Security

Your data is never stored, reviewed, or used to train any AI model.

CFI's security posture is purpose-built for the governance, sovereignty, and vendor risk requirements of public sector institutions: government ministries, National Designated Authorities, and Accredited Entities operating in multilateral climate finance. Three layers of protection. Contractually guaranteed.

What They're Saying

"Integrating this software into our workflow means we can deliver superior quality proposals faster. This isn't about replacing expertise — it's about amplifying it."
Qavah Earth · Cape Town
"The ability to rapidly evaluate a concept note against Donor criteria is a game-changer. It saved us days of work and allowed us to deliver a superior product at a fraction of the traditional cost."
Project Developer · South Africa
"It would be wise to have the Concept Note Evaluator in the initial assessment and in the final stage as well. Useful for project developers, private players, and Donor applicants with limited experience."
Development Bank · Southern Africa
"The Converter tool was a lifesaver, migrating our Concept Note to the new Donor format in under two hours. The summary of changes would have taken us days of research."
Project Proponent · Africa
"I found your AI assistants very helpful in organizing ideas and aligning them with Donor criteria. Most importantly, it saved loads of time."
International Delivery Partner · Africa
"The Concept Note Converter has been an invaluable resource that bridges this gap, ensuring our CNs were aligned with the latest Donor standards."
Project Proponent · Zimbabwe

The stakes are high: General-purpose AI isn't built for this

Generic AI infers answers from the open web — hallucinations, no traceability, and an agreeable streak that hands you whatever case your prompt implied. CFI is anchored to documents you own or are authorized to use. Every finding is tied to verifiable source text, with an emphasis on critical evaluation over affirmation.

Built On Your Own Files
CFI is populated with the materials you own or are authorized to use: your past submissions, technical notes, and the external sources you select. It is strictly private — your dataset is never shared and never used to train AI models.
Every Insight Is Cited
Each response traces to specific source text. Built-in references let you verify exactly where a finding comes from — not inferred, not paraphrased, not invented.
Critical In Evaluation
The platform can only draw on what's in your dataset, so it cannot manufacture support that isn't there. The assistants are configured to evaluate critically rather than just agree.
Three Pillars of Trust

State-of-the-art capability. Uncompromising security. No trade-off.

Pillar 01
EU-Hosted Infrastructure by Default

Core application infrastructure hosted on Hostinger VPS servers in Frankfurt, Germany, providing European data residency as the standard deployment posture.

Physical servers in an ISO/IEC 27001-certified German data centre. TLS 1.2+ in transit. AES-256 at rest. Dedicated VPS instances with no shared infrastructure.

Pillar 02
Google-Approved Zero-Retention AI

In January 2026, Google's Generative AI Services team granted Janus a formal, written exception to its standard prompt logging policy. Your documents and queries are not logged, not stored, not reviewed, and not used to train any model.

This is a contractually binding guarantee, not a best-efforts commitment.

Pillar 03
Flexible Deployment to Match Your Governance Posture

From EU-hosted SaaS to full on-premises installation on your sovereign infrastructure, with Azure cloud deployment available on request.

Role-Based Access Control, MFA, and SSO via Active Directory/LDAP available across all options. Your institution selects the architecture that fits your mandate.

Google-Approved Zero Retention — Confirmed January 19, 2026

The single most important data protection assurance we can offer.

Google's Generative AI Services team granted Janus Advisory a formal, written exception to its standard prompt logging policy for our designated Google Cloud Project. This is not a default setting or a vendor best-effort promise — it is a contractually binding policy, confirmed in writing on 19 January 2026, and reproduced in full in our security brief (J-SEC-WP-CFI-001).

Prompts sent to Gemini via Vertex AI are NOT logged by Google
Your data is NOT used to train Google's AI models
Your data is NOT stored or retained after response generation
Your data is NOT reviewed by Google personnel
Prompts are processed in-memory only, then permanently discarded
Contractually binding — not a best-efforts commitment
Deployment Options

One deployment model cannot address every governance mandate. We offer three.

Your institution selects the architecture that best aligns with your data sovereignty, procurement, and risk requirements.

Option B
Licensed On-Premises Installation
CFI installed directly onto your approved private infrastructure. Complete data sovereignty — all data stays within your walls.
Database, project data, and documents never leave your infrastructure
Full physical and logical control over all sensitive data
SSO via Active Directory/LDAP and SIEM integration
Client selects and controls their own AI provider
Best for: Strict sovereignty mandates, government infrastructure requirements
Option C
Azure Cloud Deployment
Full CFI stack on Azure — available on request. Architecture design and migration planning are complete.
Azure App Service, PostgreSQL with pgvector, Azure AI Search
Transactable through Microsoft Azure Marketplace
Apply existing Azure consumption commitments (MACC) to your CFI licence
Eliminates separate procurement for Azure-native institutions
Best for: Institutions operating within a Microsoft Azure environment
Security Posture at a Glance

Everything your security team needs to evaluate CFI.

EU Data Residency
Core infrastructure in Frankfurt, Germany; Hostinger VPS in ISO/IEC 27001-certified data centre
Google-Approved Zero Retention
Formal written exemption from prompt logging (Jan 19, 2026) — data never stored, reviewed, or used for model training
Encryption
AES-256 at rest; TLS 1.2+ in transit across all infrastructure components
Flexible Deployment
EU SaaS, on-premises, or Azure cloud — each designed to meet a different governance posture
ISO/IEC 27001-Aligned
Operating practices aligned to the globally recognised standard; GCP infrastructure fully certified (27001/27017/27018)
Access Control
RBAC, MFA, SSO via Active Directory/LDAP, GCP IAM least-privilege enforced across all deployments
GDPR-Compatible
EU hosting, zero-retention AI, and Data Processing Agreements available on request
Annual Penetration Testing
Independent third-party testing to OWASP ASVS methodology; results available to clients on written request

Questions for your vendor risk assessment?

Request our full security brief, a Data Processing Agreement, or a direct conversation with our security team.