IPS(k)
Investment Policy Statement Builder
Fund(k) Scoring
IPS Sections
    Completion
    0%
    Live IPS Preview Auto-updating
    Begin answering questions on the left to see your IPS build in real time
    πŸ“‹ Sample Plan Scenarios
    Pre-built IPS configurations demonstrating different governance patterns and plan complexities

    Each scenario pre-fills every field across all 8 IPS sections β€” governance structure, investment philosophy, menu design, selection criteria, monitoring framework, fee policy, and participant services. Select a scenario to explore, then customize any field before generating your IPS document.

    πŸ”’
    Security & Trust Center

    Enterprise-grade protection for your retirement plan data

    βœ“

    All Systems Secure

    Your data is protected with enterprise-grade security and never used for AI training.

    πŸ”Œ API-First Architecture β€” Not a Chatbot

    IPS(k) connects to Anthropic's enterprise API, not consumer chatbots. When you use "Enhance with Claude AI," your plan metadata is sent via the enterprise API tier β€” never used for training, never stored in shared conversation logs, and never reviewed by humans. All form data stays in your browser until you explicitly generate a document.

    How Your Data is Protected
    πŸ“
    Form Data
    β†’
    πŸ–₯️
    Browser
    β†’
    πŸ”
    TLS 1.3
    β†’
    πŸ€–
    Claude API
    β†’
    πŸ“„
    IPS Doc
    β†’
    πŸ—‘οΈ
    Auto-Delete
    Core Security Features
    🚫
    Zero Training Guarantee
    Anthropic's enterprise API never uses your inputs or outputs to train models. Contractually guaranteed.
    πŸ”
    End-to-End Encryption
    AES-256 at rest, TLS 1.3 in transit. Data encrypted at every stage between your browser and AI provider.
    ⏱️
    Zero Data Retention
    Anthropic offers Zero Data Retention (ZDR). AI queries are processed and immediately discarded β€” nothing stored.
    πŸ‘οΈβ€πŸ—¨οΈ
    No Human Review
    Unlike consumer chatbots, enterprise API data is never reviewed by humans at Anthropic.
    Compliance Certifications
    πŸ†
    SOC 2Type II Certified
    🌐
    ISO 27001Information Security
    πŸ₯
    HIPAABAA Available
    πŸ‡ͺπŸ‡Ί
    GDPRCompliant
    πŸ‡ΊπŸ‡Έ
    CCPACompliant
    πŸ’‘ Tip: See the Compliance tab for detailed regulatory alignment information.

    IPS(k) uses Anthropic's enterprise Claude API exclusively for the "Enhance with Claude AI" feature. Your plan data is never used for training and has strict retention limits.

    Consumer Chatbot vs. Enterprise API
    Security AspectConsumer ChatbotsEnterprise API (What We Use)
    Training on your data❌ May train on conversationsβœ“ NEVER trains on your data
    Data retention❌ Stored indefinitelyβœ“ Zero Data Retention available
    Human review❌ May review for qualityβœ“ No human review of content
    Privacy policies❌ Consumer privacy termsβœ“ Enterprise DPA / BAA available
    Compliance❌ Limited certificationsβœ“ SOC 2, ISO 27001, HIPAA-ready
    Our AI Provider
    Claude

    Anthropic Claude

    Claude Sonnet 4 API
    SOC 2 Type II ISO 27001 HIPAA
    • Zero Data Retention (ZDR) option
    • No training on API data β€” ever
    • 30-day max retention (without ZDR)
    • Enterprise DPA available
    • Used only for optional "Enhance with Claude AI" β€” local template engine requires no AI
    πŸ’‘ Note: IPS(k)'s built-in "Generate IPS Document" button uses a local template engine that requires no AI at all β€” your data never leaves the browser. The "Enhance with Claude AI" button is optional and the only feature that calls the Anthropic API.
    πŸ”„ How Your Data Flows

    Understanding exactly what data is sent where gives you confidence in our security architecture.

    IPS(k) Secure Processing Pipeline
    πŸ“
    Your Inputs
    Plan metadata
    β†’
    πŸ–₯️
    Browser
    Form fields
    πŸ”’β†’
    πŸ€–
    Claude API
    AI enhancement
    πŸ”’β†’
    πŸ“„
    IPS Document
    Generated text
    β†’
    πŸ’Ύ
    Export
    HTML / PDF / Word
    πŸ“¦ What Data Is Sent
    βœ…
    Plan Metadata Only
    Only plan governance choices (plan type, committee structure, fee policy, etc.) are sent to Claude. No participant data, no SSNs, no account balances.
    πŸ”
    Encrypted in Transit
    All data uses TLS 1.3 encryption between your browser and Anthropic's API endpoint.
    πŸ–₯️
    Browser-Only Processing
    All form data, the IPS preview, and export generation (HTML, PDF, Word) happen entirely in your browser. No server stores your inputs.
    πŸ—‘οΈ
    Nothing Stored
    IPS(k) has no backend database. When you close the tab, your data is gone. Exports are generated client-side and saved to your device.
    ⚠️ Important: No files are uploaded. IPS(k) collects plan governance decisions via form fields β€” no documents, no participant data, no PII. The "Enhance with Claude AI" feature sends only plan metadata (company name, plan type, policy choices).
    βš–οΈ Regulatory Compliance
    βš–οΈ
    ERISA
    Designed for fiduciary compliance. The IPS documents the prudent process for investment selection, monitoring, and fee oversight required by ERISA Sections 402 and 404.
    πŸ›οΈ
    DOL Fiduciary Rule
    Transparent methodology supports documented, objective investment monitoring processes aligned with DOL's emphasis on procedural prudence.
    πŸ“‹
    DOL Cybersecurity
    Aligned with DOL's cybersecurity guidance for plan fiduciaries. Encryption, access controls, and no unnecessary data retention.
    πŸ‡ͺπŸ‡Ί
    GDPR
    Data minimization by design. No PII collected. No unnecessary retention. Clear data processing purposes. DPA available from Anthropic.
    βœ… Security Controls Implemented

    πŸ” IPS(k) Security Checklist

    βœ“ No PII collected or stored
    βœ“ Encrypted transmission (TLS 1.3)
    βœ“ No AI training on plan data
    βœ“ SOC 2 Type II certified providers
    βœ“ No backend database or server storage
    βœ“ Client-side export generation
    πŸ“„ Documentation: For fiduciary due diligence, SOC 2 reports are available under NDA from Anthropic's trust center.
    ❓ Frequently Asked Questions

    No. IPS(k) uses Anthropic's enterprise API tier. API data is NOT used to train models. Contractually guaranteed. Additionally, the built-in template engine generates IPS documents without any AI β€” the Claude enhancement is entirely optional.

    IPS(k) has no server-side storage. All form data lives in your browser's memory and is gone when you close the tab. If you use "Enhance with Claude AI," Anthropic offers Zero Data Retention β€” processed and immediately discarded.

    No. Enterprise API data is NOT subject to human review. Only automated systems process the data briefly before deletion.

    None. IPS(k) only collects plan-level governance decisions: plan type, committee structure, investment philosophy, fee policy, etc. No participant SSNs, names, balances, or any PII is ever collected, processed, or stored.

    A structured prompt containing your plan governance choices β€” company name, plan type, committee frequency, investment philosophy, fee policy selections, etc. This is plan metadata, not participant data. Claude generates the IPS prose and returns it. The prompt and response are then discarded under Anthropic's retention policy.

    Yes. The "Generate IPS Document" button uses a built-in template engine that runs entirely in your browser. No data leaves your device. The "Enhance with Claude AI" button is a separate, optional feature.

    Anthropic: SOC 2 Type II, ISO 27001, HIPAA BAA available. Cloudflare (infrastructure): SOC 2 Type II, ISO 27001, PCI DSS Level 1, FedRAMP.

    πŸ”— Anthropic Trust πŸ”— Cloudflare Trust