Skip to content
Ripple Treasury Brings Industry’s First Governed AI for Enterprise Treasury

AI Security and Compliance

GSmart AI Security and Compliance Information

AI is a powerful amplifier of value for CFOs and Treasury teams. This power comes with great responsibility. So, trust in AI used must be earned. At Ripple Treasury, we believe transparency is the best first step to take in earning that trust.

How GSmart protects your data

Agentic AI

Agentic capabilities in GSmart are securely constrained within customer-defined boundaries. Agents interact solely with customer-specific, isolated datasets and do not utilize or train on information from other clients. Each agent operates under stringent permission sets, with comprehensive auditability, and system-defined security guardrails, empowering users to innovate safely and confidently without sacrificing data privacy or control.

Security testing

GSmart employs rigorous, multi-layered security testing integrated into Ripple Treasury’s CI/CD pipelines. This includes proactive “red team” testing against carefully curated golden datasets — validating inputs and outputs of prompts, comprehensive static and dynamic security scans on all code, and systematic benchmarking of AI models for vulnerabilities, compliance, and performance.

Risk classification

Active evaluation of AI use cases against the EU AI Act framework to ensure compliance and maintain low-risk classification.

Data usage for AI

Same idea, but enforced with Inference-Only AI policies, supported by audit logs and verification mechanisms.

Client control over AI

Clients have full control over AI capabilities through feature flags and can restrict which datasets are accessible for AI processing.

Explainability

No Black Box AI. All AI outputs are fully traceable to their originating data, with transparent reasoning steps and justifications included for every insight generated. Each customer’s data and context are processed in isolation, ensuring insights are explainable and auditable — never mixed across clients. Detailed observability is maintained for every AI interaction, so you always know how and why each decision is made.

Encryption

All data is encrypted using advanced cryptographic standards. Data in transit is secured via TLS 1.2+ protocols, employing modern cipher suites such as AES-GCM, ECDHE, and SHA-384 hashing algorithms. Data at rest utilizes AES-256 encryption, with key management rigorously controlled and regularly rotated per Azure’s enterprise-grade standards. Our encryption practices fully align with SWIFT Customer Security Controls Framework (CSCF).

Auditability & observability

Full auditability, every AI interaction is logged with a unique trace_id and captured by our observability platform, giving complete visibility into every prompt, response, and decision. Observability data is protected by the same encryption and access controls as the rest of the platform.

Data privacy & residency

AI is now available in every region of the platform, so storage and AI processing follow your business operating needs. Client data is encrypted in transit and at rest, stays in your selected region, and is never used to train models.

Zero Trust Security

GSmart employs a comprehensive Zero Trust Security Architecture, anchored by Azure Managed Identity. This approach eliminates risks from hardcoded credentials and enforces strict role-based access controls (RBAC). All resources and interactions are continuously authenticated and validated. This principle of least privilege ensures is used to cause systems to have only the minimum access necessary, significantly reducing the attack surface and enhancing security resilience. All interactions are meticulously logged and monitored, enabling swift detection and response to any anomalies or unauthorized access attempts.

See Ripple Treasury in action

Get connected with supportive experts, comprehensive solutions and untapped possibility today.