Scott Molluso · for Safeguard Properties

Safeguard OS
The new moat.

safeguardprop.comrulekeeper.aiBoth live. Open them while we talk.

Arrow keys to advance

The thesis

Product isn’t the moat anymore.
Which is why I’m building you a new one.

The new moat is a system that compounds. Every order, every state, every denial makes the next decision better — so what you own is worth more next year than the day it shipped.

Who is saying it

I have built operating systems before.
And I have already started building yours.

20+ years in proptech

Property data, disclosure, brokerage, field services.

Founder and operator

Built and ran platforms. Two past $3M ARR. Carried the P&L.

Builder

25+ production systems. Nobody writes them for me.

What you run today

Five products. No two built together.

SafeView Connect

Integration gateway

Vendors, clients, partners

SafeView Inspect

Mobile app + portal

Inspectors

SafeView Preserve

Mobile app + portal

Contractors

SafeView Access

Portfolio and results

Clients

SafeView Analytics

Reporting

Clients and internal

Inspect is a card list with map and grid tabs. Preserve is a station checklist that looks a decade older. Two crews at the same address open two apps that do not look like they came from the same company — and Connect exists to join them, which is a product you only build when the things being joined are separate systems.

What I am proposing

Five become one.

SafeView ConnectSafeView InspectSafeView PreserveSafeView AccessSafeView AnalyticsSafeguard OSOne record. One login. One chain of custody.

The rebuild, running

Here it is. All of it, running.

safeguardprop.com
Safeguard OS Dashboard. What needs a decision today, priced by what is still recoverable.
Safeguard OS Claims. Every claim by attempts spent. Two appeals, and the second is final.
Safeguard OS Compliance. SCRA, PTFA and complaint signals pulled out of free-text field notes.
Safeguard OS Work orders. Allowables resolved against investor and state before dispatch.
Safeguard OS Portfolio. Every property, its history, and the evidence attached to it.
Safeguard OS Fleet. Six agents, their governing documents, and every run they have made.

What needs a decision today, priced by what is still recoverable.

The fix, in the field

Two apps go in. One comes out.

Live prototype

In SafeView today

Inspect and Preserve are separate applications. A contractor holding both orders for one address opens two apps, and neither knows the other exists.

In Safeguard OS

One queue, both work types, ordered by the drive rather than by which app owns the record. The two orders at 14553 US 33 sit together because they are one stop.

Labels come from the work code, the missing photo is raised on the lot, and there is no Transmit button.

Installable today · native code written

Open safeguardprop.com/app on a phone, then Share → Add to Home Screen. Own icon, full screen, no browser chrome.

The iOS and Android projects are in the repository, so a native binary is a build step rather than a rewrite.

Matching what your crews already have

Everything both apps do.
Without either transmit queue.

CapabilityInspect and Preserve todaySafeguard OS
Works with no signalTwo queues, two Transmit buttonsOne queue, writes when signal returns
Getting work to the crewPush notificationPush notification
Photo captureIn-app camera, labels picked by handIn-app camera, labels from the work code
Scheduling and contact attemptsInspect only, its own tabOn the order, both work types
List, map and grid viewsInspect onlyOne queue, sorted by the drive
Background uploadYes, nativeNeeds the native build. It is in the repository.
Getting a fix to the fieldApp store release, if the crew updatesThe moment it deploys

Offline is not the thing I would remove — the queue is right and the button on top of it is not. Two of them, in two apps, is the same failure twice.

Which is the whole disagreement

Your ask

An agent built on top of SafeView finds the missing photo at the denial.

My build

An agent built inside Safeguard OS finds it before the truck moves.

Same model either way. I would build the agents you asked for — I would just put them somewhere they can still change the answer.

The fix, underneath

One stack, one record, AI on top.

AI, on top

Allowance ClassifierDenial AnalystVacancy Gap DetectorDamage ClassifierField Report TriageVendor Support

6 agents, each governed by five versioned documents, gated at every irreversible action and scored by an eval suite before a rule change reaches a live order.

One record

IntakeOrderDispatchScheduleField captureEvidenceAllowablesBid & approvalClaimPackageInvoiceRemittanceVendor pay

Thirteen stages, one row. An order arrives from a servicer, gets routed to a crew, worked, evidenced, bid, claimed, packaged, invoiced and paid without being re-keyed once — which is the only reason the claim can still cite the photograph.

Surfaces

Field app · crewsOperations console · 22 screensClient portal · servicersIntake gateway · orders in, status out

Four ways in, writing to and reading from the same record rather than to four databases that have to be reconciled afterwards.

One stack

TypeScriptNext.jsPostgres · 53 tablesLangGraphOne deploy

The only gateway here faces outward, at servicers. Connect faces inward, between five products that all belong to you — and there is nothing left for it to integrate.

Underneath it

One database.
Nothing to reconcile.

The property

Inspected in March, conveyed in November, one record throughout.

properties · work_orders · inspections · claims

The rules

Every decision stamped with the rules in force that day, and they cannot be edited after.

agents · governance_versions · eval_runs

The proof

Every irreversible action carries who approved it, what happened, and what it cost.

agent_runs · agent_actions · escalations

The guidance

HUD rules stored as data with page citations, so changing one does not mean redeploying an agent.

hud_chunks · pp_allowances · schedules

Thirty-two migrations, every one reviewed like code. The rules that matter are enforced by the database itself, so nobody can write a screen that skips them.

One of your asks, already answered

Oh — and the governance layer
is already wired in.

Your brief asks for versioned agent instructions and a regression process that proves a prompt change did not break anything. I built that as its own product, in a day, and the agents in your OS already run inside it.

rulekeeper.ai
6
Agents governed
60
Eval fixtures behind the gate
31
Regression runs recorded
14
Runs that scored below their suite

How the moat gets built

Every order makes
the next one better.

  1. 01

    A call gets made

    An agent approves an allowable or drafts an appeal, against the rules in force that day.

  2. 02

    The answer comes back

    Paid or denied, tied to the exact rule that made the call.

  3. 03

    The rule improves

    What the denial taught gets written down, rather than remembered by whoever was there.

  4. 04

    It has to prove itself

    The new rule is tested against every past case before it is allowed to decide anything.

The next call is made on a rule already proven better than the last one.

You do not have to take my word for step four. A rule that scores worse than the one it replaces is refused by the database itself — not by a policy somebody has to remember to enforce.

One more thing

Everything you have just seen
took thirty-six hours.

47,721
Lines of code
89
Commits, from 5 August 17:22
60
Eval fixtures
2
Products, both live

One person. No access to your data, systems or people. Both repositories have a git log.

The proposal

Now imagine what I can do
for the business in twelve months.

Sell what you already know

Condition, occupancy and cost history on millions of properties. Insurers, investors and valuation firms buy exactly this today, from companies holding far less of it.

Charge for certainty, not visits

You can tell a servicer which properties will cost them money before they know. That is a subscription, and it is priced differently from a work order.

Compete on recovery rate

Publish what share of disputed dollars you get back. Nobody else can put that number in a pitch, because nobody else has the evidence attached to the order.

Move into adjacent lines

Insurance inspections, title condition, tax and code. The loop is identical, the corpus is already yours.

Install me in a portfolio company

Same move, different asset class. Whatever this becomes is a template the next one starts from.

Build a SaaS we take to market

Field services runs on software somebody has to build. We own it together and sell it to the industry.

None of these are software problems any more. They are all the same problem: the knowledge exists and nothing can currently act on it.

The arithmetic

What it costs.
And what it gets back.

What it costs

One builder, twelve months.

Against the squad this scope normally takes: six engineers, a product manager and a designer, for a year. Price both from your own payroll and the gap is the number.

What it saves in time

Months, against a multi-year bet.

A surface rebuild has carried a two-to-three year estimate for as long as anyone has been quoting it. Twenty-six hours of evidence sits four slides back.

What it costs to run

$25.40

Every model call this system has ever made, across 7 production runs. Read from the database as this slide rendered. The agents are not the expensive part.

Denials never appealed

Revenue you earned and did not collect. Two attempts exist per decision and most are abandoned.

Work performed, then denied

Cost incurred with no bill behind it, because approval was decided after dispatch.

Regulatory exposure

One SCRA or PTFA finding, against a banner somebody was supposed to remember.

Crew hours re-keyed

Capacity is the constraint in this business. Every hour re-entering a job is an hour off a property.

I have not seen your claim volume, your denial rate or your engineering budget, and I am not going to invent them. Put your own numbers against these four lines. Every one of them is something the rebuild changes.

The obvious objection

No, you do not migrate first.
You do not migrate until it has earned it.

Month one

It reads yours

The new system queries your system of record where it already lives. Nothing is copied, nothing is converted, and your database does not change. If month one fails you have lost a month and no data.

Months two to six

Both are written

New work is written in both places and the old one stays authoritative. Every screen can be checked against the system you already trust, on the same order, on the same day.

Only then

You decide

Migration becomes a decision made with a year of evidence behind it rather than a leap taken on a promise. If the answer is never, the system still works.

A rebuild that needs a data migration on day one is a rebuild nobody approves, because all of the risk arrives before any of the benefit. This one runs beside what you have until you would rather it did not.

The ask

I’m not an employee. I’m a build
partner installed inside your company.

Twelve months

Paid monthly, against an outcome. Month one is your exit.

Bonus on delivery

Measured on what is in production, not in progress.

My platforms stay mine

Listed in writing. Everything built for you is yours.

Give me a month and the keys. If it does not land, you stop. The rebuild runs three to six months after that, depending on whether the servicer integrations and the history come with it.

Why I am confident about the timeline

Forty-five live platforms.
Most of them in proptech.

RoofBoard is the closest to your business: dispatch a crew, prove the work was done, invoice, defend it when somebody disputes the evidence. Draw does the second half of that for construction. The rest are why twelve months is an estimate rather than a hope.

See all 45 at molluso.ai

Where this goes

I have already started.
One month tells you if I’m right.

One module of your five, rebuilt end to end, with your data and your people. If it does not land you have spent a month. If it does, the other eleven build the thing this deck is about.

Appendix · diligence

A resume only tells part of the story.
My code tells the rest.

  • ConcededEnterprise engineering depthI have not shipped gRPC or protobuf, and my infrastructure is not Terraform-managed. All three are coordination tools for many teams, which is a different thing from capability.What does travel: 32 migrations reviewed as artifacts with the reasoning attached, and rules enforced as database constraints rather than application code.
  • AnsweredAgent governance layerFive versioned documents per agent. Every production run stamps the exact versions in force, and a draft governs nothing until it scores at or above the standing baseline.governance_versions · 37 rows. Migration 0017 introduced drafts; 0023 fixed a bug in the gate itself, where several rows were flagged as baseline so the threshold moved.
  • AnsweredMulti-agent orchestration frameworksLangGraph and LangChain are what all six agents run on today. The resume was wrong, not the reading of it.createReactAgent from @langchain/langgraph/prebuilt, in six agent files. Tools are @langchain/core/tools. It is the prebuilt ReAct agent, not a hand-authored StateGraph.
  • AnsweredObservability and security rigorCost priced at write time per run. Approval, result, retries and reversal recorded per irreversible action. An enterprise security review is not something I have sat through.agent_runs.cost_usd · agent_actions · run_steps · escalations. Every figure on this deck is read from those tables when the slide renders.
  • Half rightScale of prior systemsTwo claims in one sentence. Working inside standards and stakeholders is a different job and that half is right. The platform being a moat is an assumption.26 live platforms, two past $3M ARR. The half I dispute is the one this deck opens on.

Every line on the right is a file, a table or a column. All of it is checkable in under a minute, by anyone, without asking me.

Safeguard OS
Scott Mollusomolluso.ai