The typical client
FINMA-licensed banks (license under Art. 1a Banking Act), FinTech licensees under Art. 1b Banking Act, asset managers and securities dealers. SG or SG-branch structures with MAS equivalence. Also cantonal banks with a hard data-sovereignty mandate.
AML triage with an audit chain
First review of transaction alerts by agentic pipelines. Every triage decision — escalate as suspicion, let subside, escalate — is Ed25519-signed and stored chained with the model version hash and the policy version hash. The audit trail is tamper-evident and immediately available to the compliance function.
Regulatory reporting pipelines with reproducibility
A generated regulatory report (FINMA, ESMA mirror via SIX-SDX) can be deterministically regenerated from the source snapshot, the pipeline version hash and the report template. When the regulator asks in two years how a particular report came about, there is an answer — not a "that's how we calculated it back then" guess.
Data room on Swiss soil
Operational data center in Switzerland or in an EU data center (Helsinki). No connection to US cloud APIs in the data plane. Identity, access logs and cryptographic keys do not leave the country.
AMLA- and FADP-compliant data flows
A data card per pipeline with processing purpose, retention period, legal basis. Machine-readable, checked in the PR diff.
Evidence from practice
A banking engagement example will follow — with the customer's approval. Architecture sketch for an AML triage pipeline discussed with FINMA, Q4 2025.
What we do not do
We are not licensing consultants. We do not deliver reg-mapping tables for FINMA Circular XYZ.YYYY. We do not deliver a KYC software license. We deliver the substrate on which your AML and regulatory reporting functions work with agentic support — and which stands up to the regulator.