FAQ
What business leaders ask first.
Security, data handling, model customization, and compliance — answered in plain terms.
FAQ
Security, compliance & data handling.
Straight answers on security, data handling, model customization, and compliance — the questions your CISO, legal team, and regulated partners will ask before signing. The examples lean on our advisor and brokerage work; the answers apply to any business.
SOC 2 Type II aligned
ISO 27001 aligned
FINRA / SEC 17a-4 ready
Deploys in your tenancy
You own the IP
Full audit logging
Where does our client data live, and who can see it?
By default, every engagement runs inside your tenancy — your cloud account (AWS, Azure, or GCP), your VPC, your CRM, and your carrier connections. We never pool client PII across customers, and access is scoped to a named engineering team under signed BAAs and NDAs. If you require an on-prem or sovereign deployment, that is a first-class option, not a custom upcharge.
How do you handle PII, NPI, and HIPAA-class information?
We treat NPI, PHI, and HNW client data as restricted by default. Standard controls include field-level encryption at rest, TLS 1.2+ in transit, tokenization of identifiers before they reach any model, role-based access with SSO/MFA, and full audit logging. For health-adjacent workflows (LTC, disability, life underwriting) we operate under HIPAA BAAs and minimum-necessary data principles.
Do you train foundation models on our data?
No. Your data is never used to train shared or third-party foundation models. When we fine-tune, we fine-tune private models inside your environment on your data, for your use only. When we use hosted LLMs, we use providers and endpoints that contractually disable training on inputs, and we route through a gateway that enforces this.
How is a model 'custom-fit' to our practice?
We start from your book, your products, and your voice — not a generic vertical template. That means ingesting your CRM (Redtail, Wealthbox, Salesforce FSC), AMS, illustration tools, carrier feeds, and historical correspondence; encoding your suitability rubric and house view; and tuning prompts, retrieval, and fine-tuned models against your own evaluation set. Every system ships with a reviewer-in-the-loop and a measurable accuracy bar agreed up front.
How do you address FINRA, SEC, NAIC, and state insurance compliance?
Compliance is engineered in, not bolted on. We support FINRA 17a-4 / SEC 17a-4 recordkeeping, NAIC Model #275 best-interest documentation, state suitability requirements, and books-and-records retention with WORM-compliant storage. Every AI-assisted output is logged with prompt, response, model version, and reviewer action so your compliance team can reconstruct any interaction.
What about SOC 2, ISO 27001, and vendor due diligence?
We deliver inside SOC 2 Type II and ISO 27001 aligned environments, and we routinely complete enterprise vendor security questionnaires (SIG, CAIQ, custom brokerage DDQs). We can provide architecture diagrams, data-flow maps, pen-test summaries, and sub-processor lists as part of onboarding.
How do you prevent hallucinations on advice-adjacent outputs?
We do not let raw LLM output reach a client. Advice-adjacent workflows use retrieval-grounded responses tied to your approved knowledge base, citation requirements, deterministic guardrails on numerical and regulatory claims, suitability checks, and a human reviewer step before anything is sent. We track factuality and refusal rates as first-class production metrics.
Who owns the IP — the models, prompts, and code?
You do. Custom models, fine-tunes, prompts, datasets, and source code produced under your SOW are your property, delivered with full documentation. We retain no residual rights to your data or domain-specific artifacts.
What does an engagement cost?
Mindfulware works in fixed-price engagement sprints, so you know the number before we start. A 1-Day Working Session is $2,500. A 2-Week Discovery Sprint is $18,000. A 4-Week Prototype Sprint is $48,000. Post-launch AI Drift Reviews are billed hourly at $225 per hour with a two-hour minimum. Full custom builds are scoped from the Discovery Sprint, never quoted blind.
How long does it take to see something working?
Four weeks to a working prototype against your real data. The 4-Week Prototype Sprint exists so you can validate impact before committing to a full build. If you are still deciding what to build, the 2-Week Discovery Sprint produces a scoped solution architecture and roadmap first. If you want to pressure-test one idea before spending either, the 1-Day Working Session gets you a concrete next step in a day.
What industries do you work in?
Mindfulware builds for business owners and mid-market operators across industries. The deepest reference work is with independent financial advisors, high-net-worth wealth advisors and family-office practices, and insurance brokerages and carriers, where we already speak the language of suitability, KYC, AUM, policy illustrations, and carrier feeds. Delivered systems also cover behavioral health records, trade-union research, and member self-service messaging for labor organizations.
Where are you located, and do you work with clients remotely?
Mindfulware is based at 8230 Old Federal Road, Montgomery, Alabama 36117, and serves clients across the United States. The firm is veteran-founded, established in 2009, with the AI and machine learning practice launched in 2023. Delivery runs through a global team across five time zones, so engagements are remote by default with on-site work available when the work calls for it.
How do we get started?
Book a 30-minute consultation with the founder, or email info@mindfulware.com or call +1 (334) 221-3282. Tell us the problem you are solving and we reply within one business day with a clear next step. Most engagements begin with either a 1-Day Working Session to pressure-test one use case or a 2-Week Discovery Sprint to scope the roadmap.