Your data is protected
AML PROOF employs enterprise-grade security measures and maintains the highest standards of data protection to ensure your sensitive compliance data remains secure, private, and accessible only to authorized personnel.
Data Encryption
Data is stored with certified providers (Vercel, Neon) with encryption at rest. Data in transit is protected with TLS encryption.
Modern Authentication
Authentication is protected via magic links and OAuth 2.0 (Google, Microsoft). MFA is planned for phase 2.
Secure Infrastructure
Our infrastructure is hosted on Vercel, which is SOC 2 Type II certified with 24/7 monitoring, automated threat detection, and regular security audits.
Access Controls
Role-based access control (RBAC) with principle of least privilege. All access is logged. Automated alerts for suspicious activities are in preparation.
Data Backup & Recovery
Automated daily backups with point-in-time recovery capabilities. Disaster recovery procedures ensure business continuity with RTO of less than 4 hours.
Audit Logging
Comprehensive audit trails for all system activities, user actions, and data access. Logs are tamper-proof and retained according to regulatory requirements.
Regulatory Compliance
We maintain strict compliance with international data protection and privacy regulations to ensure your data is handled according to the highest legal standards.
GDPR Compliance
Designed and operated in accordance with the General Data Protection Regulation (GDPR).
- Data minimization and purpose limitation principles
- Right to access, rectification, and erasure (right to be forgotten)
- Data portability and consent management
- Breach notification within 72 hours
Legitimate Interest Assessment (LIA)
We conduct thorough Legitimate Interest Assessments for all data processing activities:
- Purpose and necessity testing for each processing activity
- Balancing test between our interests and individual rights
- Regular review and documentation of assessments
- Safeguards implementation to protect individual rights
Data Protection Impact Assessment (DPIA)
A data protection impact assessment (DPIA) is being conducted in line with Art. 35 GDPR.
- Mapping of all personal data processing operations (completed)
- Assessment of risks to the rights and freedoms of data subjects (in progress)
- Consultation with the Data Protection Officer
- Adoption of technical and organisational measures based on findings
Records of Processing Activities (ROPA)
Detailed records maintained for all data processing activities:
- Complete inventory of all processing activities
- Legal basis documentation for each processing purpose
- Data categories, retention periods, and transfer records
- Regular updates and supervisory authority availability

Data Storage & Encryption
Encryption Standards
- Encryption at rest with certified providers (Vercel, Neon)
- TLS 1.3 for data in transit
Storage Infrastructure
- Geographically distributed data centers
- Real-time replication across multiple zones
- Automated failover and load balancing
- Target 99.9% availability
24/7 Security Monitoring
Our systems are monitored continuously by automated tools. We typically resolve security incidents within 24 hours of detection.
Current System Status
Check real-time availability and API performance. We share transparent uptime history.
Questions About Our Security?
Our security team is available to answer any questions about our data protection measures and compliance standards.
Register your obliged entity
Registration is simple — just a few clicks, and it's free.
Starter plan at no cost. No credit card required.