Security & trust

Specific answers about how the platform is governed.

This page is written to be forwarded: to your compliance officer, your licensee, your board. Plain English, no marketing. If a question isn't answered here, ask us directly and we'll answer it in writing.

The harness, in plain English

A large language model is an engine: powerful, but not something you put on the road by itself. The harness is the steering, the brakes and the rules of the road. Every capability in the platform operates inside four constraints:

01 · Validated financial logic

Calculations, projections and financial rules run through validated, deterministic engines, not free-form model output. The model explains; it does not compute unsupervised.

02 · Permission architecture

Every user, whether client, adviser or firm administrator, sees only what their role allows. Access is explicit, granted, and revocable. There is no ambient access to anything.

03 · Complete audit trails

Every interaction, every surfaced insight and every data access is logged and reviewable. When your licensee asks what happened and why, the answer is a record, not a reconstruction.

04 · Human oversight

Anything that reaches a client as analysis is adviser-authored or adviser-approved. The adviser is always accountable, and always in the loop.

Why it's different

Generic AI starts with a blank conversation. TIFIN.AI starts with the client.

The difference isn't the model. It's everything built around it. A general-purpose assistant knows nothing about your client, your firm or the rules you operate under. Ours starts inside all three.

Standard AI assistantTIFIN.AI

General-purpose knowledge

Purpose-built financial services harness

Context supplied again and again

Authorised CRM, document and financial context

Open-ended responses

Regulatory boundaries and adviser escalation

No firm investment framework

Firm knowledge, model portfolios and preferred investments

Separate from client service

Secure communication, documents and adviser connection

Limited business oversight

Consent, monitoring and auditable activity

The advantage isn't a chatbot. It's the governed connection between client, adviser and firm.

How client data is handled

Residency

Australian client data is stored in Australian data centres. Where a processing step involves offshore infrastructure, it is documented and disclosed. We will name it, not gesture at it.

Storage and transit

Data is encrypted at rest and in transit. Environments are segregated; production access is limited, logged and reviewed.

Who sees what

The permission architecture governs every view: a client sees their own picture; an adviser sees their clients; a firm sees its practice. Our staff do not browse client data. Operational access is exceptional, ticketed and audited.

Model training

Your client data is never used to train shared models. Full stop. This commitment appears in our agreements, not just on this page.

Our AI posture

The platform educates and informs. It does not give financial product advice. Analysis presented to a client is authored or approved by their adviser, who remains accountable for it. The distinction between education and advice is enforced in the product's design: in what the system is permitted to generate, and in what must pass through an adviser before a client sees it.

We operate within Australia's licensed-entity framework and engage constructively with the direction of regulatory reform. We describe the regulatory environment; we do not make predictions about it or build claims on it.

Running due diligence?We answer compliance and security questionnaires directly, in writing, with named owners.