Ava removes client identity from a financial document, so the work can be done in the best AI available.
Then it puts the identity back into the finished work. The document leaves. The client’s name does not.
The tools are good enough. The files cannot be uploaded.
A commercial credit file is a stack of dense documents. Statements, appraisals, rent rolls, tax records. Reading them properly and writing the analysis is hours of skilled work per deal. Today’s AI does that work well, and it does it in minutes.
Those documents also carry client names, home addresses, social insurance numbers, business numbers and bank account details. A firm handling client credit files does not put client credit files on somebody else’s platform. So the practical choice has been to do the work by hand, or take a risk that should not be taken.
The usual answer is to build a private AI application so nothing leaves the walls. That answer solves the privacy problem by discarding the reason the tools are valuable, and it commits a small firm to out-building companies whose entire business is staying ahead of it.
Ava takes the opposite approach. What identifies a client and what makes a deal analyzable are two different things sitting in the same document. Names, addresses and account numbers identify. Loan amounts, appraised values, coverage ratios, rates and three years of margins are what make it analyzable. Remove the first, leave the second exactly as written, and the AI still sees the whole financial picture. It simply does not know whose deal it is.
One boundary, crossed twice.
Ava contains no chat and no reasoning model. It is a gateway, not an AI application. The intelligence stays outside the perimeter, where it is built and maintained by people who do that for a living. What crosses is a de-identified derivative. What never crosses is the key.
Raw client documents stay on Canadian infrastructure under your control. Only de-identified derivatives cross the border.
The same document, before and after.
Every dollar figure, rate, ratio and date is left exactly as it was. That is deliberate. The numbers are what make the analysis possible, and the numbers are not what identifies the client.
Built for the questions that are coming.
OSFI’s Guideline E-23 on model risk management takes effect on 1 May 2027, and it defines a model broadly enough to include AI tools that materially affect decisions. It binds federally regulated institutions directly. Independent firms are reached a different way: through B-10 third-party risk, when the institutions they serve begin asking their channel what AI touches client data, and through the privacy and professional obligations that already apply.
Those questions arrive before the deadline, not after. Ava is built so that a firm of any size below enormous has an answer.
Ava 1.0 in 2026.
Ava is not a concept. The engine is built and it runs. It is also not finished, and this page distinguishes the two.
Ava does not compete with the AI. It removes an obstacle to using it. As the models improve, the work routed through the gateway becomes more valuable, which makes the gateway more valuable. They rise together rather than one replacing the other.
It does not care which model you use, so there is no commitment and nothing to rebuild when something better appears. And the constraint it solves does not expire: client confidentiality obligations do not relax as technology improves.
Building a private AI application is a bet that a small firm can out-build a frontier lab. Ava makes the opposite bet. Every improvement those companies ship arrives at your desk for free.
A click-through of the application as it runs locally. No engine and no model run in that page.