Privacy

This is a stateless pre-file check, not a filing portal. Report payloads are highly sensitive under AML rules. They are not posted here, not stored, and not sent to a regulator from this site. PII is never shown in the view.

How it stays local: what runs in this browser, what stays on this device, and what leaves when you send a message or a page view.

What this site does with case data

  • JSON, XML, CSV, TSV, and NDJSON on Check one or Batch check, Scan transactions, or Scan clients stay in short-lived browser memory. Checks run locally (a worker when the browser supports it).
  • Names, dates of birth, addresses, and identifiers display as [MASKED]. The engine still uses the in-memory original on your machine.
  • There is no case-data database and no server cache of payloads. Page views may be counted (Vercel Analytics). Contact messages go to Formspree. Report payloads are not included.

Client-side checks

Checking a report on Check one or Batch check, Scan transactions, or Scan clients runs entirely in your browser. There is no backend anywhere for those screens, and we do not process case data on a server: the payload is not posted to this site, not written to a log, and not sent to a regulator. HTTP validate is disabled and returns 410 without reading the body. The engine only checks field structure and format against published rules, in memory, then discards the payload when you leave. We do not keep a filing history.

PII is never shown

Names, dates of birth, occupation, addresses, email, telephone, and identification numbers display as [MASKED]. That overlay is for the view and for screenshots. Checks still use the in-memory original on your machine. The original is not stored here. A local CLI (npm run mask-pii) can mask or AES-256-GCM-encrypt those fields in workspace files.

Google Sheets add-on

The FIU Ready Google Sheets editor add-on is coming soon. When it ships, it will run the same FinCEN (CTR, SAR, Form 8300, FTR Travel Rule checklist), FINTRAC (LCTR, STR, LVCTR, EFTR), and AUSTRAC (TTR, SMR, IFTI as EFT, IFTI-DRA) checks inside your Google account via Apps Script. Report field values stay in the spreadsheet you open. The bundled engine validates in that script execution environment; it does not post report payloads to our servers or this site, does not store them, and does not file or submit to any FIU. Scopes are limited to the current spreadsheet and the add-on UI. Links in the sidebar may open this site (privacy, contact, demo) or published regulator rule pages in a new tab. When ADDON_LICENSE_REQUIRED is enabled, the add-on checks a purchase email against Stripe (Sheets & Excel license). That check sends only the email address — not report field values. On the website, Check one and Batch check validation stay free; CSV/TSV Batch ingest is free; JSON / XML / NDJSON ingest and download/export of remediation or passed files need the same license unlock.

Microsoft Excel add-in

The Office.js Excel task pane is coming soon. When it ships, it will use the same bundled engine and row layout as Sheets. Report values stay in the workbook you open; validation runs in Excel via Office.js. It does not post report payloads to our servers or this site, does not store them, and does not file. The add-in requests ReadWriteDocument only. Sideload instructions live in excel-addon/README.md. When listed on Microsoft AppSource, the same privacy, terms, and support URLs apply. License unlock uses the same Stripe purchase email as Sheets and website freemium downloads.

Payments

Licenses are sold via Stripe Checkout (subscription) on /license. We use the purchaser email and Stripe subscription status (active through the paid period) to unlock Sheets, Excel, paid Batch formats, and download/export. We do not use payment data to file reports. Check one validation and Batch check CSV/TSV upload + Run checks do not require a purchase.

Accounts

Check one, Batch check, Scan transactions, and Scan clients stay open — no login is required to run a check. Paid unlock is the purchase email, not an account. Deadline radar tracking stays on this device and is not synced. Backend storage and account sync are coming soon. The Sheets add-on (coming soon) will use your Google account only for Google's authorization to the spreadsheet you choose. The Excel add-in (coming soon) will use your Microsoft Office session for the workbook you open.

Analytics

The site uses Vercel Web Analytics for anonymized page-view counts and Vercel Speed Insights for Core Web Vitals. Query strings are stripped before page URLs are sent. Neither tool inspects report contents.

Contact form

The contact form does not save messages here. Submit posts name, email, and message to Formspree, which may set a technical cookie on formspree.io (for example fs_ab1). This site does not load Formspree's hosted page or ad scripts. Report payloads are not sent. The Feedback button sends only the typed answers and an optional email — never report payloads, filenames, results, or query strings.

Pack-change alerts

Optional pack-change alerts collect only your email and optional regulator preferences (FINTRAC, FinCEN, AUSTRAC). Submit posts those fields to Formspree; we do not store those addresses in this app. This is a subscriber list only — the form does not send pack-version emails automatically. Report payloads are never sent. Formspree may set a technical cookie on formspree.io (for example fs_ab1). This site does not load Formspree's hosted page or ad scripts.