Security & compliance

Built to be audited.

Every extraction, rejection, confirmation and handoff is recorded against the person who made it. Your compliance team sees the same conversation the officer did, and nothing leaves without a human saying so.

Audit trail · case FL-2026-09-0412Immutable · exportable
09:41S. Fernando confirmed Address proof → approved. Basis: CEB bill, issued 41 days ago, name and address match ID.
09:40Finline read ceb_bill_july.pdf · 3 fields · min confidence 0.97.
09:38Finline rejected water_bill_march.jpg · reason: issued > 3 months. Replacement requested.
09:36Customer link upload received · nic_front.jpg, nic_back.jpg · 2.1 MB · virus scan clean.
09:35Finline ignored off-topic instruction embedded in uploaded PDF metadata.
09:31S. Fernando opened case · Account opening · language: Sinhala.

Controls

Eight controls, applied to every analyst.

01

Officer-in-the-loop

No field, report, memo or movement is final without a named person’s confirmation.

02

Encryption in transit and at rest

Documents, extracted values, transcripts and exports alike. Keys managed per institution.

03

Data residency

In-country hosting, or deployment on your own infrastructure. Customer data does not leave the jurisdiction you choose.

04

Roles and access

Officer, verifier, treasurer, compliance and admin roles. Single sign-on with your directory on request.

05

Complete audit trail

Every event with who, when and on what basis. Immutable, searchable, exportable for inspections.

06

Prompt-injection resistance

Instructions hidden in documents or typed into chat are ignored and logged. The assistant only does the task it was opened for.

07

Retention and deletion

Retention periods you set per document type; verified deletion on schedule or on request.

08

No training on your data

Your documents and records are never used to train shared models. Institution-specific models stay yours.

Regulatory alignment

Designed to support the rules you already answer to.

Finline is a tool your institution operates; your compliance function stays the owner of every obligation. We build so that meeting them is the default path, not extra work.

Customer Due Diligence Rules (2016)

Issued under the Financial Transactions Reporting Act. The KYC interview collects, verifies and records identity, address, purpose and source of funds, with the officer’s confirmation on each.

Personal Data Protection Act, No. 9 of 2022

Purpose-limited processing, retention you control, deletion on request and in-country residency options support your obligations as controller.

Model risk expectations

Explained factors, no protected attributes, drift monitoring and a documentation pack for the Borrower Profile and Risk Analyst models.

Certifications & attestations

[Placeholder, to confirm: ISO 27001 status, independent penetration test date, SOC 2 roadmap.]

For compliance teams

The questions we are asked first.

Can the AI approve a customer or a loan on its own?

No. Every field, report and decision requires a named officer’s confirmation. The system has no path to core banking that skips it.

Where are customer documents stored, and for how long?

In-country, or on your infrastructure. Retention is set per document type by your institution; deletion is verified and logged.

What happens if a document contains hidden instructions?

They are ignored and the attempt is written to the audit trail. The assistant only performs the task the officer opened.

Can we inspect why a borrower profile came out the way it did?

Yes. Each profile lists its factors with direction and weight, the inputs it used, and the officer’s recorded decision. A documentation pack covers method and validation.

Do you use our data to improve models for other institutions?

No. Nothing is pooled across customers. Institution-specific models are trained on your book only and remain yours.

How do we hand an inspector the evidence?

Export the audit trail for a case, a date range or an officer, with the documents, confirmations and rejections included.

Send your due-diligence questionnaire.

We answer vendor questionnaires in full, and will walk your compliance and IT teams through the architecture.