---
title: "The architecture of trust | Whitepapers | SurrealDB"
description: "Why the data foundation - not the model - is the real bottleneck for financial AI, and the architecture that satisfies SR 11-7, BCBS 239, and the EU AI Act."
url: https://surrealdb.com/whitepapers/architecture-of-trust
---

WHITEPAPER

# The architecture of trust

Data infrastructure for the AI age in financial services

Read the whitepaper

Enter your email to read “The architecture of trust”.

1. ![Babcock](https://surrealdb.com/assets/static/babcock.lo4rnVg1.svg)
2. ![ING](https://surrealdb.com/assets/static/ing.X3I6S3_V.svg)
3. ![British Airways](https://surrealdb.com/assets/static/british-airways.KEsZiwV-.svg)
4. ![Nvidia](https://surrealdb.com/assets/static/nvidia.DaIEuMil.svg)
5. ![Apple](https://surrealdb.com/assets/static/apple.D5pq4flY.svg)
6. ![SpaceX](https://surrealdb.com/assets/static/spacex.CQJEk-IL.svg)
7. ![Samsung](https://surrealdb.com/assets/static/samsung.CH-vQgnb.svg)
8. ![adidas](https://surrealdb.com/assets/static/adidas.DdTC5qhk.svg)
9. ![Tencent](https://surrealdb.com/assets/static/tencent.paQmLxyy.svg)
10. ![Alibaba](https://surrealdb.com/assets/static/alibaba.B16idgfM.svg)
11. ![PolyAI](https://surrealdb.com/assets/static/poly-ai.c3w_fAg6.svg)
12. ![Later](https://surrealdb.com/assets/static/later.Ds736jFO.svg)
13. ![Verizon](https://surrealdb.com/assets/static/verizon.BI7CajdX.svg)
14. ![Liberty Mutual](https://surrealdb.com/assets/static/liberty-mutual.B7qOU1pd.svg)
15. ![Walmart](https://surrealdb.com/assets/static/walmart.BjDg_Sr8.svg)
16. ![Carrier](https://surrealdb.com/assets/static/carrier.D21gC6NX.svg)
17. ![Saks Fifth Avenue](https://surrealdb.com/assets/static/saks-fifth-avenue.COIDpLSb.svg)
18. ![San Francisco Compute Company](https://surrealdb.com/assets/static/sfcc.B7jlImq4.svg)
19. ![Shield AI](https://surrealdb.com/assets/static/shield-ai.pINZ0KJr.svg)
20. ![Wix](https://surrealdb.com/assets/static/wix.DvHhmoBi.svg)

Tobie Morgan Hitchcock, Co-founder and Chief Executive Officer, SurrealDB

Financial institutions are deploying AI faster than the data infrastructure beneath it can support. This paper makes the architectural case that the dominant failure mode of financial AI is not the model - it is the fragmented data estate underneath it. It sets out the three architectural commitments a trustworthy financial AI platform requires, and how a unified, transactional, governed foundation satisfies SR 11-7, the EU AI Act, BCBS 239, MiFID II, and DORA structurally rather than procedurally.

Financial services

AI governance

Regulatory compliance

Agent Memory

## Key takeaways

Why only 2 of 31 global systemically important banks are fully BCBS 239 compliant after twelve years - and why the root cause is architectural, not procedural.

The three non-negotiable commitments a financial AI platform requires: a unified multi-model substrate, structured agent memory with provenance, and governance by design.

How bi-temporal data, record-level access control, and write-back audit trails satisfy SR 11-7, the EU AI Act, BCBS 239, MiFID II, and DORA structurally rather than procedurally.

Five questions every institution should answer before choosing between open infrastructure and closed AI platforms.

A reference architecture mapping each layer - from object storage to reasoning model - to the financial AI capability it enables.

## What's inside

A note from the CEO

Why financial AI keeps failing at the foundation

Why financial data is structurally different

What the architecture of trust requires

Agent Memory: Agent Memory built into the database

SurrealDB v3.1: the current platform

Open infrastructure vs. closed platforms: five questions

The reference architecture

Four principles for the AI age in financial services

Key regulatory frameworks referenced

![The architecture of trust](https://surrealdb.com/assets/static/architecture-of-trust.CPQIfbr_.avif)

GET STARTED

## Build on the unified data layer

Documents, graphs, vectors, and time-series in one ACID transaction - from object storage to agent memory.

![Samsung](https://surrealdb.com/assets/static/4c58b81e7b3c9466.C_Hv0eml.svg)![NVIDIA](https://surrealdb.com/assets/static/nvidia.DaIEuMil.svg)![Apple](https://surrealdb.com/assets/static/f7dc2519e0d212bc.Cn8MYAK7.svg)![Verizon](https://surrealdb.com/assets/static/18b99996c689000f.B5PQ-nI9.svg)![Tencent](https://surrealdb.com/assets/static/401d8346058682c8.DqM87mst.svg)

SOC 2 Type 2

GDPR

Cyber Essentials Plus

ISO 27001

[Start free with SurrealDB](https://studio.surrealdb.com/current/instances/deploy) [Explore the platform](https://surrealdb.com/surrealdb)

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://surrealdb.com"},{"@type":"ListItem","position":2,"name":"Whitepapers","item":"https://surrealdb.com/whitepapers"},{"@type":"ListItem","position":3,"name":"The architecture of trust","item":"https://surrealdb.com/whitepapers/architecture-of-trust"}]}
```

```json
{"@context":"https://schema.org","@type":"Organization","name":"SurrealDB","url":"https://surrealdb.com","logo":"https://surrealdb.com/assets/static/logo.BG7_TG2b.svg","description":"SurrealDB is the unified data layer for AI. A multi-model database for documents, graphs, vectors, and time-series.","foundingDate":"2022","legalName":"SurrealDB Ltd","identifier":{"@type":"PropertyValue","propertyID":"GB-COH","value":"13615201"},"address":{"@type":"PostalAddress","streetAddress":"3rd Floor, 1 Ashley Road","addressLocality":"Altrincham","addressRegion":"Cheshire","postalCode":"WA14 2DT","addressCountry":"GB"},"contactPoint":[{"@type":"ContactPoint","contactType":"customer support","email":"support@surrealdb.com","url":"https://surrealdb.com/contact","availableLanguage":"English"},{"@type":"ContactPoint","contactType":"sales","email":"info@surrealdb.com","url":"https://surrealdb.com/contact","availableLanguage":"English"},{"@type":"ContactPoint","contactType":"security","email":"security@surrealdb.com","url":"https://surrealdb.com/.well-known/security.txt","availableLanguage":"English"},{"@type":"ContactPoint","contactType":"legal","email":"legal@surrealdb.com","url":"https://surrealdb.com/legal","availableLanguage":"English"}],"hasCertification":[{"@type":"Certification","name":"SOC 2 Type 2"},{"@type":"Certification","name":"GDPR"},{"@type":"Certification","name":"Cyber Essentials Plus"},{"@type":"Certification","name":"ISO 27001"}],"owns":[{"@type":"SoftwareApplication","name":"SurrealDB","url":"https://surrealdb.com/surrealdb"},{"@type":"SoftwareApplication","name":"Agent Memory","url":"https://surrealdb.com/agent-memory"}],"knowsAbout":["multi-model databases","document databases","graph databases","vector search","time-series databases","SurrealQL","Agent Memory","real-time databases","embedded databases","context layer","graph ontology","distributed database","knowledge graphs","distributed transaction protocols","highly-scalable databases"],"sameAs":["https://www.wikidata.org/wiki/Q124316308","https://github.com/surrealdb/surrealdb","https://twitter.com/surrealdb","https://www.youtube.com/@surrealdb","https://www.linkedin.com/company/surrealdb","https://discord.gg/surrealdb","https://www.reddit.com/r/surrealdb","https://www.instagram.com/surrealdb","https://medium.com/surrealdb","https://dev.to/surrealdb"]}
```
