CFI's security posture is purpose-built for the governance, sovereignty, and vendor risk requirements of public sector institutions: government ministries, National Designated Authorities, and Accredited Entities operating in multilateral climate finance. Layered protection, contractually guaranteed.
Google's Generative AI Services team granted Janus Advisory a formal, written exception to its standard prompt logging policy for our designated Google Cloud Project. This is not a default setting or a vendor best-effort promise — it is a contractual commitment between Google and Janus, confirmed in writing on 19 January 2026, and reproduced in full in our security brief (J-SEC-WP-CFI-001). Equivalent terms are available in a client Data Processing Agreement on request.
From the EU AI Act to funder disclosure expectations, the direction of travel is the same — institutions need to be able to show where an AI-generated claim came from. CFI was built that way from the start.
Retrieval, not recall.
CFI does not answer from model memory. Every response is assembled from documents in the corpus — approved proposals, climate science, and your own institutional files — and the system reports when the corpus has nothing to offer rather than filling the gap.
Attribution by default.
Every substantive claim carries its source, down to the passage. Nothing is asserted that a reviewer cannot open and check independently.
Human oversight by design.
CFI evaluates, drafts, and cites. It does not approve, score for decision, or submit. Every output is built for review by the practitioner who owns the deliverable.
Auditable after the fact.
The retrieval trail persists. When a funder, an auditor, or your own board asks how a conclusion was reached, the answer is a document rather than a description of a model.
Yes. This is exactly why we offer a self-hosted deployment option: your own infrastructure or cloud environment, with your data never leaving your control. For institutions where document confidentiality is a hard requirement, self-hosted deployment is the default recommendation, not an upsell.
The full web application, delivered as a container image, along with an installation guide and technical support through deployment. You install it on your own infrastructure — your servers or your cloud environment. We don't host anything on your behalf.
Because hosting your data — even briefly — would undermine the guarantee that matters most to our clients. A local install is the only deployment model that ensures full data residency and sovereignty: your documents live on your infrastructure, under your jurisdiction, governed by your access policies. We built the delivery model around that requirement rather than treating it as an add-on.
Your institutional documents — submissions, internal files, reviewer feedback — are indexed and stored entirely within your deployment. Nothing is transmitted to Janus. We have no access to your instance, your corpus, or your queries.
CFI runs as a standard container deployment, so it fits infrastructure most IT teams already operate — on-premises servers or your own cloud tenancy. The installation guide covers system requirements, and our technical team supports your IT staff through setup and validation.
Your administrators, entirely. You decide who can use the platform, which document collections they can query, and how the retrieval trail is reviewed. Janus has no administrative access to your deployment.
We provide updated container releases, which your team applies on your own schedule through the same process as the initial install. Donor guideline and policy updates are included — you're never locked to the version you installed.
An installation guide written for your IT team, direct technical support through deployment and validation, and staff training and onboarding included with the license — no separate consulting engagement required.
Yes — the architecture supports fully isolated deployment for institutions whose security posture requires it. Talk to our technical team about your specific environment during scoping; requirements like model hosting inside the enclave are addressed in the deployment plan.
Request our full security brief, a Data Processing Agreement, or a direct conversation with our security team.