Back to dashboard

Compliance & Audit Framework

CrestPoint AI is designed to support your organization's regulatory obligations — not replace your compliance program. This page documents the governance architecture built into the platform.

Not Investment Advice

CrestPoint AI is an intelligence and risk monitoring platform. The information, signals, scores, alerts, and analysis provided by CrestPoint AI are for informational and intelligence purposes only.

Nothing on this platform constitutes investment advice, financial advice, legal advice, or a recommendation to buy, sell, or hold any security, asset, fund interest, or investment of any kind.

CrestPoint AI is not registered as an investment adviser with the U.S. Securities and Exchange Commission or any state securities authority, and does not provide investment advisory services as defined under the Investment Advisers Act of 1940 or applicable state law.

Users of this platform are solely responsible for their own investment, operational, and risk management decisions. All outputs should be independently verified before being relied upon for any purpose.

Compliance & Audit Framework

How CrestPoint AI supports your regulatory obligations

Active

Not Investment Advice. CrestPoint AI is an intelligence platform only. Outputs do not constitute investment, legal, or financial advice. CrestPoint AI is not registered as an investment adviser with the SEC or any state authority.

Data provenance

Every signal tagged with source, timestamp, and confidence score. Full traceability from alert to origin.

Immutable audit log

Every query, lookup, export, and alert acknowledgment is logged with user identity and timestamp. Append-only — records cannot be altered.

Role-based access

Multi-tenant org isolation. Admins control feature access per user. GeoIntel and sensitive features are permission-gated.

Data retention & export

24-month default retention. Full structured export available for regulatory examinations, LP audits, and internal reviews.

Supports AML/KYC due diligence · TPRM · OSINT governance · Data privacy alignment

Full framework →

Regulatory Frameworks Supported

Family offices & PE funds

AML / KYC due diligence support

CrestPoint's entity risk scoring and sanctions monitoring supports clients' AML and KYC obligations by providing documented, sourced intelligence on counterparties, LPs, and portfolio companies. Outputs are audit-ready and exportable.

Enterprise & corporate

Third-party risk management (TPRM)

CrestPoint supports vendor and counterparty due diligence programs by providing continuous, documented risk monitoring. Integrates with existing TPRM workflows via API or structured report export.

Government & defense

OSINT governance & chain of custody

Full data provenance and immutable audit logs support chain-of-custody requirements for government intelligence workflows. Role-based access and permission gating align with need-to-know principles.

All clients

Data privacy alignment

CrestPoint does not sell client data or share it across tenants. Data handling is consistent with GDPR principles for EU-connected clients and CCPA for California-based users. A data processing agreement (DPA) is available on request.

Data Retention Policy

Signal history & alert records24 months (default)
Audit log entries24 months (default, configurable for Enterprise)
Disclaimer acknowledgmentsPermanent (immutable compliance record)
User access logs24 months
Report export history24 months
Data export on requestStructured format, available within 5 business days
Deletion requestsHonored with documented confirmation within 30 days

Compliance Inquiries

For data processing agreements, audit log exports, regulatory inquiries, or compliance documentation requests, contact us directly.

Contact Compliance

Disclaimer v1.0 · Last updated April 2026 · CrestPoint AI / GDI Risk Advisory Group LLC
This page does not constitute legal advice. Consult qualified counsel for your specific regulatory obligations.