Security
Not a feature we bolt on — it is how we engineer every system.
Engineering principles across everything we build
Encryption everywhere
We encrypt data in transit with TLS and at rest with AES-256 across the systems we deliver. Sensitive fields, model inputs, and decision records are protected end to end.
Least-privilege access
Role-based access control, scoped credentials, and short-lived tokens are the default. Every system is designed so people and services can reach only the data they genuinely need.
Data minimization
We collect and retain only what a workflow requires to function. Personal and financial data is scoped to purpose, and we favor pseudonymized or aggregated inputs wherever a decision allows it.
Auditability & explainability
Append-only audit logs and explainable decision trails are built in. Every automated underwriting, credit, or collections decision can be traced to the inputs, rules, and model factors behind it.
Flexible, isolated deployment
We support single-tenant, VPC-isolated, and on-premise deployment so client and prospect data can stay inside the institution's own environment and regulatory boundary.
Secure SDLC
Code review, dependency scanning, secrets management, and environment isolation run through our delivery pipeline. Security checks sit alongside testing rather than after release.
Auditable, explainable credit and collections decisions
Galileo (autonomous loan underwriting), CredAI (credit decisioning on alternative data), and CollectEye (agentic collections) make decisions that affect real people and must withstand regulatory scrutiny. We build them so every outcome is traceable, contestable, and grounded in defensible logic.
Explainable decision trails
Galileo and CredAI record the inputs, rules, and model factors behind every approval, decline, or referral. Outcomes can be reproduced and reviewed:
- Reason codes attached to each decision for adverse-action transparency
- Designed to support ECOA / Regulation B and fair-lending obligations
- Model inputs versioned so a past decision can be replayed exactly
Compliant collections by design
CollectEye automates borrower outreach with guardrails that keep agentic behavior inside the rules collectors must follow:
- Built to support FDCPA contact-frequency and disclosure requirements
- Every message and action written to an append-only activity log
- Policy controls and escalation paths configurable per institution
Careful handling of alternative data
CredAI scores creditworthiness using alternative data. We treat those inputs with the same rigor as bureau data — minimized to what the model needs, encrypted at rest, access-controlled, and excluded from features that would introduce prohibited bias into a lending decision.
Defensible portfolio analytics
InvestorIQ (BTL property and mortgage underwriting) and Amplifi (portfolio intelligence for community-development lenders) work on sensitive borrower and portfolio data. Outputs are tied back to their source records so analysts and auditors can verify how a figure was derived.
A financial-operations platform that stays inside your boundary
gaigenticOS is our AI financial-operations and compliance platform. Because it sits across regulated workflows, it is architected for isolation, traceability, and tight control over who and what can touch institutional data.
Single-tenant & on-prem options
Institutions can run gaigenticOS as a dedicated single-tenant instance, inside their own VPC, or fully on-premise. Data does not have to leave the institution's environment, which keeps it within the relevant regulatory and residency boundary.
Append-only audit ledger
Actions, approvals, and automated decisions are written to an append-only audit ledger. Records cannot be silently edited or removed, giving compliance and internal-audit teams a tamper-evident history they can rely on during review.
Granular access control
Role-based permissions, scoped service credentials, and segregation of duties are built in. Access to sensitive financial operations can be limited, reviewed, and revoked, and every privileged action is logged.
Human-in-the-loop controls
Automated agents operate within configurable limits, with thresholds that route higher-risk actions to human review. Institutions decide where automation acts on its own and where a person must sign off.
Outputs grounded in the rules that govern them
CardOS (payment-scheme compliance and invoice reconciliation) and Greenshield (EU multi-regulation ESG compliance) produce outputs that have to map directly to published rules. We design them to cite the obligation behind each result rather than assert conclusions on their own.
What grounded outputs avoid
CardOS: scheme-aligned reconciliation
CardOS reconciles invoices and checks transactions against payment-scheme rules. Each flag links back to the specific scheme requirement it relates to, so finance and compliance teams can verify a finding instead of taking it on faith.
Greenshield: cited ESG obligations
Greenshield is built to support EU ESG obligations such as CBAM and CSRD. Reported positions reference the underlying regulation and the source data behind them, so filings can be defended line by line.
Built to support, not certify
Our systems are designed to help institutions meet obligations such as Basel, ECOA / Regulation B, FDCPA, CBAM, and CSRD. They are deployed and configured to align with each client's specific regulatory and supervisory requirements.
Honest about claims
We describe engineering practices, not certifications we do not hold. Where a client needs a formal attestation or audit, we deploy and operate in a way that supports their certification program rather than overstating our own.
How we handle data on this site
This marketing site collects only what we need to respond to enquiries. Client and customer product data is governed by separate customer agreements, not by this page.
Minimal lead data
When you contact us we collect the details you provide — name, work email, and your message. We use them to reply and to follow up about working together, nothing more.
Encrypted in transit
Traffic to this site is served over TLS. Any information you submit through a contact form is encrypted on the wire between your browser and our infrastructure.
Limited sharing
We share site data only with the infrastructure and email providers needed to host the site and deliver our reply. We do not sell visitor or prospect data.
Separate from product data
Data processed inside the products we build for clients lives in those deployments and is governed by the relevant customer agreement and our security commitments to that institution.
Report a security concern
If you believe you have found a vulnerability in this site or in a flipprr product, please disclose it responsibly. Email us with the details and steps to reproduce, and we'll investigate promptly and keep you updated.