Known limitations

What this platform does not do, stated plainly

A tool that assesses the honesty of business cases has to hold itself to the same standard. This page lists what is absent, what is weak, and what needs work outside our control before it can be relied upon.

Boundaries of the product

It does not advise

DUN-AI does not provide legal, regulatory, financial, investment, clinical or safety advice, and does not substitute for a lawyer, a data protection officer, a clinical safety officer, an actuary or an accountable executive.

It does not verify

It assesses what you tell it. It does not inspect your systems, audit your data, test your models or confirm your regulatory position. An assessment built on inaccurate inputs will produce a confident and wrong result.

It does not guarantee

No outcome, saving, return, regulatory position or delivery success is promised. Financial outputs are ranges derived from stated assumptions, and they carry the uncertainty of those assumptions.

It does not decide

A recommendation is an input to a human decision. Accountability for the decision stays with the people who make it, which is why every sealed verdict records a named accountable owner.

Content maturity

Owner gate: specialist and legal validation

All five industry packs and all five regional overlays currently carry a validation status of unvalidated. They were authored from general domain knowledge, not retrieved from primary sources, and no qualified specialist or legal counsel has reviewed them. Named instruments exist and the general shape of the obligations is described, but the content must not be relied upon as a statement of your obligations. The global baseline overlay deliberately contains no jurisdiction-specific citations at all.

Content volume is also below the depth targets set for the platform. The shortfall is reported by the content loader as a warning on every load rather than concealed by filler entries, and the counts are visible on each industry page and inside the product.

The scoring profiles used to rank the thirteen alternatives are internally authored engineering judgement, not measured data. They materially affect which option wins a comparison and have not been calibrated against real outcomes.

Not yet built

These were in scope and are absent. Nothing in the platform simulates them: a missing capability returns an explicit error or states its own absence rather than substituting something that looks like a result.

Components that are not present, and what that means in use.
ComponentConsequence
Opportunity portfolio reportSix of the seven report types render. This one states in its own output that the builder has not been written and that nothing has been substituted.
PDF and spreadsheet exportJSON, HTML, print-ready HTML, CSV, Markdown and plain text are produced. PDF and XLSX raise an explicit error rather than quietly returning a different format.
Evidence file uploadEvidence can be described and cited but not attached. Files are modelled and the upload route is not implemented.
Incident and milestone managementMilestones are created from conditions of approval but no workflow updates or closes them. Incidents are modelled only.
Vendor and contract managementSupplier records are modelled and deliberately unreachable from the decision engines, but no service manages them.
Notification deliveryNotifications are modelled and configurable; no delivery code exists, so nothing is sent.
Legal documentationThe legal pages published on this site are the current set. The wider contractual suite has not been drafted and requires qualified counsel.
AI assistance gatewayNarrative assistance is architecturally provided for but not implemented. The platform is fully functional without it, and no output today is model-generated.

Verification that has not been done

Each of these requires someone outside the build to perform it. None has been performed, and none is claimed.

  • No independent security assessment. No penetration test, code audit or third-party review has taken place.
  • No independent accessibility audit. The interface is built to target WCAG 2.2 AA and has been checked against automated and manual criteria during development, but no external audit has been carried out and no conformance is claimed.
  • No production deployment. The platform has not been run in a production environment, and no live infrastructure exists.
  • No customer use. There are no customers, no deployments and no outcomes. Any figures shown in demonstrations are synthetic and labelled as such wherever they appear.
  • No performance benchmarking. No load, latency or throughput testing has been performed, so no performance figures are published.
  • No payment processing. Billing is modelled but no payment provider is integrated and no transaction has ever been processed.

Where the engineering is weak

  • Static type checking does not pass. Formatting and linting are clean; the type checker reports errors, mostly missing annotations and database typing friction. This is a real gap, not a configuration preference.
  • Migration from an empty database is untested in the form intended for production. Schema creation currently works directly from the model definitions.
  • The demonstration set contains no approved AI investment. The synthetic scenarios resolve to outcomes such as conventional automation and a request for further evidence. That is the framework behaving correctly on the evidence it was given, but it leaves an intended demonstration case unmet.

How security and data handling are approached →