JUSTE supports regulated organisations with AML risk screening, identity verification, due diligence and decision governance.
Because these workflows may involve confidential client information and identity evidence, security, privacy and accountability are built into how JUSTE operates.
This page provides a public overview of our approach. More detailed security, data-processing, subprocessor and AI-governance documentation is provided to customers, integration partners, auditors and competent authorities through controlled disclosure.
01Security by design
JUSTE applies layered technical and organisational measures intended to preserve the confidentiality, integrity and availability of customer information.
Our security approach includes:
- encrypted communications;
- authenticated user access;
- role-based permissions;
- customer and tenant separation;
- server-side authorisation controls;
- controlled third-party integrations;
- vulnerability identification and remediation;
- security and operational logging;
- incident-response procedures;
- business-continuity and recovery measures;
- contractual confidentiality and data-protection safeguards.
Security controls are reviewed as the platform, its integrations and the applicable risk environment evolve.
02Hosting and data location
JUSTE’s primary production environment is hosted on UK-based cloud infrastructure.
Customer records, screening results, reports and application data managed directly by JUSTE are stored within the controlled JUSTE environment.
Selected specialist providers may process limited information where required to deliver functions such as identity verification, payment processing, transactional email or AI-assisted analysis.
Where information is processed outside the United Kingdom, JUSTE applies appropriate contractual, organisational and data-transfer safeguards.
Detailed subprocessor information is provided to customers and authorised reviewers under the JUSTE contractual documentation.
03Access control
Access to JUSTE is restricted to authenticated users.
JUSTE applies server-side controls designed to ensure that users can access only:
- the customer environment to which they belong;
- the information permitted by their assigned role;
- the actions appropriate to their authority;
- the client files and workflows they are authorised to manage.
Customer environments are separated through application-level multi-tenancy controls.
Passwords are stored using secure one-way hashing. Browser sessions use cryptographically secure identifiers, and security attributes are applied to authentication cookies.
Administrative and production access is restricted to authorised personnel with a legitimate operational need.
04Application and infrastructure security
JUSTE requires HTTPS for application and integration communications.
Application controls include input validation, request sanitisation, output encoding and structured database queries designed to reduce exposure to common web-application risks, including:
- cross-site scripting;
- cross-site request forgery;
- injection attacks;
- broken access control;
- sensitive-information exposure;
- insecure configuration.
Application dependencies are monitored for known vulnerabilities. Issues are assessed according to severity, exploitability and system exposure, with critical and high-risk findings prioritised for remediation.
Where an immediate permanent fix is not available, temporary mitigating controls may be applied while the underlying issue is resolved.
05Security of the Clio integration
JUSTE connects to Clio Manage through the OAuth 2.0 Authorization Code Flow.
Customers must actively authorise the connection. JUSTE does not receive or store a customer’s Clio username or password.
In the current integration, an authorised Clio user initiates a JUSTE workflow from a specific contact or matter. JUSTE then accesses only the information required to perform that workflow.
Depending on the information available and the action requested, this may include:
- contact and matter identifiers;
- name and contact information;
- address and date-of-birth information;
- company details;
- associated client or matter information;
- document-folder references required to return the report.
Clio access and refresh tokens are stored in encrypted form and remain available only to authorised backend services.
Each connected Clio firm is mapped to its own JUSTE customer environment and policy configuration.
When the requested workflow is complete, JUSTE returns the relevant screening or inspection report to the associated Clio contact or matter documents.
JUSTE does not continuously copy an entire Clio account as part of the standard user-initiated workflow.
06Data minimisation
JUSTE seeks to process only the information required for the requested screening, verification or due-diligence task.
The information required depends on:
- the type of customer;
- the regulated service;
- the applicable risk factors;
- the customer’s own AML Risk Policy;
- whether SDD, CDD or EDD is required;
- the evidence needed to resolve identified risk.
Low-risk customers should not be subjected to unnecessary information collection merely because a more complex customer might require deeper due diligence.
07AI security and governance
JUSTE uses AI to assist with defined AML workflows, including risk analysis, policy comparison, due-diligence preparation, quality review and report generation.
AI does not replace the regulated organisation’s decision-making responsibility.
The operating principle
AI executes.→Policy governs.→Humans supervise.
AI operates within controlled workflows and under the customer’s codified AML Risk Policy.
Material outputs remain subject to:
- policy rules;
- authorised human review;
- escalation requirements;
- approval controls;
- recorded intervention;
- the customer’s final decision authority.
High-Risk files may be held until the required senior authority reviews and approves the next step.
Where an AI recommendation and the customer’s policy differ, the policy governs. The system records the applicable rule, policy version and resulting outcome.
Material outputs may include provenance information identifying the relevant:
- model;
- agent;
- prompt version;
- policy version;
- review or override;
- responsible human;
- timestamp;
- final rationale.
Customer information is not used by JUSTE to train or calibrate external general-purpose AI models.
08Human oversight
Human oversight is a structural part of JUSTE.
Depending on the customer’s operating model, responsibilities may be assigned to:
- AML Team LeadsManage routine screening, SDD and CDD administration within defined authority and policy guardrails.
- MLROs or nominated senior authoritiesReview escalated and High-Risk files, assess EDD outcomes and authorise decisions that require senior authority.
- Senior managementApprove the organisation’s AML Risk Policy, risk appetite, escalation structure and governance framework.
Authorised users can review, question, adjust, stop or escalate an AI-assisted output. Material human interventions are recorded.
09Decision provenance and audit evidence
JUSTE is designed to preserve the operating history of an AML decision.
Depending on the workflow, the resulting record may show:
- what information was considered;
- which sources and checks were used;
- when the screening took place;
- what the AI found and recommended;
- which policy rule governed;
- whether policy changed the recommended classification;
- what additional evidence was requested;
- who reviewed or authorised the outcome;
- why the final decision was reached.
This allows a customer to answer a more important question than whether a screening was performed:
How did the organisation’s policy govern this particular decision?
JUSTE supports the customer’s ability to evidence its process. It does not provide a warranty that every customer decision is legally correct or that use of the platform alone satisfies every regulatory obligation.
10Data protection
JUSTE enters into a Data Processing Agreement with its customers.
Under that agreement:
- the customer remains the controller of its client information;
- JUSTE acts as processor for the contracted services;
- information is processed only for agreed purposes and authorised instructions;
- personnel with access are subject to confidentiality obligations;
- subprocessors must operate under appropriate contractual safeguards;
- customers are supported with data-subject and regulatory requests;
- personal-data incidents are handled under documented notification and cooperation procedures;
- customer information is returned or deleted in accordance with the applicable agreement and legal requirements.
Customers remain responsible for establishing the lawful basis for their own processing and for providing any required client-facing privacy information.
11Retention and deletion
JUSTE retains customer information according to:
- the contracted service;
- customer instructions;
- configured retention requirements;
- applicable AML and professional-record obligations;
- legitimate audit and security needs;
- applicable data-protection law.
On termination, access is withdrawn and customer information is returned, deleted or retained only where the applicable agreement or law requires it.
Residual information held within backup systems is removed through the applicable backup lifecycle.
Detailed retention arrangements are contained in the customer’s contractual documentation.
12Service availability and resilience
JUSTE maintains a contractual monthly service-availability target of 99.5%, subject to scheduled maintenance, emergency maintenance and events outside reasonable operational control.
The platform is monitored through automated availability checks.
JUSTE maintains procedures intended to support:
- service monitoring;
- incident detection;
- emergency maintenance;
- service restoration;
- backup and recovery;
- customer communication;
- corrective action following significant incidents.
Specific service levels and remedies are described in the customer’s Service Level Agreement.
13Security incidents
JUSTE maintains an incident-response process for suspected or confirmed security and personal-data incidents.
The process may include:
- assessment and classification;
- containment;
- investigation and evidence preservation;
- remediation;
- restoration of affected services;
- assessment of contractual and legal notification duties;
- customer cooperation;
- post-incident review and corrective action.
Where a confirmed incident affects customer information, JUSTE will notify the affected customer without undue delay and in accordance with the applicable agreement and legal obligations.
14Contractual assurance
Every JUSTE customer enters into contractual documentation governing the service.
Depending on the product and integration, this may include:
- the Service Provider Agreement;
- the Service Level Agreement;
- the Data Processing Agreement;
- the Security and Technical Measures Schedule;
- the AI Governance and Transparency Schedule;
- the Subprocessor Schedule;
- integration-specific security terms.
These documents provide customers with more detailed information than is appropriate for unrestricted public publication.
15Detailed documentation
Detailed security and governance information is available to:
- contracted customers;
- prospective customers conducting legitimate vendor due diligence;
- integration partners;
- external auditors;
- insurers;
- competent regulators and supervisory authorities.
Access may be subject to confidentiality obligations or a non-disclosure agreement.
Available information may include:
- technical and organisational measures;
- data-flow descriptions;
- integration permissions;
- subprocessor information;
- AI-governance documentation;
- incident-response information;
- continuity and recovery information;
- audit-support documentation;
- data-retention and deletion arrangements.
17Contact
Security, privacy and supplier due-diligence enquiries may be sent to:
71–75 Shelton Street
London WC2H 9JQ
United Kingdom
Email: support@juste.ai
Please do not include passwords, API credentials or live identity documents in an initial enquiry.