Skip to main content
United States

Intelligence, AML and cyber defense for US agencies and banks

Our US office is in Dover, Delaware, and our US operations center provides 24/7 security monitoring alongside our Southern African centers. Gov AI supports open-source and social media investigations for federal, state and local agencies, FinCrimes supports Bank Secrecy Act monitoring and SAR preparation for banks, and our cybersecurity team delivers SOC, penetration testing and vCISO services.

Regulatory context
Dover, DE
Priorities

What we do in United States

Regulatory context

The rules your program answers to

A plain summary for orientation, not legal advice. Your own counsel and compliance function decide how each applies.

Bank Secrecy Act and FinCEN reporting
Requires banks and other financial institutions to run an AML program, verify customers and the beneficial owners of legal-entity customers, keep records, and file suspicious activity reports and currency transaction reports with FinCEN. FinCEN guidance asks SAR narratives to explain the who, what, when, where and why of the activity.
OFAC sanctions
US persons must block or reject transactions involving parties on the sanctions lists kept by Treasury’s Office of Foreign Assets Control. Civil liability is strict, so institutions screen at onboarding and again when payments are made.
CJIS Security Policy
Sets the security requirements for any agency or contractor system that stores, processes or transmits criminal justice information, covering advanced authentication, encryption, audit logging and personnel screening.
NIST SP 800-53 and the NIST Cybersecurity Framework
SP 800-53 is the catalog of security and privacy controls federal systems are assessed against under FISMA. The Cybersecurity Framework gives any organization a common structure to govern, identify, protect, detect, respond and recover, and many state agencies and private-sector programs use both.
State privacy and breach-notification laws
California’s CCPA, as amended by the CPRA, and comprehensive privacy laws in a growing number of other states give residents rights over their personal information. Every state also has a breach-notification law, which shapes incident response.
Deployment & data residency

Your data stays where it must

  • On-premises inside agency facilities, including air-gapped networks with no outside connection.
  • Government cloud environments for agencies that need them.
  • Hybrid deployments with selective data synchronization between on-premises and cloud systems.
  • Multi-factor authentication with PIV/CAC card support, role-based access aligned with clearance levels, AES-256 encryption and a tamper-evident audit trail that agencies can map to their own CJIS and NIST SP 800-53 assessments.
In the field

Scenarios in this region

FAQ

Regional questions

Get started

Take the next step

Talk to the team serving United States. We will work within your data-residency and regulatory requirements from the first conversation.

Trust & security