QWED Finance v3.0.1 is the current release. It fixes three security advisories: ISO 20022 business rules now read the parsed XML, sanctions screening resists in-word perturbations, and
QueryGuard rejects MySQL executable comments. See the overview for details.Overview
QWED Finance is a verification library for AI financial agents, banking pipelines, and financial LLM applications. An LLM proposes a number, a decision, a payment message, or a query; QWED Finance recomputes or checks it deterministically before your system acts on it. It combines formal and exact tools: SymPy for cash-flow math, Z3 for compliance logic, mpmath andDecimal for pricing and risk, an XML/schema validator for ISO 20022 and SWIFT, and an SQLGlot AST parser for SQL safety.
The principle: LLM text generation is probabilistic; financial accounting is exact. QWED Finance checks LLM outputs against deterministic computations and fails closed when an input is ambiguous or malformed.
Key capabilities
11 verification guards
Compliance, Calendar, Derivatives, Message, ISO, Query, Cross, Bond, FX, Risk, and Trading.
Exact arithmetic
Decimal and mpmath precision for bond pricing, option Greeks, IRR, NPV, FX, and risk metrics.Receipts and audit logs
Verification receipts with keyed HMAC-SHA256 signatures, an audit log, and AML/KYC/sanctions checks.
Integrations
OpenAI-compatible tool calls through Open Responses, the Universal Commerce Protocol (UCP), and a GitHub Action for CI.
What’s new in v3.0.x
v3.0.1: security fixes
v3.0.1: security fixes
- ISO 20022 business rules read amounts and currencies from the parsed XML tree (GHSA-mrrj-6m2q-jch9).
- Sanctions screening folds diacritics and look-alike letters and compares separator-free names (GHSA-mv2c-jwm9-pfrq).
QueryGuardrejects MySQL/*! ... */and MariaDB/*M! ... */executable comments (GHSA-q8r4-6gpp-5fx2).
v3.0.0: keyed receipts and fail-closed inputs
v3.0.0: keyed receipts and fail-closed inputs
VerificationReceipt.get_signature(key): HMAC-SHA256 over all receipt fields, with no default key.- ISO amount and currency limits in receipts and UCP;
verify_iso20022_paymenttakeskyc_verified. - Fail-closed AML, sanctions, amount, and message validation.
- Breaking (npm): the
@qwed-ai/financebridge sends JSON over stdin with runtime validation; malformed inputs are rejected.
Quick navigation
Quickstart
Install
qwed-finance or @qwed-ai/finance and run your first check.Verification guards
Explore the 11 verification guards with working examples.
CI/CD Action
Verify financial calculations in GitHub Actions.
QWED Finance is part of the QWED verification ecosystem. For the core protocol and other modules, see docs.qwedai.com.