Alpheous·
Platform Overview

Security, Compliance, and Governance

This page explains how Alpheous keeps the work it does for your firm inside your rules. It covers where your data lives and what leaves the appliance, the compliance check an outbound draft passes before a person sees it, who owns those rules, how an accountable person approves outbound before it goes, and how the product's actions are recorded for later examination.

The short version: the agents prepare the work, your rules decide what is allowed, and a person always has the final say. Nothing skips that path.

:::info Why This Matters Your Chief Compliance Officer and your operations leaders need to know that an AI team cannot put something in front of an advisor, an LP, or a prospect that breaks a rule, and that anything it did can be reviewed afterward. Alpheous is built so the answer to both questions is yes, on the product's own terms. :::

Where Your Data Lives and What Leaves It

Alpheous runs on an appliance in a facility your firm controls, on your network and behind your firewall. The model providers and most of the services it depends on run on accounts in your firm's name and on your firm's billing, so you can see the usage, set the limits, and revoke a key without asking anyone.

Model calls go to the model provider under your firm's own agreement with that provider, whose API terms do not permit training on submitted content. A firm whose policy requires certainty on that point should confirm it against that agreement. Alpheous does not train or fine-tune models on your content.

Data leaves the appliance in three ways, and only these:

  • Model calls carry the prompt and the context that call needs, not your database.
  • Backups are encrypted on the appliance before upload and stored in a bucket in your firm's name.
  • Named sub-processors receive the data listed against them on the sub-processor list. A small number are contracted by Alpheous on your behalf rather than in your name, and the list says which.

The platform never emails or calls an advisor, an LP, or a prospect on its own. Outbound email and outbound calling each have a switch that ships off, and a setting that is missing or cannot be read counts as off. Correspondence is written into your own drafts for a person to send. The email Alpheous does send is internal: notices to your own staff, such as the daily brief and meeting prep.

Compliance Comes Before You See a Draft

Every agent follows the watch, draft, approve model: it does the work and posts a draft back to you. What sits between "draft" and "you see it" is a compliance check. Before any outbound draft reaches your screen, it runs against your firm's rules, and the system rewrites it automatically where it can.

What happens to a draft that still has not cleared depends on how it was asked for:

  • Drafting emails for a Work Queue card. Only a draft that passes the check is written to your drafts folder. One that fails is not written at all: the result tells you how many advisors were skipped because their draft did not pass the compliance check, alongside any skipped for other reasons.
  • An agent's own outreach and follow-up drafts. After the automatic rewrite attempts, a draft that still carries a rule hit reaches your review flagged, with the specific rule hits attached, so you can see exactly why. A draft the check rejects outright is never written to your drafts.

This means the drafts you review have either cleared the bar your compliance team set or tell you exactly where they did not. Your judgment goes to the things that need judgment: tone, fit, timing, whether the message is right for the relationship, and any flagged rule hit.

The check applies to outbound correspondence and content: an email to a wholesaler, a follow-up to an advisor, the brief behind an outbound call, and marketing content before it publishes.

Your Compliance Team Owns the Rules

The rules are not buried in the product. They are configuration that your compliance team owns and can change. Required disclosures, restricted claims, the language your firm must include or must avoid, the categories that need extra review: these live as data, not as something hardcoded that only an engineer can touch.

When your firm's obligations change, your compliance team updates the rules and every agent picks up the change. There is no waiting for a release. The same set of rules governs all the agents at once, so distribution, intelligence, and operations work all answer to one policy rather than each agent having its own.

For how an operator and a compliance reviewer manage these rules day to day, see the operator-side governance pages.

A Person Always Approves Before Anything Goes Out

Nothing an agent prepares sends on its own. Every outbound artifact stops at an explicit approval step, separate from the drafting, with a named person accountable for releasing it. The product fails closed: if the approval and notification checks cannot confirm who is signing off, nothing sends.

The guarantee runs deeper than the approval step itself. Every outbound channel, email, voice calling, text, physical mail, personalized video, and gift, carries its own send switch, and every one of them ships off by default. A channel only transmits once your firm has explicitly turned it on; until then, the platform cannot send through it no matter what an agent drafts. LinkedIn has no automated send path at all, on or off: sending a LinkedIn message is always a person copying an approved draft into their own account.

Separation of duties is enforced, not just expected: a release is denied when the approver is the same identity that originated the work, so a person cannot sign off on their own. The control is fail-closed (an approval that cannot resolve an accountable approver is denied, and a release carrying no readable value is treated as in scope rather than waved through) and the threshold and scope are part of the governance configuration your compliance team owns, adjustable per firm. Each release is its own gated, attributed action with its own audit record, including a recorded denial when separation of duties blocks a release, so who asked for a piece of work and who signed off on it leaving the building are recorded distinctly and reviewable after the fact.

The check covers the two channels that release work automatically: email, where the originator is whoever the message sends as, and voice calling, where the originator is whoever put the call in the queue. The two are governed separately, so your compliance team can run four-eyes on one and not the other, and each can be adjusted per firm.

Voice is the channel where it matters most, and it is worth knowing why. An approved email draft lands in a person's own drafts and still needs a second deliberate act before it leaves. An approved call dials. The gap between approval and the advisor's phone ringing is where a self-approval has the most consequence, so the check runs before the call is released rather than after.

On the remaining outbound channels (text, physical mail, personalized video, and gift) a person still has to release the work, that channel's own send switch still has to be on, and every release is still attributed and audited the same way, but the check that the approver differs from the originator is not applied for you.

Every Action the Product Takes Is Logged

Everything the product does to client data, communications, and decisions is recorded: who or what acted, what changed, and when. A draft created, the compliance verdict on it, the rule that flagged it, the approval, the write into your drafts folder: each step is part of an examinable chain.

That chain is what lets you reconstruct, after the fact, how a given draft came to exist, what the check said about it, and who stood behind it. When an examiner, an auditor, or your own compliance review asks what happened on a particular communication, the record is there to answer. Nothing the agents do happens off the books.

One step sits outside it. With outbound sending switched off, which is how Alpheous ships, an approved email is sent by a person from their own mail client, and Alpheous does not see or log that send. Your email system, and the archive your firm keeps of it, is the record of what actually went out and when.

:::tip For the Operator The audit record and the rule configuration both surface on the operator console. If you run compliance or operations for your firm, that is where you set the rules, watch what the agents are doing, and pull the history when you need it. :::

How This Shows Up in Daily Work

You do not have to think about any of this to get value from it. You ask an agent for something, you get back a draft that has been checked against your firm's rules, you approve or edit it, and you send it with a clean record of how it was made. The controls run underneath the watch, draft, approve rhythm described in Getting Started.

The same model holds for every agent on the roster, whether it is the Signal Outreach agent drafting advisor outreach or the Meeting Assistant preparing a follow-up after a call. Outbound is gated, rules are applied, and the action chain is recorded, every time.

  • Getting Started: the watch, draft, approve model these controls sit inside.
  • Signal Outreach: an agent whose outbound passes the compliance check before you review it.
  • Regulatory Digest: how the product keeps the regulatory record in front of your compliance team.