Security & Governance | Built AI

Built for capital that has to be defended.

Institutional real estate runs on money that answers to someone else: limited partners, investment committees, auditors, regulators, lenders. Software that touches that money has to be defensible to all of them. Built AI is engineered to be more auditable, more isolated, and more accountable than the analyst-and-spreadsheet process it replaces, not less.

Multi- or single-tenant · No model training on your data · SOC 2 Type II (in progress) · GDPR-aligned

Verify our posture in real time.

Our controls are continuously monitored and published to a hosted Trust Center. Certification status is shown live, and our security policies, control evidence, and audit reports are available to your team on request under NDA. Personnel and vendor specifics are kept private.

100% Auditable outputs

0 Autonomous external actions

In progress

Your choice

Multi- or single-tenant, self-host or on-prem

At a glance

The black-box problem, and our answer.

Models whose reasoning cannot be reconstructed are disqualified from regulated capital. Our answer is to be more auditable than the analyst-and-Excel flow we replace.

EY named the obstacle that keeps most AI out of regulated finance the "black-box problem": models whose reasoning cannot be reconstructed or audited are disqualified from any process where capital is held in trust. For institutional real estate, that is the line between software you can deploy and software you cannot.

Most AI tools fail this test by construction. They generate plausible answers from a probabilistic model and present the output without a verifiable chain back to the underlying facts. The number looks right, but no one can prove it, and "the model said so" is not an answer a fiduciary can give. That is precisely the property that makes a tool unusable for an asset manager reporting NOI to an LP, a controller signing off on a distribution waterfall, or a GP whose underwriting will be re-examined years later in diligence.

Built AI is designed the opposite way. The platform is deterministic by design: every number it produces traces to a specific source, every computation it performs is reproducible, and every agent run can be replayed step by step. When the system reports that a property is running 4.2% under budget on operating expenses, you can click that figure and follow it back through the calculation to the line items, and from those line items to the source documents they were extracted from. Nothing is asserted. Everything is shown.

Two ways to produce a number

Black-box model vs Deterministic by design

Black-box model

Deterministic by design

The reasoning is not hidden inside model weights. It is laid out as a lineage you can audit, the same way you would audit a workpaper.

What this means for you

If you are the InfoSec lead or the controller who has to put your name on what the system produces: you are never asked to trust an unexplained output. Every figure carries its provenance. When diligence, an audit, or an IC challenge arrives, you reconstruct exactly how each number was reached in seconds, not by re-deriving it by hand.


Your data stays yours. As architecture, not a promise.

Whichever way you deploy, your data stays inside your boundary and is never training data.

The most important sentence on this page is this: your data never leaves your tenant, and it is never used to train any model, ours or anyone else's. We want to be clear about why that is a statement about how the system is built rather than a line in a policy document you have to take on faith.

Built AI runs multi- or single-tenant, whichever your mandate calls for. In the managed multi-tenant deployment, isolation is enforced with per-tenant encryption, scoped credentials, and continuously tested access controls. When your mandate requires infrastructure-level isolation, the single-tenant deployment gives your firm its own instance, its own data store, its own compute, and its own boundary. You are not one row in a shared database alongside other funds; the isolation boundary is infrastructure you control, not configuration you have to trust. Firms that need that guarantee choose single-tenant or self-hosted; the managed rollout is the faster path.

For firms whose mandate or jurisdiction requires it, the instance can run inside your own cloud account or on-premise environment. In that configuration your deal data, rent rolls, financials, and investor information never traverse our infrastructure at all. They stay within a boundary you already control, govern, and have already cleared with your own security organization. Data residency requirements are met by putting the system where the data is allowed to live, rather than by promising to handle it carefully somewhere else.

No model, ours or anyone else's, is ever trained on your data. Your numbers are used to answer your questions, and for nothing else.

What this means for you

For the GP and the LP: confidential deal economics, fund performance, and investor data sit inside a boundary you control, on infrastructure you already trust. For the InfoSec team: there is no shared model and no training pipeline to interrogate, and in a single-tenant deployment there is no shared store at all.


Human-in-the-loop by default

Nothing auto-sends. The system drafts; humans decide.

Built AI performs zero autonomous external actions. Nothing the platform does reaches outside your walls without a person approving it first. It does not auto-send an email to a lender. It does not auto-post a journal entry to your accounting system. It does not auto-commit a figure to an investor report. The catalog of agents that runs your investment lifecycle is built to do the work right up to the decision, then stop and wait for a human.

Human-in-the-loop by default

  1. The system drafts
  2. It pauses
  3. A human decides
  4. Then it sends

Built AI performs zero autonomous external actions. The catalog of agents does the work right up to the decision, then stops and waits for a person.

What this means for you

For the controller and the IR lead: no number reaches your books or your investors without passing through the person who is supposed to approve it. The system compresses the work of preparing the draft, then hands you a fully sourced version to accept, change, or reject. Accountability stays exactly where your governance already places it.


The complete audit trail

Every number cited. Every run replayable. Every action logged.

Auditability is not a feature bolted onto Built AI. It is the substrate the whole platform is built on. Three things are always true, by design, for everything the system does.

  1. Every number is cited to its source. No figure stands alone. Each one carries a link back to the document, statement, or system field it came from, and to the calculation that combined those inputs.
  2. Every computation is replayable. An agent run is not a one-time event whose logic vanishes after it finishes. It is a recorded sequence of steps. You can replay any run and watch the system reach the same result from the same inputs, which is what makes the output reproducible rather than merely plausible.
  3. Every action is logged. Who ran what, who reviewed it, who approved it, what was changed before it went out, and when each of those things happened, all captured in an immutable trail.

What this means for you

For the auditor, the IC, and the diligence team: the support package is a live property of the system, not a fire drill. Provenance, reproducibility, and the full decision log are available on demand.


Compliance posture & roadmap

SOC 2 Type II and ISO 27001, both in progress, GDPR principles as a baseline, access role-based end to end. We will be precise about what is done and what is in progress, because vague compliance claims are exactly the kind of thing a serious security team is trained to distrust.

SOC 2 Type II is in progress. We are undergoing examination of our controls for security, availability, and confidentiality across an observation period.

ISO 27001 is also in progress. We are progressing both deliberately rather than collecting badges.

Data handling follows GDPR principles as a baseline: data minimization, purpose limitation, and the ability to export or delete your data on request.

Access is role-based, end to end. Permissions are granular and follow the principle of least privilege.

What this means for you

For the compliance and InfoSec reviewer: you get a vendor that states plainly what is complete, what is in progress, and what is on the roadmap, with a security team ready to substantiate each claim under NDA.


Integrations respect your controls

Connections are read-only by default and inherit the permissions your systems already enforce. Built AI connects to the systems you already run: your accounting platform, your asset management software, your data room, your property management systems.

Connections are read-only by default. The platform pulls the information it needs.

What this means for you

For the InfoSec team evaluating the integration surface: connections are read-only unless a human explicitly approves a write, and existing permissions are inherited, not bypassed.


A buyer's checklist

Questions to ask any AI vendor.

Where does our data physically live?

If the answer is a shared environment with no isolated alternative, treat that as a flag.

Is our data ever used to train your models?

Our answer is direct: never. Your data is not used to train any model, ours or anyone else's.

Can we isolate or self-host the deployment?

We can: the system supports single-tenant, self-hosted, and on-premise deployment.

Is every output auditable back to a source?

Every figure Built AI produces is cited to its source, every computation is replayable.

Can the system take actions on its own?

Built AI performs zero autonomous external actions.

What happens to our data if we leave?

Because your data lives in your tenant, it is yours throughout and yours at the end. You can export it, and on termination it is deleted from any environment we operate.

What this means for you

Bring this list to every vendor conversation you have, ours included.


Bring your security team. We'll answer every question.

We expect the hard questions about data, isolation, auditability, and control, and we are glad to take them.