Security and governance
Controls that begin before the model ships.
Deployment, access, data boundaries, validation, evidence, release governance, and operations are defined into the delivery scope.
Control model
Private by default. Auditable by design.
FiboRisk does not claim a control or certification that has not been contractually defined and independently established. The public website describes the delivery model; the executed SOW controls the customer environment.
Provision a dedicated tenant or agreed private deployment with separated environments, controlled connectivity, and responsibilities defined in the SOW.
- No public self-service production accounts
- Environment and connectivity boundaries
- Customer-specific service responsibilities
Keep approved customer data within the agreed deployment and retention boundary, with access, transfer, encryption, and deletion requirements defined before delivery.
- Approved sources and processing purpose
- Encryption and retention requirements
- Controlled export and deletion paths
Customer administrators invite named authorized employees and manage roles aligned to development, validation, approval, operation, and audit responsibilities.
- Enterprise identity integration
- Least-privilege roles
- Separation of duties and administrator control
Retain the source, feature, model, scenario, policy, decision, action, override, reviewer, approval, and applicable version as one inspectable chain.
- Versioned evidence objects
- Exportable acceptance records
- Change, incident, and release history
Model documentation
Purpose, scope, assumptions, limitations, data, features, methods, intended use, and excluded use.
Validation evidence
Performance, stability, sensitivity, drift, bias, explainability, limitations, and challenger results.
Control evidence
Access, environments, approvals, changes, monitoring, overrides, incidents, and operational ownership.