EEA data residency
All compliance data stored in EU-West (Belgium). Suitable for firms subject to GDPR, UK GDPR and equivalent EEA data protection requirements.
Security and data
CompliantID handles identity documents, ownership structures, wallet data, source of funds information and MLRO decisions. Every aspect of the architecture reflects the sensitivity of that data.
Data storage and residency
Every piece of client compliance data — onboarding files, documents, screening results, MLRO decisions and audit records — is stored in EU-West infrastructure in Belgium. Data does not leave the EEA during normal operation. You remain the data controller at all times. CompliantID acts as your data processor under a formal Data Processing Agreement.
All compliance data stored in EU-West (Belgium). Suitable for firms subject to GDPR, UK GDPR and equivalent EEA data protection requirements.
Data encrypted at rest using AES-256 and in transit using TLS 1.2 or higher. Applies to all stored files, records and transmitted data.
Analysts, compliance managers, MLROs, administrators and read-only reviewers each have separate access levels. No user sees more than their role requires.
Every file access, document upload, decision record, case note and approval is logged with user identity, timestamp and action. The log cannot be edited.
MFA is required for all MLRO dashboard access. Dashboard sessions expire automatically after inactivity.
Data retention configured to 10 years from the end of the client relationship, in line with AMLA, UK MLRs and equivalent provisions. Adjustable to your regulatory requirements.
AI data handling
CompliantID uses AI models via a commercial API under a formal Data Processing Agreement. Client data submitted to AI models for review or analysis is processed transiently — it is not retained beyond the immediate request and is not used to train AI models under any circumstances.
This is categorically different from consumer AI tools. The API operates under commercial terms that explicitly prohibit model training on customer data. This distinction is documented and can be provided to your DPO, legal team or regulator on request.
Procurement support
Compliance and financial crime teams purchasing software will typically need to involve information security, privacy, legal and procurement before approving a new system. We provide the documentation those teams need without requiring lengthy back-and-forth.
For firms in regulated sectors, we can also provide documentation suitable for presentation to the FCA, VQF, MAS, VARA or equivalent regulators as part of tool evidence requirements. A complete AML tool evidence pack is available on request.
Data ownership
CompliantID does not use client compliance data for any purpose other than delivering the service. Your client files, decision records and audit trails are not shared with third parties, not used for benchmarking, not used for product development and not sold. On termination, data is made available for export for 90 days before deletion in accordance with your DPA.
Book a product walkthrough
Share the type of firm you support, your current review process and the main evidence problem you want to solve. We will show the workflow around your use case.