R
RegNexusGenesis

Security & Trust

Regulatory work requires controlled infrastructure.

Genesis holds the facts, evidence, documents and financials behind an FCA application. That work demands infrastructure that is controlled, separated and auditable — with AI used deliberately and under human review.

Security principles

How we think about protecting regulatory work.

These are the principles we design and operate to. They are practices and controls, not certifications — we do not claim standards we have not been independently certified against.

Security is a design constraint, not a feature added after the fact.
Every institution's data is separated from every other institution's data.
Access is granted on least privilege and removed when it is no longer needed.
Actions that matter leave a durable, reviewable record.
Regulatory determinations remain traceable to the facts and logic behind them.
AI assists people; it does not replace the judgement of accountable individuals.

Trust pillars

The capabilities that carry the trust.

Each pillar reflects a capability that genuinely exists in the platform — not an aspiration and not a claim we cannot stand behind.

Controlled access
Tenant separation
Encryption
Audit trails
Version history
Evidence provenance
Human approval controls
Secure document generation
Data retention controls
Business continuity

Controls and practices

Encryption, access, isolation, audit and recovery.

The operational controls that protect the institutional record Genesis builds — from the day a firm starts an assessment to the day it operates under authorisation.

Data encryption

Data is encrypted in transit and at rest using industry-standard protocols. Encryption keys are managed by the underlying platform providers with rotation.

Access control

Role-based access on least-privilege principles. Administrative access is limited, logged and reviewed. Authentication is passwordless by default.

Tenant isolation

Each institution operates within an isolated tenant boundary. Data separation is enforced at the database level so cross-tenant access is not structurally possible.

Audit trails

Access, governance actions and administrative operations are logged with user, timestamp and action context so activity can be reconstructed and reviewed.

Version control

Regulatory outputs and their underlying facts carry version history, so changes are attributable and earlier states can be recovered.

Backup and recovery

Platform data is backed up on a managed schedule with recovery procedures, supporting continuity of the institution being built.

Secure development

Security is integrated into the development lifecycle — code review, dependency scanning and pre-deployment checks before changes reach production.

Incident management

Documented incident procedures with severity levels, escalation paths and post-incident review, so issues are contained and learned from.

AI and data use

Genesis uses AI deliberately, and is explicit about where and how.

We distinguish the parts of the platform that calculate deterministically from the parts that generate assistance, because a regulated firm needs to know which outputs are computed and which are drafted for review.

  • Client data is not used to train models. Your regulatory data is not represented as training data unless it is contractually and technically true.
  • Where AI is used, we disclose it. Generative assistance is labelled and separated from deterministic calculation.
  • Deterministic calculations — route rules, capital and validation gates — are computed, reproducible and traceable, not generated.
  • Human review is required. Accountable individuals review and approve regulatory outputs before they are relied upon or submitted.
  • Model providers are disclosed where required, and the sub-processors supporting AI features are listed on request.

Data handling

Location, sub-processors, retention and deletion.

Where regulatory data lives, who processes it on our behalf, and how long it is kept.

Data location

Platform data is hosted with established infrastructure providers in the United Kingdom and European region. Specific hosting locations can be confirmed on request.

Sub-processors

Genesis relies on a small set of infrastructure sub-processors for hosting, authentication and email delivery. A current sub-processor list is available on request.

Retention and deletion

Data is retained for the life of the engagement and defined periods thereafter. On request, and subject to legal obligations, data can be exported and deleted.

Data protection

Data is handled in line with UK GDPR. RegNexus Limited acts as data controller for the platform. Data processing agreements are available on request.

Responsible disclosure

Reporting a security concern.

We welcome responsible disclosure. If you believe you have found a security issue, please contact us before disclosing it publicly so we can investigate and remediate.

Security contact

Send disclosures, sub-processor requests and data protection enquiries to info@reg-nexus.com. We aim to acknowledge reports promptly and keep reporters informed.

RegNexus Limited provides regulatory operating infrastructure. Genesis supports the preparation and operation of regulated firms; it does not guarantee authorisation and is not a substitute for the professional judgement of the firm and its advisers. The controls described here are our security principles and practices — they are not, and are not presented as, formal certifications.

Build regulatory work on controlled infrastructure.

Start a Genesis assessment, or see how Genesis protects the institutional record it builds in a live demonstration.