For the most sensitive data in finance.
MNPI, LP records, deal documents, trading infrastructure. RFA is engineered to protect what financial firms cannot afford to expose, with controls verified by independent auditors and demanded by the world's most rigorous allocators.
Encryption everywhere
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256), with keys managed in HSM-backed vaults.
Your data is never training data
Model training on client data is contractually prohibited, with zero-data-retention agreements in place with every AI subprocessor.
Access under your control
SSO and SCIM provisioning, role-based access, least privilege by default, and just-in-time elevation, every action logged.
Data residency by design
Hosting options in the US, UK, EU, and Singapore, aligned to the jurisdictions your regulators and LPs expect.
Defended around the clock
The same 24/7 SOC and managed detection that guards our clients guards RFA itself, one standard, no exceptions.
Independently verified
SOC 2 Type II and ISO 27001 audits, annual external penetration tests, and investor due-diligence support on request.
Certifications & partnerships
Agentic AI, governed like a regulated system.
The Titan platform treats every agent the way finance treats any system of record: scoped, supervised, logged, and recertified. Autonomy is earned, never assumed.
Explore the Titan platformMapped to ISO/IEC 42001
Every agent is designed, tested, and recertified against RFA's agentic trust framework.
Human-in-the-loop
Agents draft; operators approve. Nothing executes autonomously against your environment.
Complete audit trail
Every agent action is logged and reviewable: built for SEC/FINRA recordkeeping and exam readiness.
MNPI guarded at every layer
Purview labeling, DLP, and Prompt Security protect MNPI, PII, deal, LP, and client data.
Coverage in every market.
Wherever you do business, RFA meets local regulatory requirements,
with records and controls to match.
North America
New York · Boston · Connecticut · San Francisco · Raleigh · Miami · Toronto
United Kingdom
London
European Union
Luxembourg · Paris
Asia-Pacific
Singapore
Asked by allocators. Answered in writing.
Is our data used to train AI models?+
No. Model training on client data is contractually prohibited, and every AI subprocessor operates under zero-data-retention terms. Your data is used to serve your firm, nothing else.
Where does our data live?+
You choose. RFA offers data residency in the US, UK, EU (Luxembourg), and Singapore, with client-controlled retention and deletion policies aligned to your regulatory obligations.
Who at RFA can access our environment?+
Background-checked engineers with role-based, least-privilege access. Elevated access is granted just-in-time, scoped to the task, and every session is logged and reviewable.
How is RFA itself secured?+
RFA runs on the same controls it sells: 24/7 SOC monitoring, managed detection and response, continuous vulnerability management, and annual penetration tests by independent firms.
What happens if there's an incident?+
A documented, tabletop-tested incident response plan with contractual notification windows. Clients get direct communication from the response team, not a status page.
How are AI agents kept safe?+
Through the agentic trust framework: scoped permissions per agent, human approval before execution, full action logs, and periodic recertification, mapped to ISO/IEC 42001 and ISO 27001.
Running a due-diligence process? Request our full security documentation.
Let's talk about your
technology needs.
Speak with an RFA advisor about IT, cybersecurity,
AI, and compliance for financial services.