The AI is not allowed to decide.

A mortgage file holds some of the most sensitive personal data a small business will ever handle. We built the deterministic floor first, and put the model on top of it — never in the verdict path.

Recognition

Australian AI Awards 2026 finalist

Our Healthy Wealthy Investor brand was named a finalist in the Australian AI Awards 2026, AI Innovator — Property Investment, announced 7 September 2026 by Momentum Media.

Australian AI Awards 2026 finalistAustralian Credit Representative CR 464548Finsure ACL 384704Aubelia Enterprise Pty Ltd t/a AeFinClients Australia-wide

What we have built

Named systems, not a statement of intent

Each of these runs today. Where something is still in development we say so on this page rather than counting it as a capability.

ProofMemo

A deterministic assurance engine for regulated credit files. It reads a client's documents, reconciles the figures across them, and produces a dated record of what was checked — including what it could not establish. The verdict path contains no model.

Learn more →

SMSF Concierge

A question-answering layer on our published education, live on Healthy Wealthy Investor. It answers general questions about SMSF borrowing and structure, cites what it drew on, and refuses at the point where a question becomes personal advice.

Learn more →

The workflow engines

Client onboarding and document ingestion, deterministic serviceability using the Household Expenditure Measure and the regulator's buffers, the twenty-step compliance workflow mapped into code, and an SMSF borrowing qualifier. Built between February and June 2026.

Learn more →
4,705Automated tests passing on every build, measured 9 September 2026
19Assessment stations, each classified by who acts and whether it touches your rights
0Client documents that leave the practitioner's machine during reading and assessment
Mar 2026First deterministic data-classification gate in production code

Responsible AI

Measured against Australia's six essential practices

In October 2025 the National AI Centre replaced the Voluntary AI Safety Standard with Guidance for AI Adoption — six essential practices. This is our own assessment against each, with what we point to. It is a first-party declaration, not a certification.

1

Decide who is accountable

Every station in the assessment line is classified by who acts there — the practitioner, the software, or neither — and whether it touches a client's rights. The record states on its face that the professional judgement is the broker's, and declines to certify that the best interests duty was discharged. That duty cannot be delegated to software.

2

Understand impacts and plan accordingly

Our AI System Impact Assessment sets out who the system can affect, how, and the mitigation in place for each impact. It is published in full and reviewed at every major release.

3

Measure and manage risks

We keep a ranked list of the ways our own product can be defeated, ordered by exposure, damage and ease of attack. It opens on our worst weakness rather than our best feature, and it doubles as the build queue.

4

Share essential information

We publish what we cannot yet catch, and we publish evaluation results including the cases our own system fails. A control nobody can inspect is an assertion.

5

Test and monitor

4,705 automated tests run on every build. A regression test fails the build if any station in the assessment line is found deciding on its own. Content is classified before it reaches a model, and identity documents, tax file numbers and account numbers are stripped before any model sees them.

6

Maintain human control

The software's headline behaviour is that it declines to act. It refuses at the boundary between general information and personal advice, records the refusal, and stops an assessment run rather than guessing at an unfamiliar document layout. An unreadable field is marked unobservable and located on the page.

Standards

Where we stand against the recognised standards

A first-party self-assessment against the international standards the field is measured by. We name what we conform to today and what we are working toward, and we hold no third-party certification yet.

ISO/IEC 42001 — AI management

We have self-assessed against the international standard for managing an AI system. We conform today on how the system runs and how its risks are managed and monitored — the decision path has no model in it, the controls are tested on every build, and we keep a live risk register. We are working toward certification on the surrounding management system, and say so.

Read the AI System Impact Assessment →

ISO/IEC 27001 — information security

The technical security controls are strong because the architecture is built for it — documents stay on the practitioner's machine, access to raw identity data is gated, and the record is cryptographically signed against a key we publish outside the file. The full statement of applicability and the organisational controls are the work in progress.

SOC 2 — an auditor's report, not a claim

SOC 2 is an independent auditor's report produced over a period of observation, not something an organisation declares of itself. We make no SOC 2 claim. We are working toward a SOC 2 Type 2 report over our hosted verification service, and will name it here when it is issued.

The boundary

Where the software stops

The line between general information and personal advice is a legal one. We enforce it in code rather than asserting it in a policy.

General information, never personal advice

Nothing produced by any system on this page is personal credit, financial, tax or legal advice. None of it considers your objectives, financial situation or needs. Suitability for your own fund belongs to your licensed adviser and your accountant.

The record is the broker's, not the software's

ProofMemo records what a credit practitioner did. It never makes the professional determination, never endorses one, and says so on the face of every record it produces.

We assist the human to carry out their duty — we do not take it from them

In real time, the software helps the licensed human carry out their duty to the best standard the market offers, and in compliance with the regulations, acts and standards that govern the work — every required check, run the same way each time. What it never does is take that duty over, because a professional duty cannot be delegated to software and should not be. So the system runs locally, in the broker's own browser, holding no second copy — the client's data stays in the broker's hands and the judgement stays with the person the law trusts to make it. We take full responsibility for what our software does and build it to strengthen the human's hand, never to replace it and never to quietly shift the onus onto you.

A first-party declaration, not a certification

The assessment on this page is our own, made under the form of ISO/IEC 17050-1 for a supplier's declaration of conformity. We hold no third-party AI certification today. Work toward independent certification has begun and we will name it here when, and only when, it is issued.

A system that can only be trusted cannot be checked. We would rather be checked.

Why we built it this way

The instruction on day one was deterministic, and no model in the verdict path. Not because models are useless — we use them, and we say where. Because a system that resists testing also resists certification, and in regulated credit the record is the product.

Everything above is either running now or named as not running. If we announce something on this page, it has to be working and measured the day we say it.

AeFin is a trading name of Aubelia Enterprise Pty Ltd, an Australian Credit Representative (CR 464548) of Finsure Finance and Investment Pty Ltd (ACL 384704). What you read here is general information about how we build software. It is not personal credit or financial advice.

Structure first. The software only ever records what was done.

Book a strategy session