Trust & Security

Trust is engineered, not assumed.

Fiden is the governed agentic platform for wealth and asset management — built so a regulated firm can move at the speed of AI without inheriting its risk. Security and data protection are the foundations on which the platform is built.

Learn more
Seven layers of protection ↓
Defense in depth

Seven layers of enterprise grade security.

Every interaction runs through a defined sequence of controls — each one designed, deployed, and audited on its own terms, so no single safeguard carries the weight alone.

Policy

AI policy enforcement

Your rules, enforced at the moment of inference.

A configurable policy engine ingests your firm’s AI-usage policies, ethical guidelines, and regulatory constraints, then applies them to every input and output as a gate rather than a guideline. Policies change without retraining a model, and every decision is written to an audit trail.

  • Real-time enforcement of allowed and disallowed topics, tone, decision boundaries, and escalation rules.
  • Distinct policy sets by user group, application, or data classification.
  • A logged decision — allow, modify, block, or escalate — behind every action.

SOC 2 CC6–CC7 · GDPR/DPDP purpose limitation · ISO 42001

INPUTRequestPOLICYENGINEAllowModifyBlockEscalateEVERY DECISION LOGGED · ALLOW / MODIFY / BLOCK / ESCALATE
Data protection

PII redaction

Sensitive data never reaches a model.

Mandatory pre-processing detects and removes personally identifiable information, non-public information, and financial identifiers inside your environment — before any payload is sent to an LLM. What the model never receives, it can never expose.

  • Detection through pattern matching, ML classifiers, and dictionaries you define.
  • Redaction your way, per entity: mask, tokenize, substitute a placeholder, or block.
  • Bring your own redaction model where you already have one.

HIPAA de-identification · GDPR Art. 32 · SOC 2 CC6

Live · redaction before inference
Masked — PII · NPI · financial identifiers · model sees no PII / NPI
Quality & safety

Guardrails

Checks on both sides of the model.

Dedicated filters inspect user inputs and model outputs, kept deliberately separate from policy so each can evolve on its own. Inputs are screened for prompt injection and abuse; outputs are checked for grounding, toxicity, and format before they ever reach a client.

  • Input screening for prompt injection, jailbreak attempts, and out-of-scope queries.
  • Output checks for hallucination signals, toxicity, bias, and grounding against approved sources.
  • Configurable thresholds with clear remediation: rewrite, refuse, or escalate to a human.

SOC 2 CC7 · GDPR/DPDP accuracy · ISO 42001 robustness

INPUTOUTPUTGUARDModelGUARDINJECTION · JAILBREAK · SCOPEGROUNDING · TOXICITY · FORMAT
Assurance

Evals & observability

Every turn is measured, logged, and reviewable.

Turn-level logging and automated evaluation give full visibility into each interaction. Scores are computed continuously, and anything below the thresholds you set is flagged for review the moment it happens — not discovered in an audit months later.

  • Turn-level logging of post-redaction inputs, outputs, latency, and policy decisions.
  • Automated scoring with real-time and batch alerting against your thresholds.
  • Human-in-the-loop review queues, dashboards, and exportable audit reports.

SOC 2 CC7–CC8 · HIPAA audit controls · ISO 42001 Clause 9

evals.log — score per turn
Threshold 0.80 · 1 turn flagged · queued for human review
Deployment

Deployment sovereignty

Runs where your regulator requires.

The customer-specific stack deploys into your on-premises data center, an air-gapped environment, or a dedicated single-tenant cloud managed for you alone. Proprietary data stays isolated with its own compute, storage, and endpoints; residency is set to your jurisdiction, and no data leaves without your consent.

  • On-premises, air-gapped, or dedicated cloud tenancy — one isolated environment per firm.
  • Residency aligned to GDPR (EU), DPDP (India), and PDPL (UAE).
  • Delegated support only under just-in-time, session-recorded, least-privilege access you authorize.

SOC 2 availability & isolation · GDPR/DPDP residency · ISO 42001 governance

ON-PREMAIR-GAPPEDDEDICATED CLOUDONE ISOLATED ENVIRONMENT PER FIRMRESIDENCY · GDPR (EU) · DPDP (IN) · PDPL (UAE)
Access

Role-based access control

Least privilege, for people and agents alike.

Access minimization runs throughout the platform. Users — and the agents acting on their behalf — reach only the data and actions their role and use case require, all administered centrally and logged in full.

  • Advisor A cannot see Advisor B’s book or households.
  • Agents are scoped to only the data and tools their use case needs.
  • Auditable role assignment and a complete record of every access change.

SOC 2 CC6 · HIPAA access controls · GDPR/DPDP minimization

BOOKHOUSEHOLDSTOOLSAdvisor AAdvisor BAgentGRANTEDDENIEDADVISOR A CANNOT SEE ADVISOR B’S BOOK
Cryptography

Encryption at rest and in motion

Encrypted end to end, under your keys.

All data is encrypted with industry-standard algorithms throughout its life — moving between services and sitting in storage — with key management you can hold yourself.

  • TLS 1.3 or higher in transit; AES-256 at rest across storage, logs, and artifacts.
  • Customer-managed keys (CMK / BYOK) through your own KMS or HSM.
  • Periodic key rotation on your schedule.

SOC 2 CC6 · HIPAA encryption · GDPR Art. 32

IN MOTION · TLS 1.3+AT REST · AES-256BYOKCUSTOMER-MANAGED KEYS · YOUR KMS / HSM · ROTATION
AI governance

AI you can put in front of a client.

The hardest problem in applied AI for a fiduciary is not capability — it is accountability. Fiden is built so the machine carries the load and a person carries the judgment.

Before the model

Nothing sensitive gets through

Sensitive data is redacted inside your environment before any model receives it, and every input is screened for injection and abuse. What the model can’t see, it can’t leak.

At the decision

A human owns what matters

Agents draft, propose, and prepare; consequential actions wait for review. Human judgment — trust, empathy, accountability — stays with your people by design, not as a fallback.

After the output

Nothing is taken on faith

Every turn is evaluated, scored, and logged on one execution path, so behavior doesn’t drift between test and production and every action can be explained after the fact.

Talk to us

For any security assessments, please request at security@fidenai.com

Talk to security →

A note on what this page claims

The controls described here are architectural commitments of the Fiden platform. Named standards — SOC 2 Type II, HIPAA, GDPR, India’s DPDP Act, the UAE’s PDPL, and ISO/IEC 42001 — indicate the frameworks our controls are designed and mapped to; they are not a claim of current certification. Formal certification is in progress and not yet complete. Deployment-dependent capabilities vary by configuration. Current attestations, control mappings, and roadmap are available under NDA.