Skip to content
Plain-Language Privacy & Governance

Data Handling, Privacy & Model Boundaries

Clear, unambiguous answers about how information moves, what runs locally, how model endpoints are configured, and how human sign-off is enforced.

Source ControlInspectable source evidence

Material quantitative claims can be connected to source cells, pages, sections, or source records.

AuditabilityInspectable provenance records

Provenance records document model calls, source reads, and reviewer decisions for the configured deployment.

Sensitivity RoutingEngagement-scoped governance

Data handling, retention, and model routing are aligned with the executed engagement agreement.

Nine questions every investment buyer asks

1. What can be done with public or synthetic data?

Initial discovery conversations, workflow reviews, and preliminary demonstrations can be conducted using public data (e.g. SEC EDGAR filings, earnings transcripts) or synthetic mock data. No confidential firm data is required to map your process or see a demonstration.

2. When does information reach a model provider?

Information reaches a model provider during active workflow execution according to your configured endpoint settings. Data handling and model use are configured around the workflow's sensitivity. Any client-approved third-party model endpoint remains governed by that provider’s contractual and data-handling terms.

3. What can run locally versus remotely?

Depending on the configured deployment, sessions, memories, document caches, and provenance records can reside in local files on your system. Local model endpoints or private enterprise gateways can be configured where an engagement requires local execution.

4. Which tools are enabled during a workflow?

Under configured deployment profiles, only approved file access, Office document tools, evidence tracking, and review gates are enabled. Shell operations, tool execution, and cloud routing are scoped explicitly per engagement.

5. How are approved sources defined?

Before any drafting occurs, approved internal files, licensed data feeds, and public web sources are explicitly declared in a workflow specification. Unapproved sources are ignored or blocked.

6. What gets logged, and what is retained?

In configured deployments, run records capture input files, workflow versions, source links, and reviewer decisions locally. Telemetry, retention, local execution, logging, redaction, and model routing claims are scoped to the relevant configured deployment or engagement.

7. What is configured per engagement?

Data sensitivity rules, MNPI redaction, trusted data paths, model endpoint routing, and review criteria are configured around your firm's specific compliance requirements and executed engagement agreement during the sprint.

8. Who performs the final review?

A human professional (analyst, VP, or partner) always performs final review. Conviction Studio workflows generate drafts with inspectable evidence and flag unresolved items; judgment is left to the reviewer.

9. Is client work published or shared?

Client templates, internal documents, and workflow outputs remain governed by the executed engagement agreement. Model use and retention follow the engagement agreement and the selected provider’s contractual terms — not an absolute product-wide non-training guarantee.

Ready to discuss your firm's data boundaries?

We map data sources, sensitivity tiers, and review requirements before any internal material is used.