SiteGPT · Financial Services
Make AI your customer service agent, without the guesswork
In finance, a confident wrong answer is a liability. SiteGPT answers from the policy documents and product pages you approve, cites where it got each answer, and routes anything binding to a person. It explains your products. It does not advise a customer on theirs.
- Grounded in your content
- Educates, never advises
- Human handoff for regulated cases
- SOC 2 Type II and GDPR
SOC 2 Type II examination completed with zero exceptions noted. GDPR certified. Conversations are never used to train AI models.
- Account and loan requirements
- What a policy covers
- Fees, applications, and next steps
Powered by
SiteGPT
Why it matters
Support is a sales channel in finance. So is a wrong answer.
Loans, insurance, and investment products need explaining before anyone converts. The risk is that the same assistant that explains a product can invent one, which grounding is built to prevent.
A generic GPT bot
- Answers from a frozen memory of the internet it cannot check
- Fills a knowledge gap with the most likely-sounding text
- Can invent a rate, a term, or a commitment you never made
- No source to point a compliance reviewer at
With SiteGPT
- Retrieves from your approved documents, then answers from those
- Declines and routes when your content does not cover it
- Explains products and fees without advising the customer
- Cites where each answer came from, so it can be checked
How it works
Grounded, guarded, and routed
Ground it in your documents
Train the bot on your product pages, policy documents, and FAQs. It answers from those, not from a model's open-internet memory.
Set the rules and route list
One owner-set instruction keeps the bot on education, and a route list sends eligibility, disputes, and advice requests to a person.
Answer, cite, escalate
The bot answers with citations, declines when content is thin, and hands binding conversations to a human with the transcript.
Grounding
Grounded answers, not confident guesses
- How the retrieve, ground, generate loop works is in what RAG is.
- Citations so an answer can be checked, and a decline when content is thin
- The four controls that catch the residual risk are in how to stop a chatbot hallucinating.
Educate, not advise
The line that keeps a finance bot lawful
- An owner-set instruction keeps every answer on education
- A route rule sends any request for advice to a licensed person
- Product questions convert; advice questions escalate
The educate-versus-advise test
“What does term life insurance cover?”
Education → the bot answers
“Should I buy term or whole life?”
Advice → routed to a person
Human handoff
A person for anything binding
- Escalation is on demand, with the full transcript, on every plan
- Lead qualification: the bot informs and collects, a human decides
- How platforms differ on handoff is compared in the best AI chatbots with human handoff.
Enterprise-grade security
Your data is encrypted, access-controlled, and never used to train AI models. There is no EU residency: transfers rely on SCCs with Article 27 representatives, and a DPA is executed for Enterprise at onboarding.
The full picture, subprocessor by subprocessor, plus the DPA, is on the compliance hub.
“We've got the bot dialled in. We're using GPT-4, have an avenue for escalations to Zendesk, and so far I have no complaints.”

Brent Burrows II
Vice President, Retail and Sales at CBS Bahamas
FAQ
Questions a financial services buyer asks
How does the chatbot avoid giving wrong financial answers?
It answers only from the content you approve, using retrieval-augmented generation: it retrieves the relevant passage from your policy documents and generates the answer from that, rather than from a model's memory of the open internet. When your content does not cover a question, the bot is instructed to say so and route to a person rather than guess. Grounding is the largest single accuracy lever, though it is not a compliance control on its own.
Can it give financial or investment advice?
No, and it should not be set up to. The bot explains your published policies, products, and processes: how a loan application works, what a policy covers, what a fee is. It does not tell a specific person what to buy or how to invest. Personalized advice is a regulated activity, so the design keeps the bot on education and routes any request for advice to a licensed person.
What happens with a regulated or high-stakes conversation?
It goes to a human. Anything binding or irreversible, an eligibility decision, a complaint, a dispute, or a request for advice specific to someone's situation, is handed off on demand with the full transcript. Escalation is triggered by the visitor asking, not by the AI guessing at sentiment, and it works on every plan.
Is SiteGPT secure enough for a financial services review?
SiteGPT has completed a SOC 2 Type II examination covering the security, availability, and confidentiality trust service criteria, with zero exceptions noted, and the report is available to Enterprise customers through the trust portal. Data is encrypted in transit and at rest, and customer conversations are never used to train AI models. SiteGPT is also GDPR certified by DPLMC International.
Where is data stored, and is there EU residency?
There is no EU data residency option and none is planned. Subprocessors are primarily in the United States, with Cloudflare operating globally. Transfers of EU, EEA, and UK personal data rely on the European Commission's Standard Contractual Clauses, and SiteGPT has appointed Article 27 representatives in both the EU and the UK. A DPA can be generated and is executed for Enterprise customers at onboarding.
Can it help qualify loan or insurance leads?
Yes. The bot can answer product questions, walk a visitor through what an application needs, and capture the details your team asks for, then hand a qualified inquiry to a person. It informs and collects, and a human makes the decision. Lead records persist until you delete them.
Bring your policy documents, and the review can start there
The accuracy story is only as good as the content behind it, so the useful first step is to ground the bot in your real product and policy pages and test the answers your team is asked most.
- SOC 2 Type II
- GDPR certified
- No training on your data