Security & compliance

An MC outsourcing a function
is not discharged of it.

Which means you have to diligence us. This page exists so that conversation can start from facts rather than reassurance — and so the answers are the same ones written into your contract.

What Otto never does

These six rules are identical in this page, the sales deck and the client contract. They convert the buyer's biggest objection into the reason a regulated firm can adopt Otto at all.

Delete or modify an original source document
Submit a return to the MRA, CBRIS or the FSC
Make a payment
Send an external email without a human pressing send
Alter an approved record without writing a new audit entry
Hide an assumption or an uncertain match

Accountants carry professional liability and MIPA ethical obligations. MCs and brokers hold FSC licences. An autonomous system that files, pays or emails clients on their behalf is a liability they must refuse — so Otto is not one.

The controls

Enforced by the system, not by good intentions.

Every claim on this page is a property of the code or the database, and every one of them is testable. We would rather show you the test than tell you about the policy.

Tenant isolation, in the database

Every row belongs to one firm, and PostgreSQL row-level security refuses cross-tenant reads and writes. Otto's own application role is neither superuser nor table owner, so it cannot bypass the policies even by accident.

A query with no tenant context returns zero rows, not everything.

An audit trail that cannot be rewritten

Every extraction, edit, approval, export and command is an event. The log table rejects UPDATE and DELETE at the database level — not by convention, by permission. Altering an approved record writes a new entry rather than changing the old one.

This is directly the artifact an FSC inspection asks for.

Preparer and approver are different people

A preparer can edit but cannot approve. Anyone who can approve a record or sign an AML risk rating must carry a second factor, because the audit trail names them and a name has to mean something.

Role separation is what makes the trail worth having.

The AML boundary

The customer risk rating is a regulated judgement owned by a named MLRO who must defend it to an inspector. Otto pre-populates your board-approved matrix and shows every weighting. It does not score, does not adjudicate a screening hit, and does not decide to onboard.

The scoring is a deterministic matrix, never model-generated.

Credentials never reach the browser

Integration credentials are encrypted at rest and used server-side only. Agent commands are signed and idempotent, so a retry or a double click cannot produce a duplicate invoice or a second payment request.

Webhook signatures verified on every inbound event.

Where the work actually runs

Self-hosted models for anything touching identifiable client data; commercial APIs only for de-identified work. Documents are stored once, by Otto — connected systems keep results, not copies, so there is one retention policy and one deletion path.

One storage boundary means one place to prove deletion.

The AML boundary

Otto prepares. The MLRO decides.

The single most important constraint in the management-company offering. Getting it wrong turns Otto from a tool into a liability.

Otto does

Your MLRO or Compliance Officer does

Extract data from identity, address and corporate documents
Approve the identification
Check expiry dates and name consistency across documents
Judge whether the documentation is sufficient
Call a licensed screening provider for sanctions, PEP and adverse media
Adjudicate every hit — clear false positives, escalate true ones
Pre-populate the CRA matrix using your own documented methodology
Assign and sign the final risk rating
Assemble the CDD file, flag gaps, chase missing documents
Decide to onboard, decline, or apply enhanced due diligence
Track periodic review dates and trigger the refresh
Decide whether to file a suspicious transaction report

Deterministic, never generated

A model producing a score is unauditable and indefensible in an inspection. A transparent matrix showing Seychelles +3, PEP +5, cash-intensive industry +2 = 14 = High is exactly what an inspector wants to see. Otto's value is filling that matrix in from the documents and showing its working.

Screening from a licensed provider

Nobody should be building their own sanctions, PEP or adverse-media list, and we do not. Screening comes through a contracted licensed provider, and that cost is priced into your quote rather than discovered later.

Mauritius has amended its AML legislation in almost every year since exiting the FATF grey list in 2021, and Government Notice No. 112 of 2025 introduced tiered administrative penalties for KYC and reporting failures. We verify the current position with your compliance officer before making any claim in a proposal, and we would rather say “let us check” than be confidently wrong in front of your regulator.

Due diligence

Assembled before
you ask for it.

Your diligence targets mySmart Ltd — the licensed, contracting, insured entity — not a product name. Everything on this list exists, is current, and is one email away.

Company profile and ownership
Written security policy
Data processing agreement (DPA)
Master services agreement (MSA)
Professional indemnity certificate
Backup, restore and RTO statement
Tenant-isolation test results
Client references

Send us your security questionnaire.

We would rather answer it early than have it surface three weeks into a proposal. Most of the answers are already written.