Security built for regulated Singapore.
hifis is built for banks, insurers, healthcare groups and government-linked companies. Here is how we protect your data and your people.
| Framework | What it covers | hifis status |
|---|---|---|
| PDPA 2012 (Singapore) | Personal data protection and DPO obligations | Controls mapped · DPO appointed |
| MAS Technology Risk Management | Guidelines for financial institutions | Controls mapped for FI customers |
| MAS Outsourcing Guidelines | Material outsourcing arrangements | Due-diligence pack available |
| IMDA AI Verify | AI governance testing framework | Testing in progress |
| ISO/IEC 27001 and 42001 | Information security and AI management | Audit roadmap |
| SOC 2 Type II | Security, availability, confidentiality | Audit roadmap |
| MTCS SS 584 | Singapore multi-tier cloud security | Via hosting provider |
Update each status to match your certification progress before launch.
Singapore data residency
Customer data is stored and processed in Singapore by default. Cross-border transfers happen only with your written approval.
PII detection and redaction
NRIC, FIN, passport, bank account and salary data are detected and masked before any model sees them.
Human in the loop
Set approval thresholds by amount, entity or risk. hifis never pays, hires or fires without the approvals you configure.
Encryption everywhere
AES-256 at rest, TLS 1.3 in transit, and customer-managed keys on dedicated deployments.
No training on your data
Your data is never used to train shared models. Model providers are contracted with zero data retention.
Immutable audit trail
Every prompt, tool call, approval and output is logged and exportable for internal and external auditors.
Work, done.
AI employees for Finance, HR and Sales. Made in Singapore.