Security & Compliance

Financial AI must be permissioned, logged, and bounded

FDE.HK emphasises secure deployment methods, data permission design, auditability, NDA workflow, and clear compliance-support boundaries. It does not claim to replace regulated professional judgement.

Control areas

Security design before production deployment

These controls are part of the implementation scope and should be adapted to each client’s internal policy.

AI usage permissions

Role-based access for users, departments, AI employees, and knowledge bases.

Sensitive data handling

Non-sensitive samples first; sensitive materials after NDA and access scoping.

Knowledge isolation

Separate indexes, access policies, and retrieval boundaries for different business units.

Usage and audit logs

Record usage events and review paths for operational visibility.

Internal AI policy

Policy templates for allowed use, prohibited data, review flow, and escalation.

Compliance support boundary

FDE.HK provides AI deployment and workflow enablement. It does not replace licensed professionals, lawyers, compliance officers, or internal accountable owners.

Boundaries

Compliance support does not replace licensed judgement

FDE.HK provides AI deployment and workflow enablement. It does not replace licensed professionals, lawyers, compliance officers, or internal accountable owners.

No licence claim

FDE.HK does not claim to hold financial licences unless separately verified and published with evidence.

No replacement of counsel

AI outputs must be reviewed by authorised internal and professional reviewers.

No sensitive upload by default

Initial forms request business context only; sensitive documents wait for NDA and access design.

Audit-ready workflow

Usage records, source references, and escalation paths are considered during deployment.

FAQ

Security questions

A concise FAQ for procurement, compliance, and technology teams.

Can FDE.HK sign an NDA?

Yes. The request flow supports an NDA preference, and sensitive data should wait until NDA and access rules are confirmed.

Can AI outputs be used directly for regulated decisions?

No. AI output is supporting material and requires review by the client’s authorised professionals.

How are permissions handled?

Permissions are scoped by department, role, knowledge base, AI employee, and task.

Start with a secure diagnosis

Clarify data boundaries and risk controls before choosing tools or building workflows.

Book Financial AI Diagnosis
Enterprise Procurement Route

Start with non-sensitive context, then move into an accepted AI deployment route

FDE.HK connects intake, diagnosis, solution design, delivery, and managed operations into one enterprise buying path for business, technology, compliance, and management teams.

Non-sensitive first
Sensitive materials wait until NDA, permission, and data boundaries are confirmed
Diagnose before build
Clarify scenarios, users, data, budget, and acceptance criteria first
Accepted delivery
Plans, workflows, training, operations, and acceptance checklists stay traceable