Industries / Finance · banks & asset managers
AI protection for banks, built for Swiss banking secrecy.
Art. 47 BankG carries fines and up to three years' imprisonment for disclosing client information, and a prompt containing client-identifying data sent to a US LLM provider is a potential criminal disclosure. Here is the full compliance picture for finance, and the part we solve.
The AI governance framework for finance
Seven obligations. Here's our part, honestly.
No vendor solves a regulatory framework alone. We mark what NativeAI Guard solves for the channels we protect, where it contributes, and what stays with your processes.
Seen in Swiss banks
A user removes the Purview confidentiality label from a client file and uploads the now "public" content to an LLM. Classification-based DLP sees nothing. Auditors will.
A relationship manager drafts a client letter with ChatGPT: name, IBAN, portfolio details in the prompt. Under Art. 47 BankG, that is disclosure to a third party.
Internal automation calls OpenAI's API directly from backend code, past the browser extension, the proxy and the CASB. Client data flows through a channel with no controls at all.
Password-protected files are a blind spot. Users declassify, then upload.
Policies, managed
The rulebook for banks is already written. You adapt it instead of inventing it.
A base rulebook is already written and active from day one: the rules from the Swiss DSG, GDPR and the EU AI Act, plus the requirements your industry is specifically subject to. It covers the standard cases without you writing a single line. Security and compliance practitioners review it, and we keep it current as the law changes. On top of it sit the rules that apply only to you: your own data structures, your internal requirements, your exceptions.
During onboarding we tune the pack to your own data structures and internal rules, working from the compliance documents you already have.
Common questions
Frequently asked questions
We are moving to full rights-management classification in Purview. Can you inspect encrypted or password-protected files?
Password-protected files are covered: the upload is intercepted and the user enters the password so the content is scanned before anything leaves the company. Files encrypted with rights management, Microsoft Purview Information Protection and Azure RMS in particular, are not inspected yet. They are on the roadmap, and the work is an integration with the rights-management service itself, so that a file is decrypted for inspection under your own keys. If your bank is heading for full DRM classification, tell us during the pilot phase: a requirement that comes from a customer with a live deployment moves an item up the roadmap, and in the meantime a policy can stop these files at upload so nothing passes uninspected.
What stops someone removing a confidential label and uploading the file as "public"?
Nothing stops them removing the label, which is exactly the point. NativeAI Guard inspects the content rather than the classification state, so client-identifying data is caught whether or not the label survived. This scenario, declassify then upload, has been described to us independently by security leaders at a cantonal bank and at a Swiss financial market infrastructure, which is why it is a standard part of our demo.
Our SOC works in Sentinel. How do alerts reach us, and will single-hit detection flood us?
Events export one-way into Sentinel, so you build alert rules where you already work; we do not ask you to run our dashboard as a second console. On volume: a detection that fires on every single hit over-blocks in practice, so thresholds are configurable, including aggregation across a document rather than firing on the first match. We tune this to your specific requirements during the pilot phase.
FINMA-ready AI protection, with a pilot phase that we run for you.
A banking policy starter pack, plus a report for management on data leaks, shadow AI, AI usage and model costs. Banks need full visibility into prompts, so the full, unmasked audit trail is available to your compliance team by default.