# AI, platform and security architecture

*ARCHITECTURE*

> For the engineer, the security reviewer and the model risk officer.

## Deployment and isolation

- **Tenancy** — Private sandbox per customer. No shared storage.
- **Data isolation** — Customer-scoped, enforced at the platform layer.
- **Environments** — Sandboxed per customer.
- **Data residency** — US and EU region deployments.

## Data handling

- **Encryption at rest** — AES-256.
- **Encryption in transit** — TLS 1.2 or above.
- **Model training** — Customer data is never sent to the foundational model labs or used to train any models.
- **Retention** — Immutable interaction records, retained to your policy.

## Access control

- **Authorisation** — RBAC with least-privilege defaults.
- **SSO** — SAML and OIDC — Okta, Azure AD, Google Workspace.
- **MFA** — Enforced for all administrative actions.

## Assurance

- **Certifications** — SOC 2 Type II and PCI DSS Level 1, both audited. GDPR-ready: EU data residency, and no customer data in model training.
- **Penetration testing** — Independent third party, annually.
- **Vulnerability scanning** — Continuous, across all services.
- **Monitoring** — Continuous, via SIEM tooling.
- **Patching** — Critical patches within defined SLAs.

## Decisions and evidence

- **Decision path** — Triple Check — reasoning against the Rulebook, an independent validation pass, then confidence scoring.
- **Evidence Trail** — Reasoning, rule and citation kept for every decision, across underwriting, closing, QC and conversation.
- **Citations** — Findings cite the source document and page, or the call timestamp.
- **Reasoning trace** — Logged in full for every agent decision.
- **Exception routing** — Below threshold routes to your human-in-the-loop as a named exception.
- **Audit export** — Regulator- and audit-ready log export.

## Integration boundary

- **Position** — Sits above the LOS you originate in rather than replacing it.
- **Write-back** — Results are written back into the LOS.
- **Systems** — LOS: ICE Encompass, Calyx, MeridianLink. CRM: Salesforce, HubSpot. Telephony: Genesys, RingCentral, Twilio.
- **Custom integrations** — Supported during onboarding by a dedicated account team.

## AI governance

- **[Model risk management](/blog/model-risk-management-ai-agents-sr-11-7-nist-rmf)** — Governance mapped to SR 11-7 and the NIST AI Risk Management Framework.
- **[Third-party risk](/blog/third-party-risk-management-ai-vendors-banking-tprm-playbook)** — Built for the TPRM review your vendor management team will run, in line with SR 23-4.
- **[Grounding and citation](/blog/preventing-ai-hallucinations-banking-grounding-citation-architecture)** — Findings resolve to a retrieved source rather than a model’s recollection.
- **[Prompt-injection defense](/blog/prompt-injection-defense-banking-ai-agents-red-team)** — Red-teamed against instructions hidden in borrower documents and call transcripts.

## Available on request, under NDA

- Model risk documentation and SR 11-7 control mapping
- Foundation model providers and version policy
- Prompt-injection red-team scope and cadence
- Default retention periods by record type
- Confidence threshold configuration and how it is tuned
- SOC 2 Type II report, penetration test summary and subprocessor list

**Running a vendor review?** Request the TPRM pack: SOC 2 Type II report, penetration test summary, subprocessor list, model risk summary and our DPA.

---

_Source: [https://seiright.com/tech-specs](https://seiright.com/tech-specs) · Sei AI_
