Skip to content
Security & Trust

How Sanctix protects your data

A straight answer to the questions a compliance or security team asks before signing off on a sanctions-screening vendor. If something below isn't enough detail for your procurement process, email us — we'd rather have that conversation directly than leave you guessing.

Sanctix is not yet SOC 2 certified. We'd rather tell you where we actually are on that path than imply a certification we don't hold — see the compliance roadmap below.

Data protection

Encryption in transit & at rest

All traffic to Sanctix is served over TLS. Screening data and reports are stored in a managed Postgres database with encryption at rest, provided by our infrastructure provider.

Authenticated access only

Every API request requires a JWT session or a scoped API key. Keys can be revoked individually without affecting the rest of your workspace.

Rate limiting & abuse protection

Per-key and per-org rate limits protect against runaway automation and credential abuse across every screening endpoint.

Immutable audit trail

Every screening decision, plan change, and API key event is written to an append-only audit log tied to the acting user.

Data residency & cross-border transfer

Built for the China–MENA corridor

Sanctix screens data across jurisdictions that take data residency seriously, including Mainland China. Where processing involves personal information subject to China's Personal Information Protection Law (PIPL), cross-border transfer follows the applicable statutory mechanism. Full detail is in our Privacy Policy.

Compliance roadmap

TLS encryption, scoped API keys, rate limiting Live
Immutable audit logging across all workspace actions Live
Two-factor authentication for user accounts Planned
Formal security questionnaire / vendor pack Planned
SOC 2 Type II certification Planned

Need a specific attestation for procurement before something above is live? Tell us your timeline — we prioritize this roadmap based on real deal requirements, not guesswork.

Infrastructure & sub-processors

Who processes your data

Sanctix runs on managed infrastructure for application hosting and database storage, and uses Polar.sh as merchant of record for billing. We don't sell screening data or use it to train public AI models — see our Privacy Policy for the full sub-processor list and data handling terms.

Report a vulnerability

Found a security issue? Email security@sanctix.io with details and reproduction steps. We aim to acknowledge reports within 2 business days.