Evidence-backed capability register

FinanceGPT Trust Center

Security, privacy and assurance information for customer due diligence, with capability status separated from implementation intent.

Certification status: FinanceGPT does not claim SOC 2 attestation or ISO/IEC 27001 certification. Readiness controls and evidence-management features are not a substitute for independently issued attestations or certificates.
Operational
Implemented, represented as usable, and subject to deployment verification.
Configurable
Implemented but requires customer/environment configuration before use.
Preview / Planned
Not represented as generally available production capability.
Not claimed
FinanceGPT explicitly does not make this public claim.
Current capability claims
SurfaceCapabilityStatusStatement
Institutional CloudPrivate networkingPlannedPrivate networking is a deployment roadmap capability and must not be represented as generally live until provisioned and evidenced.
Investment IntelligenceBroker trade executionNot claimedM25 does not execute securities trades. Investment actions remain analytical or governed proposals.
Trust CenterHashed API credentialsOperationalFinanceGPT stores governed API credentials using non-plaintext credential handling in the API platform.
Trust CenterHMAC-signed webhooksOperationalFinanceGPT supports HMAC-signed enterprise API webhooks where the API platform is enabled and configured.
Trust CenterISO/IEC 27001 certificationNot claimedFinanceGPT does not claim ISO/IEC 27001 certification in M25.
Trust CenterMicrosoft Entra OIDCConfigurableMicrosoft Entra OIDC support is implemented but requires customer and environment configuration before it is operational.
Trust CenterSCIM 2.0 provisioningConfigurableSCIM token and provisioning controls are implemented and require customer configuration and deployment validation.
Trust CenterSecurity incident registerOperationalFinanceGPT includes a governed security incident register within the assurance layer.
Trust CenterSHA-256 evidence digestsOperationalAssurance evidence packages and governed records use cryptographic digests where implemented by the relevant evidence service.
Trust CenterSOC 2 attestationNot claimedFinanceGPT does not claim a SOC 2 attestation in M25.
Trust CenterVendor risk registerOperationalFinanceGPT includes a governed third-party/vendor risk register within the assurance layer.
Governance principles
  • Workspace role-based access and approvals
  • Data and model lineage where implemented by the relevant subsystem
  • Separate configuration from externally verified compliance status
  • Usage metering does not imply automatic billing
Financial action boundary
  • Investment analysis and governed proposals are supported surfaces
  • Legacy direct rebalance and tax-harvesting actions remain disabled; governed proposal and execution workflows are used instead
  • Broker execution is available only through separately governed investment execution connectors and policies
  • Financial actions and investment execution pass separate governed execution gateways
Capability status is an internal product representation, not an independent assurance opinion. Customers should rely on formally issued third-party reports and certificates where required.