An MC outsourcing a function
is not discharged of it.
Which means you have to diligence us. This page exists so that conversation can start from facts rather than reassurance — and so the answers are the same ones written into your contract.
What Otto never does
These six rules are identical in this page, the sales deck and the client contract. They convert the buyer's biggest objection into the reason a regulated firm can adopt Otto at all.
Accountants carry professional liability and MIPA ethical obligations. MCs and brokers hold FSC licences. An autonomous system that files, pays or emails clients on their behalf is a liability they must refuse — so Otto is not one.
Enforced by the system, not by good intentions.
Every claim on this page is a property of the code or the database, and every one of them is testable. We would rather show you the test than tell you about the policy.
Tenant isolation, in the database
Every row belongs to one firm, and PostgreSQL row-level security refuses cross-tenant reads and writes. Otto's own application role is neither superuser nor table owner, so it cannot bypass the policies even by accident.
A query with no tenant context returns zero rows, not everything.
An audit trail that cannot be rewritten
Every extraction, edit, approval, export and command is an event. The log table rejects UPDATE and DELETE at the database level — not by convention, by permission. Altering an approved record writes a new entry rather than changing the old one.
This is directly the artifact an FSC inspection asks for.
Preparer and approver are different people
A preparer can edit but cannot approve. Anyone who can approve a record or sign an AML risk rating must carry a second factor, because the audit trail names them and a name has to mean something.
Role separation is what makes the trail worth having.
The AML boundary
The customer risk rating is a regulated judgement owned by a named MLRO who must defend it to an inspector. Otto pre-populates your board-approved matrix and shows every weighting. It does not score, does not adjudicate a screening hit, and does not decide to onboard.
The scoring is a deterministic matrix, never model-generated.
Credentials never reach the browser
Integration credentials are encrypted at rest and used server-side only. Agent commands are signed and idempotent, so a retry or a double click cannot produce a duplicate invoice or a second payment request.
Webhook signatures verified on every inbound event.
Where the work actually runs
Self-hosted models for anything touching identifiable client data; commercial APIs only for de-identified work. Documents are stored once, by Otto — connected systems keep results, not copies, so there is one retention policy and one deletion path.
One storage boundary means one place to prove deletion.
Otto prepares. The MLRO decides.
The single most important constraint in the management-company offering. Getting it wrong turns Otto from a tool into a liability.
Otto does
Your MLRO or Compliance Officer does
Deterministic, never generated
A model producing a score is unauditable and indefensible in an inspection. A transparent matrix showing Seychelles +3, PEP +5, cash-intensive industry +2 = 14 = High is exactly what an inspector wants to see. Otto's value is filling that matrix in from the documents and showing its working.
Screening from a licensed provider
Nobody should be building their own sanctions, PEP or adverse-media list, and we do not. Screening comes through a contracted licensed provider, and that cost is priced into your quote rather than discovered later.
Mauritius has amended its AML legislation in almost every year since exiting the FATF grey list in 2021, and Government Notice No. 112 of 2025 introduced tiered administrative penalties for KYC and reporting failures. We verify the current position with your compliance officer before making any claim in a proposal, and we would rather say “let us check” than be confidently wrong in front of your regulator.
Assembled before
you ask for it.
Your diligence targets mySmart Ltd — the licensed, contracting, insured entity — not a product name. Everything on this list exists, is current, and is one email away.
Send us your security questionnaire.
We would rather answer it early than have it surface three weeks into a proposal. Most of the answers are already written.