Trust, data, and compliance

This is the most personal data in your firm.

Not account numbers. What a client is afraid of. What they haven't said out loud. What a marriage looks like from the inside when money is involved.

Firms are right to ask hard questions before letting that kind of information near an AI system. This page explains how client information is handled at each step, and what is being developed.

Four things that are true of every brief we produce.

01 · Sanitized first, and tested

Identifying and sensitive details are removed before any analysis begins, and we test that removal continuously rather than assuming it holds.

02 · Fully traceable

Every brief carries a complete internal record of what produced it, from what went in to what came out. Nothing is unexplainable after the fact.

03 · Advisors only

Nothing we produce goes to a client. Every brief goes to the advisor, and only the advisor decides what to do with it.

04 · Your client data stays yours

Your firm owns its client data. Nothing sensitive or identifiable about your clients ever enters our system.

What happens to a client's information, step by step.

  1. 1

    Client data arrives

    Meeting notes and transcripts, CRM records, questionnaire answers, and an advisor's own notes. It comes in by upload or by a connection to your systems, and only what your firm chooses to send.

  2. 2

    Personal info comes out

    Personal identifiers are removed before any analysis begins: names, account numbers, institutions, medical details, and the less obvious identifiers that turn up in CRM exports and transcripts. We test this continuously. Identifiers are deliberately included in test material, and every document that comes out is checked to confirm none remain and that nothing meaningful was lost.

  3. 3

    Signals are interpreted

    The de-identified material is interpreted against our research into how life transitions unfold, to connect what the notes show into a picture of what the client may be going through. This is where the meaning is formed, and it happens without any identifying information present.

  4. 4

    Briefs are built

    Only once that picture is formed is the brief written. Every brief passes our language and compliance rules before it reaches the advisor, opens with what it was built from and what it does not know, and carries a complete internal record for audit.

  5. 5

    Delivered to the advisor only

    The client's name is applied at delivery, and the brief goes to the advisor in the tools they already use. There is no client-facing delivery and no third-party sharing.

Most recent full privacy test · July 2026

Identifiers included in test material63
Found in any output document0
Insight quality lost0 of 52

Tested, not assumed

The risk isn't only where the data goes. It's what the brief claims about a person.

An AI that confidently states a client is anxious, grieving, or hiding something is a liability in a regulated business, and it's wrong about people more often than its confidence suggests. So we built that limit into how every brief is produced. It is a rule of the system, not a guideline someone might forget.

Every brief separates three things, and cannot be produced without doing so:

  • What is known. Drawn from what you provided.
  • What is identified. Something in the material points this way.
  • What may be worth exploring. A possibility for the advisor to validate in conversation, not a conclusion.

Language rules sit on top of that separation, so the system doesn't produce diagnosed-sounding statements about a client's emotional state. And every brief opens by naming what it was built from and what it does not know, telling the advisor what to confirm rather than assume.

The standard we hold it to: better inquiry, not false certainty. The goal is a better question, deeper understanding, and never a verdict about a person.

Indicators, questions, and cautions are possibilities to consider, not conclusions. You remain responsible for how you interpret this and guide the conversation.

Client historyexcerpt
Known
Identified
Worth exploring

Built from: two meeting notes, one intake. Unconfirmed: see "what to check first".

The boxed line is printed at the top of every brief and Deep Dive we produce.

Who owns what.

Your client data

All of it. It stays under your control and is never pooled, shared, or sold.

Our analysis and interpretations

Years of work on how life transitions unfold, applied to what your firm already knows.

Our intelligence engine improves over time by learning the patterns and feedback it encounters across different scenarios. Nothing sensitive or identifiable about your clients ever enters our system.

Built today, and what's next.

ControlStatus
Identifying details removed before any analysis, with stricter handling for CRM exports and transcriptsRunning today
A continuous privacy test that checks whether any identifier reaches a document and whether meaning is lostRunning today
Every brief keeps what is known, what is identified, and what is worth exploring apart, and cannot be produced otherwiseRunning today
Language rules preventing diagnosed-sounding claims about a clientRunning today
Complete internal audit trail behind every documentRunning today
Every brief goes to an advisor. Nothing is ever delivered to a clientRunning today
Only the data a brief needs is used, and each brief is built in its own separate workspaceRunning today
Each client is represented inside the system by a code that cannot be traced back to their name, so the system never knows who anyone isBuilt, switching on
The list that matches those codes to real names is kept outside the system and deleted once a brief is deliveredBuilt, switching on
A record of what was read and when, kept as a verifiable fingerprint rather than a copy of the contentBuilt, switching on
SOC 2 readinessIn progress
Role-based access controlsIn progress
Firm-configurable retention and deletion settingsIn progress
A formal vendor due-diligence packet, PIPEDA-aware and built for US enterprise reviewIn progress
An online questionnaire for new clients, held back until its own legal review and privacy testing are completeIn progress

If your firm needs something on these lists before you could proceed, tell us. Early access firms are shaping this roadmap, and several items are on it because a firm asked.

Advisor support, not autonomous advice.

AskGraice prepares an advisor for a conversation. It does not make recommendations to clients, does not deliver anything to clients, and does not replace professional judgment at any point. Advisors remain fully responsible for the advice they give and how they use what we provide.

We're a Canadian company serving firms across North America. We build to Canadian privacy expectations and US enterprise requirements at the same time, so neither is an afterthought.

Meeting Briefpage 2 of 2
What to avoid, and why
AskGraice is an advisor preparation tool. It is not financial advice, therapy, or client-facing guidance. Advisors remain responsible for how they interpret and apply it.

For the advisor, not shared with the client

Questions about security, privacy, or compliance?

If you are responsible for security, privacy, or compliance at your firm, we would rather answer your questions before early access than after. Send them to us. We will answer directly, including where the answer is "not yet."