trust and security

Built for regulated workloads

Compliance teams get audited on the data they rely on. This page states plainly how the data is kept traceable, how the service is secured, and what we do not claim.

Data integrity

Every record keeps its source attributions — any match traces back to its issuing feed and from there to the issuing authority; the itemised source list is available on request.
Every entity merge made by the resolution layer carries a human-readable rationale a reviewer can follow — no black-box clustering.
Sources are monitored continuously; each document carries an indexed_at timestamp so freshness is inspectable per record, not asserted in marketing copy.
Fields are only present when the source published them. Missing data is preserved as missing — never back-filled, inferred or defaulted.

Service security

API-key authentication on all data endpoints, compared with constant-time checks. Unconfigured auth fails closed, not open.
HTTPS-only in production. Secrets live in Azure Key Vault and reach services via managed identity — no credentials in code or config files.
Cross-origin access is locked to explicit origins. The screening API is a server-to-server surface by default.
Rate limiting and per-key usage tracking on every request, so anomalous usage is visible and attributable.

What we do not claim

No SOC 2 certificate yet. Controls are designed with SOC 2 in mind; the audit itself has not been performed, and we will not imply otherwise.
Match scores are relevance rankings, not calibrated probabilities. We recommend review workflows built on ranked results plus the structured evidence on each record.
No adverse-media or crypto-wallet coverage today. New categories are announced when they reach production quality, not before.

Privacy

The index contains data published by government and regulatory authorities about designated and politically exposed parties. For privacy questions, data-subject requests or our privacy policy, contact hr@satyapan.xyz — requests are acknowledged within two business days.