Key facts
| RAG endpoints | POST /v1/embeddings, POST /v1/rag/collections and POST /v1/rag/query |
| Citations | Ranked chunks return with source attribution for verification |
| Audit logs | Per-request model, tokens, latency, user and region with SIEM export |
| Access control | Scoped keys and per-collection isolation; RBAC and SSO on enterprise |
| Residency | Region selection plus VPC, on-prem and air-gapped options |
| Data handling | Per-collection encryption at rest; API data is not used to train models |
| Formats | PDF, DOCX, TXT, MD and HTML |
| Product status | Live |
TL;DR
- Every answer must trace to a source passage; unsourced finance answers are unusable.
- Separate research, filings and internal policy into different collections.
- Audit logs plus citations create a reviewable record of who saw what.
- Residency and retention must be settled before sensitive documents load.
- Never present model output as investment advice; keep humans in the loop.
How it works, step by step
- Classify corpora: public filings, licensed research, internal policy and client data.
- Choose a deployment plane and region that matches each classification.
- Ingest with metadata such as filing date, entity, period and source.
- Require citations and validate them before answers reach analysts.
- Enable audit logging and connect it to your compliance tooling.
- Define retention and deletion for closed reviews and engagements.
- Run an evaluation set of real analyst questions before rollout.
Try it yourself
Open the AI data residency checklist →
Where RAG helps in finance
Finance work is document-heavy and citation-driven. Analysts read filings, research reports, credit agreements and internal policy, then need to quote them accurately. Retrieval-grounded search shortens that loop: ask a question, get the relevant passage with a source reference, and verify it in seconds rather than opening dozens of PDFs.
Common uses include earnings document review, policy and procedure lookup, contract clause search, and internal knowledge for operations teams. In each case the value is not a fluent paragraph; it is finding the right passage and knowing where it came from.
Controls finance teams need first
Access control comes before ingestion. Licensed research, material non-public information and client records should live in separate collections with scoped keys, so a query from one team cannot reach another team's corpus. Enterprise controls including RBAC, SSO and per-collection encryption map cleanly onto that model.
Audit logs provide the second layer: per-request records of model, tokens, latency, user and region, exportable to your SIEM. Combined with chunk-level citations, they let compliance reconstruct what was asked, which sources were returned and who asked.
Handling numbers, tables and periods
Financial documents are full of tables, footnotes and period comparisons, which are the hardest content for retrieval. Table rows split across chunks lose their headers and meaning, so preserve structure where possible and attach metadata such as entity, period and document type. Hybrid retrieval helps when an exact figure, ticker or filing reference matters.
Always keep a human in the loop for anything that could be read as advice. RAG is a research accelerator that cites its evidence; it is not a recommendation engine, and the interface should make that boundary obvious.
Deploying on Plugsky
Plugsky keeps retrieval and generation on one OpenAI-compatible API: collections for ingestion and search with keyword, vector and hybrid modes, optional reranking, and citations on every response. Deployment can be managed with a region lock, or private through VPC, on-prem and air-gapped options when data cannot leave your perimeter.
Review the data residency checklist with your compliance team, then start free with plugsky-micro and plugsky-lite for evaluation or the 14-day full-access trial. Current plans are on the live pricing page.
Honest comparison
| Requirement | Plugsky RAG | Shared search tool | General chatbot |
|---|---|---|---|
| Citations | Chunk-level source references | Document links | Usually none |
| Access control | Collections, scoped keys, RBAC and SSO | Tool permissions | Uncontrolled |
| Audit trail | Per-request logs with SIEM export | Search history | Chat history only |
| Residency | Region choice and private deployment | Provider-dependent | Provider-dependent |
| Data use | API data not used to train models | Varies | Varies |
Frequently asked questions
Can RAG handle financial tables?
It can retrieve passages that contain tables, but tables are difficult because rows lose meaning when split. Preserve structure where possible and attach period and entity metadata.
Is RAG output investment advice?
No. Treat it as a research tool that cites sources. Keep a human in the loop for any decision and make that boundary visible in the interface.
How do we keep research separate?
Use separate collections for licensed research, filings and internal policy, with scoped keys so each team can only reach its own corpora.
What audit evidence is available?
Per-request audit logs cover model, tokens, latency, user and region with SIEM export, and citations show which chunks supported each answer.
Is there a free plan?
Yes. The free plan includes plugsky-micro and plugsky-lite with 2 API keys and no credit card, and a 14-day full-access trial is available.
How is pricing structured?
Self-serve plans are flat monthly with unlimited fair-use usage and no per-token charges or overage fees. Enterprise deployments are quoted separately.