AdvisorDraft
/AI Safety & Security Policy

Compliance Document

AI Safety & Security Policy

How we govern AI behaviour, prevent hallucination, and protect your data within the IFA Letter Generator.

Classification: Internal, Compliance & Client Assurance · Last Updated: February 2026

1. AI Governance Model

AI is used exclusively for decision-support. it drafts, analyses, and suggests. It never makes financial decisions, sends correspondence on your behalf, or takes autonomous action.

FeatureAI RoleHuman Role
Meeting Note AnalysisIdentify template type, extract client details & fund instructionsReview extracted data, confirm or correct fields
Letter DraftingPre-fill suitability letter from 41 approved templatesEdit, complete, and submit for compliance review
Template SelectionMatch meeting note content to the correct letter templateConfirm template selection, override if needed
Field ExtractionExtract fund names, ATR ratings, switch instructionsVerify all extracted values before proceeding

Every AI output is presented as a draft requiring human review, never as a final document.

2. Anti-Hallucination Controls

AI carries a specific risk in financial services: fabricated fund names, incorrect ATR ratings, or misattributed instructions. We address this with multiple layers of control:

1

Closed Template Set

The AI can only select from 41 pre-approved letter templates. It cannot invent new formats or deviate from approved structures.

2

Explicit System Instructions

Every AI prompt includes directives: "Only use fields extracted from the meeting note", "Flag uncertain values rather than guessing", "Do not fabricate client details."

3

Low Temperature Setting

All AI calls use temperature: 0.3, which reduces creative output and favours deterministic, factual responses.

4

Confidence Flagging

When the AI is uncertain about an extracted field (e.g. ATR rating), it flags it with ⚠️ for manual confirmation rather than guessing.

5

Mandatory Limitation Language

When the meeting note doesn't contain enough information to populate a field, the AI leaves it blank and flags it. It never fills gaps with speculation.

Important: No AI system can guarantee zero hallucination. These controls are designed to significantly reduce the risk, but users should always verify all extracted fields and letter content before approving.

3. Data Privacy & Processing

Meeting notes are processed with a privacy-first approach:

Browser-side document processing

Uploaded PDFs and Word documents are read directly in the user's browser. The original file is never sent to our servers.

Transient processing

Meeting note text is processed transiently. It is not stored after AI extraction. Only structured fields (template type, fund names, adviser details) are retained.

Active: PII Masking Gateway

A browser-side PII masking layer automatically detects and replaces personal identifiers (client names, addresses, NI numbers, postcodes, email addresses, phone numbers, dates of birth, and account references) with neutral placeholders before text reaches the AI model. Original values are reinjected after extraction. The AI never sees actual client identity data.

4. Infrastructure & Access Security

Data Residency

UK/EU only. Hosted in London region

Encryption at Rest

AES-256 encryption on all stored data

Encryption in Transit

TLS 1.2+ for all connections

Authentication

Email/password with two-factor authentication (planned TOTP)

Tenant Isolation

Row-level security. Each firm's data is fully partitioned

Session Management

Automatic timeout after period of inactivity

Audit Trail

All actions logged with user, timestamp, and outcome

5. Incident Response & Model Changes

AI Output Incident

If a user identifies an AI output that appears inaccurate, misleading, or fabricated, they should reject it via the compliance review workflow. The compliance team can flag it for investigation, and patterns are reviewed to improve system prompts and controls.

Model Version Changes

Any change to the underlying AI model version is tested against a benchmark set of meeting notes before deployment. Changes are documented and communicated to stakeholders.

Data Breach Protocol

In the event of a suspected data breach, we will notify the ICO within 72 hours (where required) and affected data subjects without undue delay, in accordance with UK GDPR Article 33/34.

This document sets out our AI safety and security controls. It does not constitute legal advice.

···

Questions? Contact info@caseflowautomation.co.uk