Your data does not leave your environment.
Pyligent Allocate is decision support. It runs where you put it, reads extracts you already produce, and returns a proposal a person approves. It holds no settlement rail, sends no instruction, and does not receive a copy of your book.
This page is written for security, vendor risk and model risk review. It is intended to be read on its own and filed.
Where it runs
Two options. Neither places data with us.In your cloud tenancy
A container in your own VPC or subscription, behind your network controls and your keys. Extracts are read from a bucket you own.
Data crossing the boundary: noneOn a workstation, offline
A local binary on a desk machine or an air-gapped host. No outbound network is required for a run.
Data crossing the boundary: noneUnder both options we receive no positions, no counterparty names and no identifiers. What we see is what you choose to show us in a review session.
The list of things Pyligent will not do is fixed, not a configuration.
These are properties of the software, not settings an administrator can change or a roadmap item. Each is verifiable in a review session.
Is this a model, and can you challenge it?
- classification
- Decision support. It ranks and proposes; it does not value positions, calculate margin, or execute. Where your framework still scopes it in, the evidence below is built for that review.
- method
- Deterministic linear programming by default. Constraints are cover the requirement, respect ineligibility, bind concentration limits, cap movements, hold back excluded assets.
- reproducibility
- Same inputs, same version, same result. Every run records input hashes, the version identifier, the constraints that bound the outcome, and the solver used.
- use of language models
- None on the daily path. Reading of agreement text is a separate, optional capability that cannot certify its own output and is not part of a shadow run.
- explainability
- Each proposed line names the rule that permitted it and the limit that bounded it. A rejected candidate names the constraint that excluded it.
- failure behaviour
- Abstains rather than estimating. Missing price, unknown limit scope, unstated concentration base, or an unresolved classification conflict each halt the run with a named reason.
- challenger
- Your current process is the challenger. A shadow run is scored against what your desk actually pledged, not a benchmark we chose.
- terminal states
- ReadyWarnings Human reviewAbstain
The questions a data processor answers do not apply to us.
Because no client data reaches Pyligent, the usual assessment — residency, retention, encryption at rest, deletion evidence, breach notification — has nothing to assess. That is a property of how the software is deployed, not a policy we could change without telling you.
| Item | Status | Note |
|---|---|---|
| SOC 2 Type II | Planned | We hold no client data, so the controls a SOC 2 report covers have nothing to cover here. Planned regardless, as procurement teams ask. |
| Penetration test | Completed | Summary letter available under NDA to a named reviewer. |
| Business continuity | Documented | A shadow run is not in your critical path; there is no service to restore. |
| Standard questionnaires | Answered | Completed in your own template; we do not require ours. |
Designed to meet the expectations your framework already applies.
Compliance is your institution's determination, not ours to assert. What we provide is the evidence your reviewers ask for: reproducible runs, an identified version, named constraints, an explicit failure state, and a human decision point that cannot be bypassed.
- OSFI E-23
- Model risk management, extending to third-party AI. Effective 1 May 2027.
- OSFI B-10
- Third-party risk. Options A and B materially reduce the assessed criticality.
- SR 11-7
- Documentation and challenge. Reproducibility and named constraints are built for it.
- DORA
- ICT third-party risk where the engagement is in scope for an EU entity.
Architecture diagram, data flow, deployment guide, questionnaire responses and the penetration test summary are available under NDA to a named reviewer. The control plane this runs inside is published as Pyligent Agents, with the governed-harness paper, on Pyligent Lab — so the architecture can be reviewed rather than taken on trust. What is open, and what is not →