Governance and security
This page is written for two readers: the person who runs the firm, and the person who checks suppliers for security. Each topic starts with a plain answer, then says what is built and tested today and what is designed and not built yet.
Who is in control
A person at your firm approves every step that carries risk. Fidvela prepares; your people decide.
Built and tested
- Only people your firm gives approval rights can approve.
- An approval covers the exact content approved. If the content changes, the approval is void and a new one is needed.
- In Watch mode, nothing is sent outside your firm.
Designed, not built yet
- No “approve all”: each approval is for one file.
- Approvals that wait too long go to a reminder, then to your named backup approver, then to your admin, with timings your firm sets.
- A pause for one worker and an emergency stop for all, for your admins.
What is recorded
Every action is recorded: what arrived, what was done, by whom or by what, and who approved it.
Built and tested
- Entries are added and never edited. Each entry is linked to the one before it, so a changed or missing entry shows when the record is checked.
- Every figure Fidvela uses links back to the page of the document it came from.
Designed, not built yet
- The record cannot be switched off.
- Search by your own file number, and export of the record.
- Limiting who can write the record, once Fidvela runs in the cloud.
How your data is kept
Your files are kept apart from every other firm's, and identity numbers are hidden from AI models.
Built and tested
- Each firm's data is kept separate. Tests that try to read one firm's files from another run on every change to the code.
- Identity and account numbers are found by ordinary software and replaced with a stand-in before any AI model sees the text.
- Messages are checked before sending. A message carrying an identity number, a link outside your approved sites, or a recipient who is not on the file is stopped, and the reason is recorded.
Designed, not built yet
- Encryption in transit and at rest.
- Each step receives only the information it needs.
- Our own staff have no standing access to your files. Access is requested with a reason, limited in time, recorded, and visible to you.
- Export of your files and records, and their deletion.
- We will not use your data to train or tune AI models, and our agreement with you will say so.
Where your data is stored and processed
It is agreed with each customer, in writing, before you send any data.
Built and tested
- If the AI service agreed for your firm is unavailable, work waits. It is not moved to another service.
Designed, not built yet
- A written statement naming where your records, documents and keys are stored, and where document reading and AI processing happen.
Outside services
We will give you the list of outside services that process your data, and what each one does, before you send any. We will tell you before that list changes.
If something goes wrong
Our agreement will set out how and when we tell you about a security incident affecting your data.
What we do not have yet
No customer uses Fidvela yet. We hold no security certification yet. We have no measured accuracy or time-saving figures, and we will not quote any until they are measured on real use.
Where each control stands today
| Control | Status |
|---|---|
| Approval tied to the exact content approved | Built and tested |
| Only people with approval rights can approve | Built and tested |
| In Watch mode, nothing is sent outside your firm | Built and tested |
| Messages checked before sending: no identity numbers, no links outside approved sites, only people on the file | Built and tested |
| Messages to borrowers say they were written by an AI assistant and how to reach a person | Built and tested |
| Mail from unknown senders held, unread, until a person releases it | Built and tested |
| Each firm's data kept separate | Built and tested |
| Identity and account numbers hidden from AI models | Built and tested |
| Every figure linked to the page it came from | Built and tested |
| Records that show if anything was changed | Built and testedThe part that limits who can write the record waits for the cloud setup |
| Spending and activity limits | Built and tested |
| Work waits when the agreed AI service is unavailable | Built and tested |
| Plain-word reasons when work stops for a person | Partly built |
| Package and cover report | Designed, not built yet |
| Pause and emergency stop for your admins | Built and tested |
| Reminders and a backup approver for waiting approvals; no “approve all” | Built and tested |
| Export of every record and document, and deletion with a dated record of it | Built and tested |
| Search by your own file number | Designed, not built yet |
| Encryption in transit and at rest | Designed, not built yet |
| Staff access only on request, with a reason, time-limited and recorded | Designed, not built yet |
| Each step receives only the information it needs | Designed, not built yet |
| The record cannot be switched off | Designed, not built yet |
| Written statement of where your data is stored and processed | Designed, not built yet |
| List of outside services that process your data | Designed, not built yet |
| No training on your data, written into our agreement | Designed, not built yet |