Security & compliance

You trust us with your customers. Here's exactly how we handle it.

Compliance software has to be held to a higher standard than the institutions it serves. This page sets out how Sentinel protects data, which regulations it is designed around, and where our responsibility ends and yours begins.

Regulatory position

What Sentinel is, and what it isn't.

What Sentinel is

  • Software, provided as a service by Drame Corp.
  • Designed around the CBN Baseline Standards for Automated AML Solutions, with an evidence pack that shows how your configuration covers each capability.
  • Built to produce STRs and CTRs in the NFIU's goAML XML format.
  • A data processor acting on your instructions for the customer data you send us.

What Sentinel isn't

  • Licensed, approved, certified or endorsed by the CBN, the NFIU, the SEC or any other regulator. None of them licenses AML software.
  • A substitute for your MLRO, your compliance function or your board's oversight.
  • A filer of reports on your behalf. Your institution reviews and submits its own reports.
  • A guarantee of compliance. Your institution remains responsible for its AML/CFT/CPF programme and the decisions it takes on customers.
Data protection

Built for the Nigeria Data Protection Act.

For the customer data you send us, your institution is the data controller and Drame Corp is the data processor. We process it only to provide Sentinel, under a data processing agreement, and never sell it or use it for advertising.

Minimised by design

BVNs, NINs, phone numbers and account numbers are stored as one-way keyed hashes, with a different key for every institution. Screens show masked values only. Identity-check results are trimmed to what an investigation needs.

Consent and lawful basis

Every identity verification records the customer's consent. Fraud-network sharing runs on a documented legitimate-interest basis, is opt-in, and shares only keyed hashes, never raw identifiers.

Where data lives

Our shared cloud runs in the UK and EU. Transfers outside Nigeria are governed by the safeguards set out in our data processing agreement. Institutions that must keep data in Nigeria can choose a dedicated, in-country Enterprise deployment.

Security controls

Defence in depth, from the database up.

Tenant isolation

Every institution's data is separated by row-level security enforced inside the database itself, not only in application code. A query from one tenant can't return another tenant's rows, even if the application has a bug.

Encryption

All traffic is encrypted with TLS end to end, from the browser to our edge and from the edge to our servers. Sensitive fields such as two-factor secrets and payment authorisations are additionally encrypted inside the application.

Access control

Six built-in roles separate analysts, compliance officers, auditors, developers and administrators. Two-factor authentication, strong password rules and single sign-on with your identity provider are available.

Accountability

An audit log records configuration changes, case decisions, reviews and exports, with who did what and when. Case closure needs a second officer's approval.

API security

Every API request is HMAC-signed with a timestamp, so intercepted requests can't be replayed. Keys can be restricted to your server IPs, and webhooks we send you are signed the same way.

Resilience

SDKs fail open, so an outage on our side never blocks your customers' payments. Events are queued and retried, and databases are backed up regularly to separate storage.

Assurance

Certifications and registrations.

We'd rather tell you exactly where we are than imply an audit we haven't finished. This table is kept up to date.

ItemStatus
CAC company registration (Drame Corp)In progress
NDPC registration (data controller / processor)In progress
Data processing agreement for customersAvailable
SOC 2 Type IIPlanned
ISO/IEC 27001Planned

Report a vulnerability. If you believe you've found a security issue in Sentinel, email [email protected]. We'll acknowledge your report within two working days. Please don't access other customers' data or disrupt the service while testing.

Due diligence pack. Procurement and risk teams can request our security questionnaire answers, data processing agreement and architecture overview at [email protected].

See Sentinel on your own transaction patterns.

Book a 30-minute walkthrough with our team, or start in the free sandbox today and send your first event in minutes.