Hard-coded compliance. Cannot be overridden. By design.

COMPLIANCE isn’t a checkbox.

It’s the architecture. Hard-coded, runtime-enforced, applied to every turn of every conversation — without ever asking the subscriber to acknowledge it mid-flow.

How it works

The compliance engine is part of the platform — not a layer on top of it.

CoolBiz®’s compliance logic is hard-coded into the platform core. It cannot be overridden by a system prompt, by training data, by the subscriber’s instructions, or by anything an end-user types into the chat surface. The AI still functions as an AI — full conversational range, full feature set — but the compliance layer refuses to let it lie about what it saw or expose what the law says must stay protected.

Conditional logic runs invisibly behind every conversation. When sensitive data appears — a card number, a national identifier, a clinical diagnosis — the engine masks it before it ever reaches a foundation-model provider. Country-specific identifier recognition fires automatically based on the user’s detected language and locale.

The result: a chatbot that talks like a chatbot and complies like an enterprise system. Audit-ready by design. Multilingual by default. Operating across 195 countries with one engine.

Coverage Tiers

Where CoolBiz® protects.

Three coverage tiers describe how the platform engages with each jurisdiction. The full list — by country, by framework, by industry — is one click away.

Fully Covered

Named-framework coverage

Explicit, named compliance with the privacy and data-protection law of each region. ISO 27001:2022 controls active across all covered jurisdictions. Country-specific pattern recognition implemented where the law requires it.

Covered by Default

Global unified masking

Countries without active national privacy laws are protected under CoolBiz®’s ISO-aligned strictest-policy enforcement. Universal PII masking, sensitive-data redaction, 30-day data purge, encryption in transit and at rest.

Expansion Tier

Vertical Pro Tier rollout

Jurisdictions with emerging or unique data frameworks, rolling out alongside CoolBiz®’s Vertical Pro Tier launches. Each requires a per-subscriber attestation flow at connection time.

Industry Coverage

Verticals where compliance has shape.

Industry tiles below describe coverage outcomes — not the specific legal acronyms. The granular per-industry framework matrix is available on request to qualified subscribers.

Healthcare

Patient communications, scheduling, intake. Mental health, reproductive, addiction-care heightened sensitivity tier.

$

Finance & Banking

Account, card, and transaction protection. Card data masked in real time and never stored.

Legal Services

Privileged communications, case data, client confidentiality. Bar-rule compliant by design.

Insurance

Claims, policy data, member IDs. Vertical Pro Tier identifiers per state license requirements.

Real Estate

Buyer/renter PII, mortgage qualification, FCRA-protected credit references.

HR & Employment

Employee records, payroll, GDPR Article 9 special categories, works council rules.

Education

Student communications outside FERPA scope, admissions, campus services.

Retail & E-Commerce

Consumer PII, payment data, cookies and tracking under all major frameworks.

Vertical Pro Tiers

Add-ons for the industries that need more.

Pro Tiers layer industry-specific APIs, identifier prompts, role-based gating, and CRM/database read-write capability onto the base subscription. Available as consumption-based add-ons with applicable minimum monthly commitments.

Healthcare-Pro

HIPAA flows + medical CRM access

Athenahealth, Dentrix, and other BAA-eligible CRMs auto-connect with role assignment. NPI, DOB and specialty identifier prompts. Healthcare-tier STT for medical vocabulary.

Legal-Pro

Bar-compliant client communications

State bar identifier prompts. Privileged-communication handling. Practice-management CRM integrations as available.

Finance-Pro

Series 7 / CFP / CPA flows

License-number and broker-dealer affiliation identifiers. GLBA-protected NPI data handling. Connected CRM detection at the API tier.

Insurance-Pro

Lines-of-authority verification

State license + line-of-authority identifiers. AgencyBloc and other carrier CRMs gated by plan-tier detection.

Pro Tier subscribers can upload structured data files (Excel, CSV) for the AI to inject into connected systems, and pull records back into the chat surface or as downloadable Excel / PDF / Word artifacts — all gated by role-based access. CRMs detected as below-BAA-eligible tier are filtered out automatically.