Security at DwellFi | Enterprise AI Platform Protection
April 28, 2026 — TMF Group has chosen DwellFi for agentic fund operations. Read more
Your data never leaves your environment.
DwellFi runs within your cloud, in your region, with no shared infrastructure. Your data, model outputs, and audit logs stay where you control them.
Architecture· Controls· Trust Center
Sovereign._Deterministic._Owned.
Audit log · Tenant WB-042026-05-23 14:09:22Z
NAV close, Westbrook Growth Fund III
agent run 4127 · in-tenant ·47 LPs ·$24.2M
Sources cited 3 of 3
Models in agreement 3 of 3
Reconciled to source yes
Output $84,213,847.22
Stamped to tenant log Exportable to SIEM
One tenant boundary. Structural by design.
DwellFi is not a multi-tenant platform with a security wrapper. It is a single-tenant deployment inside the cloud account you already trust. The boundary is set at deployment, not at the demo.
Your data sits in your tenant. Your models run in your tenant. Reconciliations, NAV figures, audit logs, prompts, and completions all live inside the perimeter your security team already monitors.
DwellFi’s control plane orchestrates the work but never touches the payload. Inference stays inside your tenant, under your encryption keys.
Where data lives
Your cloud, your region, your encryption keys.
Where inference runs
Inside your tenant, against endpoints you control.
What we see
Operational metadata. Never your fund data.
What the boundary buys you.
The controls in place today are consequences of the architecture, not features bolted on top of it. The full set, including the SOC 2 Type II report, lives in the Trust Center.
01
Structural tenant isolation
Each customer runs in their own cloud tenant. Isolation is set at the architecture layer, not enforced by policy or shared-database row filtering.
There is no shared customer datastore to misconfigure.
02
Data residency, by contract
Deploy to AWS, GCP, Azure, or Oracle. Choose the region. Choose the encryption posture. The platform follows the contract, not a default.
Cross-region replication only when the customer requests it.
03
SOC 2 Type II, in production
SOC 2 Type II report available on request. Vendor risk teams receive a response from the security team within one business day.
The full record, at the source.
The SOC 2 Type II report, security questionnaires, and supporting documentation are hosted on trust.dwell.fi. Vendor risk teams can request access directly. A member of the DwellFi security team responds within one business day.
trust.dwell.fi · One business day response
SOC 2 Type II, in production.
Status Active
Report Available on request
Response SLA One business day
Portal trust.dwell.fi