Security and Governance
Security You Can Verify, Not Just Read About
Argivio runs inside your own cloud account. Client data never leaves it, every request is checked and logged, and your analysts decide. Here is exactly how, written for your CISO, DPO, compliance and model risk teams.
How Argivio Fits into Your Institution
Your analysts work with Argivio inside your own cloud account. We run the platform from outside, with no access to what is inside.
What Exactly Leaves Your Account?
Client and transaction data: never, including prompts, outputs, documents and logs. Operational health metrics: only these, which you can inspect or switch off. Managed AI: only the public sources and non-client tasks you route to it, under a monthly cap you set. See the full data-flow breakdown.
What Exactly Leaves Your Account
The full data-flow breakdown, line by line.
| Data | Leaves your account? | Details |
|---|---|---|
| Client, account and transaction data | Never | Prompts, outputs, documents, embeddings and logs stay in your account. |
| Your risk models and their scores | Never | Models run and are evaluated inside your account. |
| Operational health metrics | Only these | CPU, memory, latency and error rates so we can operate the platform. You can inspect them or switch them off. |
| Requests you route to managed AI | Only public, non-client tasks | Regulatory texts, public research and templates, under a monthly cap you set. You can switch managed AI off entirely. |
Controls Built In from Day One
Isolation
- Your Account, Your RegionArgivio is deployed into your own cloud account or data centre, in the region you choose.
- No Access to Your DataWe operate the platform from outside your data boundary, with no access to prompts, documents or outputs.
- Network ControlsPrivate networking, encryption in transit and at rest, and keys you control.
Governance
- Policy Check on Every RequestAnything involving client data, or where the check is unsure, stays private.
- Audit TrailsEvery request, source, route, score and approval is logged in your account.
- Role-Based and Four-Eyes AccessUsers see only what their role allows, with second approval where your policy requires it.
How Argivio Supports Your Regulatory Obligations
A map from the frameworks your teams work with to the controls in the platform.
| Framework | What it asks of you | How Argivio supports it |
|---|---|---|
| GDPR | Lawful, minimal processing; control over processors and transfers; impact assessments. | Client data is processed only in your own account and region. We supply documentation for your DPIA. |
| DORA | ICT third-party risk management, a register of information, incident handling and exit strategies. | Runs in infrastructure you control, with documented operations, incident logs and an exit path where everything keeps running without us. |
| EU AI Act | For high-risk uses such as credit scoring of individuals: risk management, logging, human oversight and documentation. | Every request, source and approval is logged; an analyst reviews every output; we provide documentation to support your conformity work. |
| AML rules (AMLR, national law) | Explainable monitoring decisions, thorough case records and reporting of suspicious activity. | Case summaries and SAR/STR drafts cite their sources; investigators decide and file; case records are retained in your account. |
| GLBA and US privacy rules | Safeguards for customers’ non-public personal information. | Customer information stays in your environment under your access controls. |
| Model risk management | Validation, ongoing monitoring and documentation of models, as in SR 11-7 and supervisory guidelines. | Evaluation on your own cases, versioned releases with rollback, and explanation packs written to your validation standard. |
Argivio is designed to support these obligations. Compliance itself depends on how your institution uses the platform, and your institution remains the controller and the decision-maker. We provide documentation for your assessments; this page is not legal advice.
Trust You Can Verify, Not Just Read About
Financial institutions rightly ask for proof. Here is what you can inspect before you decide, and what your pilot hands you at the end.
Inspect Before You Decide
- The Security OverviewControls, telemetry and access model, written for your CISO, DPO and third-party risk team.
- The Evaluation MethodHow analysts rate answers, and the thresholds that decide what goes live.
- The Ownership TermsWhat you own and keep, including exit and continuity terms, set out in the contract.
What Your Pilot Produces
- A Private ScorecardHow each model performed on your cases: accuracy, false positives, missed cases and more.
- An Outcome ReportHandling time and acceptance rates, compared with your own baseline.
- Governance EvidenceDocumentation to support your impact assessment, third-party risk register and model validation.
- A Costed PlanWhat production will cost at your real alert volumes, based on measured usage rather than estimates.
Security Questions
Can your staff see our data?
No. We operate the platform from outside your data boundary. Our access covers deployment and health metrics only, never prompts, documents, outputs or logs containing client data.
Where does Argivio run?
In your own cloud account on a major public cloud, in the region you choose in Europe or North America, or in your private cloud or data centre.
Can we switch off managed AI completely?
Yes. Managed AI is off until you enable it for specific task types, and it can be switched off at any time. Everything then runs on private models.
How do you handle model changes?
Every new model or configuration is evaluated on your own cases in a staging environment. It goes live only when it meets the thresholds your team set, and rolling back takes one step.
What happens if we stop working with you?
Your models, knowledge base, ratings and settings stay in your account and keep running. The exit path is set out in the contract.
Get the Security Pack
Architecture, data flows, controls and ownership terms, ready for your security and third-party risk review.