Trust is not a feature.
It's the foundation.
qalitAI is purpose-built for regulated financial institutions. Every architectural decision, from data handling to model governance, is designed with compliance and auditability at its core.
Vanta Trust Center
Our compliance posture is continuously monitored and independently verified through Vanta. Review our full security documentation, active controls, and audit reports in real time.
View Trust Center ↗Regulatory Standing
qalitAI is deterministic. It applies arithmetic and classification rules to directly observed bank transactions and returns measured facts. It produces no estimate, no probability, and no inference. That single architectural choice is the reason qalitAI sits outside the regulatory frameworks that govern AI in financial services, and it is why the institutions that use qalitAI carry no added compliance burden.
On April 17, 2026, the Federal Reserve, OCC, and FDIC issued SR 26-2, the first revision to United States model risk management guidance in fifteen years. Under SR 26-2, a tool is a model only when it uses quantitative or statistical methods, produces outputs used in consequential decisions, and those outputs involve uncertainty or rely on inputs that are not directly observed. qalitAI meets none of the three. Every figure it returns is the direct arithmetic result of an observed transaction, traceable to its source. qalitAI's deterministic data work is carved out of SR 26-2's model scope. There is no tier for it under the risk-based framework, because it is not a model at all, and there is no model validation or model governance requirement for the institutions that rely on it.
The same line holds in Europe. The European Union AI Act directs its scrutiny, its risk tiers, and its obligations at AI systems that infer, predict, or generate. Deterministic, rule-based computation on directly observed data is not that. qalitAI's method falls outside the risk-tiered obligations the Act places on AI systems, for the same reason it falls outside SR 26-2: it does not infer, it measures. Two of the most significant financial-AI regulatory regimes in the world draw the same line, and qalitAI is on the safe side of both.
This is the forward position, not a backward one. As institutions adopt AI under guidance that is still taking shape, the quality, explainability, and traceability of the underlying data matter more than ever. qalitAI is the deterministic data foundation that work is built on. Every output can be traced to source and explained to an underwriter, a property manager, or an examiner, without a black box in between.
Deleting a completed analysis
When you complete a verification, we mint a deletion link and show it to you exactly once, on the completion screen. That link belongs to you alone. Showing it a single time is itself a security measure: because we never display it again and never keep a copy, the only copy in existence is the one in your hands, and there is nothing on our side for an intruder to steal, an email to expose, or a support request to trick out of us. We store only a one-way fingerprint of it, which lets us recognize your link when you present it but can never be turned back into the link itself.
This design has a consequence we chose deliberately: we cannot tell which analysis belongs to which person. We do not hold the information that would connect them. The GDPR anticipates this posture in Article 11, which addresses organizations that do not require identification of the individuals whose data they process. Holding your deletion link is what establishes your standing to delete, and nothing else is required of you.
Deletion happens at qalitai.com, on the same site where you completed your verification, at the deletion page your link takes you to. It is not performed through the client portal, and the business that requested your verification cannot trigger it or reverse it. The deletion page asks you for one explicit confirmation, and nothing is removed until you give it. Once you confirm, the deletion is permanent and applies to that single analysis.
One honest boundary. Deletion removes the analysis from our systems. If a report was already delivered to the business that requested your verification, that delivered copy is in their possession and beyond our reach. What we hold, we delete. What has left our hands, we cannot recall, and we will not pretend otherwise.