Security
Security and transparency from the foundation.
These are the controls being built into Neo-Invest.AI, each labelled with its honest, current status.
Data minimisation
In developmentOnly the data a feature genuinely needs is collected, and retention is limited by purpose.
Encryption
In developmentEncryption in transit and at rest across services and stores.
Access control
In developmentLeast-privilege, role-based access with strong authentication for internal systems.
Vendor governance
PlannedProviders are assessed before onboarding and separated by function and data scope.
Consent
PlannedClear, revocable consent governs every data connection — nothing is connected silently.
Audit logs
PlannedAdministrative and data-access events are logged for accountability.
Incident readiness
PlannedDefined processes for detecting, containing and communicating incidents.
Responsible AI controls
In developmentGuardrails, source grounding and human review paths for AI-generated explanations.
Neo-Invest.AI does not claim any security certification (such as ISO 27001, SOC 2 or Cyber Essentials) or completed penetration testing until independently verified. Statuses above are maintained centrally and updated as controls mature.
Your data is context, never inventory.
Portfolio data exists to power your own analytics. It is not sold, not shared for marketing, and never placed in analytics events or chat logs.