FAQ
You have a number of questions.
Business first, IT second — straight answers, current as of today. If something here is out of date, tell us and we’ll fix it.
For the business
What does this replace?
Nothing. It sits above your existing stack — core, LOS, GRC, BI — and captures the thing none of them hold: the decision itself, with its owner and rationale, at the moment it was made.
How is this different from our GRC platform?
GRC tracks controls, policies, and findings — whether a control exists and who owns it. Decision Governance captures the decision the control was meant to govern: who decided, on what basis, with what authority, and how it turned out. They complement each other; one is about the framework, the other about the call.
Who at our institution actually uses it day to day?
The people already making the calls — lenders, BSA analysts, treasury, compliance owners — file the record inside the workflow they work in. Executives and the board read the exports. There’s no dedicated admin team to staff.
Do our teams have to change how they work?
The record is captured in the flow of the decision, not as a second system to visit. Structured fields, evidence attached from sources you connect — minutes, not paperwork.
What does onboarding one workflow really involve?
One workflow, on your data, in about three days: map the decision type, connect the evidence sources you already have, and name the owners. The free tier starts you on one.
What does it cost, and what’s the free tier?
Productized pricing — three tiers, no negotiation. The free tier is one workflow, one user, watermarked exports, no credit card. See pricing.
You’re a small company — what happens if you go away?
Your records are yours, exportable at any time in open formats — PDF and structured data. Continuity, portability, and exit terms are covered directly in vendor due diligence; ask and we’ll walk you through them rather than leaving it to the third call.
For IT & security
Single-tenant or multi-tenant? Where is data hosted?
Multi-tenant with logical isolation per institution, hosted on DigitalOcean’s US infrastructure. Each institution’s records are segregated and never commingled in export or view.
Read-only against core, or does it write back?
Read-only by design, in both directions. Data comes in as a copy; evidence goes out as a copy. Nothing writes back to your system of record. You can upload data directly or integrate via API.
SSO / SAML support?
Yes — SAML-based SSO is supported today.
What integrations are live today vs. API vs. roadmap?
Evidence can be uploaded directly or connected through our API. Named core and system integrations are added per engagement — ask us for the current list rather than trusting a logo wall.
What’s the vendor-management packet (NCUA 18-CU-09)?
A third-party risk packet mapped to NCUA 18-CU-09 is available on request. It includes the SOC 2 Type II infrastructure certification (inherited from our cloud provider), a data-flow description, business-continuity summary, and exit plan.
SOC 2 status — the honest answer?
The infrastructure we run on is SOC 2 Type II certified, inherited from our cloud provider; that report is available under NDA during vendor review. That’s an infrastructure certification — DataVisuals does not claim its own company-level SOC 2 attestation, and we won’t imply one.
Is our data used to train AI models?
No. Your records are not used to train shared or third-party models. They exist to be the evidence of your decisions — nothing else.
Can we export everything and leave?
Yes, at any time, in open formats — PDF for the record and structured data for the underlying fields. Your evidence trail leaves with you.