Changelog

What we have built so far, newest first. We started building Semak AML in July 2026. Dates are shown as DD/MM/YYYY.

  1. New screening data provider and stronger browser protection

    • Support for an additional third-party screening data provider.
    • Stronger security headers on every page of the platform, including protection against the platform being shown inside other websites.
  2. –

    Software updates and security checks

    • Upgraded the platform's main software components, including the PDF report engine, to current versions.
    • Automatic checks of third-party software packages for known security vulnerabilities on every change.
    • Temporary copies of data provider responses are now kept separate for each client organisation.
  3. Name-free notification emails

    • Notification emails no longer include the names you screened.
    • Clearer messages when the connection to the platform fails, and actions such as starting a search are never repeated automatically.
  4. Clearer result wording and automatic token credits

    • Results and PDF reports now describe potential matches as returned by the data provider, and each review decision is attributed to the client user who entered it.
    • If a search fails because of a platform or provider error, the token is credited back automatically.
    • Searches that stop responding are detected and closed, with the token credited back.
  5. –

    Easier to use, and team management for clients

    • Interface fixes and accessibility improvements across the screening steps.
    • Client administrators can invite, deactivate and reactivate their own team members.
  6. Better screening form, DD/MM/YYYY dates and bulk screening

    • All dates on the platform, in PDF reports and in exports are shown as DD/MM/YYYY.
    • The screening form asks for identifying details suited to individuals or organisations; an individual can be identified by national ID or passport number.
    • Screen many names at once by uploading a spreadsheet, using one token per name.
  7. Security hardening

    • A full security review of the platform, followed by fixes across sign-in, screening records, data provider connections, file uploads and emails.
    • Screening results are protected against later changes at several layers of the system.
  8. Two-step login for client users

    • Two-step login for client users: a password plus a one-time code sent by email.
    • A second layer of separation in the database, so each client organisation's data stays separate from other clients'.
    • Changing or resetting a password signs the account out everywhere.
  9. Sign-in protection

    • Accounts are temporarily locked after repeated failed sign-in attempts, and sign-in requests are rate-limited.
    • Authenticator-app two-step login for the platform's most privileged administrator accounts.
  10. Foundations for launch

    • Prepaid token accounts: 1 token = 1 name search, with every credit and deduction recorded.
    • Versioned client terms with a record of each user's acceptance.