Beat 5 · Governed by Construction

Built for your compliance officer's questionnaire

Human approval is the default everywhere. The controls explain how we keep it that way.

CloudLink is architected to keep your firm the regulated entity and to keep us a vendor outside your perimeter. The summary below answers the questions a CCO and an SEC examiner ask. A full security-questionnaire answer key (SIG/CAIQ-style) is available on request.

AI specifics

Can the AI give advice or trade on its own?

No. Human-in-the-loop is the default everywhere. Autonomy is earned per workflow, through measured evaluations — never assumed. Client-facing work always carries a named human approver — the author of record — on a tamper-evident audit trail.

What about hallucinations in client communications?

Outputs are grounded and cited in your own data, reviewed and approved by a human (the author of record), and screened by automated evals for unsupported claims, Marketing-Rule issues, and data leakage before reaching a person.

Your data & NPI

Is our client data used to train AI models?

No. Inference runs through enterprise channels under contractual no-training and retention limits, in-region. There is no fine-tuning on your data.

How is NPI handled?

Classified at ingestion, minimized (we take only what a workflow needs), encrypted in transit and at rest, and sensitive identifiers redacted before anything leaves your boundary.

Encryption & keys

How is data encrypted?

TLS in transit; KMS-backed encryption at rest with per-firm keys — which also enable clean, verifiable deletion (crypto-shredding) on exit.

Multi-tenancy & isolation

Is our firm isolated from your other clients?

Yes — structurally. Each firm gets its own isolated data store, vector namespace, and keys, resolved from a signed identity context, not a query filter that could be forgotten. "Cross-tenant data bleed" is a first-class, automatically tested failure mode that gates every release.

Compliance mapping

How do you support our regulatory obligations?

Controls are mapped to specific rules: Books & Records (204-2) → immutable, exportable audit trail; Marketing Rule (206(4)-1) → human-approved, screened client content with records retained; Reg S-P (incl. 2024 amendments) → safeguards, incident response, and breach notification within your ≤30-day window. The FINRA 17a-4 WORM module is available for hybrid RIA/BD firms.

What is the obligation overlay?

It is a machine-readable map of your compliance obligations, each tied to its evidence. The overlay is a mirror for review and exam preparation; it is not prompt content and it is not legal advice.

How is this verified?

Verification is the culture: ~30 verification gates / 200+ automated checks as of July 2026, including adversarial scenarios and clean-day negative controls.

Are we still the record-holder?

Yes. Your authoritative books and records stay in your existing, already-compliant systems by default; the twin is a derived layer. You can export everything at any time.

Vendors, access & resilience

Who can access our data, and what about sub-processors?

Vendor access is least-privilege, time-bound, and audited; staff federate to your identity provider with MFA. We maintain a disclosed sub-processor list (cloud + model provider) with no-training/retention flow-downs, and a written information-security program. We are building toward SOC 2 Type II covering the data plane, gateway, audit store, and key management.

Business continuity & incident response?

Multi-AZ redundancy, tested backups, and a documented DR runbook; an incident-response process notifies you fast enough to meet your customer-notification duty. The platform is documented as a dependency in your BCP.

Exit

What happens to our data if we leave?

No lock-in. Full export in open formats (canonical data, documents, twin-generated records, audit trail), then verified deletion. Because your authoritative records live in your own systems throughout, leaving never puts your books and records at risk.

Due diligence

Need the full security questionnaire answered?

We'll provide a point-by-point answer key for your CCO.

See resources →