Security & Compliance

Security and regulatory compliance

Protecting your data is the first obligation, not an afterthought. tessavorsolution builds to recognised security control requirements and runs compliance programs across the jurisdictions it serves, so you can operate with confidence. What follows is written the way we would answer on a call: eight questions, in the order they usually come up, with the facts underneath each one.

8 sections · five programmes · one posture

01 Verify

How is a customer verified?

Automated identity checks cover people and companies alike — document validation, biometric matching, and monitoring that never pauses.

Verification is not a one-off gate at onboarding. The same checks keep running afterwards, so a change in status, ownership or paperwork surfaces on its own rather than at the next review.

Scope
People and companies alike
Method
Document validation and biometric matching
Cadence
Monitored without pause

Read the verification API

02 Screen

What is screened, and how often?

Screening runs continuously against sanctions lists worldwide — OFAC, UN, EU and HMT — rather than on a schedule someone has to remember.

Alerts are raised on their own, and each case is tracked through to closure, so nothing sits unresolved in a queue.

Lists
OFAC · UN · EU · HMT
Reach
Worldwide, ongoing
Alerts
Raised on their own
Cases
Tracked through to closure

Read the screening API

03 Watch

How is suspicious activity caught as it happens?

Monitoring is AI-backed: rule-based logic combined with behavioural analytics and thresholds you define.

That mix catches the patterns rules alone miss, without handing your team a queue of noise you did not ask for.

Engine
AI-backed
Logic
Rule-based logic plus behavioral analytics
Thresholds
Set by you

Read the monitoring API

04 Report

Who files the reports, and with which authorities?

Reporting is prepared for FinCEN, FinTRAC, AUSTRAC, and other authorities as required, with SAR/STR filing support built in.

We can walk your team through the filing path for each jurisdiction you operate in.

Authorities
FinCEN · FinTRAC · AUSTRAC
Filing
SAR / STR filing support
Scope
Other authorities as required

Ask about filing support

05 Protect

How is access controlled, and how is data sealed?

Multi-factor authentication, role-based access control, API key management, IP allow-listing, and audit logging sit at every level.

Stored data is guarded with AES-256; data in motion with TLS 1.3. Redundant infrastructure spread across multiple regions keeps the service answering — engineered for continuous availability rather than best effort.

Access
Multi-factor authentication, role-based access control, API key management, IP allow-listing, audit logging at every level
Encryption
AES-256 at rest, TLS 1.3 in motion
Availability
Redundant infrastructure across multiple regions, engineered for continuous availability

Request the documents

06 Found

What does all of this stand on?

AWS and Azure environments hosted in data centers aligned to SOC 2 Type II controls, guarded by DDoS mitigation, a web application firewall, and round-the-clock vulnerability scanning.

An information security management program aligned to ISO 27001 practices sits over that, backed by regular risk assessments and continuing improvement.

Personal data is handled in line with GDPR and CCPA, encrypted at rest and in transit, with residency choices and a DPA available on request.

Cloud infrastructure
AWS and Azure, in data centers aligned to SOC 2 Type II controls
Information security
A management program aligned to ISO 27001 practices
Data privacy
GDPR and CCPA, with residency choices and a DPA on request

Request the DPA

07 Posture

Which standards are you aligned to?

Programs are built to SOC 2 Type II and ISO 27001 control requirements, alongside PCI DSS–aligned payment handling and GDPR/CCPA privacy practices.

Alignment is documented rather than merely asserted: the paperwork is shared with customers on request.

SOC 2
Type II control alignment
PCI DSS
Aligned payment handling
ISO 27001
ISMS-aligned practices
GDPR
EU privacy compliance

Request the documents

08 Assurance

How do you keep that alignment current?

A compliance function staffed in-house follows rule changes and refreshes policies as they take effect — the spine that keeps the rest of the program current.

Controls are mapped to the NIST framework and reviewed on a fixed cycle. Assessments are performed by qualified security assessors, and penetration testing is folded into the release cycle, with round-the-clock vulnerability scanning running alongside automated security testing.

Controls
Mapped to the NIST framework, reviewed on a fixed cycle
Assessment
Performed by qualified security assessors
Testing
Penetration testing folded into the release cycle
Scanning
Round-the-clock vulnerability scanning and automated security testing
Documents
Compliance documentation shared with customers on request

Talk to the compliance team

05 Assurance strip

Five programmes, one posture.

What each alignment means in practice — and what we hand over when your review asks for it.

Controls are mapped to the NIST framework and reviewed on a fixed cycle, and assessments are performed by qualified security assessors.

An information security management program aligned to ISO 27001 practices, backed by regular risk assessments and continuing improvement.

Payment handling aligned to PCI DSS control requirements across the platform.

Personal data encrypted at rest and in transit, with residency choices and a DPA available on request.

The same handling under CCPA, with residency choices and a DPA available on request.

5 programmes · documentation on request

Request the documents Browse the API docs