Security & data handling

How we handle your firm's data.

A direct answer for RIAs and law firms bound by fiduciary and confidentiality duty — before you share anything with us.

What we ask for, and why.

The Workflow Diagnostic and the Operational Intelligence Assessment ask about how a workflow runs — volumes, exception patterns, tooling, decision points. We do not require access to your client records, case files, or underlying systems to complete either engagement. Where a deeper Assessment benefits from sample documents or workflow traces, scope is agreed in writing first, and anything shared is limited to what that specific engagement needs.

Confidentiality.

Every engagement is covered by a mutual NDA before any workflow detail, sample data, or system access changes hands. Client identities, workflow specifics, and any materials reviewed are never referenced publicly, in case studies, or in published Insights content without separate written permission.

Where the model sits.

Our methodology draws an explicit determinism boundary in every system we design: verifiable, auditable logic handles anything that must be correct; a language model is used only where its output is reviewed by a human or is otherwise recoverable. That boundary — and where your data crosses it, if at all — is documented as a deliverable of the Assessment, not left implicit. See the Determinism Boundary essay.

Vendor posture.

We don't operate our own model infrastructure or store client data on our own servers as a default. Recommended architectures route through your firm's existing compliance-approved vendors and cloud environment wherever one exists, rather than introducing a new data custodian. Any exception to that is called out explicitly in the deliverable, with rationale.

Solo-operator continuity.

Rios Applied AI is disclosed as a solo operation. What happens to your systems, documentation, and data if Richard becomes unavailable is answered directly, not glossed over — see the continuity statement.

If your firm has specific security or compliance requirements — a vendor questionnaire, an infosec review, a due-diligence checklist — bring it before you sign anything. We'll answer directly. Start a conversation →

Bring your security questions before you sign.

A vendor questionnaire, an infosec review, a specific compliance requirement — ask directly.