1. Data Privacy & Model Training
Q: Is our portfolio or proprietary customer data used to train or fine-tune AI models?
A: No. Customer data, portfolio analytics, search queries, user prompts, and generated responses are never used to train, fine-tune, or improve foundation or third-party AI models. We enforce strict zero-data-retention and zero-training contractual agreements with approved enterprise AI infrastructure providers.
Q: Where is customer data hosted and processed when using AI features?
A: All customer data and AI inference workloads operate strictly within EU/EEA-resident cloud environments (utilizing enterprise-managed infrastructure such as AWS Bedrock deployed in European regions). No customer or client-identifiable data is transferred outside the EU/EEA.
Q: What personal data (PII) is sent to the AI?
A: We practice strict data minimization. Raw personal identifiers (such as national IDs, personal contact details, or unnecessary investor metadata) are filtered prior to query execution. The system transmits only the minimum analytical context required to fulfill the user's specific request.
2. Accuracy & Financial Integrity
Q: How does Jay Solutions prevent financial hallucinations in AI outputs?
A: Jay AI is architected as an analytical interpreter and narrator, not a calculator. Quantitative metrics (returns, volatility, asset allocations, drawdowns, benchmarks) are deterministically computed by Jay's backend analytics engine and Snowflake-backed data layer. The AI layer queries these verified figures and translates them into natural-language summaries with source citations.
Q: Can the AI execute automated investment transactions or provide regulated advice?
A: No. Jay AI features are strictly designated as assistive decision-support tools with mandatory human-in-the-loop oversight. Built-in system boundaries prohibit automated trade placement, order routing, or autonomous regulated financial advisory actions.
3. Architecture, Access Control & Governance
Q: How is cross-tenant and cross-user data isolation maintained?
A: AI interactions inherit the exact authentication and Role-Based Access Control (RBAC) boundaries of the authenticated user. A user cannot query, summarize, or surface data from portfolios, organizations, or silos outside their verified permissions.
Q: How are user prompts, conversational histories, and agent traces secured?
A: Conversation histories, agent reasoning traces, and operational logs are classified as confidential records. They are user-scoped, encrypted at rest and in transit, and governed by defined retention and redaction policies to prevent leakage in system logs.
Q: How does Jay Solutions evaluate and select underlying LLM providers?
A: We apply a formal LLM evaluation framework that assesses prospective models across security architecture, enterprise contractual commitments, EU hosting availability, deterministic retrieval performance, vulnerability posture, and alignment with the EU AI Act and GDPR.
4. Compliance & Security Certifications
Q: What security certifications and standards govern Jay Solutions' AI?
A: Jay Solutions operates an ISO/IEC 27001:2022-certified Information Security Management System (ISMS) audited by Bureau Veritas. Our cloud environments are continuously monitored using automated CSPM/CWPP tools, and we undergo regular independent third-party penetration testing and threat modeling specifically covering AI attack vectors (e.g., prompt injection, data extraction).
Q: How does Jay Solutions support DORA and third-party risk management requirements?
A: We maintain documented ICT third-party risk assessments, sub-processor registers, and formal exit strategies aligned with DORA Article 28, ensuring regulatory readiness and resilience across all critical cloud and AI service dependencies.
