0 errors in 64 independently re-verified claims. See how we measure →

Diligence you can prove.

Sanctions screening and company diligence, with every figure traced to its primary source. When we cannot reach a source, the report says so.

Rosneft Oil Company5 checked · 2 not covered · 6 cited
  • OFAC Specially Designated NationalsChecked
    list of 2026-07-23 · 1 result
  • OFAC Consolidated (non-SDN)Checked
    list of 2026-07-23 · 1 result
  • EU Consolidated Financial SanctionsChecked
    list of 2026-07-20 · 0 results
  • UN Security Council ConsolidatedChecked
    list of 2026-07-24 · 0 results
  • CourtListener RECAP (PACER mirror)Not reached
    checked 2026-07-25fetch failed: the read operation timed out
  • Adverse mediaChecked
    8 articles retrieved · 0 carried adverse language
  • Corporate registry / beneficial ownershipOut of scope
    no primary registry source licensed for it yet

A source we could not reach is a statement about our coverage, not about the subject. It ships on the report either way.

Checking the work stops being the work.

A tool you cannot audit does not save the time it promises. It moves it — into re-deriving every number before anyone will sign it. That is the verification tax, and it is why the last one stalled.

59%re-verify or re-create AI output all or most of the time
84%of firms that call themselves fully trusting still do
12%have put AI into a core financial process
75%say explainability would raise their confidence in it

Centiment for Hebbia, 510 finance professionals, May 2026 · insightsoftware, 311 senior finance professionals, spring 2026

We measured where our own name matcher misses, and published it.

Against 20,746 real sanctions designations on the OFAC and UN lists.

100%of designations found when the list itself carries the spelling we were given.
27%when it does not. This is the harder number, and it is the one that decides a missed designation.

Three steps, and the third is the one that matters.

Inside a run
01

Retrieve

It pulls the filings, sanctions lists and registries itself, including sources behind a login that have no API.

02

Verify

Each figure is checked back against the document, the period and the arithmetic.

03

Fail closed

A check that cannot run returns not reached, with the reason. It never returns clear.

The numbers behind the files.

Including the 154 items our briefs declared a gap rather than estimating, and a bound on how often we are silently wrong — the two numbers a diligence tool is not supposed to publish.

305Figures verified against a primary source, across every brief we have run
154Items those briefs declared a gap instead of estimating
0 in 64Re-verified claims with a silent error
5.7%Upper bound on the silent-error rate, 95% confidence
30sMedian time from a name to a sourced screen file
2 in 17Screens where a source could not be reached — and the file says so
5,200Subjects screened
62%Of the checking a reviewer used to do before signing

Built for whoever signs it.

Financial crime and forensics

Screening files where the record of what you could not check is the regulated part.

Deal teams

Target workups built from primary filings, before a data room exists.

Compliance

Evidence a reviewer can reopen months later and land on the same source.

No badge we have not earned.

We are not SOC 2 certified, and we are not going to put the shield up until we are. Here is what the system actually does instead — each of these is code, and we will walk your reviewer through it.

No training on your data

Your documents and results are processed to run the workflow you asked for, and for nothing else. They do not train models — ours or our provider's.

Encrypted in transit and at rest

TLS on every connection. Stored credentials are sealed with per-account keys derived from a master key, and API keys are stored as hashes we cannot reverse.

Tenant isolation in the database

One account cannot reach another's rows. It is enforced by the database itself, not by remembering to add a filter to a query.

Append-only audit log

Who ran what, when, and what came back — written to a table your compliance team can read and nobody can quietly edit.

It fails closed

A check that could not run comes back as not reached, with the reason and the timeout on it. It never comes back clear. That is a security property, not just a reporting one.

Certifications

SOC 2 Type II and ISO 27001 — not held, and we say so here rather than leaving you to ask. GDPR is a different thing and we are subject to it: a data processing agreement and our control documentation are available for your review.

Where this goes.

Finance is where being wrong costs the most, so it is where we start. The engine underneath is not finance-specific. It retrieves, verifies and acts on anything behind a login, and it refuses to guess. The goal is to perform any consequential task on the web and prove it. Diligence and screening are the first.

Run it on a company you already know.

Pick one you know cold. It is the fastest way to see what it proves and what it flags. 52s for the last one, with 25 primary sources attached.