ARCHITECTURE
AI, platform and security architecture
For the engineer, the security reviewer and the model risk officer.
01
Deployment and isolation
- Tenancy
- Private sandbox per customer. No shared storage.
- Data isolation
- Customer-scoped, enforced at the platform layer.
- Environments
- Sandboxed per customer.
- Data residency
- US and EU region deployments.
02
Data handling
- Encryption at rest
- AES-256.
- Encryption in transit
- TLS 1.2 or above.
- Model training
- Customer data is never sent to the foundational model labs or used to train any models.
- Retention
- Immutable interaction records, retained to your policy.
03
Access control
- Authorisation
- RBAC with least-privilege defaults.
- SSO
- SAML and OIDC — Okta, Azure AD, Google Workspace.
- MFA
- Enforced for all administrative actions.
04
Assurance
- Certifications
- SOC 2 Type II and PCI DSS Level 1, both audited. GDPR-ready: EU data residency, and no customer data in model training.
- Penetration testing
- Independent third party, annually.
- Vulnerability scanning
- Continuous, across all services.
- Monitoring
- Continuous, via SIEM tooling.
- Patching
- Critical patches within defined SLAs.
05
Decisions and evidence
- Decision path
- Triple Check — reasoning against the Rulebook, an independent validation pass, then confidence scoring.
- Evidence Trail
- Reasoning, rule and citation kept for every decision, across underwriting, closing, QC and conversation.
- Citations
- Findings cite the source document and page, or the call timestamp.
- Reasoning trace
- Logged in full for every agent decision.
- Exception routing
- Below threshold routes to your human-in-the-loop as a named exception.
- Audit export
- Regulator- and audit-ready log export.
06
Integration boundary
- Position
- Sits above the LOS you originate in rather than replacing it.
- Write-back
- Results are written back into the LOS.
- Systems
- LOS: ICE Encompass, Calyx, MeridianLink. CRM: Salesforce, HubSpot. Telephony: Genesys, RingCentral, Twilio.
- Custom integrations
- Supported during onboarding by a dedicated account team.
Available on request, under NDA
Running a vendor review?
Request the TPRM pack: SOC 2 Type II report, penetration test summary, subprocessor list, model risk summary and our DPA.
AI governance
The questions a model risk officer asks, and where we have written our answer out in full.
Model risk management
Governance mapped to SR 11-7 and the NIST AI Risk Management Framework.
Read the field guide →Third-party risk
Built for the TPRM review your vendor management team will run, in line with SR 23-4.
Read the field guide →Grounding and citation
Findings resolve to a retrieved source rather than a model’s recollection.
Read the field guide →Prompt-injection defense
Red-teamed against instructions hidden in borrower documents and call transcripts.
Read the field guide →
You Ain't Seen Nothin' Yet
Book a Demo
Pack up some of your complex historical files — any loan type, any investor. We run them through intake, income and condition clearing, and in 30 minutes you see every condition we created and cleared efficiently for your own team, and why.
- Any loan type, any agency guideline or custom investor overlays.
- Every finding cited to the guideline or document it came from