Trust & Security: Data Protection | Global RADAR

Trust & Security

  • Home
  • Trust & Security

RegTech that handles examiner-grade data is held to examiner-grade controls. Global RADAR runs on SOC 2 Type II and ISO/IEC 27001 certified infrastructure, and applies its own controls at the application layer. The sections below separate what our hosting provider is attested for from what Global RADAR operates directly, so your security team can scope its review accurately. Signed reports are available on request under mutual NDA.

Assurance information current as of 20 August 2026. This page is reviewed and dated each time an attestation is issued or renewed.

SOC 2 Type II (hosting infrastructure)

Held by Rackspace Technology, Global RADAR’s hosting provider. Trust Services Criteria: Security, Availability, Confidentiality.

  • Attestation held by: Rackspace Technology
  • Scope: Physical security, environmental controls, infrastructure availability, and the operational controls of the hosting environment
  • Report access: Rackspace’s signed SOC 2 Type II report is provided to Global RADAR clients on request under mutual NDA
  • Global RADAR application layer: Application-layer attestation is in progress. Current status available on request.

ISO/IEC 27001 (hosting infrastructure)

Held by Rackspace Technology. Information Security Management System certification covering the hosting environment in which Global RADAR operates.

  • Certification held by: Rackspace Technology
  • Scope: Information Security Management System for the hosting environment
  • Certificate access: Provided to Global RADAR clients on request under mutual NDA
  • Global RADAR application layer: Information security practices aligned to ISO/IEC 27001 controls. Formal certification in Global RADAR’s own name is in progress.

GDPR and Privacy

Data processing aligned with UK GDPR and EU General Data Protection Regulation requirements. Global RADAR hosts customer data in the United States and the United Kingdom.

  • DPA available: Yes, on request
  • Data residency: United States for US and international clients. United Kingdom for European clients.
  • Transfer mechanism: EEA to UK transfers rely on the European Commission’s UK adequacy decision. Standard Contractual Clauses (2021/914, Module Two) apply where onward transfer to the United States is involved.
  • DPO contact: privacy@globalradar.com

Encryption Standards

All customer data is encrypted at rest and in transit using industry-standard cryptographic primitives.

  • At rest: AES-256
  • In transit: TLS 1.3
  • Key management: Industry-standard managed KMS
  • Key rotation: Annual key rotation, plus event-driven rotation on key personnel changes

Annual Penetration Testing

Independent third-party penetration testing of production application and infrastructure.

  • Tester: Available upon request under NDA
  • Last test: Available upon request under NDA
  • Cadence: Annual plus on major release
  • Findings: Summary available on request

Business Continuity and Disaster Recovery

Documented business continuity and disaster recovery plans with annual tabletop testing.

  • Recovery Point Objective: Standard target: 1 hour
  • Recovery Time Objective: Standard target: 4 hours
  • Multi-region: Available upon request
  • Last DR test: Available upon request under NDA

Service levels

These are the platform support commitments Global RADAR contracts to. They cover availability and support response for the software. They are not a clearing turnaround commitment. Where an accredited delivery partner performs alert clearing under Managed Clearing, turnaround times and coverage hours are set in the service schedule agreed with that partner.

  • High priority, major application functionality does not work and no workaround exists: 1 hour response or fix
  • Medium priority, functionality does not work but a workaround exists: 2 hours
  • Low priority, minor defects, informational requests and product enhancement requests: 24 hours
  • Uptime service level: 99.5 percent
  • Business continuity: full recovery of services within 24 hours
  • New client instance: processed, tested and operational within 5 business days
  • Support hours: Monday to Friday, 09:00 to 18:00 EST, and 08:00 to 18:00 GMT

First line support runs through the client portal, which assigns a case number automatically and tracks status through to resolution. Cases are prioritised when logged, and either party can escalate by changing a case priority.

Screening data and its provenance

Global RADAR screens against more than 1,400 sanctions and watchlists. The underlying data falls into two categories.

Official government and supranational lists, ingested directly from the issuing authority. These include the OFAC sanctions programmes maintained by the United States Treasury, the consolidated sanctions list of the European Union, the UK sanctions list maintained by the Foreign, Commonwealth and Development Office, and the OFAC Consolidated list. Updates are ingested on the publisher cadence, and a change in a client alert volume is normally traceable to a specific list update rather than to a change in our matching.

Commercially licensed data for politically exposed persons, ultimate beneficial ownership and adverse media, supplied by third party providers under commercial agreement. We name our data suppliers to clients under a mutual non disclosure agreement as part of vendor due diligence. Ask us and we will provide the list.

We do not resell or redistribute licensed list data. It is used to screen your records inside your instance.

Model validation and tuning

The AI Alert Clearing Agent performs identity resolution only. It does not make a final regulatory determination and it does not replace human review. Every invocation records the model identifier, the prompt version, the input payload, the raw response, the parsed outcome, a confidence score, the risk factors identified, the rationale and the resulting state transition. Any historical decision can be reproduced by replaying the recorded input through the recorded prompt version.

Validation to date: a 1,000 name validation run was completed in a controlled non-production environment in April 2026, measured against the same population processed without the Agent. It produced a 47.4% reduction in manual workload and a 98.2% reduction in raw, uncategorised alerts. The clearance rate improved from 94.3% to 97.0%.

Institutions operating under United States model risk management expectations, including SR 11-7, should validate against their own data before relying on the Agent in production. That is what the pilot is for. It runs 30 to 90 days scoped to your volume, on your own alert queue, and it produces the evidence your model validation function needs rather than a vendor assertion.

The full methodology, the escalation rules, the decision logic and the audit design are published at Alert Clearing Methodology and Model Governance.

Where the AI runs and who processes your data

The Agent runs on AWS Bedrock using the Amazon Nova model family in the us-west-2 region, under an IAM execution role with no static keys. Zero data retention is configured. Customer content is not used for model training. Traffic is encrypted in transit using TLS 1.2 or above.

There are exactly two subprocessors: Amazon Web Services and Rackspace Technology. A data processing agreement is available on request.

What to ask us for

A buyer running vendor due diligence on a compliance platform should be asking for specific evidence. Here is the list, so you do not have to construct it.

  • The SOC 2 Type II report for the hosting infrastructure, and the current status of our application layer attestation
  • The ISO/IEC 27001 certificate for the hosting infrastructure
  • The data processing agreement and the subprocessor list
  • The names of our commercially licensed data suppliers, under mutual NDA
  • The clearing methodology pack and the model governance documentation
  • The most recent penetration test summary
  • Client references at institutions of comparable size and regulatory profile
  • Our data residency position for your jurisdiction

All of it goes to security@globalradar.com or through your account contact.

Request Signed Reports

Procurement and InfoSec teams: request the Rackspace SOC 2 Type II report and ISO/IEC 27001 certificate covering the hosting environment, the Global RADAR penetration test letter, or completed CAIQ/SIG questionnaires. Reports are delivered under mutual NDA.

Request Signed Reports Under NDA

Disclosure cadence

Global RADAR reviews and updates this page each time a new attestation is issued or renewed.

Reporting a vulnerability

Independent researchers may report vulnerabilities to security@globalradar.com. We acknowledge reports within 2 business days.

Regulatory guides

Plain English explainers on the obligations behind sanctions screening, each written from primary sources and dated: