Skip to content
OfacScanner

Security and Data Protection for Your Screening Data

OfacScanner protects the names you screen with encryption in transit and at rest, role based access, a full audit log and retention you control. Scale adds single sign-on, and every customer can sign a data processing agreement.

Security lead reviewing access settings with a hardware key on the desk

What sanctions screening data needs protection

Screening data is personal data. A name, a date of birth and a country tied to a possible sanctions match is sensitive for the person and for your business.

When you screen a customer, you send us the details you already hold about them: a full name, often a date of birth, a country and sometimes an identifier or a reference from your own system. The result adds a risk rating, candidate entries from public sanctions lists and, on paid plans, a case with your team's notes and decision.

We treat all of it as customer data that you control. You decide what to send, how long to keep it and who in your team can see it. We process it only to screen, monitor and keep the evidence you ask for. The public sanctions lists themselves come from official government sources described on our sanctions lists page.

Controls built into every workspace

Encryption in transit and at rest

Every page, API call and webhook uses HTTPS with modern TLS. Databases and backups are encrypted at rest by the hosting provider.

Roles that match the work

Analysts screen and propose decisions, Reviewers decide on cases, Admins manage users, billing and settings. Growth and higher plans include all three roles.

Audit log of every action

Logins, screenings, case decisions, setting changes and API key events are written to an audit log with user, time and IP address. Scale and Enterprise can export it.

Strong sign-in

Passwords are stored as one-way hashes. New accounts confirm their email address with a one time code. Scale adds single sign-on with SAML, Enterprise adds SCIM provisioning.

API keys and signed webhooks

API keys are shown once and stored only as a hash. Sandbox and live keys are separate. Every webhook is signed with HMAC SHA-256 so your system can reject forged calls.

Retention you control

Evidence and audit records are kept for 12 months on Starter and 5 years on Growth and higher. On request we delete records earlier when your policy requires it.

Who processes data on our behalf

We use a small number of service providers, each limited to one job and bound by data processing terms. We list them by category. The full list with locations is part of the data processing agreement.

Categories of service providers that process data for OfacScanner
Category What it receives
Hosting provider in the US or the EUAll workspace data, stored encrypted
Payment operatorBilling name, email and card details entered at checkout, never screening data
Email delivery providerYour email address and the text of codes, alerts and receipts

How to review us before you buy

Four steps most security and procurement teams follow.

  1. 01

    Read this page and the privacy policy

    The privacy policy explains what we collect, why, for how long and your rights.

  2. 02

    Check the API and webhook design

    The API documentation shows authentication, idempotency and webhook signatures.

  3. 03

    Ask your questions by email

    Send your questionnaire or specific questions to [email protected]. Enterprise includes a prepared questionnaire pack.

  4. 04

    Sign the DPA

    A data processing agreement is available to every paying customer. Enterprise adds an uptime SLA and data residency.

Security of the results themselves

A screening result is only as good as the list behind it. Every result stores the exact list version used, so you can prove later which data a decision was based on. Lists are checked against the official sources every 30 minutes, and a failed download never replaces a good version.

Results support your compliance decisions, and the final decision stays with your team. OfacScanner is an independent tool and is not affiliated with OFAC or the U.S. Department of the Treasury. Read more about OFAC compliance software and how evidence fits a sanctions program.

Security questions

Another question? Write to [email protected].

Do you sell or share the names we screen?

No. Names, results and cases belong to your workspace. We use them only to provide the service, we never sell them and we never use them to build lists for anyone else.

Which certifications does OfacScanner hold?

We do not claim certifications we do not hold. Instead we describe the controls on this page and answer security questionnaires. The questionnaire pack is part of the Enterprise plan, and any team can ask questions at [email protected].

Can we delete our data?

Yes. Write to [email protected] from an admin account and we delete the screenings, monitored records or the whole workspace you name. Deleting data never refunds checks already used, and evidence you delete cannot be restored, so export what you must keep for your own records first.

Where is our data stored?

With a hosting provider that keeps the data in data centers in the United States or the European Union. Enterprise customers choose US or EU data residency for their workspace.

How do we report a security issue?

Write to [email protected] with the steps to reproduce. We confirm receipt, investigate and tell you what we changed.

Screen your first name in seconds

Type a person or company name, see the risk rating and top candidates from the current OFAC list, and keep the evidence when you sign up.

Results support your compliance decisions, and the final decision stays with your team. OfacScanner is not affiliated with OFAC or the U.S. Department of the Treasury.