Trust Centre

Built for the security, control and governance wealth management demands.

Protect client data, control how AI operates and give teams the oversight they need across the platform.

Privacy

Protect client and firm data.

Defined processing controls, residency boundaries, encryption and data minimisation across the platform.

Current framework
GDPR / UK DPA 2018
Security

Operate on layered controls.

Protect the platform through layered controls across infrastructure, identity, applications, operations and third-party services.

Review the seven-layer security architecture
Compliance

Work towards recognised certifications.

Meet regulatory requirements through defined controls, independent assessment and ongoing governance.

In progress
ISO 27001SOC 2 Type IICyber Essentials Plus
Regional requirements
Swiss FADPFINMA-related requirements
AI governance

Keep AI explainable, controlled and auditable.

Control how AI uses data, what agents can do and how teams review decisions, with clear evidence from input through to human action.

Explainability
Show why the system reached an outcome.

Combine deterministic processing with AI reasoning so teams can trace how flags, outputs and actions were produced.

Human oversight
Keep people accountable for consequential decisions.

Route sensitive outcomes through human review and record who reviewed them, when they acted and what they decided.

Auditability
Maintain evidence from detection through to resolution.

Capture the chain of activity behind model outputs, reviewer actions and follow-up so teams can produce a complete record when required.

Data protection
Keep client data out of shared model training.

Use controlled model environments and data-handling rules to protect prompts, documents and client information.

Agent controls
Define what agents can access and what they can do.

Restrict agents to approved tools, data and actions, and require explicit approval where workflows create higher-risk outcomes.

Model governance
Apply the right controls to every model and use case.

Route work across models and deterministic logic based on the level of quality, consistency, risk and oversight each workflow requires.

L1
Cloud & infrastructure

Protect the infrastructure that runs the platform.

Run production workloads across controlled cloud environments with private endpoints, managed keys, monitoring and resilience built into the architecture.

Technical proof

Azure UK South · AWS Frankfurt DR · Microsoft Sentinel SIEM · Key Vault HSM · Private Endpoints

L2
Identity & access

Control who can access what.

Use enterprise identity controls, strong authentication and least-privilege access to govern how users and administrators enter the platform.

Technical proof

SAML / OIDC SSO · FIDO2 / TOTP MFA · Per-Tenant RBAC · Least Privilege · JIT Access

L3
Data protection & residency

Protect data across storage, transit and tenant boundaries.

Encrypt data, isolate tenant environments and control where information resides and how long it remains available.

Technical proof

AES-256 at Rest · TLS 1.3 in Transit · Row-Level Isolation · UK / EU Residency · Configurable TTL

L4
Application security

Secure every release.

Run automated security testing, dependency checks and independent penetration testing throughout the software lifecycle.

Technical proof

Automated SAST / DAST · SBOM Verification · Dependency Guard · Annual CREST Pentest · CI/CD Signoff

L5
AI governance

Control how models and agents use data.

Set model boundaries, restrict agent actions and require human approval where workflows create higher-risk outcomes.

Technical proof

Zero Model Training · Prompt Guard · Strict Tool Schemas · Human-in-the-Loop · Source Citations

L6
Operational resilience

Keep the platform monitored and recoverable.

Monitor activity continuously, test recovery processes and maintain an auditable record of platform actions.

Technical proof

Real-Time Telemetry · FCA BCP Runbooks · Automated Failover Tests · Immutable Audit Log

L7
Third-party risk

Control the services connected to the platform.

Assess vendors, manage sub-processors and review model providers as part of ongoing risk management.

Technical proof

Sub-Processor Register · Article 28 DPAs · Vendor Concentration Risk · LLM Provider Reviews

SSO via SAML / OIDC

Connect your identity provider so access stays governed through the directory and policies your firm already uses.

MFA enforced for all users

Multi-factor authentication is required for every account, with no tenant-level opt-out.

Role-based access & per-tenant isolation

Permissions scoped by role, with row-level isolation so one firm’s data never crosses into another.

AES-256 at rest, TLS 1.2+ in transit

Encryption applied across storage and network boundaries by default — not as an optional add-on.

Immutable audit log

A tamper-evident record of user and system activity, available for oversight, review and regulatory response.

Annual independent penetration testing

CREST-accredited third-party testing of the production environment, with findings tracked to resolution.

Secure SDLC with SAST/DAST gates

Automated security checks in the release pipeline before code reaches production.

Customer-managed retention

Configurable data retention windows within a firm-defined ceiling of 365 days.

Primary

Azure UK South

Application, control plane and encrypted data store.

Disaster recovery

AWS Frankfurt

Recovery environment and backups.

Planned

Swiss region

Support for firms requiring Swiss-hosted workloads.

Platform provider

WealthAi

  • Platform security, encryption and infrastructure resilience
  • Identity controls, permissions and AI governance
  • Sub-processor due diligence and vendor oversight
Regulated entity

Client firm

  • Regulatory obligations and data controller responsibilities
  • Data accuracy, user provisioning and access decisions
  • Human review of AI outputs and secure handling of exports
Trust documentation

Access the trust framework.

Enter your details to unlock the Trust Centre and review WealthAi’s privacy, security and compliance framework.

Immediate access

Submit your details to open the Trust Centre directly within the site.

Questions before you start? Email security@wealthai.tech