Compliance · United States
AI that fits your GLBA safeguards program.
Customer financial information stays in your environment, under the controls your examiners already review, with logs that support breach assessment.
- Covers
- Customer financial information
- FTC breach notice
- 30 days, 500+ consumers
- In effect since
- 13 May 2024
- Our approach
- Your controls, your logs
In short
The Gramm-Leach-Bliley Act requires financial institutions to protect customer information through a written safeguards program. Since 13 May 2024, FTC-regulated institutions must notify the FTC within 30 days of discovering a breach of unencrypted information affecting 500 or more consumers. Self-hosted AI keeps that information inside your existing controls.
What it asks
Requirements, and how we meet them.
| Requirement | How DeepVox addresses it |
|---|---|
| Written information security program | The AI system is documented as part of your program. |
| Access controls | Role-based access by department and person, synced from your directory. |
| Service provider oversight | No AI vendor in the data path; components and owners documented. |
| Monitoring and logging | Every access and action logged in your environment. |
| Breach notification | Logs support fast scoping of any incident against the 30-day FTC window. |
FAQ
Questions, answered.
Does the 30-day rule apply to banks?
The FTC rule applies to non-bank financial institutions under FTC jurisdiction; banks follow their own regulators’ requirements. Our deployment model supports both.
Where does customer data go?
Nowhere outside your environment unless you choose a hosted model for a specific, non-sensitive task.
Related
HIPAA
Clinical knowledge search, patient lines and documentation tools, running inside the covered entity’s infrastructure so PHI isn’t sent to an AI vendor..
Learn more →Other markets
Europe, the United States and India.
Learn more →General information, not legal advice. Have your counsel confirm how each rule applies to you. Sources: FTC Safeguards Rule breach notification. Updated October 2026.
Start with two weeks of evidence, not a sales call.
A fixed-price discovery sprint, credited against whatever comes next. Or write to sales@deepvox.ai.