Learn
Inside the Rexfin Platform: How the Trust Machinery Works
Ingestion, verification, security, residency, and governance: the operational plumbing that makes Rexfin's numbers defensible, not just the AI that talks about them.
Most vendor evaluations for an AI finance tool ask the wrong first question. They ask whether the AI is smart. The question that actually determines whether you can rely on it is duller and matters more: what happens between the moment your data arrives and the moment a number appears on screen? Who touched it, what checked it, where does it sit, and what do you do the day something breaks or someone leaves the company?
That’s the machinery this pillar covers. The reliability layer pillar explains why a language model shouldn’t be trusted to do arithmetic and how a deterministic engine fixes that. This one is the operational half of the same argument: the ingestion, verification, security, residency, and governance work that has to hold up before any of that math is worth trusting. A reconciled model built on data nobody can account for is not a reconciled model. It’s a spreadsheet with better manners.
Getting data in and checking it on the way
Everything starts with how ingestion works: connecting an accounting system, banking feed, or warehouse, or uploading statements directly, and mapping accounts, dimensions, and periods into one structure instead of leaving them scattered across formats that don’t agree with each other. Ingestion alone doesn’t buy trust. What buys trust is what happens next, which is how verification works: figures get checked against each other and against the totals the source documents actually printed, so a number that doesn’t reconcile gets flagged instead of quietly waved through.
Underneath both sits a structural decision worth naming on its own: the canonical atom store. Every figure Rexfin holds is a single, addressable fact with a source and a lineage, not a cell copied into three spreadsheets that each drift a little further from the ledger over time. That’s also why deterministic calculation is a hard requirement rather than a nice-to-have: an engine that runs the same inputs through the same logic every time is the only kind of math you can hand to an auditor without a caveat.
Where the data lives and who can touch it
Security is not a badge on a page. It’s a set of specific answers, and we lay out the current ones in the security architecture overview: encryption in transit and at rest, per-organization isolation, and access scoped by role. For teams in the Gulf specifically, data residency options address the question regulators are now asking directly, which is not “is the model good” but “did that figure leave the jurisdiction, and did you have the right to send it.” Retention has its own answer too: data retention and deletion covers what happens to your data if you disconnect a source or close your account, because “your data, your call” only means something if it’s specific.
Two more pieces round out the security picture, and both matter more as AI takes on more of the work. LLM provider governance covers which model providers touch your data and under what constraints, since the language layer sitting on top of your ledger is still a third-party dependency you have to manage. And prompt injection defenses address the newer risk that classic access control never had to think about: an instruction hidden inside an uploaded document trying to redirect what the model does, not just what it says.
Trust you can actually inspect
A platform that asks you to take its word for it isn’t trustworthy, it’s confident. So every material answer keeps a trail: the answer audit log records what was asked, what was retrieved, and what was computed. Answer quality evaluation is the ongoing check on whether the system is actually getting things right, not just fast. And calibration and trust tuning is how the system decides when to answer directly and when to say a figure needs a human look, rather than defaulting to false confidence either way. If you want the short version of all of it in one place, the trust center is where that posture lives.
Running it day to day
The rest of this pillar is about the parts of a rollout nobody puts in a product demo. Roles and permissions determine who on your team sees which figures. Onboarding in the first week covers what actually happens between signing up and asking your first real question. Reliability and disaster recovery covers what we do when infrastructure fails, because a platform that reconciles your numbers perfectly and then disappears for a day is still a liability. The support model and the pricing model answer the two questions procurement always asks, plainly, without a sales call required to get the shape of the answer.
Underneath all of it is one belief that shapes every other decision here, laid out in the filings-first integration philosophy: a number sourced from a filed, audited document should never be treated with the same casualness as a number pulled from an unreconciled internal export. The platform is built to keep that distinction visible, not flatten it for convenience.
None of this is exciting in the way a chat interface is exciting. It’s also the entire reason the chat interface is safe to use. If you’re evaluating Rexfin for your team, this is the part worth reading before the demo, not after it.
In this pillar
- 01
Top-Side Journal Entries and Eliminations: Who Actually Verifies Them?
Top-side entries and intercompany eliminations are where consolidated numbers quietly stop tying to the ledger. Here's what real verification requires.
- 02
The Answer Audit Log: Every AI Answer, Replayable Later
Rexfin stores every AI answer, its evidence, and its verdict in a durable record you can reopen months later, and prove hasn't been altered.
- 03
How Rexfin Measures Answer Quality (Instead of Just Claiming It)
Rexfin runs every AI answer against a graded test set that scores citation accuracy and refusal behavior, and blocks releases that regress it.
- 04
Calibration and Trust Tuning: How Rexfin Decides What Blocks an Export
Not every failed check should stop a board pack. Here is the measured, evidence-based process that decides which ones do, and why the line isn't a guess.
- 05
The Canonical Atom Store: One Verified Fact, One Record
Every number in Rexfin traces to one typed record tied to a source PDF page. Here is what that store holds and why it is the foundation everything else depends on.
- 06
Data Contracts Between Pipeline Stages: Why Errors Stop at the Seam
How each stage of Rexfin's pipeline refuses malformed data handed to it by the stage before, so a mistake gets caught at the boundary instead of reaching your model.
- 07
What Rexfin Keeps, What It Purges, and How Deletion Actually Works
Rexfin classifies every stored artifact, purges what's recomputable on a schedule, and can delete a deal on request without breaking its own tamper-evident audit trail.
- 08
Hybrid Retrieval: How Rexfin Finds the Right Evidence Before the AI Answers
Rexfin searches your filings with keyword and semantic retrieval combined, no query-rewriting model in the loop, and hands the answer engine a ranked, citable shortlist instead of a guess.
- 09
Filings First: Why Rexfin Isn't Racing to Build 200 Connectors
Rexfin treats reliable ingestion from whatever you already have as the real product, and adds live connectors deliberately, not as a checkbox war.
- 10
Data Residency Options for GCC Finance Teams
What GCC data residency actually requires, why ISO 27001 matters more than SOC 2 for regional buyers, and how Rexfin approaches hosting and disclosure honestly.
- 11
How Ingestion Works: From Uploaded Filing to Verified Data
A walk through what happens between dropping a filing PDF into Rexfin and having its numbers ready to use: identity, classification, and a refusal to guess.
- 12
How Numbers Get Normalized: From a Footnote to One Canonical Figure
How a raw cell like "1,234 (in thousands, SAR)" becomes one typed, comparable number: the scale, currency, period and sign decisions Rexfin makes before any figure is trusted.
- 13
How Verification Works: The Check Behind Every Exported Number
Rexfin proves numbers tie out with exact math, not floating-point approximation, and refuses to guess when the data doesn't support a check. Here's how.
- 14
Which AI Models Touch Your Financials, and Under What Terms
Rexfin routes each task to a cost-appropriate model, admits providers only on vetted zero-retention terms, and redacts identifiers before anything leaves the trust boundary.
- 15
Your First Week on Rexfin: What Actually Happens
Invite-only signup, a tour that matches your role, and a support model sized to what a real team can back. Here is what the first week looks like.
- 16
Planning Data vs. Filed Actuals: Why Rexfin Never Lets Them Mix
Rexfin generates the budget, forecast, and segment detail that public filings never contain, but every plan number is walled off from the cited path so it can never pass itself off as fact.
- 17
How Rexfin's Pricing Model Works (and Why It Isn't Per-Seat)
Rexfin prices the thing that actually varies, AI-assisted work, not headcount. Here is how tiers, allowances, and the firm channel are structured.
- 18
How Rexfin Defends Against Prompt Injection From Untrusted Documents
Every filing you upload is untrusted input until proven otherwise. Here is how Rexfin keeps a hostile PDF from hijacking its own AI.
- 19
What Happens When Rexfin's Verifier Goes Down (And How It Recovers)
Rexfin's verification engine is a single point of failure by design. Here's how measured SLOs, provider failover, and tested backups keep it honest under outage.
- 20
Owner, Editor, Viewer: How Rexfin's Permission Model Actually Works
Three roles, server-enforced everywhere, with deactivation instead of silent deletion. Here is how access control works on Rexfin.
- 21
Security Architecture Overview: How Rexfin Protects Your Financial Data
Encryption, per-organization isolation, fail-closed access control, and a tamper-evident audit log: how Rexfin's security architecture actually works, concretely.
- 22
The Support Model Behind Rexfin: Honest SLAs, Not Aspirational Ones
Rexfin publishes support SLAs a small team can actually keep, plus a dedicated protocol for the incident that matters most: a wrong number reaching your board pack.
- 23
Inside the Rexfin Trust Center: What We Can Prove Today, and What We Can't Yet
Rexfin's trust center states the real security controls we have, names the gaps in plain English, and never claims a certification we can't back.
- 24
When a Filing Is Not Citable: The Floor Rexfin Won't Extract Below
What happens when a scanned or degraded filing can't be read to Rexfin's evidence standard: the number doesn't ship, and the product says so instead of guessing.
- 25
Why Rexfin's Numbers Come From an Engine, Never From an AI Guess
Rexfin's modeling engine computes every statement, valuation, and scenario deterministically. The AI orchestrates and narrates; it never emits a number.