AI Dispatch
The wirewireSep 10, 2026

Wealth-management automation vendor Jiffy.ai holds five active compliance certifications and applies AI guardrails to 100% of model calls; insurance and outcome-based pricing undisclosed

Jiffy.ai, an AI agent platform marketed to wealth managers, registered investment advisers, broker-dealers and banks, holds five active third-party compliance certifications, according to the company's trust-center page reviewed by aidispatch.news — a fuller published compliance record than most agent vendors in AI Dispatch's index carry.

The company lists ISO 27001:2022, SOC 2 Type II, SOC 1 Type II, HIPAA and GDPR/UK GDPR as active certifications, with an ISO 42001 AI-management-system certification in progress. Its trust-center page states: "ISO 27001:2022 Active 2024 Valid through Jun 2027 SOC 2 Type II Active Annual Q4 Next: Q4 2026 SOC 1 Type II Active Annual Q4 Next: Q4 2026 HIPAA Active Annual Annual assessment GDPR / UK GDPR Active Annual Annual assessment." Each entry carries a status, an audit cadence and a next-review date — a level of specificity AI Dispatch's index rarely finds on agent vendor sites.

On runtime governance, the company says automated guardrails apply to every model call it makes, not a subset. "AWS Bedrock Guardrails on 100% of LLM calls — Content moderation, PII filtering, topic blocking, and grounding checks on every inference — independent of application-layer controls," the page states. High-risk actions require a human to sign off before execution, according to the same page: "High-risk AI actions require human confirmation. AI outputs cannot trigger automated downstream actions without approval."

On data handling, the company says customer data is walled off from model training both contractually and technically. "Customer data never used to train AI models — Contractually enforced in our DPA (Clause 4.2) and architecturally enforced at the AWS Bedrock API layer. Your data trains nothing," the trust-center page states.

Jiffy.ai markets specifically into compliance-sensitive workflows — the company's site describes automating "KYC, AML, and regulatory workflows" for wealth managers — which raises the stakes of the certifications it claims. AI Dispatch's index found no public information on the company's site describing an insurance policy, an indemnification commitment, a liability cap, a formal dispute process, or outcome-linked pricing, nor does the site describe its audit trail as tamper-evident. Jiffy.ai is not yet a published entry in AI Dispatch's index, which requires a minimum evidence threshold before publication; it remains under review.

Sources 5

  1. ISO 27001:2022 Active 2024 Valid through Jun 2027 SOC 2 Type II Active Annual Q4 Next: Q4 2026 SOC 1 Type II Active Annual Q4 Next: Q4 2026 HIPAA Active Annual Annual assessment GDPR / UK GDPR Active Annual Annual assessment
    trust.jiffy.ai · checked Aug 26, 2026
  2. AWS Bedrock Guardrails on 100% of LLM calls Content moderation, PII filtering, topic blocking, and grounding checks on every inference — independent of application-layer controls.
    trust.jiffy.ai · checked Aug 26, 2026
  3. Human-in-the-loop for high-risk AI workflows High-risk AI actions require human confirmation. AI outputs cannot trigger automated downstream actions without approval.
    trust.jiffy.ai · checked Aug 26, 2026
  4. Customer data never used to train AI models Contractually enforced in our DPA (Clause 4.2) and architecturally enforced at the AWS Bedrock API layer. Your data trains nothing.
    trust.jiffy.ai · checked Aug 26, 2026
  5. Risk & Compliance Simplify compliance while strengthening risk oversight. Automate KYC, AML, and regulatory workflows to reduce manual effort.
    jiffy.ai · checked Aug 2, 2026