# Acin > Acin is a London-based operational and non-financial risk (NFR) data company for financial > services, founded in 2018 and acquired by regulatory-intelligence firm CUBE in June 2025. Its > platform standardises a bank's process, risk and control inventories against Acin's published > Data Technical Standards and benchmarks them anonymously across a peer network of tier-one banks. Generated by API Evangelist on 2026-09-06 from this repository's own artifacts and from probes of Acin's public surface. This file is not published by Acin; it is an independent third-party profile. See https://apievangelist.com/about/where-our-data-comes-from ## What an agent can and cannot do here Acin has no public developer program. There is no API reference, no OpenAPI, AsyncAPI, GraphQL SDL or JSON Schema, no SDK in any package registry, no sandbox, no published pricing and no rate-limit documentation. The platform API is real but closed: a GraphQL gateway at https://apim-prod.acin.com/v1/gateway-graphql fronted by Azure API Management, which answers any anonymous request — including a GraphQL introspection query — with HTTP 401 {"statusCode":401,"message":"Authorization token is missing or invalid"}. Tokens come from Acin's own Auth0 tenant at https://app-auth.acin.com/ and are issued only to an authenticated tenant. An agent cannot integrate with Acin without a customer relationship; the route in is https://www.acin.com/contact/. What IS publicly readable, and genuinely useful, is Acin's data model: the Data Technical Standards (DTS), a 33-entity dictionary of the non-financial-risk domain with typed properties and example JSON payloads. ## Company - [Website](https://www.acin.com/) - [About](https://www.acin.com/company/about/) - [Solutions](https://www.acin.com/solution/): the operational risk platform — digitise, diagnose and assure controls against an industry peer network - [Partners and investors](https://www.acin.com/company/partners/): Barclays, BNP Paribas, Citi, J.P. Morgan, Lloyds Banking Group, Fitch Ventures, Notion Capital, Talis Capital - [Contact](https://www.acin.com/contact/) - [News](https://www.acin.com/resources/news/) - [Reports](https://www.acin.com/resources/reports/) - [LinkedIn](https://www.linkedin.com/company/acin-ltd) - [Microsoft Azure Marketplace listing](https://azuremarketplace.microsoft.com/en-us/marketplace/apps/acinltd1712061915310.acin) - [CUBE acquisition announcement, June 2025](https://cube.global/resources/news/cube-acquires-leading-ai-operational-risk-provider-acin) ## Platform - [Platform login](https://app.acin.com/) — single-page application, now titled "CUBE Platform"; Auth0-gated - [Data Technical Standards documentation](https://acin-documentation-prd01.azureedge.net/docs/intro) — public, the only technical documentation Acin publishes - [Core Model](https://acin-documentation-prd01.azureedge.net/docs/Models/Core%20Model) - [Glossary](https://acin-documentation-prd01.azureedge.net/docs/BusinessConcepts/Glossary) ## Data model (Data Technical Standards) 33 documented entities. Facts are split into a stable Fact record (Id GUID, business Code, IsDeleted, IsApproved, AuditId) and a versioned Instance record carrying descriptive attributes. - Core: [Control](https://acin-documentation-prd01.azureedge.net/docs/DataTechnicalStandards/Control), [Risk](https://acin-documentation-prd01.azureedge.net/docs/DataTechnicalStandards/Risk), [Process](https://acin-documentation-prd01.azureedge.net/docs/DataTechnicalStandards/Process), [RiskInventory](https://acin-documentation-prd01.azureedge.net/docs/DataTechnicalStandards/RiskInventory), [BusinessOrganisation](https://acin-documentation-prd01.azureedge.net/docs/DataTechnicalStandards/BusinessOrganisation), [Product](https://acin-documentation-prd01.azureedge.net/docs/DataTechnicalStandards/Product) - Indicators: [KCI](https://acin-documentation-prd01.azureedge.net/docs/DataTechnicalStandards/KCI) (key control indicators), [KRI](https://acin-documentation-prd01.azureedge.net/docs/DataTechnicalStandards/KRI) (key risk indicators) - Regulatory: [Regulation](https://acin-documentation-prd01.azureedge.net/docs/DataTechnicalStandards/Regulation), [Regulator](https://acin-documentation-prd01.azureedge.net/docs/DataTechnicalStandards/Regulator), [RegulatoryArticle](https://acin-documentation-prd01.azureedge.net/docs/DataTechnicalStandards/RegulatoryArticle), [Penalty](https://acin-documentation-prd01.azureedge.net/docs/DataTechnicalStandards/Penalty) - Network and benchmarking: [NetworkMember](https://acin-documentation-prd01.azureedge.net/docs/DataTechnicalStandards/NetworkMember), [NetworkRelationship](https://acin-documentation-prd01.azureedge.net/docs/DataTechnicalStandards/NetworkRelationship), [PeerGroup](https://acin-documentation-prd01.azureedge.net/docs/DataTechnicalStandards/PeerGroup), [PeerGroupMember](https://acin-documentation-prd01.azureedge.net/docs/DataTechnicalStandards/PeerGroupMember) - Calculations: [Network Alignment Score](https://acin-documentation-prd01.azureedge.net/docs/Calculations/Network%20Alignment%20Score), [Network Signal Strength](https://acin-documentation-prd01.azureedge.net/docs/Calculations/Network%20Signal%20Strength), [Strength of Consensus](https://acin-documentation-prd01.azureedge.net/docs/Calculations/Strength%20of%20Consensus) - Captured in this repository: data-model/acin-data-model.yml ## Authentication - Issuer: https://app-auth.acin.com/ (Auth0 custom domain on Acin's own registrable domain) - [OpenID Connect discovery](https://app-auth.acin.com/.well-known/openid-configuration) — HTTP 200 - [OAuth authorization server metadata (RFC 8414)](https://app-auth.acin.com/.well-known/oauth-authorization-server) — HTTP 200 - [JWKS](https://app-auth.acin.com/.well-known/jwks.json) — HTTP 200 - Grants: authorization_code with PKCE (S256), client_credentials, refresh_token, device_code - Captured in this repository: authentication/acin-authentication.yml, scopes/acin-scopes.yml ## Releases - [Q2 2025](https://www.acin.com/release-note/acin-release-notes-and-product-updates-q2-2025/) — control-gap workflow, regulatory alert PDFs (most recent, 2025-07-24) - [Q1 2025](https://www.acin.com/release-note/acin-release-notes-product-updates-q1-2025/) — RCQE expansion, AI-generated KCIs, control merge - [Q4 2024](https://www.acin.com/release-note/our-latest-release/) — regulatory fines analysis, 30+ report templates - Captured in this repository: changelog/acin-changelog.yml ## Security and compliance - ISO/IEC 27001 certified and Cyber Essentials accredited, per [Acin's privacy policy](https://www.acin.com/privacy-policy/) - [Trust center (Drata)](https://app.drata.com/trust/118b5648-4aaa-42bf-938c-ca51a6f2be37) — linked from acin.com; returns a bot challenge to non-browser clients - No security.txt and no vulnerability disclosure policy on any host - Captured in this repository: security/acin-trust-center.yml, security/acin-domain-security.yml, security/acin-vulnerability-disclosure.yml ## Legal - [Terms and conditions](https://www.acin.com/terms-conditions/) - [Privacy policy](https://www.acin.com/privacy-policy/) - [Cookie policy](https://www.acin.com/cookie-policy/) - [Modern slavery statement](https://www.acin.com/modern-slavery/) ## Not published - OpenAPI / Swagger — probed on acin.com, www.acin.com, app.acin.com, api.acin.com, apim-prod.acin.com and the documentation CDN; 404 everywhere - GraphQL SDL — endpoint exists, introspection returns HTTP 401 - AsyncAPI, webhooks, or any event surface - MCP server, A2A agent card, llms.txt (this file is ours, not Acin's) - SDKs or client libraries in npm, PyPI, RubyGems, crates.io, NuGet or Maven - Pricing, plans, rate limits, status page, sandbox, deprecation policy