No badge wall. Here is what we actually have.
Most vendor security pages are a row of logos and the word enterprise. This page states what RIAI does, where your data sits, and what we commit to — so your compliance consultant can check it instead of trusting it.
Last reviewed 2026-08-21 · printable
We have not completed a SOC 2 examination, and we do not claim SOC 2 certification.
When that changes, this page will say so, with the report period and scope. Until then, no logo you see here implies an audit that hasn’t happened — on this site or in anything we send you.
What we have instead is an architecture you can interrogate: your data in your own tenant, access enforced in code, an append-only record, and model terms your firm can read directly. Each one is below, with enough specifics to check.
Your data lives in your firm's tenant
RIAI consolidates your portfolio system, CRM, and Microsoft 365 into one database inside the Microsoft Azure tenant your administrators already manage. Nothing new has to be trusted with client records — the consolidated copy lives somewhere your firm already controls, and if you remove RIAI, it does not have to be moved or returned. It never left.
Our own view into a running install is the shape of the data — tables and field names, never contents. Maintenance happens from the outside. The honest cost: when something breaks, diagnosing it is slower for us than for a vendor who can read your records. We take that trade on purpose.
Four connections, each one-waylisted on ProductScope is enforced in code, not in the prompt
“We told the AI not to” is a sentence the model usually obeys. RIAI does not rely on it. Who sees what is built into the request that goes to the database: an answer is assembled only from records the person asking may see, and a household outside their book is never fetched — so no phrasing can reach it.
Every registered capability that takes a household passes the same gate, and the deliberate exceptions are whitelisted with a written reason each. One screen shows what the AI can reach and what each person can reach through it, always current.
The test we invite: open the demo and ask for another advisor’s client list. Read the refusal, then read the row it wrote.
A person signs everything that leaves
Acts that reach outside the firm stop for a person. The approval binds to the exact rendered content — change one character of what was approved and it will not run — and it executes exactly once, surviving crashes and races. If the approval store cannot be read, the act is treated as not approved. It fails closed.
Outgoing mail is drafted by RIAI and approved by a person before it goes anywhere. Licensed work — moving money, placing trades, advice of record, compliance sign-off — is refused outright, with no setting that loosens it.
Append-only, enforced by the database
Every act and every refusal lands on one record, alongside every setting the firm changed — what the AI did, and what the firm changed about the AI. The table refuses updates and deletes at the database layer, not as a policy. When an audit write fails, the action is marked as having run unrecorded; it does not quietly pass.
For the record-keeping rules your firm actually answers to: advisers are not required to keep WORM storage — that is broker-dealer territory, and a vendor telling you otherwise has told you something. Rule 204-2 asks for records that are indexed, retrievable, and safeguarded from alteration. An append-only ledger is a stronger control than the rule demands, which is the right direction for the evidence an examiner walks in asking for.
Nothing in RIAI deletes client data on a schedule, and no automatic purge path exists — rows leave only by explicit administrative action. Your five-year obligations don’t race a vendor’s cleanup job.
Whose model, running where, under what terms
The model is Claude, reached through the Anthropic API — the one subprocessor that touches request content. The arrangement is direct: commercial API terms your firm can read itself, under which the traffic is not used to train models. Your records are never used to train AI models — not by us, and not by the model provider under the terms the service runs on.
One limit, stated because it is true: we cannot guarantee which region processes a given request. If that constraint matters to your firm, it belongs in the evaluation conversation, not in fine print discovered later.
The model is also a decision your firm can revisit deliberately — it is a setting with a name on it, not an inheritance from whichever vendor bundled it.
The 72 hours, and what you'd hand the SEC
Amended Regulation S-P is fully in force — the last compliance date passed in June 2026. Your procedures must now be reasonably designed to ensure a service provider notifies you as soon as possible, and no later than 72 hours, after becoming aware of a breach of a customer-information system it maintains. Ask every vendor for that commitment in writing. We give it, and we do not condition the clock on finishing forensics first.
The 30-day notice to affected individuals is your duty, not ours — what a vendor owes you there is speed: which records, which people, which data elements, exportable from the record instead of reconstructed in a panic.
And because the SEC now enforces AI claims on marketing sites directly, every claim on this site is held against the running code before it ships. The discipline is not just posture — it is what keeps your own ADV and marketing accurate when you describe what your firm uses.
Four questions for any vendor with an AI in its product.
Where does the data live. What is retained. Who sees what through it. What can leave. We answer all four on the product page, and the printable one-pager carries no pitch — put it to every vendor in your stack, including us.
Interrogate the running system instead.
A live install on an invented firm. Ask it anything, watch the receipts land, then try to make it cross a line.
Ask us about your firmhello@riaintelligence.ai