A mortgage file holds some of the most sensitive personal data a small business will ever handle. We built the deterministic floor first, and put the model on top of it — never in the verdict path.
Recognition
Our Healthy Wealthy Investor brand was named a finalist in the Australian AI Awards 2026, AI Innovator — Property Investment, announced 7 September 2026 by Momentum Media.
What we have built
Each of these runs today. Where something is still in development we say so on this page rather than counting it as a capability.
A deterministic assurance engine for regulated credit files. It reads a client's documents, reconciles the figures across them, and produces a dated record of what was checked — including what it could not establish. The verdict path contains no model.
Learn more →A question-answering layer on our published education, live on Healthy Wealthy Investor. It answers general questions about SMSF borrowing and structure, cites what it drew on, and refuses at the point where a question becomes personal advice.
Learn more →Client onboarding and document ingestion, deterministic serviceability using the Household Expenditure Measure and the regulator's buffers, the twenty-step compliance workflow mapped into code, and an SMSF borrowing qualifier. Built between February and June 2026.
Learn more →Responsible AI
In October 2025 the National AI Centre replaced the Voluntary AI Safety Standard with Guidance for AI Adoption — six essential practices. This is our own assessment against each, with what we point to. It is a first-party declaration, not a certification.
Every station in the assessment line is classified by who acts there — the practitioner, the software, or neither — and whether it touches a client's rights. The record states on its face that the professional judgement is the broker's, and declines to certify that the best interests duty was discharged. That duty cannot be delegated to software.
Our AI System Impact Assessment sets out who the system can affect, how, and the mitigation in place for each impact. It is published in full and reviewed at every major release.
We keep a ranked list of the ways our own product can be defeated, ordered by exposure, damage and ease of attack. It opens on our worst weakness rather than our best feature, and it doubles as the build queue.
We publish what we cannot yet catch, and we publish evaluation results including the cases our own system fails. A control nobody can inspect is an assertion.
4,705 automated tests run on every build. A regression test fails the build if any station in the assessment line is found deciding on its own. Content is classified before it reaches a model, and identity documents, tax file numbers and account numbers are stripped before any model sees them.
The software's headline behaviour is that it declines to act. It refuses at the boundary between general information and personal advice, records the refusal, and stops an assessment run rather than guessing at an unfamiliar document layout. An unreadable field is marked unobservable and located on the page.
Standards
A first-party self-assessment against the international standards the field is measured by. We name what we conform to today and what we are working toward, and we hold no third-party certification yet.
We have self-assessed against the international standard for managing an AI system. We conform today on how the system runs and how its risks are managed and monitored — the decision path has no model in it, the controls are tested on every build, and we keep a live risk register. We are working toward certification on the surrounding management system, and say so.
Read the AI System Impact Assessment →The technical security controls are strong because the architecture is built for it — documents stay on the practitioner's machine, access to raw identity data is gated, and the record is cryptographically signed against a key we publish outside the file. The full statement of applicability and the organisational controls are the work in progress.
SOC 2 is an independent auditor's report produced over a period of observation, not something an organisation declares of itself. We make no SOC 2 claim. We are working toward a SOC 2 Type 2 report over our hosted verification service, and will name it here when it is issued.
The boundary
The line between general information and personal advice is a legal one. We enforce it in code rather than asserting it in a policy.
Nothing produced by any system on this page is personal credit, financial, tax or legal advice. None of it considers your objectives, financial situation or needs. Suitability for your own fund belongs to your licensed adviser and your accountant.
ProofMemo records what a credit practitioner did. It never makes the professional determination, never endorses one, and says so on the face of every record it produces.
In real time, the software helps the licensed human carry out their duty to the best standard the market offers, and in compliance with the regulations, acts and standards that govern the work — every required check, run the same way each time. What it never does is take that duty over, because a professional duty cannot be delegated to software and should not be. So the system runs locally, in the broker's own browser, holding no second copy — the client's data stays in the broker's hands and the judgement stays with the person the law trusts to make it. We take full responsibility for what our software does and build it to strengthen the human's hand, never to replace it and never to quietly shift the onus onto you.
The assessment on this page is our own, made under the form of ISO/IEC 17050-1 for a supplier's declaration of conformity. We hold no third-party AI certification today. Work toward independent certification has begun and we will name it here when, and only when, it is issued.
A system that can only be trusted cannot be checked. We would rather be checked.
The instruction on day one was deterministic, and no model in the verdict path. Not because models are useless — we use them, and we say where. Because a system that resists testing also resists certification, and in regulated credit the record is the product.
Everything above is either running now or named as not running. If we announce something on this page, it has to be working and measured the day we say it.
AeFin is a trading name of Aubelia Enterprise Pty Ltd, an Australian Credit Representative (CR 464548) of Finsure Finance and Investment Pty Ltd (ACL 384704). What you read here is general information about how we build software. It is not personal credit or financial advice.