Skip to content
Security

Security you can check.

Sieve sees your customers and every shilling and naira they move. Here is how we protect that.

  • AES-256-GCM
  • HMAC-SHA256
  • Argon2id
  • TOTP two-factor
  • Hash-chained audit log
  • 7-year records
01

Data protection

  • Names, phones, emails, national IDs and birth dates are encrypted with AES-256-GCM before storage.
  • Phones, emails, IDs, payout accounts and devices are indexed with keyed HMAC-SHA256. Sieve matches them without decrypting.
  • Live and test data are fully separate. A test key can’t touch live data.
  • Host in the region you choose, or inside your own environment.
customer record · receivedAES-256-GCM
  • NameWanjiru A. Otieno
  • Phone+254 700 000 123
  • National ID29 481 736
  • Email[email protected]
  • Date of birth1994-03-17
link index · keyed hashHMAC-SHA256

Illustrative record

02

Identity & access

  • Passwords are hashed with Argon2id. Accounts lock after repeated failures, and errors never confirm an account exists.
  • TOTP two-factor sign-in is required to create a live API key.
  • Sessions are opaque tokens in httpOnly, SameSite=Strict cookies, with CSRF protection and idle timeouts.
  • Four roles: owner, admin, analyst and viewer. Viewers see personal data masked.
03

Application security

  • API keys are shown once and stored only as SHA-256 fingerprints. Each is rate-limited and instantly revocable.
  • Every input is checked against a strict schema. Errors never expose internals.
  • Webhooks are signed with HMAC-SHA256 and a timestamp. They only go to public HTTPS endpoints.
  • Content Security Policy, HSTS and hardened headers on every response.
04

Integrity & audit

  • Every sensitive action goes into an append-only, hash-chained audit log. Alter one entry and the chain breaks.
  • Each decision stores its ruleset version and the exact response sent. You can explain it months later.
  • Screening results record the version of each list used.
audit log · per institutionappend-only
rule.updatedprev 61c8864f
hash 00000000
case.closedprev 00000000
hash 9e3779b1
decision.labelledprev 9e3779b1
hash 3c6ef362
7years of decision, screening and audit records, each chained to the last.
05

AI governance

  • The AI investigator is optional, and every run is logged.
  • Customer names, phone numbers and emails are never sent to the model.
  • Record contents are treated as untrusted. Instructions hidden in data are ignored.
  • The agent only recommends and drafts. It can’t close cases, change rules, move money or contact customers.
On-premise option

Your data never leaves the building.

Banks can run Sieve entirely inside their own network. No customer data needs to reach us, or anyone else.

Runs on your servers

On-premise
How
The engine, dashboard and database run in your data centre or private cloud. Docker, Kubernetes and air-gapped networks all work.
What that means
Your PostgreSQL, encryption keys and backups. Upgrades ship as image bundles with checksums you verify.

Your own AI model

Local AI
How
Case summaries and STR drafts run on a model you host: Ollama, vLLM or any compatible server.
What that means
Case data goes to your model only. With no model, write-ups fall back to rule-based text.

Your data stays in

Private network
How
Load history and fraud labels from your core banking exports. Screen and alert using your own list files and mail relay.
What that means
Private-network mode blocks any connection that would leave your network.
Responsible disclosure

Tell us before you tell anyone.

Found a vulnerability? Email us the details and steps to reproduce.

Report to[email protected]

Our commitment

  • We acknowledge reports within two working days.
  • We keep you updated until it’s fixed.

Please don’t

  • Access data that isn’t yours.
  • Degrade the service.
  • Go public before we ship a fix.

Evaluating Sieve? We’ll share our security questionnaire answers and architecture documents.

Request documentation
Book a demo

Bring your toughest reviewer.

We’ll take your approvers through the architecture, encryption, access and audit trail.