Security and procurement

Designed for sensitive financial crime evidence.

The authoritative case record, access model, AI processing and subprocessor relationships are documented for security, privacy, legal and procurement review.

Controlled
processing
EEA record
Role based access
Encrypted transport
Human approval
Control overview

Clear boundaries around data, access and decisions.

This public summary is intentionally high level. Detailed architecture, named provider information and control evidence are supplied during qualified procurement review.

Authoritative record

The compliance record is stored in the selected EEA infrastructure. Approved subprocessors may process only the information needed for their contracted function.

Tenant isolation

Firm data is segregated using database level controls so users from one firm cannot access another firm’s records.

Role separation

Analysts, managers, MLROs, administrators and read only reviewers receive access according to their function.

Encryption

Data is encrypted in transit and at rest using the controls provided by the managed hosting environment.

AI data use

Commercial AI services operate under contractual data protections. Client data is not used to train public models.

Human decisions

Model output does not approve a customer, submit a filing or send a material client communication without authorised human action.

Activity history

File access, uploads, screening, review generation, assignments, notes, decisions and sign offs can be recorded against the case.

Retention and deletion

Retention can be configured to the firm’s requirements, with export, termination and deletion handled under the DPA.

Incident response

Material incidents are triaged, contained and communicated to affected firms in line with contractual and data protection obligations.

Procurement materials

Available to qualified prospective clients.

Confidential detail is provided to qualified prospective clients under the appropriate commercial and data protection process.

Procurement and security pack

Platform overview, data flow, access model, encryption, AI use, subprocessors, retention and incident response.

Data Processing Agreement

Controller and processor roles, processing instructions, security measures, subprocessor terms and transfer safeguards.

Named subprocessor schedule

Provider, purpose, location, assurance and relevant contractual safeguards.

AI data use statement

Model use, training restrictions, data minimisation, retention configuration and human control boundaries.

Sample audit pack

A fictional complete case showing the evidence, findings, challenge and human decision record.

Implementation and control evidence

Configuration evidence, test materials and available assurance supplied according to the stage of procurement.

Data residency

The authoritative compliance record is stored in EEA infrastructure. Approved subprocessors may process limited data outside the EEA under applicable contractual safeguards.

This distinction is important. Storage location and processing are not the same thing, and firms should assess both when reviewing data residency. We state the position precisely rather than claiming that no data ever leaves the EEA.

Working session

Start the security review early.

We can provide the procurement pack, DPA and controlled technical detail alongside the product evaluation.

Fictional demonstration dataSecurity pack availableControlled pilot option

By submitting this form, you agree that we may use your details to respond to your enquiry. See our privacy notice.