding, bind, or payout decision.
Use cases
Start with the file that can move money.
Customer fileIncome docs, claim photos, estimates, extracted text
Citadel scanThreats, authenticity, sensitive data, risk, redaction
After routingFund, bind, pay, store, or review
Same four routes every time: continue, pause, review evidence, or stop.
For setting recipes, see Choose Scan Settings.
Use case map
| Use case | What can go wrong | Where Citadel sits | Suggested settings |
|---|---|---|---|
| Mortgage income and assets | Altered paystubs, W-2s, bank statements, or tax returns clear review and come back as a buyback. | Before underwriting trusts the file, and before you fund. | content_type=document or pdf, focus=steg, profile=strict for high value. |
| Insurance underwriting | Generated or edited attachments used to qualify a policy. | Before the packet is treated as true and the policy binds. | data_sensitivity=tolerant, focus=steg for structured docs, focus=all for image or PDF evidence. |
| Claims intake | Altered photos, estimates, or invoices. Hidden instructions in the packet. | Before storage, extraction, routing, or adjuster automation. | data_sensitivity=tolerant, profile=strict for high value. Use focus=steg for structured documents and focus=all for known image or PDF evidence. |
| Damage photo review | Damage added, erased, or generated to match the loss. | Before claim, repair, or payment decisions. | content_type=image, focus=all, mode=comprehensive for deep review. |
| Invoice and estimate review | Line items and totals altered. Fabricated charges. | Before extraction, approval, or payment. | content_type=pdf or document, data_sensitivity=tolerant. |
| Text already read from a file | Hidden instructions become trusted fields. | Scan the original file, then the extracted text with the same scan_group_id. | focus=steg, data_sensitivity=tolerant. |
| User-generated uploads | Hidden instructions, sensitive data, unsupported file size. | Before permanent storage, indexing, or sharing. | content_type=auto, mode=secure, focus=steg, async for large evidence. |
| Review assistant | A summary carries a tampered source forward as trusted. | Before showing generated summaries or recommendations. | scan_phase=output, data_sensitivity=tolerant. |
| Batch intake | Many records hide risky items and lose traceability. | Per item before batch automation writes state. | One session_id per batch, one scan_group_id per item. |
| Chat or agent tools | Hidden instructions in a prompt, tool result, or retrieved file. | Before the model call, and before tool output enters context. | mode=secure, focus=steg, profile=ai_safety for public output. |
| Audio intake | Transcripts can carry unsafe instructions or disputed statements. | Scan transcript text today. Audio scanning is closed beta. | content_type=text for the transcript, same session as the source audio. |
Why scan here
A bad file can become a trusted income figure, a bind decision, a payout, or an automated summary.
- Income docs: catch the alteration before you fund.
- Underwriting packets: catch the fake attachment before you bind.
- Claims photos and estimates: catch the edit before you pay.
- Extracted text: catch hidden instructions before they become a field.
- Model output: catch a summary that treats a tampered source as clean.
Value by workflow
| Workflow | Value |
|---|---|
| Mortgage | Flag an altered paystub, W-2, or bank statement before funding. |
| Insurance underwriting | Flag a generated or edited attachment before bind. |
| Claims | Flag a doctored photo, estimate, or invoice before payout. |
| Extracted text | Keep hidden instructions out of workflow fields. |
| Review queues | Give reviewers IDs, risk fields, the original file, derived text, and scan history. |
| Agents | Keep untrusted tool output out of model context. |
Build order
- Start with the workflow that moves money: income docs before funding, or claim evidence before payout.
- Add
POST /v1/scanbefore that step. - Store IDs and action.
- Route ALLOW, REVIEW, WARN, and BLOCK; keep inconclusive evidence details and a pending scan state separate from the action.
- Scan derived output with the same
scan_group_id. - Add review metrics so you can tune tolerance later.
Next step
Ready to scan real traffic?
Book a working session on your files. Starting October 1, 2026, new commercial terms are enterprise or custom.
AI-agent prompt
AI-ready prompt
Choose Citadel use cases
Paste this into Cursor, Codex, Claude Code, or Windsurf.
Find the Citadel use cases in this product.
For each workflow, identify:
- The customer file or derived text.
- Whether the next step is funding, bind, payout, storage, or a model call.
- The right content_type, scan_phase, mode, focus, profile, and data_sensitivity.
- Where scan_group_id and session_id should be stored.
- How ALLOW, REVIEW, WARN, and BLOCK are routed, with inconclusive evidence details and pending scans handled separately.
Prioritize:
- income and asset documents before funding
- new-business attachments before bind
- damage photos, estimates, and invoices before payout
- text already read from those files
- model summaries of those files
- agent tool output
- batch intake
Acceptance criteria:
- Every high-risk file has a server-side scan.
- Every derived output scan reuses the correct scan_group_id.
- Review wording says Citadel flags suspicious evidence, not that it proves fraud.