Evidence-backed capability register

FinanceGPT Trust Center

Security, privacy, governance and execution information for customer due diligence, with product capability status separated from independent assurance.

Independent assurance boundary

Certification status

FinanceGPT does not claim SOC 2 attestation or ISO/IEC 27001 certification. Product controls and evidence-management features are not substitutes for independently issued attestations or certificates.

Operational
Implemented and represented as usable, subject to deployment verification.
Configurable
Implemented but requires customer or environment configuration.
Preview / Planned
Not represented as generally available production capability.
Not claimed
FinanceGPT explicitly does not make the public claim.
SurfaceCapabilityStatusStatement
Institutional Cloud Private networking Planned Private networking is a deployment roadmap capability and must not be represented as generally live until provisioned and evidenced.
Investment Intelligence Broker trade execution Configurable Broker execution is available only through the separately governed Investment Execution workflow with an active connector, execution policy and approved order batch.
Trust Center Hashed API credentials Operational FinanceGPT stores governed API credentials using non-plaintext credential handling in the API platform.
Trust Center HMAC-signed webhooks Operational FinanceGPT supports HMAC-signed enterprise API webhooks where the API platform is enabled and configured.
Trust Center ISO/IEC 27001 certification Not claimed FinanceGPT does not claim ISO/IEC 27001 certification.
Trust Center Microsoft Entra OIDC Configurable Microsoft Entra OIDC support is implemented but requires customer and environment configuration before it is operational.
Trust Center SCIM 2.0 provisioning Configurable SCIM token and provisioning controls are implemented and require customer configuration and deployment validation.
Trust Center Security incident register Operational FinanceGPT includes a governed security incident register within the assurance layer.
Trust Center SHA-256 evidence digests Operational Assurance evidence packages and governed records use cryptographic digests where implemented by the relevant evidence service.
Trust Center SOC 2 attestation Not claimed FinanceGPT does not claim a SOC 2 attestation.
Trust Center Vendor risk register Operational FinanceGPT includes a governed third-party/vendor risk register within the assurance layer.

Governance principles

Workspace role-based access and approvals
Data and model lineage where implemented
Configuration status separated from externally verified compliance

Financial action boundary

Analysis and governed proposals are distinct from execution authority
Broker execution requires separately governed connectors and policies
Financial actions and investment execution use separate governed gateways
Capability status is an internal product representation, not an independent assurance opinion.