Security
Security
Your trade compliance data is sensitive. This page describes current platform controls and protections provided by our infrastructure providers.
Platform controls
Encryption in Transit & at Rest
Our infrastructure providers (Supabase and Railway) provide encryption features for data in transit and at rest.
Security Controls
The platform uses access controls, logging, and infrastructure-provider encryption features.
API Key Authentication
Plaintext API keys are shown once, stored as hashes, and can be revoked or rotated from the dashboard; selected public endpoints do not require a token.
Multi-Tenant Isolation
Each customer's data is isolated via row-level security policies. Your compliance data is not shared with other customers.
Audit Logs
Audit trail of classification requests, screening results, and compliance decisions with SHA-256 hash chaining for integrity verification.
Data Retention & Deletion
Retention varies by workflow and service configuration. Contact [email protected] with data-retention or deletion questions.
Supported Sanctions Lists
We screen against the supported sanctions and restricted-party lists shown below. Source availability and synchronization can vary.
Sanctions Lists & Update Frequency
| List | Description | Update |
|---|---|---|
| OFAC SDN List | Office of Foreign Assets Control Specially Designated Nationals | As designations occur (polled daily) |
| EU Consolidated List | European Union sanctions and restricted parties (FSF) | Approx. daily (RSS change feed) |
| UN Security Council | United Nations sanctions list | As published by the UN |
| BIS Entity List | Bureau of Industry and Security restricted entities | As published by BIS |
| UK Sanctions List | UK Sanctions List (published by FCDO/OFSI) | As designations occur |
Security Practices
Current Security Posture
Below are implemented technical controls. No third-party certification is claimed here.
SHA-256 Audit Trail
ImplementedClassification, screening, and compliance records can be included in a hash-chained audit trail.
Provider Encryption
ImplementedOur infrastructure providers support encryption for customer data in transit and at rest.
JWT Authentication
ImplementedStateless signed session tokens with Supabase Auth; optional per-tenant API keys.
Responsible Disclosure
We welcome security researchers to report vulnerabilities. If you discover a security issue, please report it responsibly.
Reports should include: description of the vulnerability, steps to reproduce, and potential impact assessment.
Security Contact
For security inquiries, vulnerability reports, or to request our security questionnaire, email us at [email protected] with "Security" in the subject line.
[email protected]