ComplianceCompliance Overview

Compliance Overview

Sterling is built for financial advisors who handle sensitive client information every day. Compliance is not an afterthought. It is foundational to how the platform operates, especially when it comes to using artificial intelligence to generate advice.

AI in Financial Services

Modern financial planning benefits enormously from AI-powered analysis. Sterling uses large language models to review household data and identify opportunities that might otherwise be missed. However, using AI with client data requires careful attention to data handling and privacy.

Financial advisors face strict regulatory obligations under SEC, FINRA, and state regulations. Any technology that touches client data must meet enterprise-grade security and compliance standards. Sterling was designed with these requirements in mind.


Enterprise-Grade AI Infrastructure

Sterling processes AI requests through two enterprise platforms: Google Cloud Vertex AI and Amazon Web Services Bedrock. Which one handles a given request depends on the feature — advice generation and chat use different models — but both are enterprise services, not consumer AI products, and both provide:

  • SOC 2 Type II compliance for security and availability
  • Data encryption in transit and at rest
  • Regional data processing within the United States
  • Enterprise service agreements with strict data handling terms

Where the Models Come From

Sterling uses models from Google and Anthropic. Both are accessed through the Google Cloud and AWS platforms above under those platforms' enterprise terms — client data does not go to the model developers' own consumer services.


Your Data Is Never Used for Training

When Sterling sends client data to AI models for analysis, that data is processed and discarded. Unlike consumer AI products, enterprise AI services operate under strict contractual terms:

  • No model training: Client data is never used to train or improve AI models
  • No data retention: Submissions are deleted immediately after processing
  • No human review: Data is not reviewed by AI provider employees
  • Isolated processing: Each request is processed independently with no cross-client data exposure

Enterprise vs Consumer AI

Consumer AI products often use submitted data to improve their models. Sterling uses enterprise APIs specifically designed for regulated industries where this is prohibited.


What This Means for You

When you use Sterling to generate advice for a household, the client's financial data is:

  1. Encrypted and sent to Google Cloud or AWS secure infrastructure
  2. Processed by the AI model to generate recommendations
  3. Returned to Sterling as advice output
  4. Immediately deleted from the AI provider's systems

The AI models have no memory of previous requests. Each analysis starts fresh with no retained knowledge of your clients.

Document Your Due Diligence

Many compliance officers appreciate documentation of AI data handling practices. This page can serve as part of your firm's vendor due diligence records.

Newsletter

Insights on AI in wealth management

A short email when we publish something worth your time. Practical notes on AI, compliance, and running an advisory practice. No filler.

By subscribing you agree to receive the RK Sterling newsletter. Unsubscribe anytime.