Skip to content
Introducing Managed AI: governed AI for financial servicesLearn more →
Trust Center

For the most sensitive data in finance.

MNPI, LP records, deal documents, trading infrastructure. RFA is engineered to protect what financial firms cannot afford to expose, with controls verified by independent auditors and demanded by the world's most rigorous allocators.

01

Encryption everywhere

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256), with keys managed in HSM-backed vaults.

02

Your data is never training data

Model training on client data is contractually prohibited, with zero-data-retention agreements in place with every AI subprocessor.

03

Access under your control

SSO and SCIM provisioning, role-based access, least privilege by default, and just-in-time elevation, every action logged.

04

Data residency by design

Hosting options in the US, UK, EU, and Singapore, aligned to the jurisdictions your regulators and LPs expect.

05

Defended around the clock

The same 24/7 SOC and managed detection that guards our clients guards RFA itself, one standard, no exceptions.

06

Independently verified

SOC 2 Type II and ISO 27001 audits, annual external penetration tests, and investor due-diligence support on request.

Certifications & partnerships

SOC2
ISO 27001
GDPR
CSSF PSF Certified
Claude Partner Network
Responsible AI

Agentic AI, governed like a regulated system.

The Titan platform treats every agent the way finance treats any system of record: scoped, supervised, logged, and recertified. Autonomy is earned, never assumed.

Explore the Titan platform

Mapped to ISO/IEC 42001

Every agent is designed, tested, and recertified against RFA's agentic trust framework.

Human-in-the-loop

Agents draft; operators approve. Nothing executes autonomously against your environment.

Complete audit trail

Every agent action is logged and reviewable: built for SEC/FINRA recordkeeping and exam readiness.

MNPI guarded at every layer

Purview labeling, DLP, and Prompt Security protect MNPI, PII, deal, LP, and client data.

Global compliance

Coverage in every market.

Wherever you do business, RFA meets local regulatory requirements,
with records and controls to match.

North America

New York · Boston · Connecticut · San Francisco · Raleigh · Miami · Toronto

SECFINRANFAOSFISOC 2NIST

United Kingdom

London

FCACyber EssentialsISO 27001

European Union

Luxembourg · Paris

CSSFGDPRDORA

Asia-Pacific

Singapore

MAS TRMPDPA
Questions we get in every DDQ

Asked by allocators. Answered in writing.

Is our data used to train AI models?+

No. Model training on client data is contractually prohibited, and every AI subprocessor operates under zero-data-retention terms. Your data is used to serve your firm, nothing else.

Where does our data live?+

You choose. RFA offers data residency in the US, UK, EU (Luxembourg), and Singapore, with client-controlled retention and deletion policies aligned to your regulatory obligations.

Who at RFA can access our environment?+

Background-checked engineers with role-based, least-privilege access. Elevated access is granted just-in-time, scoped to the task, and every session is logged and reviewable.

How is RFA itself secured?+

RFA runs on the same controls it sells: 24/7 SOC monitoring, managed detection and response, continuous vulnerability management, and annual penetration tests by independent firms.

What happens if there's an incident?+

A documented, tabletop-tested incident response plan with contractual notification windows. Clients get direct communication from the response team, not a status page.

How are AI agents kept safe?+

Through the agentic trust framework: scoped permissions per agent, human approval before execution, full action logs, and periodic recertification, mapped to ISO/IEC 42001 and ISO 27001.

Running a due-diligence process? Request our full security documentation.

Let's talk about your
technology needs.

Speak with an RFA advisor about IT, cybersecurity,
AI, and compliance for financial services.