Screening is easy. Proving the decision later is the hard part.
Verifex returns the decision, coverage, candidate-completeness, and evidence state needed for compliance, risk, and operations teams to review a screening result without treating a zero-match result as universal clearance.
Decision contract
A zero-match result is not enough on its own.
The API returns the conditions a caller must check before treating a screening result as clear. A retrieved candidate is not a confirmed identity, and an unavailable, partial, or capped result is not complete coverage.
- screening_mode
- An `exact_only` result may never be read as a clearance. The mode deliberately skips fuzzy, phonetic, transliteration and typo recovery, so “no exact candidate” is not evidence the party is unlisted.
- clearance_eligible
- When false, no combination of other fields makes the result clean. Treat it as unresolved regardless of `risk_level`.
- coverage_status
- Partial or unavailable coverage cannot clear. Absence of a hit in the sources that answered says nothing about the ones that did not.
- candidate_set_complete
- A truncated set cannot clear. No-hit inside a capped set is not no-hit — it is no-hit in the part that was examined.
Auditors ask five questions.
Most screening tools answer the first one. Verifex is designed to answer all five.
What was screened?
When was it screened?
Which list version was active?
Why was it cleared or reviewed?
Who approved the decision?
Verifex preserves all five.
Use an Evidence Capsule only once the response reports its evidence record as available.
Verifex works beside your existing workflow.
Many regulated teams already screen names. The gap appears later — when someone asks what was checked, which list version was active, why a match was cleared, and who approved the decision.
Secondary screening & evidence layer
Add a transparent second opinion with preserved match rationale and audit IDs.
Audit capsule generator
Generate structured proof behind every clear, review, or block decision.
Internal benchmark layer
Run test cases, compare scoring visibility, and perform regression checks.
Regional KYB desk
Turkey/Azerbaijan company verification with registry evidence and structured delivery.
What the evidence capsule contains.
queryThe exact name and context submitted for screening
entity_typePerson, company, vessel, or aircraft
screened_atISO timestamp with millisecond precision
list_versionsVersion identifiers of every source checked
screening_modeThe screening contract that ran, including the Exact-Only limitation where applicable
clearance_eligibleWhether this result can support a clearance at all
coverage_statusWhether every in-plan core source was actually screened
candidate_set_completeWhether the evaluated candidate set was complete or capped
evidence_persistenceWhether the evidence record is available, pending, or unavailable
evidence_capsule_idDeterministic cross-reference for compliance reconstruction
From match result to reviewable evidence.
Legacy screening
Name → Match result → Spreadsheet note → Lost context
Verifex
Name → Match result → Evidence capsule → Reviewer action → Audit export
Controls designed for compliance review.
Audit trail
The response exposes whether evidence is available, pending, or unavailable. Availability is not a retention commitment. Screening and canonical decision records use the current ten-year default retention policy. This describes the service implementation, not a universal legal requirement or a substitute for a customer's retention policy.
Screening logs
Use the recorded decision context, source scope, and review activity available to your account for compliance documentation.
Reviewer actions
Analyst activity is distinct from the machine decision. A disposition cannot turn a candidate into a confirmed identity or weaken a safety constraint.
Exportable evidence
Use a capsule only after its evidence state reports it available. Available export routes depend on your plan and configuration.
Retention
Screening and canonical decision records use the current ten-year default retention policy. This describes the service implementation, not a universal legal requirement or a substitute for a customer's retention policy. Confirm contractual recordkeeping terms before relying on a retention period.
Monitoring
Add entities to continuous monitoring and configure available notifications for changed screening results.
Risk can hide behind ownership.
A company may not appear on a sanctions list and still create sanctions exposure through ownership or control. Verifex provides ownership-chain context where source data supports it — including GLEIF-based parent linkage and aggregate sanctioned-ownership calculations.
- GLEIF-based context where available
- Aggregate sanctioned-ownership calculations
- Ownership-chain visibility where source data supports it
- Manual-enhanced reports where official data is limited
- Analytical support, not legal determination of blocking status
Important
OFAC 50% Rule calculations are provided as analytical support to help compliance teams identify ownership-control risk direction. They are not a legal determination of blocking status. Final decisions should always be reviewed by qualified legal and compliance personnel.
Designed for production workflows.
Monitored infrastructure, clear operational logs, and security controls built for regulated environments.
API Key Security
SHA-256 hashed API keys. Keys are never stored in plaintext.
Webhook Integrity
HMAC-signed webhook payloads for tamper-evident delivery verification.
Password Security
bcrypt password hashing with salt rounds for account security.
Rate Limiting
Per-key rate limiting with brute-force protection.
Security Controls
Encryption in transit (TLS) and daily database backups. Verifex has not completed a SOC 2 examination and holds no ISO 27001 certification. Security documentation is available on request.
Data Handling
Screening requests and results are stored as your account-scoped audit evidence and retained per plan; we keep no more personal data than is needed to run and evidence a screen.
Common questions.
Can I use Verifex as my primary sanctions screening tool?
Verifex can serve as the screening API inside your compliance workflow. It should be configured and reviewed as part of your own risk-based program, internal policies, and legal obligations.
How quickly are new sanctions reflected?
Source freshness and execution state are recorded with each screen. Do not treat a published timing estimate as a substitute for the result's actual coverage and availability fields.
Do you support ongoing monitoring?
Continuous monitoring can be used for watched entities. Notification and webhook availability depend on your plan and configuration, and a notification is not a substitute for reviewing the served result.
Does Verifex distinguish between PEP hits and sanctions hits?
Yes. A PEP status is a risk-based screening category, not a finding of wrongdoing, a sanctions designation, or an automatic block. The served decision and applicable policy remain distinct from that category.
What is entity resolution and why does it matter for compliance?
Entity resolution merges duplicate records across configured sources into a single canonical profile. Without it, similar names across different sources can generate multiple alerts. With entity resolution, they resolve to one profile — reducing alert volume and making it easier to see every alias and source in one place.
Do you support OFAC 50% Rule calculations for corporate entities?
The UBO chain tool traverses corporate ownership chains where source data supports it and calculates aggregate sanctioned ownership under the OFAC FAQ No. 401 (50% Rule). It flags ownership-control risk direction where sanctioned parties own 50% or more in aggregate. This is analytical support, not a legal determination of blocking status.
What happens if your service goes down?
Verifex is designed for production workflows with monitored infrastructure and clear operational logs. If a screening request fails, we recommend implementing retry logic with exponential backoff. Your compliance obligations require you to screen — if our service is unavailable, queue the screening and retry.
Do you provide a vendor due diligence questionnaire?
Yes. Contact us at [email protected] for our security documentation and vendor due diligence materials.
Where does your PEP data come from?
PEP records are sourced from configured data feeds, including Wikidata (CC0 license) where applicable. Wikidata is a community-maintained knowledge base with known gaps: coverage of family members and known close associates varies by jurisdiction, historical records may be incomplete, and record quality depends on volunteer curation. Customers should validate PEP source suitability for their regulatory program and jurisdiction. Verifex does not claim regulator-grade PEP coverage.
Generate reviewable screening evidence
Start with 50 free screens/month. No credit card. No sales calls. Audit trail access begins on Starter.