Industries / Finance · banks & asset managers
AI protection for banks, built for Swiss banking secrecy.
Art. 47 BankG carries up to three years' imprisonment for disclosing client information. Client-identifying data sent to a US LLM provider is a potential criminal disclosure.
See it in action
Omnichannel protection, across all devices.
ChatGPT, Claude, Gemini, Copilot, DeepL and whatever your employees try next week: the same policies, anonymization and audit trail on the work laptop and the work phone.
See scenarios →Draft a letter to Herr Steiner, IBAN CH93 0076 2011 6238 5295 7, confirming the rebalancing of portfolio 4471-0923.
Draft a letter to <PERSON>, IBAN <IBAN>, confirming the rebalancing of portfolio <ACCOUNT>.
Here is the customer list:
Q3_Kundenliste.xlsx (2,400 rows)
NativeAI Guard, BLOCKED: Blocked attachment: Q3_Kundenliste.xlsx. Blocked by policy: Customer Data Leakage Prevention.
The AI governance framework for finance
Seven obligations. Here's our part, honestly.
No vendor solves a regulatory framework alone. We mark what NativeAI Guard solves for the channels we protect, where it contributes, and what stays with your processes.
Seen in Swiss banks
A user removes the Purview confidentiality label from a client file and uploads the now "public" content to an LLM. Classification-based DLP sees nothing. Auditors will.
A relationship manager drafts a client letter with ChatGPT: name, IBAN, portfolio details in the prompt. Under Art. 47 BankG, that is disclosure to a third party.
Internal automation calls OpenAI's API directly from backend code, past the browser extension, the proxy and the CASB. Client data flows through a channel with no controls at all.
Password-protected files are a blind spot. Users declassify, then upload.
Policies, managed
The rulebook for banks is already written. You adapt it.
Swiss DSG, GDPR and EU AI Act, plus your industry's specific duties. Security and compliance practitioners review it; we keep it current as the law changes.
During onboarding we tune the pack to your own data structures and internal rules, working from the compliance documents you already have.
Common questions
Frequently asked questions
We are moving to full rights-management classification in Purview. Can you inspect encrypted or password-protected files?
Password-protected files are covered: the upload is intercepted and the user enters the password, so the content is scanned before anything leaves the bank. Files encrypted with rights management (Microsoft Purview Information Protection, Azure RMS) are not inspected yet; the planned integration decrypts them for inspection under your own keys. If you are heading for full DRM classification, tell us during the pilot phase, and in the meantime a policy can stop these files at upload, so nothing passes uninspected.
What stops someone removing a confidential label and uploading the file as "public"?
Nothing stops them removing the label, which is exactly the point. NativeAI Guard inspects the content rather than the classification state, so client-identifying data is caught whether or not the label survived. This scenario, declassify then upload, has been described to us independently by security leaders at a cantonal bank and at a Swiss financial market infrastructure, which is why it is a standard part of our demo.
Our SOC works in Sentinel. How do alerts reach us, and will single-hit detection flood us?
Events export one-way into Sentinel, so you build alert rules where you already work; we do not ask you to run our dashboard as a second console. On volume: a detection that fires on every single hit over-blocks in practice, so thresholds are configurable, including aggregation across a document rather than firing on the first match. We tune this to your specific requirements during the pilot phase.
FINMA-ready AI protection.
A pilot phase, run by us: a banking policy starter pack plus a report on data leaks, shadow AI, usage and costs. The unmasked audit trail is available to compliance by default.

