Calmony connects to the OFSI consolidated list with nightly automated sync, exposes a REST API v1 for server-to-server use, and sends real-time alerts via SMS and email — no custom plumbing required.
[ SANCTIONS DATA SOURCE ]
Calmony pulls the latest UK Office of Financial Sanctions Implementation (OFSI) list automatically each night. Your screening database is never more than 24 hours behind an official update.
Automated nightly sync The consolidated list is fetched and diffed each night without any manual trigger.
Fuzzy name matching Aliases, transliterations and near-matches surface entities a literal-text search would miss.
Version-controlled imports Each sync creates a versioned snapshot so you can see exactly what changed and when.
Sanctions change log A dedicated List Changes view shows every addition, removal and amendment since your last review.
Discovered CSV URL validation The sync engine validates the source URL against approved gov.uk domains before fetching, preventing spoofed updates.

[ REST API v1 ]
The REST API v1 lets your own systems submit individuals and entities for screening, retrieve match results, and query the sanctions list — all without touching the UI.
Generate a scoped API key from Settings. Keys are revocable and audit-logged on every use.
POST a name, date of birth and nationality. Calmony screens against the active OFSI list immediately.
Poll or webhook-trigger to receive structured match results with confidence scores and OFSI entity detail.
Every person added via API is re-screened automatically after each nightly sanctions sync with no extra calls needed.
Join the waitlist and be first to screen with automated OFSI sync, a full REST API and real-time alerts. Questions? Email us at sf-core-org-support-calmony-sanctions-monitor@saas-factory.ai
[ ALERTS / NOTIFICATIONS ]
When a new match is detected or the OFSI list changes, a text message reaches your compliance lead immediately — no dashboard login required.
Structured email alerts include the matched entity name, confidence score and a direct link to the review queue — ready to act on from any inbox.
[ AUTHENTICATION / SSO ]
Calmony supports OAuth single sign-on via Google, GitHub and Microsoft Entra ID. No separate credential management. Your existing IT policy governs access.
Let your compliance team sign in with their existing Google accounts. Works with Google Workspace domain restrictions.
Ideal for organisations that operate technical compliance functions alongside development teams.
[ PAYMENTS / BILLING ]
Screening credits are purchased through Calmony Pay. Webhooks confirm payment and apply credits instantly — with idempotency built in so a replayed event never double-credits your account.
Webhook-confirmed credits Credits are applied only after payment confirmation via a signed webhook event.
Auto top-up option Set a credit threshold and Calmony tops up automatically so screening never stops mid-workflow.
Full transaction history Every credit purchase, consumption and balance change is recorded with a timestamp in the billing dashboard.
[ DATA LAYER ]
All screening data, people records, match results and audit logs are stored in a fully managed Neon Postgres database. No self-hosting, no patching.
PII fields — names, dates of birth, nationality — are encrypted at the field level using AES-256-GCM before writing to the database.
[ ADVERSE MEDIA ]
Beyond the OFSI list, Calmony includes an adverse media screen accessible from the same dashboard. Compliance teams get a more complete risk picture without switching tools.

[ FREQUENTLY ASKED ]
Every alert also lands in the Match Review screen so your whole compliance team has a shared audit trail of every decision made.

MATCH REVIEW — LIVE
Matches surface in the review queue with the full OFSI entity record alongside your submitted data. Reviewers can accept, dismiss, or escalate — every decision is timestamped and audit-logged automatically.
Confidence score per match
Side-by-side entity comparison
Reviewer notes field
Immutable audit log of every action
Connect your Azure Active Directory tenant. Access is governed by your existing Entra ID policies and MFA configuration.
No subscription lock-in Buy credits when you need them. There is no monthly commitment — pay for what you screen.

A GDPR delete endpoint anonymises all personal data on request. Retention periods are documented and the platform includes a full ROPA and lawful basis page.
Every create, update, delete and data-access event is written to an audit log with user ID, timestamp and resource reference — ready for regulatory inspection.
The adverse media screen sits alongside the OFSI sanctions view in the same navigation. Results are surfaced with the same review workflow — reviewable, audit-logged and tied to the same person record.
Same person record across sanctions and media
Reviewable results with notes
Unified audit trail