Checked on every call and every sign-in
An API call is signed, time-stamped and checked against its key before a screening runs. A sign-in can take a second step, and each person on your team reaches only what their role allows.
- Signed with the key’s secretAn HMAC-SHA256 signature that only the secret can produce.
- Made in the last five minutesAn old request can’t be sent again later.
- Something the key may doRun screenings, download reports, or both — your choice per key.
- From an address the key allowsWhen you give a key an allow-list, nowhere else gets in.
- Within the key’s rate limitEach key has its own, so one integration can’t crowd out another.
- Covered by your plan and balanceA search the account can’t pay for doesn’t run.
Fail any one and the call is refused with the reason — except a bad signature, which says no more than that, by design.
The console, protected person by person
For everyone who signs in — the account owner and every member of the team.
Passwords never stored as typed
Each one is kept only as a salted PBKDF2 hash, run 600,000 times, so a stored password can’t be read back.
A second step
Anyone can add a code from an authenticator app to their sign-in, so a password on its own isn’t enough.
Signs itself out
Ten minutes without use and the console signs out — and forgets “remember me” too, so it can’t quietly sign back in.
Links that expire
A password-reset link works for five minutes. An invitation to join the team works for 24 hours.
Roles the server enforces
A page a role doesn’t allow is refused by the server, not just hidden from the menu — typing its address doesn’t get round it.
Who’s in, and what changed
See who is signed in right now and from where. Sign-ins, team, role, company and workflow changes are logged with who, when and from which address.
Secrets that stay secret
A secret shown once
A key’s secret appears when you create it and never again. Requests carry a signature made with it, never the secret itself.
Expire or delete any key
Give a key an end date, or delete it the moment an integration is retired. Your other keys carry on untouched.
Report links that don’t linger
The download link a screening returns lasts five minutes — and even then it opens only for a signed request.
Refusals that don’t leak
A refused call names what to fix. It never repeats a credential back, and a bad signature isn’t explained, so it can’t be guessed at.
What’s kept about every search
Kept against your account, so any screening can be accounted for later.
- What was askedThe name, the details sent with it, and the kind of search.
- What was foundEvery record returned, with its match score — or that nothing matched.
- What it costThe amount charged to your balance.
- Where it came fromThe time, the key it used and the address it was sent from.
Questions about hosting, retention or your own regulatory obligations? Ask us — we’ll answer for your case.
Have security or compliance questions?
Talk to our team about how AMLPRO fits your security review and
your regulatory obligations.
