Answers to the hard questions.

Our architecture does not eliminate compliance obligations. It makes meeting them automatic, mathematically provable, and auditor-ready by default. Here is exactly how each pillar works.

Pillar 1: Software Only Deployment

What exactly is Software Only Deployment?

We do not host your data. We do not provide a web interface that connects to our servers. We provide pure Docker containerization. You download our software containers from our secure registry. You run them entirely on your own infrastructure. You control the network perimeter absolutely.

How does this guarantee zero vendor data egress?

When you deploy our Docker containers, you place them strictly behind your own firewall. The software does not require an external internet connection to process your internal data. It connects only to your internal databases. Because the container logic executes locally and never transmits telemetry to Ace Digital Enterprise, data egress to our servers is zero.

How does self-hosted deployment eliminate third-party cloud data custody audits?

Cloud security audits exist because third-party SaaS vendors store and process your customer data on external multi-tenant infrastructure. Because Finai deploys strictly within your own firewall and never receives or stores your customer records, we are not an external cloud data processor. Your institution retains absolute data sovereignty. You avoid lengthy cloud vendor data custody audits, saving months of procurement friction.

What infrastructure is required to run the Docker containerization?

Any modern server environment supports Docker. You can run our containers on AWS, Azure, Google Cloud, or on-premise bare-metal servers in your own data center. We do not dictate your hardware choices. If it runs a standard Linux kernel, it runs our architecture.

Pillar 2: Enterprise Identity RBAC and LBAC

What is the difference between a logic engine and a data broker?

A data broker takes your user information, stores it indefinitely, and monetizes it across multiple clients. A logic engine only provides the strict instructions for verification. We provide the pure logic engine. When you need to verify a NIN or BVN, our middleware executes the check using your own credentials. We never store the result. We never see the actual data payload.

How does BYOK middleware work?

Bring Your Own Key means you hold the ultimate encryption keys. You generate the keys internally. You manage the rotation schedule. Our middleware uses your specific keys to execute identity checks. If a malicious actor compromises our entire company, they get absolutely nothing. Your data remains locked with keys that only you possess.

What are RBAC and LBAC?

Role Based Access Control ensures that only authorized personnel within your organization can trigger specific identity workflows. Logic Based Access Control ensures that the system only executes when predefined mathematical conditions are met. This prevents rogue employees from mass downloading user records. It restricts internal access strictly to necessary business operations.

How does the identity middleware handle upstream network timeouts during verification checks?

When upstream verification endpoints experience network latency or timeouts, our middleware executes client-side exponential backoff and localized queue management within your internal database buffer. All transient requests remain encrypted with your own keys (BYOK) inside your firewall. The middleware retries the verification logic automatically once connectivity is restored, without persisting unencrypted customer records.

Pillar 3: Middle Office Advisory Copilot

What does the Middle Office Advisory Copilot actually do?

Risk teams waste thousands of hours reviewing false positives. The Copilot is an advanced asynchronous risk tool. It connects directly to your transaction logs. It analyzes behavioral patterns silently in the background. It surfaces only the genuine anomalies that require urgent human review. It prepares the exact documentation required for SCUML and goAML reporting automatically.

Why is asynchronous behavioral monitoring better than rigid transaction blocking?

Mandatory statutory sanctions screening against watchlists is always executed in real time before wire release. However, applying rigid blocking scripts to behavioral heuristics creates high false-positive rates that block legitimate customers at checkout. Our asynchronous Copilot monitors complex behavioral heuristics, multi-account velocity anomalies, and structuring patterns in the background. It alerts your compliance officer and pre-compiles goAML XML and NFIU STR dossiers, allowing your team to freeze suspicious accounts before final settlement while preserving a frictionless experience for honest users.

Does the Copilot replace our compliance team entirely?

It replaces the manual data entry phase. It does not replace the final human decision maker. Your compliance officer receives a perfectly formatted report. They simply click approve or block. They stop acting as spreadsheet managers. They return to acting as strategic risk analysts.

How exactly does the Copilot generate goAML reports?

The Copilot maps your internal database schema to the strict XML requirements dictated by the NFIU. It extracts the relevant variables, formats them deterministically against official UNODC XSD schemas, and drops the finished XML file into your designated secure folder.

Pillar 4: NDPA Anonymizer Shield and Encryption

What is the NDPA Anonymizer Shield?

The Nigeria Data Protection Act requires strict control over Personally Identifiable Information. The Anonymizer Shield is a highly optimized local PII scrubber. It sits cleanly between your production database and your development logs.

How does the local PII scrubber work in practice?

When an engineer queries the database for debugging, the scrubber intercepts the response instantly. It replaces real names and real account balances with structurally identical dummy data. The engineer can fix the critical bug without ever seeing the real identity of the user. This enforces strict technical compliance with NDPA data minimization requirements.

What encryption standard do you use?

We use AES 256 encryption exclusively. This is the global standard for securing highly sensitive financial information. It is mathematically unbreakable with current computing technology. When combined with our BYOK middleware, your internal data achieves the highest possible security rating available in the industry.

Enterprise AI Workspace

What is the Finai Enterprise AI Workspace?

Finai includes a ChatGPT-like chat interface that runs entirely inside your organization's own infrastructure. Every authorized staff member — compliance officers, legal teams, HR, finance, and engineers — can use it for their daily work. No data leaves your servers. No per-seat subscription fees to a third-party AI vendor. You own the workspace outright.

Which AI models does the workspace support?

The workspace supports two categories of models. Local Ollama models run entirely on your own hardware with zero internet dependency and zero data egress. For tasks that require higher capability, the workspace connects to the latest frontier models from OpenAI, Anthropic (Claude), Google (Gemini), and aggregator APIs such as OpenRouter — all via your own API keys, never ours. Intelligent sensitivity-based routing selects the appropriate model for each prompt automatically, directing sensitive internal queries to local models and complex reasoning tasks to frontier models based on rules your team defines.

How does the AI Workspace protect our customer data from frontier LLMs?

The NDPA Anonymizer Shield intercepts every staff prompt before it reaches any frontier model. It replaces all PII with structurally identical tokenized placeholders — customer names, BVNs, NINs, account numbers, transaction references, and any other sensitive field your team configures — before the prompt is sent. The frontier model processes only the anonymized version. The real identity data never leaves your servers under any circumstances. This is cryptographic enforcement, not a usage policy.

Can we use the workspace without an internet connection?

Yes, in local Ollama-only mode. The local model layer runs entirely on your internal servers with no external network dependency. Your staff can continue working during internet outages, and sensitive queries never touch the public internet under any circumstances. Frontier model access requires internet, but you retain full control over which queries are routed there.

How does Finai guarantee zero hallucinations in regulatory filings and AI queries?

In financial compliance, probabilistic guessing is an existential liability. For statutory reporting (UNODC goAML XML 4.0, NFIU STR/CTR, and SCUML schemas), Finai never allows an LLM to guess XML schemas or financial math. It compiles regulatory files using strictly typed deterministic validation engines with official XSD schema verification. In the Enterprise AI Workspace, deterministic guardrails and strict document-grounding layers mathematically intercept and eliminate hallucinated claims before outputs ever reach your staff.

Why should an institution deploy Finai over generic ChatGPT Enterprise licenses?

Generic ChatGPT enterprise licenses are third-party cloud products that leave financial institutions vulnerable to employee jailbreaks, ungrounded advice, and untracked prompt manipulation. Finai gives you: (1) 100% self-hosted deployment behind your own firewall; (2) Inbound NDPA PII tokenization; (3) Outbound post-generation guardrails that intercept role manipulation and hallucinations before text renders on screen; and (4) An automated immutable compliance audit log where every policy interception is recorded for one-click CISO and compliance review.

General Operations

How do we integrate your architecture?

Your engineering team pulls our Docker containers. They configure the simple environment variables to point to your internal databases. They insert your encryption keys. The entire process takes days, not months. You do not wait for our sales engineers to provision cloud instances. You control the deployment speed completely.

Do we need a dedicated compliance officer to use this?

You still need a designated reporting officer for official regulatory interactions. However, they will no longer need a massive team of analysts to support them. The software handles the heavy reporting pipeline. The officer handles the final executive authorization.

What happens when regulations change abruptly?

We update the logic engine immediately. We push a new Docker container to the registry. Your engineering team pulls the new container and restarts the service. The new compliance rules apply instantly across your entire organization. Your data never moves. You remain fully compliant with zero downtime.

Ready to deploy sovereign AI behind your firewall?

Schedule a 10-minute architecture walkthrough with our engineering team. See how Finai eliminates third-party data risk and automates goAML and NFIU compliance.

Request an Architecture Demo