Combine deterministic processing with AI reasoning so teams can trace how flags, outputs and actions were produced.
Built for the security, control and governance wealth management demands.
Protect client data, control how AI operates and give teams the oversight they need across the platform.
Protect client and firm data.
Defined processing controls, residency boundaries, encryption and data minimisation across the platform.
Operate on layered controls.
Protect the platform through layered controls across infrastructure, identity, applications, operations and third-party services.
Review the seven-layer security architecture →Work towards recognised certifications.
Meet regulatory requirements through defined controls, independent assessment and ongoing governance.
Keep AI explainable, controlled and auditable.
Control how AI uses data, what agents can do and how teams review decisions, with clear evidence from input through to human action.
Route sensitive outcomes through human review and record who reviewed them, when they acted and what they decided.
Capture the chain of activity behind model outputs, reviewer actions and follow-up so teams can produce a complete record when required.
Use controlled model environments and data-handling rules to protect prompts, documents and client information.
Restrict agents to approved tools, data and actions, and require explicit approval where workflows create higher-risk outcomes.
Route work across models and deterministic logic based on the level of quality, consistency, risk and oversight each workflow requires.
Cloud & infrastructureProtect the infrastructure that runs the platform.
Run production workloads across controlled cloud environments with private endpoints, managed keys, monitoring and resilience built into the architecture.
Technical proof
Azure UK South · AWS Frankfurt DR · Microsoft Sentinel SIEM · Key Vault HSM · Private Endpoints
Identity & accessControl who can access what.
Use enterprise identity controls, strong authentication and least-privilege access to govern how users and administrators enter the platform.
Technical proof
SAML / OIDC SSO · FIDO2 / TOTP MFA · Per-Tenant RBAC · Least Privilege · JIT Access
Data protection & residencyProtect data across storage, transit and tenant boundaries.
Encrypt data, isolate tenant environments and control where information resides and how long it remains available.
Technical proof
AES-256 at Rest · TLS 1.3 in Transit · Row-Level Isolation · UK / EU Residency · Configurable TTL
Application securitySecure every release.
Run automated security testing, dependency checks and independent penetration testing throughout the software lifecycle.
Technical proof
Automated SAST / DAST · SBOM Verification · Dependency Guard · Annual CREST Pentest · CI/CD Signoff
AI governanceControl how models and agents use data.
Set model boundaries, restrict agent actions and require human approval where workflows create higher-risk outcomes.
Technical proof
Zero Model Training · Prompt Guard · Strict Tool Schemas · Human-in-the-Loop · Source Citations
Operational resilienceKeep the platform monitored and recoverable.
Monitor activity continuously, test recovery processes and maintain an auditable record of platform actions.
Technical proof
Real-Time Telemetry · FCA BCP Runbooks · Automated Failover Tests · Immutable Audit Log
Third-party riskControl the services connected to the platform.
Assess vendors, manage sub-processors and review model providers as part of ongoing risk management.
Technical proof
Sub-Processor Register · Article 28 DPAs · Vendor Concentration Risk · LLM Provider Reviews
SSO via SAML / OIDC
Connect your identity provider so access stays governed through the directory and policies your firm already uses.
MFA enforced for all users
Multi-factor authentication is required for every account, with no tenant-level opt-out.
Role-based access & per-tenant isolation
Permissions scoped by role, with row-level isolation so one firm’s data never crosses into another.
AES-256 at rest, TLS 1.2+ in transit
Encryption applied across storage and network boundaries by default — not as an optional add-on.
Immutable audit log
A tamper-evident record of user and system activity, available for oversight, review and regulatory response.
Annual independent penetration testing
CREST-accredited third-party testing of the production environment, with findings tracked to resolution.
Secure SDLC with SAST/DAST gates
Automated security checks in the release pipeline before code reaches production.
Customer-managed retention
Configurable data retention windows within a firm-defined ceiling of 365 days.
Azure UK South
Application, control plane and encrypted data store.
AWS Frankfurt
Recovery environment and backups.
Swiss region
Support for firms requiring Swiss-hosted workloads.
WealthAi
- Platform security, encryption and infrastructure resilience
- Identity controls, permissions and AI governance
- Sub-processor due diligence and vendor oversight
Client firm
- Regulatory obligations and data controller responsibilities
- Data accuracy, user provisioning and access decisions
- Human review of AI outputs and secure handling of exports
Access the trust framework.
Enter your details to unlock the Trust Centre and review WealthAi’s privacy, security and compliance framework.
Submit your details to open the Trust Centre directly within the site.
