Skip to main content
QWED Finance v3.0.1 is the current release. It fixes three security advisories: ISO 20022 business rules now read the parsed XML, sanctions screening resists in-word perturbations, and QueryGuard rejects MySQL executable comments. See the overview for details.

Overview

QWED Finance is a verification library for AI financial agents, banking pipelines, and financial LLM applications. An LLM proposes a number, a decision, a payment message, or a query; QWED Finance recomputes or checks it deterministically before your system acts on it. It combines formal and exact tools: SymPy for cash-flow math, Z3 for compliance logic, mpmath and Decimal for pricing and risk, an XML/schema validator for ISO 20022 and SWIFT, and an SQLGlot AST parser for SQL safety.
The principle: LLM text generation is probabilistic; financial accounting is exact. QWED Finance checks LLM outputs against deterministic computations and fails closed when an input is ambiguous or malformed.

Key capabilities

11 verification guards

Compliance, Calendar, Derivatives, Message, ISO, Query, Cross, Bond, FX, Risk, and Trading.

Exact arithmetic

Decimal and mpmath precision for bond pricing, option Greeks, IRR, NPV, FX, and risk metrics.

Receipts and audit logs

Verification receipts with keyed HMAC-SHA256 signatures, an audit log, and AML/KYC/sanctions checks.

Integrations

OpenAI-compatible tool calls through Open Responses, the Universal Commerce Protocol (UCP), and a GitHub Action for CI.

What’s new in v3.0.x

v3.0.1: security fixes

  • ISO 20022 business rules read amounts and currencies from the parsed XML tree (GHSA-mrrj-6m2q-jch9).
  • Sanctions screening folds diacritics and look-alike letters and compares separator-free names (GHSA-mv2c-jwm9-pfrq).
  • QueryGuard rejects MySQL /*! ... */ and MariaDB /*M! ... */ executable comments (GHSA-q8r4-6gpp-5fx2).
  • VerificationReceipt.get_signature(key): HMAC-SHA256 over all receipt fields, with no default key.
  • ISO amount and currency limits in receipts and UCP; verify_iso20022_payment takes kyc_verified.
  • Fail-closed AML, sanctions, amount, and message validation.
  • Breaking (npm): the @qwed-ai/finance bridge sends JSON over stdin with runtime validation; malformed inputs are rejected.
See the full changelog.

Quick navigation

Quickstart

Install qwed-finance or @qwed-ai/finance and run your first check.

Verification guards

Explore the 11 verification guards with working examples.

CI/CD Action

Verify financial calculations in GitHub Actions.
QWED Finance is part of the QWED verification ecosystem. For the core protocol and other modules, see docs.qwedai.com.