
Your clients shared their entire financial picture with you in confidence. Make sure where you store it deserves that confidence.
Bigby gives IFAs, wealth managers, and financial advisers encrypted, UK-based cloud storage that supports the record-keeping obligations of FCA-regulated practice.
FCA regulation sets clear expectations around client records. So does common sense when you consider what those records contain.
When a client allows you to advise on their pension, investments, protection, or estate, they hand you a complete picture of their financial life. The value of their assets, the nature of their debts, their retirement plans, their family’s financial circumstances. That information is not shared lightly.
FCA-regulated advisers are required to retain client records and suitability documentation for years. Most do so on whatever storage the firm adopted at the start. Consumer cloud services and general business platforms were not designed for the record-keeping obligations of regulated financial advice, and their data handling terms don’t reflect the sensitivity of what they are being asked to hold.

Where standard cloud storage creates risk for regulated advisers
General-purpose cloud platforms were not designed with FCA-regulated financial advice in mind. The distance between what they offer and what your obligations require is worth understanding before something goes wrong.
FCA record-keeping obligations
The FCA requires advisers to retain suitability reports, client correspondence, fact-finds, and investment recommendations for a minimum of five years, and in some cases considerably longer. Those records need to be retrievable, intact, and demonstrably secure. A storage arrangement that provides no meaningful protection, no UK data residency, and no audit trail is not a defensible basis for meeting that obligation.
The sensitivity of financial planning data
Pension values, investment portfolios, inheritance expectations, protection needs, and family financial circumstances represent some of the most personal information your clients will ever share with anyone. A data breach affecting that information is not simply a regulatory event: it is a profound breach of trust with real consequences for the people whose lives the data describes.
AML and KYC documentation
Anti-money laundering compliance requires collecting and retaining copies of identity documents, proof of address, and source of funds information. Passports, utility bills, and bank statements stored on a consumer platform with broad data usage rights or overseas data transfer is an uncomfortable combination for material collected under a regulatory obligation. The AML record-keeping requirement and the data protection obligation need to be satisfied together.
Regulatory supervision and enforcement exposure
An FCA supervision visit or complaint investigation may examine not just the quality of your advice but the security of your record-keeping. A data breach affecting client financial records is both a regulatory event and a reputational one. For advisers whose business depends on client trust, demonstrating that you took the security of their data seriously from the outset is not merely a compliance matter.
How Bigby works
Unlike the major cloud platforms, Bigby does not scan, analyse, or profit from the files you store. Here is how that works.
01. Encrypted in transit and at rest
Your files are encrypted on the way to us and while they sit on our UK servers, so they are protected in transit and never stored as readable plain text. We hold the encryption keys, which is what allows features like editing documents in your browser to work.
02. No access to file contents
Bigby does not open, scan, or read the contents of what you store. We have no business reason to and our data processing terms prohibit it.
03. No AI training or secondary use
Your stored content is not used for AI training, advertising targeting, or any analysis of any kind. The subscription fee covers the cost of running the service. That is the entire arrangement.
04. UK data residency throughout
All data is stored on UK-based infrastructure. UK GDPR applies. There is no transfer to US servers and no exposure to US jurisdiction. Your clients’ financial records do not leave the UK.
Frequently asked questions
Storage that meets the standard your clients’ financial plans deserve
Private, encrypted, UK-based cloud storage from £3.99 per month. Built for regulated advisers who understand that how they store client data is as much a part of the service as the advice itself.
See all plansAnnual or monthly billing · All prices in GBP · UK data residency · GDPR compliant