CFI's security posture is purpose-built for the governance, sovereignty, and vendor risk requirements of public sector institutions: government ministries, National Designated Authorities, and Accredited Entities operating in multilateral climate finance. Three layers of protection. Contractually guaranteed.
Generic AI infers answers from the open web — hallucinations, no traceability, and an agreeable streak that hands you whatever case your prompt implied. CFI is anchored to documents you own or are authorized to use. Every finding is tied to verifiable source text, with an emphasis on critical evaluation over affirmation.
Core application infrastructure hosted on Hostinger VPS servers in Frankfurt, Germany, providing European data residency as the standard deployment posture.
Physical servers in an ISO/IEC 27001-certified German data centre. TLS 1.2+ in transit. AES-256 at rest. Dedicated VPS instances with no shared infrastructure.
In January 2026, Google's Generative AI Services team granted Janus a formal, written exception to its standard prompt logging policy. Your documents and queries are not logged, not stored, not reviewed, and not used to train any model.
This is a contractually binding guarantee, not a best-efforts commitment.
From EU-hosted SaaS to full on-premises installation on your sovereign infrastructure, with Azure cloud deployment available on request.
Role-Based Access Control, MFA, and SSO via Active Directory/LDAP available across all options. Your institution selects the architecture that fits your mandate.
Google's Generative AI Services team granted Janus Advisory a formal, written exception to its standard prompt logging policy for our designated Google Cloud Project. This is not a default setting or a vendor best-effort promise — it is a contractually binding policy, confirmed in writing on 19 January 2026, and reproduced in full in our security brief (J-SEC-WP-CFI-001).
Your institution selects the architecture that best aligns with your data sovereignty, procurement, and risk requirements.
Request our full security brief, a Data Processing Agreement, or a direct conversation with our security team.