Webinar · Oct 22: Where to Put Your AI Money This Year — save your seat →
Security & Privacy

The safest analytics layer your bank has ever onboarded.

Built bank-first. SOC 2 compliant, bank-grade hosting. Rapid deployment. Designed to pass third-party risk review on Tuesday and the FFIEC IT exam on Wednesday.

The Architecture

Rapid deployment. Bank-grade security.

Perlucem runs on regulator-published data — your FFIEC call reports, public filings, and aggregated peer datasets — on SOC 2 Type II infrastructure with U.S.-only data residency. Up and running in days, not quarters.

✓

Rapid deployment

Up and running in days, not quarters. No long implementation cycle, no waiting on internal IT roadmap. Most banks are asking strategic questions inside their first week.

✓

SOC 2 compliant, bank-grade hosting

SOC 2 Type II infrastructure. Encrypted at rest and in transit. U.S.-only data residency. The same security posture your regulators already expect.

✓

No customer data ingested

No NPI, no PII, no account-level detail enters Perlucem. Period.

✓

Public regulatory data, normalized

FFIEC call reports, FDIC SDI, BHCPR, public filings — already public, already audited.

✓

Vendor risk friendly

Standard third-party risk questionnaire ready. Sub-processors disclosed. Insurance verified.

✓

FFIEC examiner ready

Built around guidance you already know — IT, BSA/AML, model risk management. Documentation ready for examiners.

✓

No model training on your data

Your queries do not train our models. Full stop. Your strategic questions stay yours.

The engagement

Our people, in your building.

Forward-deployed staff operate under your NDA and your access policies. They work on what's in the SOW and nothing else. Background checks and documentation available for your vendor-risk file on request. The findings, the roadmap, and every skill configured for your bank belong to you — in the SOW in plain language, before you sign.

Built to meet banking standards

Compliance posture your CISO will sign on.

🛡️

SOC 2

Type II

🛡️

GLBA

Compliant

🛡️

FFIEC

Aligned

Security FAQ

Answers the way a CISO would ask them.

Does Perlucem access my core banking system?

No. Perlucem runs on regulator-published data — call reports, public filings, peer datasets. Your customer PII, account balances, and transaction history never leave your environment.

Where is data processed and stored?

All processing occurs on SOC 2 Type II infrastructure with U.S.-only data residency. Encrypted at rest and in transit.

Can I get documentation for my examiners?

Yes. Vendor questionnaire, sub-processor list, SOC 2 letter, and model governance documentation — ready to send the day you ask.

How fast can a bank actually deploy Perlucem?

Days, not quarters. Because we run on public regulatory data, there's no core integration project plan and no waiting on internal IT to clear a roadmap slot.

Your engineers will be inside our operations. What are they allowed to see?

Whatever your access policy allows and the SOW requires — nothing more. Our diagnostic runs on process, architecture, and public regulatory data. It does not require access to customer records, and we don't ask for it.