Diligence you can prove.
Sanctions screening and company diligence, with every figure traced to its primary source. When we cannot reach a source, the report says so.
- OFAC Specially Designated NationalsCheckedlist of 2026-07-23 · 1 result
- OFAC Consolidated (non-SDN)Checkedlist of 2026-07-23 · 1 result
- EU Consolidated Financial SanctionsCheckedlist of 2026-07-20 · 0 results
- UN Security Council ConsolidatedCheckedlist of 2026-07-24 · 0 results
- CourtListener RECAP (PACER mirror)Not reachedchecked 2026-07-25fetch failed: the read operation timed out
- Adverse mediaChecked8 articles retrieved · 0 carried adverse language
- Corporate registry / beneficial ownershipOut of scopeno primary registry source licensed for it yet
A source we could not reach is a statement about our coverage, not about the subject. It ships on the report either way.
Checking the work stops being the work.
A tool you cannot audit does not save the time it promises. It moves it — into re-deriving every number before anyone will sign it. That is the verification tax, and it is why the last one stalled.
Centiment for Hebbia, 510 finance professionals, May 2026 · insightsoftware, 311 senior finance professionals, spring 2026
We measured where our own name matcher misses, and published it.
Against 20,746 real sanctions designations on the OFAC and UN lists.
Three steps, and the third is the one that matters.
Inside a runRetrieve
It pulls the filings, sanctions lists and registries itself, including sources behind a login that have no API.
Verify
Each figure is checked back against the document, the period and the arithmetic.
Fail closed
A check that cannot run returns not reached, with the reason. It never returns clear.
The numbers behind the files.
Including the 154 items our briefs declared a gap rather than estimating, and a bound on how often we are silently wrong — the two numbers a diligence tool is not supposed to publish.
Built for whoever signs it.
Financial crime and forensics
Screening files where the record of what you could not check is the regulated part.
Deal teams
Target workups built from primary filings, before a data room exists.
Compliance
Evidence a reviewer can reopen months later and land on the same source.
No badge we have not earned.
We are not SOC 2 certified, and we are not going to put the shield up until we are. Here is what the system actually does instead — each of these is code, and we will walk your reviewer through it.
No training on your data
Your documents and results are processed to run the workflow you asked for, and for nothing else. They do not train models — ours or our provider's.
Encrypted in transit and at rest
TLS on every connection. Stored credentials are sealed with per-account keys derived from a master key, and API keys are stored as hashes we cannot reverse.
Tenant isolation in the database
One account cannot reach another's rows. It is enforced by the database itself, not by remembering to add a filter to a query.
Append-only audit log
Who ran what, when, and what came back — written to a table your compliance team can read and nobody can quietly edit.
It fails closed
A check that could not run comes back as not reached, with the reason and the timeout on it. It never comes back clear. That is a security property, not just a reporting one.
Certifications
SOC 2 Type II and ISO 27001 — not held, and we say so here rather than leaving you to ask. GDPR is a different thing and we are subject to it: a data processing agreement and our control documentation are available for your review.
Where this goes.
Finance is where being wrong costs the most, so it is where we start. The engine underneath is not finance-specific. It retrieves, verifies and acts on anything behind a login, and it refuses to guess. The goal is to perform any consequential task on the web and prove it. Diligence and screening are the first.
Run it on a company you already know.
Pick one you know cold. It is the fastest way to see what it proves and what it flags. 52s for the last one, with 25 primary sources attached.