BYOC / InspectableInspectable BYOC boundary — buyer keeps IdP and approved storage; inference runs over bounded aggregate context.
Wealth-tech design partnership
The Open Portfolio design partnership for wealth-tech BYOC.
A clean-room design partnership for regulated wealth platforms — reduce audit perimeter by keeping client ledgers inside the buyer’s approved environment, and prove value via a bounded, stateless inference boundary.
Primary outcome
Audit perimeter reduction — by architecture, not policy
This surface is intentionally dense. It is written for CTO, Security, and Compliance leaders who need to reduce critical third-party scope under EU DORA / GDPR by limiting data custody.
Clean-room posture
Local-first ingestion: broker / custody exports parse in the user’s browser.
Stateless inference: AI requests are processed without per-user server persistence.
Partner/customer PII is not warehoused by Pocket Portfolio services.
Wealth-tech focus
Wealth platforms · IFAs & wealth managers · Aggregators · Enterprise SDK. The program is designed for regulated wealth platforms where institutional trust and audit scope are the gating constraints.
Canonical claim
Limited-Scope Processor
A limited-scope processor architecture: broker data parses in-browser, never warehouses server-side, and AI inference runs stateless — minimising the per-user data footprint by design.
PPI-METER/1
Stateless metering (usage without data custody)
Roadmap specification — not asserted as production metering shipped in this repository.
A design partner needs billing, quotas, and governance without expanding audit scope. Target posture: meter capability usage without ingesting partner/customer PII.
PPI-METER/1
Inputs: capability_id, event_type, timestamp, tenant_id, sku_id
Constraints:
- no raw portfolio payloads
- no customer identifiers
- no PII fields (name/email/address/account numbers)
Output: counters for billing + governance (aggregate only)
Regulatory posture
EU DORA narrative: shrink the oversight surface
Target posture: reduce partner oversight + exit-plan complexity by keeping customer data local and limiting third-party processing scope. DORA classification (critical vs non-critical ICT third party) remains a partner risk decision — our architecture is built to keep you on the non-critical side where feasible.
Escalation path
Start at the architecture map, then escalate to a diligence call. Design-partner engagement is verified without collecting portfolio/trade payloads.