Security & compliance

Built for the regulated by default.

A brokerage handles money, health and personal data. The security model is not an add-on — it is the reason the product can exist in a regulated market at all.


01Encryption

Encrypted at rest and in transit.

Message bodies, extracted document text and personal data are encrypted at rest with AES-256-GCM, with fields encrypted individually. Everything in transit is protected with modern TLS.

02Data residency

Your data stays in the EU.

Client data is hosted in the EU and kept in-region. Prompts and outputs are sent to model providers under zero-retention terms — not stored by them, and never used to train their models.

03Audit trail

Every reply, reconstructable.

Each answer traces to the exact prompt, model version and rule that produced it. The trail is immutable in the way that matters: append-only is enforced by the database itself, so no part of the application can edit or delete an audit record after the fact. That covers the AI decision trail and the record of every broker accept, reject and edit. The security log is hash-chained on top, so tampering is detectable rather than merely forbidden. When a regulator asks what happened, the answer is on file — not reconstructed from memory.

04Human accountability

A licensed human stays in the loop.

Aoibhe never advises and never binds. Claims with injury, complaints with regulatory exposure and anything she is uncertain about are escalated to a broker with structured context. The licensed entity owns every decision.

05Regulatory posture

Aligned to the CBI Code and EU AI Act.

Complaint acknowledgement, durable-medium notices and record-keeping are built to the revised Central Bank Consumer Protection Code, and the traceability, oversight and logging the EU AI Act requires of high-risk systems. GDPR data-subject rights are supported.

06Access & isolation

Scoped, tenant-isolated access.

Each brokerage’s data is isolated to its own tenant. Aoibhe is trained on your knowledge base, not the open web, and cites only documents your firm provided.

No claim of SOC 2 certification or end-to-end encryption is made. Detailed architecture and a subprocessor list are available under NDA — see subprocessors.


Security FAQ

Straight answers for your compliance lead.

Is brokerage data encrypted?
Yes. Message bodies, extracted document text and personal data are encrypted at rest with AES-256-GCM, with fields encrypted individually, and everything in transit is protected with modern TLS.
Where is client data hosted, and does it stay in the EU?
Client data is hosted in the EU and kept in-region. Prompts and outputs sent to model providers run under zero-retention terms — not stored by them and never used to train their models.
Do you use client data to train AI models?
No. A brokerage’s data is never used to train third-party models. Aoibhe is trained only on the knowledge base your firm provides, and cites only documents your firm wrote.
How does AI Broker meet the EU AI Act?
The EU AI Act’s high-risk duties land in August 2026: traceability, human oversight and logging for AI that touches consumer decisions. Aoibhe reconstructs every reply to the exact prompt, model version and rule behind it, keeps a licensed human accountable, and logs every tool call.
Is it compliant with the Central Bank Consumer Protection Code?
Complaint acknowledgement, durable-medium notices and record-keeping are built to the revised Central Bank Consumer Protection Code, in force since March 2026. Each item traces to the provision behind it and the date logic behind its deadline.
How does it work for UK brokerages under the FCA?
The audit pipeline is the product, and it ports across regimes. The same engine that maps to the Central Bank rules in Ireland applies FCA and ICOBS obligations in the UK — per-market regulatory rules on top of a single, reconstructable audit trail, with the licensed broker accountable in both.
Is AI Broker SOC 2 certified?
No SOC 2 certification is claimed today, and no end-to-end encryption is claimed. Detailed architecture, data flows and a subprocessor list are available under NDA for a compliance review.
What does “immutable audit trail” mean here, specifically?
Append-only is enforced by the database with a trigger, not by application convention, so no code path can edit or delete an audit record once written. It covers the AI decision trail, every tool call, and the ledger of every broker accept, reject and edit of an AI proposal. The security log carries a hash chain on top, so alteration is detectable and not only prohibited. A database superuser could still remove the trigger, and any vendor claiming otherwise is overstating it; what we can show is that nothing in the running system is able to.
Does a human stay accountable for decisions?
Yes. Aoibhe never advises and never binds. Claims with injury, complaints with regulatory exposure and anything she is uncertain about are escalated to a broker with structured context, and the licensed entity owns every consequential decision.

Diligence-ready

Bring your questions.

We’ll walk your compliance lead through the architecture, the data flows and the audit trail on a single call.

A 30-minute call is the whole sales process. Or email support@aibroker.ie.

Security & compliance — AI Broker | AI Broker