Security & compliance
Security & compliance, built in.
Dafin is built for regulated environments from day one — not retrofitted for compliance. Every architectural decision meets the standards of private banks, wealth managers and WealthTech platforms.
Compliance frameworks supported
MiFID II
FINMA
GDPR
SOC 2
01 — Data residency
Your data never leaves your perimeter.
On-premise, private cloud or hybrid — never shared multi-tenant. Client data is not used to train or fine-tune any model. The model sees the question; never the data.
INSIDE YOUR FIRM
Where your data lives
PMS database
Custodian feeds
KYC & compliance records
Risk models
Dafin reasoning engine
THE WALL
Question only · no data
OUTSIDE
Where the model lives
Language model (interprets)
Never sees client data
Never trained on your firm
Never stores anything
Receives question only
02 — Compliance frameworks
Audit-ready for the regulations that govern your firm.
MiFID II
Suitability & audit trail
Supports suitability assessment, recording and reporting. Every answer logged with full reasoning and citations — the audit trail required by Articles 16 and 25.
FINMA
Swiss banking standards
Documentation and audit capabilities aligned with FINMA Circular 2023/1 on Operational Risks. Reasoning logs retained per your institution’s record-keeping policy.
GDPR
European data protection
Architectural support for data minimisation (Art. 5), purpose limitation (Art. 6) and the right to explanation for automated decisions (Art. 22). DPAs available on request.
SOC 2
Trust Services Criteria
Controls aligned with SOC 2 — Security, Availability, Confidentiality and Processing Integrity. Type II audit in progress.
03 — Explainability
Every answer carries its receipts.
Dafin doesn’t generate plausible-sounding answers. Each response is calculated from your verified data sources, with full reasoning and citations attached.
When a compliance officer, auditor or regulator asks how a recommendation was made — the answer is already in the log.
D
Reasoning trace
step by step
› Interpret query intent
› Identify relevant data sources
› Pull positions, prices, dates
› Compute weighted exposure
› Compare against IPS limit doc
› Format response with citations
AUDIT READY
Every step logged. Every figure sourced.
04 — Questions security teams ask
Frequently asked.
Where is my data stored?
In your chosen environment — on-premise, your private cloud tenant, or hybrid. Never in a shared multi-tenant environment, and never used to train or fine-tune any model.
Can I review a SOC 2 report?
How are user permissions managed?
Has Dafin been penetration tested?
What happens to my data if I cancel?
Can our internal security team conduct a review?
Security review · with our team
Ready to bring your security team into the conversation?
Book a security review — we’ll walk through architecture, controls and compliance, and answer the questions your CISO will ask.

