FAQ

    What business leaders ask first.

    Security, data handling, model customization, and compliance — answered in plain terms.

    FAQ

    Security, compliance & data handling.

    Straight answers on security, data handling, model customization, and compliance — the questions your CISO, legal team, and regulated partners will ask before signing. The examples lean on our advisor and brokerage work; the answers apply to any business.

    SOC 2 Type II aligned
    ISO 27001 aligned
    FINRA / SEC 17a-4 ready
    Deploys in your tenancy
    You own the IP
    Full audit logging

    Where does our client data live, and who can see it?

    By default, every engagement runs inside your tenancy — your cloud account (AWS, Azure, or GCP), your VPC, your CRM, and your carrier connections. We never pool client PII across customers, and access is scoped to a named engineering team under signed BAAs and NDAs. If you require an on-prem or sovereign deployment, that is a first-class option, not a custom upcharge.

    How do you handle PII, NPI, and HIPAA-class information?

    We treat NPI, PHI, and HNW client data as restricted by default. Standard controls include field-level encryption at rest, TLS 1.2+ in transit, tokenization of identifiers before they reach any model, role-based access with SSO/MFA, and full audit logging. For health-adjacent workflows (LTC, disability, life underwriting) we operate under HIPAA BAAs and minimum-necessary data principles.

    Do you train foundation models on our data?

    No. Your data is never used to train shared or third-party foundation models. When we fine-tune, we fine-tune private models inside your environment on your data, for your use only. When we use hosted LLMs, we use providers and endpoints that contractually disable training on inputs, and we route through a gateway that enforces this.

    How is a model 'custom-fit' to our practice?

    We start from your book, your products, and your voice — not a generic vertical template. That means ingesting your CRM (Redtail, Wealthbox, Salesforce FSC), AMS, illustration tools, carrier feeds, and historical correspondence; encoding your suitability rubric and house view; and tuning prompts, retrieval, and fine-tuned models against your own evaluation set. Every system ships with a reviewer-in-the-loop and a measurable accuracy bar agreed up front.

    How do you address FINRA, SEC, NAIC, and state insurance compliance?

    Compliance is engineered in, not bolted on. We support FINRA 17a-4 / SEC 17a-4 recordkeeping, NAIC Model #275 best-interest documentation, state suitability requirements, and books-and-records retention with WORM-compliant storage. Every AI-assisted output is logged with prompt, response, model version, and reviewer action so your compliance team can reconstruct any interaction.

    What about SOC 2, ISO 27001, and vendor due diligence?

    We deliver inside SOC 2 Type II and ISO 27001 aligned environments, and we routinely complete enterprise vendor security questionnaires (SIG, CAIQ, custom brokerage DDQs). We can provide architecture diagrams, data-flow maps, pen-test summaries, and sub-processor lists as part of onboarding.

    How do you prevent hallucinations on advice-adjacent outputs?

    We do not let raw LLM output reach a client. Advice-adjacent workflows use retrieval-grounded responses tied to your approved knowledge base, citation requirements, deterministic guardrails on numerical and regulatory claims, suitability checks, and a human reviewer step before anything is sent. We track factuality and refusal rates as first-class production metrics.

    Who owns the IP — the models, prompts, and code?

    You do. Custom models, fine-tunes, prompts, datasets, and source code produced under your SOW are your property, delivered with full documentation. We retain no residual rights to your data or domain-specific artifacts.