Frequently Asked Questions
What regulations do you support?
We build the technical infrastructure for: AML/CTF (FinCEN in the US, FCA in the UK, AUSTRAC in Australia), sanctions (OFAC, UN, EU), EMIR and MiFID II trade reporting, FATCA/CRS for tax reporting, PSD2 for payment services, and the specific requirements of crypto asset regulatory frameworks (MiCA, VARA, FCA crypto registration). We are engineers — your legal and compliance team defines the specific obligations; we build the systems that automate them.
How do you reduce false positive rates?
False positive reduction is a calibration exercise, not a one-time configuration. We start with conservative (wider) rules, measure the false positive rate against your transaction profile, and progressively narrow rules while monitoring that true positive detection does not drop. Peer group analysis (comparing customer behaviour against similar customers) is more effective than absolute thresholds for most retail transaction monitoring.
Can you integrate with our existing AML system?
Yes. We integrate with commercial AML platforms (NICE Actimize, Napier, Temenos) via their APIs, adding custom workflow orchestration, reporting layers, or additional data enrichment. We also build overlay systems that add capabilities missing from the commercial platform.
How does real-time transaction monitoring detect suspicious patterns and smurfing?
Our rules and anomaly detection engines process transaction streams in real time using Apache Flink and Kafka. They detect structuring (smurfing) across split transactions, rapid movement of funds between newly opened accounts, sudden velocity spikes, geographic inconsistencies, and high-frequency circular payments, generating risk-weighted case alerts before funds are released.
How do you support the Crypto Travel Rule (IVMS101)?
We implement end-to-end Travel Rule compliance using the universal IVMS101 data standard. The integration layer coordinates counterparty VASP discovery, validates entity identities, securely exchanges PII data through encrypted channels, and automates transaction holding/release decisions in accordance with FATF Recommendation 16.
How is regulatory audit trail immutability maintained?
All compliance events — including KYC submissions, risk score changes, manual investigator decisions, and alert closures — are written to append-only, tamper-evident audit logs with cryptographic hash-chaining and WORM (Write Once, Read Many) compliant storage. This provides mathematical proof that records have not been altered during regulatory examinations.
Can the system automate SAR (Suspicious Activity Report) generation and filing?
Yes. When an investigator escalates an alert to a confirmed suspicious activity case, the platform auto-populates standardised regulatory report templates (such as FinCEN SAR XML or national FIU formats) with transaction histories, customer profiles, and timeline narratives, allowing one-click batch submission via secure regulatory APIs.
What is the deployment architecture for strictly regulated banks and fintechs?
We support air-gapped on-premises deployments, dedicated private VPC instances (AWS GovCloud, Azure Government, or local sovereign clouds), and hybrid models. All sensitive customer identifying data (PII) is encrypted at rest using customer-managed KMS keys (envelope encryption) and in transit with TLS 1.3, ensuring strict compliance with GDPR and banking secrecy mandates.