Security
Security overview
Practical protections for data, access, and the integrity of AML findings. Formal policies and certifications will be published as the platform matures.
Data in transit
All API and app traffic is served over TLS. State-changing requests require an explicit request header as part of our CSRF posture.
Access control
The analyst workspace is auth-gated in production with roles and an audit log, so access to findings is scoped and accountable.
Data handling
Public checks are anonymous and return redacted bands only. Full assessments stay inside authenticated accounts and are not exposed publicly.
Honest findings
Security of the verdict matters too: results are scoped to coverage with source and confidence, so decisions are never based on fabricated data.
Report a vulnerability
Found a security issue? Contact us at deals@x2b.io and we will follow up. A detailed security policy is being prepared.