---
title: "Every AI proposal dies in the security review."
url: "https://referent.app/industries/financial-services"
description: "Referent connects to core banking, policy administration and claims systems without copying data, mirroring your existing permissions. Built to clear the security review."
---

Financial Services & Insurance

# Every AI proposal dies in the security review.

Tools that train on your data, store it, or ignore your access rules never clear IT. Referent runs single-tenant, retains nothing at the model layer and mirrors the permissions your core systems already enforce. The data never leaves its system of record.

[Book a demo](/demo)[How it connects](#how-it-works)

0104How it connects

## It connects where your interface already connects.

It maps the queries, the actions and the endpoints behind the interface, then connects at that level. Nothing to rebuild, nothing to migrate.

Your team

### Questions and work, in plain language

Chat, Slack, Teams or Telegram. Ask for a number, a report, a draft or a status. No new tool to learn.

Referent

### The layer that understands your systems

Maps queries, actions and endpoints. Answers from live data with citations back to the source. Executes the work on top: pulls the numbers, builds the report, drafts the follow-up.

Your software

### Core systems that were never meant to be exposed

Policy administration, claims handling and core banking platforms built long before anyone published an API, plus the internal tools your operations team layered on top of them.

*   Core banking
*   Policy administration
*   Claims systems
*   Internal risk tools
*   Document archives

### Standard tools too

The 50+ connectors everyone advertises are included. That part is commodity. The hard systems are the point.

*   Microsoft 365
*   Google Drive
*   Slack
*   Jira
*   Salesforce

This is not RPA.

No screen reading and no bots clicking buttons. Referent connects at the data layer, so a UI change does not break it.

0204Use cases

## Four places the answer already exists but nobody can reach it.

All four run inside your permission model, on live data, with a citation attached.

01Policy questionsClaim and policy questions answered from the system of recordStatus, coverage, history and what was decided before. Referent reads the live record and cites it, so nobody works from a stale export or a colleague's memory.02File preparationFile preparation and summarisation for the people handling itPull the documents, the correspondence and the figures for a case into one place, summarised, with links back to each source. The handler reviews rather than assembles.03Recurring reportingRegulatory and internal reporting without the manual pullThe recurring reports that today require someone to query the core system, export, reconcile and format. Referent produces them on schedule from the same underlying data.04Security postureA security posture that survives the committeeSingle-tenant deployment, zero-retention model providers, no duplication of regulated data and permissions inherited from the systems themselves. The properties IT asks about first.

Live sessionPolicy administration · Claims

You: What is covered on policy POL-88214, and what has been claimed against it?

*   read policy administration · POL-88214
*   read claims · history

Referent

Cover is in force to March next year, with a €600 excess. Three claims on record, the last one closed in April.

Status

In force

Excess

€600

Claims on record

3

Last claim

Closed in April

Policy administration · POL-88214

You: Summarise it for the customer, without internal notes.

*   drafted the summary
*   excluded internal annotations

Referent

Drafted in plain language, cover and excess only. It queries as you, so a note you cannot open is a note it cannot read.

0304Deployment

## Days, not months.

There is nothing to migrate and nothing to rebuild, so the timeline is short by construction.

1.  01
    
    ### Map the system
    
    We watch how your existing app talks to the system underneath and document the queries, actions and endpoints behind it.
    
2.  02
    
    ### Connect at the data layer
    
    Referent connects directly at that level. No connector to build, no migration, no change to the software your team uses every day.
    
3.  03
    
    ### Validate with your team
    
    The people who know the process check the answers against reality. Permissions are mapped to the roles you already have.
    
4.  04
    
    ### Live
    
    Your team asks in plain language and gets answers from live data, with citations. Scope grows from there.
    

Reference deployment

### A mid-market manufacturer, on a custom ERP.

Mapped, connected and in production in under a week, on a system no AI product could reach.

System

Custom ERP

Time to production

One week

Migration required

None

0404Security

## Built to clear the security review, not to argue with it.

Most AI proposals die in IT. These are the properties that get the conversation past that point.

*   01
    
    ### Single-tenant isolation
    
    Your deployment runs in its own environment. Nothing is shared with another customer.
    
*   02
    
    ### Zero-retention models
    
    Prompts and responses are not stored by the model providers and are never used for training.
    
*   03
    
    ### Your permissions, mirrored
    
    Referent respects the access rules your systems already enforce. Nobody sees what they could not see before.
    
*   04
    
    ### No data duplication
    
    Answers are fetched from the live system at query time. We do not build a second copy of your database.
    
*   05
    
    ### GDPR
    
    European data protection requirements are part of the deployment, not an afterthought.
    
*   [
    
    Read the security detail](/security)

## See it running on a system like yours.

[Book a demo](/demo)[Sign in](https://dash.referent.app/onboarding)

## Be the first to hear about Referent news.