Skip to content
Plain-Language Privacy & Governance

Data Handling, Privacy & Model Boundaries

Clear, unambiguous answers about how information moves, what runs locally, how model endpoints are configured, and how human sign-off is enforced.

Source ControlSources you can inspect

Every quantitative figure connects directly to cell coordinates or source document pages.

AuditabilityTamper-evident review records

Hash-chained audit records document every model call, source read, and reviewer override.

Sensitivity RoutingConfigured around sensitivity

Data handling and model selection are tailored to the sensitivity of each workflow.

Nine questions every investment buyer asks

1. What can be done with public or synthetic data?

Initial discovery conversations, workflow reviews, and preliminary demonstrations can be conducted using public data (e.g. SEC EDGAR filings, earnings transcripts) or synthetic mock data. No confidential firm data is required to map your process or see a demonstration.

2. When does information reach a model provider?

Information reaches a model provider only during active workflow execution. Quiver does not bake in a default model endpoint; the operator configures an OpenAI-compatible endpoint. When a cloud endpoint is used, file content and prompt text sent in a turn reach that provider.

3. What can run locally versus remotely?

Sessions, memories, document caches, and tamper-evident audit logs live in local files on your system. Local model endpoints (e.g. Ollama or local gateways) can be configured where an engagement requires zero remote model transmission.

4. Which tools are enabled during a workflow?

Under the hardened finance-client deployment profile, only approved file access, Office document tools, evidence tracking, and review gates are enabled. Arbitrary shell operations, runtime tool creation, and background cloud sync are disabled by default.

5. How are approved sources defined?

Before any drafting occurs, approved internal files, licensed data feeds, and public web sources are explicitly declared in a workflow specification (workflow.yaml). Unapproved sources are ignored or blocked.

6. What gets logged, and what is retained?

A local, tamper-evident audit record captures the input files, workflow version, source links, and reviewer decisions for every run. There is no telemetry, background analytics tracking, or central data collection.

7. What is configured per engagement?

Data sensitivity rules, MNPI redaction, trusted data paths, model endpoint routing, and review criteria are configured around your firm's specific compliance requirements during the sprint.

8. Who performs the final review?

A human professional (analyst, VP, or partner) always performs final review. Quiver generates drafts with inspectable evidence and flags unresolved items; it does not make autonomous investment decisions.

9. Is client work published or shared?

Never. Client templates, internal documents, and workflow outputs remain the exclusive property of your firm and are never published, shared, or used to train third-party models.

Ready to discuss your firm's data boundaries?

We map data sources, sensitivity tiers, and review requirements before any internal material is used.