Security & architecture

    The Due Diligence Platform is architected to the procurement standards applied across UK and international financial services. Each capability has been independently exercised across live tier-1 deployments, without remediation.

    Certifications

    ISO 27001
    Information security management
    ISO 9001
    Quality management
    ISO 42001
    AI management system
    CREST
    Annual independent penetration testing
    Cyber Essentials
    Certified

    ICO registered · DPO appointed · ROPA maintained · DPIA regime in place. All certificates held by the operating entity, Agora Consulting Solutions Limited.

    The diligence, pre-answered

    Eight questions taken from the supplier vendor due-diligence pack on file with the existing customer. The answers are verbatim.

    01 / Hosting

    Where is data hosted? Does it leave the UK?

    UK cloud region-pinned. Compute, databases, storage and backups, all in-region. Perimeter WAF/DDoS infrastructure in front.

    02 / Isolation

    How are customers isolated?

    Single-tenancy. Dedicated schemas, storage and access controls per client. Cross-client access is structurally prevented.

    03 / Encryption

    What encryption is in place?

    AES-256 at rest via managed key infrastructure (HSM-backed). Field-level encryption on PII. TLS 1.2+ in transit.

    04 / AI governance

    Where is AI used and how is it controlled?

    A UK-processed AI inference layer. Used for NoB inference, AI SME (RAG), PDF and document extraction, and transaction outreach. Training-set use is contractually prohibited. Outputs are confidence-scored; low confidence auto-escalates to human review.

    05 / Audit logging

    What audit logging is captured?

    Every case event, authentication, admin action, data access, QC review, verification and batch operation - with actor, timestamp and before/after. Exportable as JSON, CSV or XML.

    06 / Service level

    SLAs and recovery?

    99.9% availability. RTO 8 hours, RPO 4 hours. BCP/DRP tested annually; restoration documented quarterly.

    07 / Audit rights

    Right to audit Agora?

    Yes. Contractual right. Direct or third-party. Full ISMS on request.

    08 / Exit strategy

    Exit strategy?

    CSV / XML / JSON via SFTP. Schema documented. Keys rotated, revoked and deletion certified. Transition support included.

    Full ISMS and certificates available on request - email enquiries@agoraconsulting.ai

    Regulatory scope

    Mapped to the Money Laundering Regulations 2017 (as amended), the FCA Handbook, JMLSG Guidance and the UK GDPR. The in-platform AI SME module is RAG-trained on the same corpus, so every analyst decision can be cited back to the regulator paragraph that supports it.

    Get in touch

    Most engagements start with a 20-minute scoping call to understand your requirements and where we can help.