Privacy Policy
Last updated August 13, 2025
This policy describes, in plain terms, how Niridis approaches financial data, AI-assisted analysis and intelligence shared across institutions. It is written to explain our approach conceptually; it is not a substitute for the specific data processing agreement in place with your institution, which controls in the event of any conflict.
What data we process
Niridis processes financial activity data provided by, or on behalf of, participating institutions — such as transaction context, account references, device references and counterparty references — for the purpose of identifying relationships and patterns relevant to fraud risk.
We do not require, and discourage submitting, more data than is necessary for this purpose. Where a signal can be represented without an underlying raw record, we prefer the signal.
Data minimization
Our architecture is built around limiting what data needs to move in order to produce useful intelligence. Where possible, analysis relies on derived signals — timing, relationship structure, behavioral indicators — rather than full transaction or customer records.
Cross-institution intelligence sharing
Participating institutions may contribute to and draw on shared risk signals through the Niridis network layer. This is not unrestricted data sharing:
- Each institution controls what signals it contributes and under what conditions they may be used by others.
- Access to another institution's contributed signals requires authorization consistent with the terms agreed between that institution and Niridis.
- Raw account holder data is not broadcast across the network as a matter of course.
AI-assisted processing
Niridis uses automated analysis, including AI-assisted models, to identify relationships and patterns across financial signals and to produce investigation context such as reasoning summaries. Outputs are intended to support human investigators and are not presented as final determinations of fraud.
We do not publish specific detection rates or accuracy claims in this policy; performance varies by data, use case and configuration, and should be evaluated directly with your institution's implementation.
Authorized use
Data submitted to Niridis, and intelligence produced from it, may only be used for fraud risk analysis, investigation and related purposes authorized under your institution's agreement with Niridis. Use outside that scope requires separate authorization.
Security
We apply administrative, technical and organizational safeguards designed to protect data in transit and at rest, and to restrict access to authorized personnel and systems. No system can guarantee absolute security, and we do not claim specific certifications in this policy.
Retention and deletion
Data is retained for as long as necessary to provide the service, support ongoing investigations, and meet legal and contractual obligations, after which it is deleted or de-identified in accordance with the applicable agreement.
Your institution's responsibilities
Institutions submitting data to Niridis are responsible for ensuring they have appropriate legal basis and any required customer disclosures for that data to be processed for fraud intelligence purposes, including any cross-institution signal sharing they choose to enable.
Contact
Questions about this policy or a specific institution's data handling can be directed to your Niridis account contact or to privacy@niridis.example.