Security

Controls built around sensitive screening data.

Adverse media requests combine identity data and risk information. The product is designed to keep both out of public surfaces and routine logs.

Encrypted screening data

Sensitive subject, finding, and source fields are encrypted before they are stored.

One-time API secrets

New API keys are shown once. Only a keyed hash is kept for later authentication.

Tenant-scoped access

Workspace access is checked on each account and API request, with separate platform admin controls.

Private operational logs

Request logs exclude names, birth dates, phone numbers, email addresses, search phrases, and evidence excerpts.

Durable job processing

Asynchronous work uses bounded retries, idempotency, and atomic usage controls.

Deletion and retention

Screenings expire under a defined retention window and customers can delete completed records sooner.

Need a security review?

Share your access, retention, deployment, and audit requirements before rollout.

Contact us