Skip to main content
For risk and procurement teams

Answers for your risk review.

Reviews at banks and wirehouses ask the same questions in roughly the same order. Here are the short answers. The full engagement briefing, written for legal, risk, compliance, privacy and information security reviewers, is available on request.

Engagement

How it's structured

Who you contract with
Blue Eye Consulting LLC, a Florida limited liability company operating as BlueEye Advisory, in a consulting capacity, under a master services agreement and statement of work. Where your firm already has an approved vendor we work alongside, we can contract through that relationship instead.
What BlueEye does
Scenario and scorecard design, coaching design, manager enablement, reporting and program management. People do the work. AI is a tool inside it, not the service itself.
Platforms
Where an AI practice platform is used, it's a third-party tool, named in the engagement briefing. We tell you up front about any referral or reseller relationship with a platform we recommend, before anything is signed.
Human review
Scenarios and scorecards are defined by your firm and reviewed by people. The AI doesn't make customer-facing decisions.
Data

What the engagement touches

In scope
Participant rosters (name and business email), hypothetical practice scenarios, employees' practice conversations and the scores on them, and aggregate reporting.
Out of scope
No customer or consumer data. No account-level financial information. No CRM or custodial integration. In the reviews we've been through, practice activity hasn't been treated as a books-and-records event.
Voice
Zero data retention for voice is the default for financial services deployments. Transcripts and scorecards are the only persisted artifacts.
Model training
Your data isn't used to train or fine-tune any AI model. The platform reaches its models through enterprise cloud services with training disabled, and the briefing lists each model provider.
Hosting
US public cloud, US regions only. Encryption is TLS 1.2 or higher in transit and AES-256 at rest.
Assurance

Who holds what

BlueEye is a consulting firm, not a software vendor, so the platform certifications belong to the platform. We name it in the briefing so your third-party risk team can verify it directly.

SOC 2 Type II
Held by the AI practice platform we deploy. Report available under NDA.
ISO/IEC 27001:2022
Held by the platform. Certificate valid to June 2028.
GDPR and HIPAA
The platform offers a data processing addendum for EU and UK personal data and maintains HIPAA-aligned safeguards. Our financial services engagements involve no health information.
BlueEye insurance
Professional liability (errors and omissions) and general liability coverage in force. Certificates on request.
Subprocessors
A current subprocessor inventory for the platform, with what each one does and where it runs, is included in the briefing.
Available on request

Documents we can share

The engagement briefing, which covers the questions reviews ask in the order they ask them. Under NDA, we can also share the platform's SOC 2 Type II report, its ISO certificate, its security questionnaire, its subprocessor table, its data processing addendum, its responsible AI use policy, and our certificates of insurance.

We can also set up a working session between your information security team and the platform's head of security.