Seven layers of enterprise grade security.
Every interaction runs through a defined sequence of controls — each one designed, deployed, and audited on its own terms, so no single safeguard carries the weight alone.
AI policy enforcement
Your rules, enforced at the moment of inference.
A configurable policy engine ingests your firm’s AI-usage policies, ethical guidelines, and regulatory constraints, then applies them to every input and output as a gate rather than a guideline. Policies change without retraining a model, and every decision is written to an audit trail.
- Real-time enforcement of allowed and disallowed topics, tone, decision boundaries, and escalation rules.
- Distinct policy sets by user group, application, or data classification.
- A logged decision — allow, modify, block, or escalate — behind every action.
SOC 2 CC6–CC7 · GDPR/DPDP purpose limitation · ISO 42001
PII redaction
Sensitive data never reaches a model.
Mandatory pre-processing detects and removes personally identifiable information, non-public information, and financial identifiers inside your environment — before any payload is sent to an LLM. What the model never receives, it can never expose.
- Detection through pattern matching, ML classifiers, and dictionaries you define.
- Redaction your way, per entity: mask, tokenize, substitute a placeholder, or block.
- Bring your own redaction model where you already have one.
HIPAA de-identification · GDPR Art. 32 · SOC 2 CC6
Guardrails
Checks on both sides of the model.
Dedicated filters inspect user inputs and model outputs, kept deliberately separate from policy so each can evolve on its own. Inputs are screened for prompt injection and abuse; outputs are checked for grounding, toxicity, and format before they ever reach a client.
- Input screening for prompt injection, jailbreak attempts, and out-of-scope queries.
- Output checks for hallucination signals, toxicity, bias, and grounding against approved sources.
- Configurable thresholds with clear remediation: rewrite, refuse, or escalate to a human.
SOC 2 CC7 · GDPR/DPDP accuracy · ISO 42001 robustness
Evals & observability
Every turn is measured, logged, and reviewable.
Turn-level logging and automated evaluation give full visibility into each interaction. Scores are computed continuously, and anything below the thresholds you set is flagged for review the moment it happens — not discovered in an audit months later.
- Turn-level logging of post-redaction inputs, outputs, latency, and policy decisions.
- Automated scoring with real-time and batch alerting against your thresholds.
- Human-in-the-loop review queues, dashboards, and exportable audit reports.
SOC 2 CC7–CC8 · HIPAA audit controls · ISO 42001 Clause 9
Deployment sovereignty
Runs where your regulator requires.
The customer-specific stack deploys into your on-premises data center, an air-gapped environment, or a dedicated single-tenant cloud managed for you alone. Proprietary data stays isolated with its own compute, storage, and endpoints; residency is set to your jurisdiction, and no data leaves without your consent.
- On-premises, air-gapped, or dedicated cloud tenancy — one isolated environment per firm.
- Residency aligned to GDPR (EU), DPDP (India), and PDPL (UAE).
- Delegated support only under just-in-time, session-recorded, least-privilege access you authorize.
SOC 2 availability & isolation · GDPR/DPDP residency · ISO 42001 governance
Role-based access control
Least privilege, for people and agents alike.
Access minimization runs throughout the platform. Users — and the agents acting on their behalf — reach only the data and actions their role and use case require, all administered centrally and logged in full.
- Advisor A cannot see Advisor B’s book or households.
- Agents are scoped to only the data and tools their use case needs.
- Auditable role assignment and a complete record of every access change.
SOC 2 CC6 · HIPAA access controls · GDPR/DPDP minimization
Encryption at rest and in motion
Encrypted end to end, under your keys.
All data is encrypted with industry-standard algorithms throughout its life — moving between services and sitting in storage — with key management you can hold yourself.
- TLS 1.3 or higher in transit; AES-256 at rest across storage, logs, and artifacts.
- Customer-managed keys (CMK / BYOK) through your own KMS or HSM.
- Periodic key rotation on your schedule.
SOC 2 CC6 · HIPAA encryption · GDPR Art. 32
AI you can put in front of a client.
The hardest problem in applied AI for a fiduciary is not capability — it is accountability. Fiden is built so the machine carries the load and a person carries the judgment.
Nothing sensitive gets through
Sensitive data is redacted inside your environment before any model receives it, and every input is screened for injection and abuse. What the model can’t see, it can’t leak.
A human owns what matters
Agents draft, propose, and prepare; consequential actions wait for review. Human judgment — trust, empathy, accountability — stays with your people by design, not as a fallback.
Nothing is taken on faith
Every turn is evaluated, scored, and logged on one execution path, so behavior doesn’t drift between test and production and every action can be explained after the fact.
A note on what this page claims
The controls described here are architectural commitments of the Fiden platform. Named standards — SOC 2 Type II, HIPAA, GDPR, India’s DPDP Act, the UAE’s PDPL, and ISO/IEC 42001 — indicate the frameworks our controls are designed and mapped to; they are not a claim of current certification. Formal certification is in progress and not yet complete. Deployment-dependent capabilities vary by configuration. Current attestations, control mappings, and roadmap are available under NDA.
