Security, privacy and assurance information for customer due diligence, with capability status separated from implementation intent.
| Surface | Capability | Status | Statement |
|---|---|---|---|
| Institutional Cloud | Private networking | Planned | Private networking is a deployment roadmap capability and must not be represented as generally live until provisioned and evidenced. |
| Investment Intelligence | Broker trade execution | Not claimed | M25 does not execute securities trades. Investment actions remain analytical or governed proposals. |
| Trust Center | Hashed API credentials | Operational | FinanceGPT stores governed API credentials using non-plaintext credential handling in the API platform. |
| Trust Center | HMAC-signed webhooks | Operational | FinanceGPT supports HMAC-signed enterprise API webhooks where the API platform is enabled and configured. |
| Trust Center | ISO/IEC 27001 certification | Not claimed | FinanceGPT does not claim ISO/IEC 27001 certification in M25. |
| Trust Center | Microsoft Entra OIDC | Configurable | Microsoft Entra OIDC support is implemented but requires customer and environment configuration before it is operational. |
| Trust Center | SCIM 2.0 provisioning | Configurable | SCIM token and provisioning controls are implemented and require customer configuration and deployment validation. |
| Trust Center | Security incident register | Operational | FinanceGPT includes a governed security incident register within the assurance layer. |
| Trust Center | SHA-256 evidence digests | Operational | Assurance evidence packages and governed records use cryptographic digests where implemented by the relevant evidence service. |
| Trust Center | SOC 2 attestation | Not claimed | FinanceGPT does not claim a SOC 2 attestation in M25. |
| Trust Center | Vendor risk register | Operational | FinanceGPT includes a governed third-party/vendor risk register within the assurance layer. |