Deterministic On-Device Factor Decomposition Β· SEBI RIA Mandate Engine Β· Groq-Powered Multi-Client AI Copilot
Executive Overview β’ Architecture β’ Mobile App β’ Advisor Workstation β’ Quant Backend β’ Security & SEBI β’ Direct Downloads β’ Quick Start
Finora is a unified, institutional-grade portfolio risk and wealth advisory ecosystem designed for high-net-worth investors, family offices, and SEBI Registered Investment Advisors (RIAs).
Traditional wealth apps provide superficial NAV graphs and basic asset allocation charts. Finora penetrates beneath the surfaceβingesting Consolidated Account Statements (CAS), decomposing multi-fund portfolios into raw equity holdings, detecting hidden concentration risks, computing true pairwise portfolio overlaps, and quantifying fee drags across active funds.
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β TRADITIONAL WEALTH APPS β
β "You hold 14 Mutual Funds across 6 AMCs β Great Diversification!" β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
vs.
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β FINORA RISK DESK β
β "71.4% Overlap across 14 funds. Your actual exposure collapses into just 2.3 β
β independent equity bets with a 42.1% hidden concentration in Reliance & HDFC. β
β Annual fee drag: βΉ48,600 with zero alpha diversification." β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Finora is engineered with a strict local-first privacy posture, pairing on-device cryptographic operations with a high-throughput quantitative risk backend:
graph TD
subgraph MobileClient ["π± Finora Mobile (Flutter Engine)"]
CAS["π CAS PDF Statement (CAMS/KFin/NSDL)"]
Parser["π Pure-Dart On-Device CAS Parser"]
Storage["π Hardware Keystore / Secure Enclave"]
Lock["π‘οΈ 6-Min Auto-Lock & Biometric Gate"]
HealthScore["π Health Score (0-100) & Waterfall"]
WhatIf["π What-If Rebalancing Simulator"]
MobileChat["π¬ Groq Client Copilot + Whisper STT"]
CAS --> Parser
Parser --> Storage
Storage --> HealthScore
HealthScore --> WhatIf
Storage --> MobileChat
Lock -.-> Storage
end
subgraph DesktopWorkstation ["π₯οΈ Finora Advisor Workstation (Electron + Vite)"]
Queue["π¨ Executive Action Queue (Severity Matrix)"]
Roster["π₯ Managed Client Roster & Mandates"]
Copilot["π€ Multi-Client FRM AI Copilot (@mentions & #signals)"]
ChatDesk["π¬ Real-Time Client Consultation Chat"]
AuditDesk["π SHA-256 Hash Chain Audit Inspector"]
LookThrough["π Deep Holdings Look-Through & Weight Breakdown"]
Queue <--> Roster
Roster <--> Copilot
Queue <--> ChatDesk
LookThrough <--> AuditDesk
end
subgraph BackendCore ["β‘ Finora High-Performance Quant Backend (FastAPI)"]
Router["π Fast API Router (/api/v1)"]
Engine["βοΈ Deterministic Risk & Attribution Engine"]
GroqService["π§ Groq LLM Multi-Client Tool Execution Loop"]
AuditLedger["π Cryptographic SHA-256 Immutable Audit Chain"]
DB["ποΈ Supabase PostgreSQL (Strict Row-Level Security)"]
Router --> Engine
Router --> GroqService
Engine --> AuditLedger
Router --> DB
end
MobileClient <==> |"TLS 1.3 + SSL Pinning (Paise & Bps JSON)"| BackendCore
DesktopWorkstation <==> |"Institutional Real-Time Session (5s Live Sync)"| BackendCore
The consumer and client-facing application, built with Flutter and themed in a Warm Obsidian (#12100E) and Ember Coral (#FA5A32) luxury aesthetic.
| π 100% On-Device Ingest | π Health Score & Waterfall | π What-If Simulator |
| Parses password-protected CAMS, KFintech, and NSDL statements on-device. Zero PDF or credential upload to the cloud. | Deterministic 0β100 portfolio score with an interactive deduction waterfall revealing exact basis-point penalties. | Simulate trimming overweight securities (e.g. Reliance 42% β 30%) with live volatility reduction previews. |
| π Fund Overlap Matrix | π¬ AI Portfolio Assistant | π‘οΈ Hardware Enclave Vault |
| Look-through overlap exposing equity duplication and fee drag across large-cap and flexi-cap schemes. | Groq-powered conversational assistant with voice transcription (Whisper STT) and actionable prompt chips. | Android Keystore RSA-OAEP + AES-GCM encryption with 6-minute background auto-lock and FLAG_SECURE protection. |
- Dual Authentication: Supabase Email 6-digit OTP verification + Google OAuth sign-in.
- Strict Privacy Mode: System-wide
FLAG_SECUREblocks screen captures and recording of sensitive financial data. - Network Security Configuration: SSL certificate pinning rejecting unauthorized proxy certificates.
A specialized desktop suite for Financial Risk Managers (FRMs), Chief Investment Officers, and SEBI Registered Investment Advisors.
-
π¨ Standardized 3-Column Finding Cards:
- Every risk breach is framed cleanly:
OBSERVED VALUEvs.MANDATE CAPvs.CAPITAL AT STAKE. - Strips distracting marketing prefixes (e.g. converts
"Nippon India Small Cap Fund - Growth Option - Direct Plan"$\rightarrow$ "Nippon India Small Cap"). - Direct shortcuts for Inspect Attribution, Advisory Chat, View Portfolio, and Advance Status.
- Every risk breach is framed cleanly:
-
π€ Multi-Client FRM AI Copilot:
- Connected directly to Groq's high-speed inference engine.
-
@mentionClient Autocomplete: Type@Rahulto instantly pull that client's complete holdings, asset classes, and risk flags into the prompt context. -
#mentionSignal Autocomplete: Type#SINGLE_STOCK_CAPor#PAIRWISE_OVERLAPto analyze mathematical root causes and counterfactual rebalancing. - Interactive Chart Widgets: Renders dynamic SVG/Canvas allocation bars and pie charts directly in the advisor conversation.
- 1-Click Rebalance Proposals: Generates SEBI-compliant rebalance notes ready to copy to clipboard or send directly into client consultation threads.
-
π¬ Real-Time Client Consultation Chat:
- Direct advisor-to-client consultation threads linked to backend episodes (
/api/v1/episodes/{id}/chat). - Quick wealth advisory response chips ("Reviewing Allocation", "Rebalance Proposal", "Request Confirmation").
- Real-time 1.5-second polling while consultation modals are active.
- Direct advisor-to-client consultation threads linked to backend episodes (
-
π Cryptographic SHA-256 Audit Trail:
- Every advisory action, mandate change, and client consent is recorded in a tamper-evident SHA-256 cryptographic hash chain.
- 1-Click Re-Verify Chain button validates historical ledger integrity in real time.
-
β‘ Continuous Background Sync:
- Auto-refreshes the entire book of business and findings queue every 5 seconds as clients upload statements on mobile.
The core microservice orchestrating data normalization, risk calculations, and advisory communication.
-
Framework: Python 3.12, FastAPI, and
uv. - Database: Supabase PostgreSQL with strict Row-Level Security (RLS) ensuring complete multi-tenant advisor-client isolation.
-
Rule Engine: Deterministic math calculating HHI concentration, effective number of bets (
$N_{eff}$ ), active share, and tax-loss harvesting opportunities. -
AI Tool Execution Loop: Multi-tool calling agent with automated schema execution (
get_firm_overview,get_all_clients,get_client_portfolio,get_signal_attribution,render_chart,draft_rebalance_order).
| Security Dimension | Implementation Standard |
|---|---|
| Hardware Key Storage | flutter_secure_storage storing keys in Android Keystore and iOS Secure Enclave using RSA-ECB-OAEP + AES-GCM-256 |
| Biometric Gate | local_auth platform authentication (Biometrics / Face ID with device PIN fallback) |
| Inactivity Auto-Lock | 6-minute background idle lifecycle timer requiring biometric re-authentication upon resume |
| Screen Protection | FLAG_SECURE applied natively in Android MainActivity.kt to block screenshots & screen recordings |
| Network Security | Custom Android network_security_config.xml enforcing strict domain pinning |
| SEBI Audit Compliance | Cryptographic SHA-256 hash chains on every advisory override and consultation message |
| Data Privacy | CAS statement PDFs are parsed on-device in pure Dart. No raw statements ever touch cloud servers |
GitHub Actions CI/CD automatically compiles, tests, and publishes standalone packages on every tagged release:
| Artifact | Format | Description |
|---|---|---|
| 1-Click Setup Installer | .exe (NSIS) |
Finora-Advisor-Workstation-Setup-v1.0.0.exe (Automatic install with Desktop & Start Menu shortcuts) |
| Standalone Portable | .exe |
Finora-Advisor-Workstation-Portable-v1.0.0.exe (Zero-installation portable binary) |
| Zip Archive | .zip |
Finora Advisor Workstation-1.0.0-win.zip (Full standalone directory distribution) |
| Artifact | Format | Target Architecture |
|---|---|---|
| Universal Android APK | .apk |
Universal package compatible with all ARM & x86 Android devices |
| ARM64-v8a Android APK | .apk |
Optimized 64-bit package for modern Android smartphones |
| Google Play App Bundle | .aab |
Official production release bundle for Google Play Store |
| iOS IPA Payload | .ipa |
Unsigned iOS distribution for TestFlight or sideloading |
π Download Latest Binaries from GitHub Releases
- Flutter SDK:
^3.47.0 - Node.js:
^20.0.0 - Python:
^3.12 - uv: Fast Python package installer
cd finora_app
# 1. Install Flutter dependencies
flutter pub get
# 2. Configure environment
cp .env.example .env
# 3. Launch on connected device / emulator
flutter runcd finora_desktop
# 1. Install dependencies
npm install
# 2. Start development mode with Vite + Electron
npm run dev
# 3. Compile Windows Setup Installer (.exe) & Portable (.exe)
npm run build:execd finora_backend
# 1. Create and activate virtual environment
uv venv
.venv\Scripts\activate # On Windows
# source .venv/bin/activate # On Linux/macOS
# 2. Install dependencies
uv pip install -e .
# 3. Launch FastAPI server with auto-reload
uv run uvicorn app.main:app --host 0.0.0.0 --port 8000 --reloadInteractive OpenAPI Swagger documentation will be available at http://127.0.0.1:8000/docs.
Finora/
βββ finora_app/ # π± Mobile Application (Flutter)
β βββ lib/
β β βββ core/services/ # Secure Storage, Biometrics, Supabase, Groq Assistant
β β βββ screens/entry/ # Splash, Onboarding, Email OTP Sheet, PIN Gate
β β βββ screens/main/ # Portfolio Health Waterfall, Overlap Matrix, Simulator
β β βββ widgets/ # AppLockWrapper, Metric Cards, Charts
β βββ android/ # FLAG_SECURE MainActivity & Network Security Config
β
βββ finora_desktop/ # π₯οΈ Desktop Advisor Suite (Electron + Vite)
β βββ src/main/ # Electron Main Process & Window Controls
β βββ src/renderer/ # FRM Workstation UI, Multi-Client AI Copilot, Audit Trail
β βββ package.json # electron-builder NSIS Setup & Portable configuration
β
βββ finora_backend/ # β‘ Quant Backend Microservice (FastAPI)
β βββ app/api/v1/endpoints/ # Queue, Roster, Advisor AI Copilot, Audit Ledger, Chat
β βββ app/services/ # Factor Decomposition, Groq Tool Loop, Hash Chain
β βββ app/db/ # SQLAlchemy Models & Supabase Pooler Sessions
β
βββ .github/workflows/ # π CI/CD Multi-Architecture Release Pipeline
βββ release.yml # Automated APK, AAB, IPA, NSIS .exe, and GitHub Release
Important
Finora is a quantitative risk analysis and portfolio diagnostics engine.
- All factor decompositions, overlap matrices, and health scores are mathematical observations derived strictly from reported portfolio holdings against pre-configured risk parameters.
- The AI Copilot operates under strict non-recommendation guidelines, presenting factual variance and attribution without providing unsolicited trading advice.
- All client-specific parameter overrides require explicit justification logging stored within an immutable cryptographic audit ledger in compliance with SEBI Registered Investment Advisor (RIA) governance standards.
Distributed under the MIT License. See LICENSE for more information.
