RegTech that handles examiner-grade data is held to examiner-grade controls. Global RADAR runs on SOC 2 Type II and ISO/IEC 27001 certified infrastructure, and applies its own controls at the application layer. The sections below separate what our hosting provider is attested for from what Global RADAR operates directly, so your security team can scope its review accurately. Signed reports are available on request under mutual NDA.
Assurance information current as of 20 August 2026. This page is reviewed and dated each time an attestation is issued or renewed.
Held by Rackspace Technology, Global RADAR’s hosting provider. Trust Services Criteria: Security, Availability, Confidentiality.
Held by Rackspace Technology. Information Security Management System certification covering the hosting environment in which Global RADAR operates.
Data processing aligned with UK GDPR and EU General Data Protection Regulation requirements. Global RADAR hosts customer data in the United States and the United Kingdom.
All customer data is encrypted at rest and in transit using industry-standard cryptographic primitives.
Independent third-party penetration testing of production application and infrastructure.
Documented business continuity and disaster recovery plans with annual tabletop testing.
These are the platform support commitments Global RADAR contracts to. They cover availability and support response for the software. They are not a clearing turnaround commitment. Where an accredited delivery partner performs alert clearing under Managed Clearing, turnaround times and coverage hours are set in the service schedule agreed with that partner.
First line support runs through the client portal, which assigns a case number automatically and tracks status through to resolution. Cases are prioritised when logged, and either party can escalate by changing a case priority.
Global RADAR screens against more than 1,400 sanctions and watchlists. The underlying data falls into two categories.
Official government and supranational lists, ingested directly from the issuing authority. These include the OFAC sanctions programmes maintained by the United States Treasury, the consolidated sanctions list of the European Union, the UK sanctions list maintained by the Foreign, Commonwealth and Development Office, and the OFAC Consolidated list. Updates are ingested on the publisher cadence, and a change in a client alert volume is normally traceable to a specific list update rather than to a change in our matching.
Commercially licensed data for politically exposed persons, ultimate beneficial ownership and adverse media, supplied by third party providers under commercial agreement. We name our data suppliers to clients under a mutual non disclosure agreement as part of vendor due diligence. Ask us and we will provide the list.
We do not resell or redistribute licensed list data. It is used to screen your records inside your instance.
The AI Alert Clearing Agent performs identity resolution only. It does not make a final regulatory determination and it does not replace human review. Every invocation records the model identifier, the prompt version, the input payload, the raw response, the parsed outcome, a confidence score, the risk factors identified, the rationale and the resulting state transition. Any historical decision can be reproduced by replaying the recorded input through the recorded prompt version.
Validation to date: a 1,000 name validation run was completed in a controlled non-production environment in April 2026, measured against the same population processed without the Agent. It produced a 47.4% reduction in manual workload and a 98.2% reduction in raw, uncategorised alerts. The clearance rate improved from 94.3% to 97.0%.
Institutions operating under United States model risk management expectations, including SR 11-7, should validate against their own data before relying on the Agent in production. That is what the pilot is for. It runs 30 to 90 days scoped to your volume, on your own alert queue, and it produces the evidence your model validation function needs rather than a vendor assertion.
The full methodology, the escalation rules, the decision logic and the audit design are published at Alert Clearing Methodology and Model Governance.
The Agent runs on AWS Bedrock using the Amazon Nova model family in the us-west-2 region, under an IAM execution role with no static keys. Zero data retention is configured. Customer content is not used for model training. Traffic is encrypted in transit using TLS 1.2 or above.
There are exactly two subprocessors: Amazon Web Services and Rackspace Technology. A data processing agreement is available on request.
A buyer running vendor due diligence on a compliance platform should be asking for specific evidence. Here is the list, so you do not have to construct it.
All of it goes to security@globalradar.com or through your account contact.
Procurement and InfoSec teams: request the Rackspace SOC 2 Type II report and ISO/IEC 27001 certificate covering the hosting environment, the Global RADAR penetration test letter, or completed CAIQ/SIG questionnaires. Reports are delivered under mutual NDA.
Request Signed Reports Under NDA
Global RADAR reviews and updates this page each time a new attestation is issued or renewed.
Independent researchers may report vulnerabilities to security@globalradar.com. We acknowledge reports within 2 business days.
Plain English explainers on the obligations behind sanctions screening, each written from primary sources and dated: