FINVIJ
Request Demo
Security & Compliance

Built to live inside a bank's perimeter.

Every architectural decision in FINVIJ starts from the same constraint: the data never leaves the bank, and every decision must survive an examination. On-premise and private-VPC deployment — by design, not retrofitted.

The commitments, specifically.

Zero data egress

Borrower data, bureau responses, models, and prompts are processed entirely inside your infrastructure. Nothing is sent to third-party cloud services — including the AI layer, which runs on local models within your perimeter.

On-premise or private VPC — by design

Bare metal, private cloud, or your AWS/Azure/GCP tenant. Single-tenant in every deployment. The platform was architected for this from day one, not adapted to it.

100% in-India data residency

All data, all processing, all model inference stays within Indian jurisdiction — aligned with RBI expectations and the DPDP Act 2023.

DPDP Act 2023 alignment

Consent-aware data handling, purpose limitation, and data-principal rights supported in the data layer — not bolted on through policy documents.

Per-decision audit lineage

Every decision traces end-to-end: policy rule → data source → model version → override log. Any past decision can be reproduced bit-for-bit for any date — examination-ready by construction.

Role-based access control

RBAC with maker-checker separation on every change — policies, models, rate cards, and overrides all carry dual control and an append-only change log.

RBI IT outsourcing direction compliance

Deployment, access, and audit models designed to satisfy RBI's directions on IT outsourcing and third-party risk — because the system runs inside your perimeter, the outsourcing surface is minimal.

Ind AS 109 / IRACP-mapped templates

ECL staging, provisioning, and asset-classification outputs mapped to Ind AS 109 and IRACP norms out of the box — board-grade and examiner-legible.

Encryption in flight (TLS) and at rest (AES-256). Immutable, append-only audit logs. Model documentation packs auto-built for MRM review. Aligned with RBI MRM guidelines, Ind AS 109 / IFRS 9, ISO 27001 and SOC 2 control frameworks.

Bring your IT security team to the first call.

We would rather answer the perimeter questions on day one than on day ninety.

Request Demo