Evidence-backed capability register
FinanceGPT Trust Center
Security, privacy, governance and execution information for customer due diligence, with product capability status separated from independent assurance.
Independent assurance boundary
Certification status
FinanceGPT does not claim SOC 2 attestation or ISO/IEC 27001 certification. Product controls and evidence-management features are not substitutes for independently issued attestations or certificates.
Operational
Implemented and represented as usable, subject to deployment verification.
Configurable
Implemented but requires customer or environment configuration.
Preview / Planned
Not represented as generally available production capability.
Not claimed
FinanceGPT explicitly does not make the public claim.
| Surface | Capability | Status | Statement |
|---|---|---|---|
| Institutional Cloud | Private networking | Planned | Private networking is a deployment roadmap capability and must not be represented as generally live until provisioned and evidenced. |
| Investment Intelligence | Broker trade execution | Configurable | Broker execution is available only through the separately governed Investment Execution workflow with an active connector, execution policy and approved order batch. |
| Trust Center | Hashed API credentials | Operational | FinanceGPT stores governed API credentials using non-plaintext credential handling in the API platform. |
| Trust Center | HMAC-signed webhooks | Operational | FinanceGPT supports HMAC-signed enterprise API webhooks where the API platform is enabled and configured. |
| Trust Center | ISO/IEC 27001 certification | Not claimed | FinanceGPT does not claim ISO/IEC 27001 certification. |
| Trust Center | Microsoft Entra OIDC | Configurable | Microsoft Entra OIDC support is implemented but requires customer and environment configuration before it is operational. |
| Trust Center | SCIM 2.0 provisioning | Configurable | SCIM token and provisioning controls are implemented and require customer configuration and deployment validation. |
| Trust Center | Security incident register | Operational | FinanceGPT includes a governed security incident register within the assurance layer. |
| Trust Center | SHA-256 evidence digests | Operational | Assurance evidence packages and governed records use cryptographic digests where implemented by the relevant evidence service. |
| Trust Center | SOC 2 attestation | Not claimed | FinanceGPT does not claim a SOC 2 attestation. |
| Trust Center | Vendor risk register | Operational | FinanceGPT includes a governed third-party/vendor risk register within the assurance layer. |
Governance principles
✓Workspace role-based access and approvals
✓Data and model lineage where implemented
✓Configuration status separated from externally verified compliance
Financial action boundary
✓Analysis and governed proposals are distinct from execution authority
✓Broker execution requires separately governed connectors and policies
✓Financial actions and investment execution use separate governed gateways
LQM model evidence
Quantitative model outputs carry a versioned evidence contract.
LQM Builder separates quantitative inference from language explanation. Checkpoint, evaluation and Evidence Packet hashes remain inspectable through the developer API. Governed model-hub publication adds builder attribution, repository revision evidence, an ML-BOM and a hash-linked publication supply chain without granting runtime authority.
LQM evidence & developer guide LQM Trust EvidenceCapability status is an internal product representation, not an independent assurance opinion.