Changelog
What we have built so far, newest first. We started building Semak AML in July 2026. Dates are shown as DD/MM/YYYY.
-
New screening data provider and stronger browser protection
- Support for an additional third-party screening data provider.
- Stronger security headers on every page of the platform, including protection against the platform being shown inside other websites.
-
–
Software updates and security checks
- Upgraded the platform's main software components, including the PDF report engine, to current versions.
- Automatic checks of third-party software packages for known security vulnerabilities on every change.
- Temporary copies of data provider responses are now kept separate for each client organisation.
-
Name-free notification emails
- Notification emails no longer include the names you screened.
- Clearer messages when the connection to the platform fails, and actions such as starting a search are never repeated automatically.
-
Clearer result wording and automatic token credits
- Results and PDF reports now describe potential matches as returned by the data provider, and each review decision is attributed to the client user who entered it.
- If a search fails because of a platform or provider error, the token is credited back automatically.
- Searches that stop responding are detected and closed, with the token credited back.
-
–
Easier to use, and team management for clients
- Interface fixes and accessibility improvements across the screening steps.
- Client administrators can invite, deactivate and reactivate their own team members.
-
Better screening form, DD/MM/YYYY dates and bulk screening
- All dates on the platform, in PDF reports and in exports are shown as DD/MM/YYYY.
- The screening form asks for identifying details suited to individuals or organisations; an individual can be identified by national ID or passport number.
- Screen many names at once by uploading a spreadsheet, using one token per name.
-
Security hardening
- A full security review of the platform, followed by fixes across sign-in, screening records, data provider connections, file uploads and emails.
- Screening results are protected against later changes at several layers of the system.
-
Two-step login for client users
- Two-step login for client users: a password plus a one-time code sent by email.
- A second layer of separation in the database, so each client organisation's data stays separate from other clients'.
- Changing or resetting a password signs the account out everywhere.
-
Sign-in protection
- Accounts are temporarily locked after repeated failed sign-in attempts, and sign-in requests are rate-limited.
- Authenticator-app two-step login for the platform's most privileged administrator accounts.
-
Foundations for launch
- Prepaid token accounts: 1 token = 1 name search, with every credit and deduction recorded.
- Versioned client terms with a record of each user's acceptance.