Self-hosted by default. Built for air-gapped deployment. DPDP-aware in design.
FinRace AI runs entirely on infrastructure you control. There are no external LLM API calls — reasoning happens on a self-hosted model — and no third-party analytics or tracking scripts anywhere in the product. It is built to run on-premise or in an air-gapped environment, and its data model is DPDP-aware: per-tenant isolation, an immutable audit log, a consent ledger, and configurable retention.
Every model call is served by a self-hosted model. Confidential client tax and legal data is never sent to OpenAI, Anthropic, Google or any external AI provider. There are no analytics or tracking scripts in the product.
The platform is designed to run without outbound internet access; a hardened “sovereign mode” disables non-essential external calls. The reference cloud deployment is internet-connected — air-gapped install is a supported deployment target, not the default.
Row-Level Security on every table and a separate vector namespace per tenant. One firm’s documents and research history are not reachable from another’s.
Every consequential action is written to an append-only audit log. Retention windows are configurable per deployment. Security-event logging happens at authentication boundaries only.
A consent ledger records data-processing consent; the audit log and retention controls support data-principal-rights workflows. This is an architectural posture, not a compliance certification — your DPO remains the authority on your obligations.
Retrieved citations are validated against the source context or a canonical statute list before an answer renders. Ungrounded citations are flagged, not shown as fact.