Resources
Guides for running AI on your own servers
Guides for compliance, security, and IT leaders at privacy-first companies.
Building it
What it takes to run AI on your own servers
Architecture & Deployment
The private AI stack you’d build yourself: what it takes and how long
Running AI on your own servers: the parts to build, where it can run, what sets the timeline, and what to ask a vendor.
Read the guide →AI Costs
Bounded AI work runs well on smaller models your firm can own
Sorting files, pulling fields, summaries, and policy answers run well on smaller open-weight models. What the research shows and how to test it.
Read the guide →AI Economics
Fixed cost: AI on every document, every night
Metered AI gets rationed, and the bill still swings. How a fixed cost lets a bank or fund run AI on every file, every night, and when the cloud is cheaper.
Read the guide →Checking answers
Answers a reviewer can check
AI Governance
How to check an AI answer before it reaches an examiner
A source link beside an AI answer is a start. How to check that the passage backs the claim, the document is current, and the record holds up in an exam.
Read the guide →AI Governance
When the rule calls for judgment, the AI should say so
Some rules leave the call to a person, like whether activity is suspicious or a breach needs client notice. Good AI answers show where judgment is needed.
Read the guide →AI Governance
Human review is the control your AI policy names. New data shows what it misses.
Human review is the compensating control in nearly every regulated AI policy. New research puts numbers on what it catches and what it misses.
Read the guide →Access and data
Who can see what, and where the data goes
Security & Infrastructure
Permission-aware AI: answers and agents that reach only what the user can open
Make AI answers and agents reach only what each user can open: permission checks inside search, SSO roles, agent identity, audit logs, and tests.
Read the guide →AI Security
Where your data goes when staff use AI
Staff paste loan files and client data into AI tools. Where that data goes, who can read it, how to find shadow AI in 30 days, and what to control first.
Read the guide →AI Security
What is prompt injection?
Prompt injection hides orders in files and email your AI reads. How it works, what EchoLeak showed in Microsoft 365 Copilot, and what limits it.
Read the guide →AI Security
The agents kept a message board
OpenAI's Hugging Face postmortem: about 700 agents, a message board that began in May, missed warnings, and what a bank's security team should change.
Read the guide →Exams
What examiners ask about AI
Banking & Compliance
Bank and credit union exams in 2026: model risk, third-party risk, and fair lending
What bank and credit union examiners ask about AI in 2026: SR 26-2 model risk, AI vendor due diligence, Reg B denial reasons, and the records to keep.
Read the guide →Compliance & Risk
SEC and FINRA exams: supervision, books and records, Reg S-P, and shadow AI
How SEC and FINRA examiners test AI in 2026: supervision, books and records, amended Reg S-P, and staff use of unapproved AI at advisers and brokers.
Read the guide →BSA & Financial Crimes
BSA and AML decisions an examiner can follow
What examiners test in SAR and alert decisions, what the rules require on paper, and how to make every call trace back to your written BSA policy.
Read the guide →Banks & Credit Unions
Policy, procedure, and lending answers for banks and credit unions
Give front-line and lending staff cited answers from your own policies. What banks and credit unions need to know about the lending and data rules.
Read the guide →See it answer from real documents
A 30-minute live demo. We reply within 24 hours.
See it in action