Xapien

Automated Background Due Diligence Reports

Users can run, on-demand, a comprehensive background report on any company, organisation or individual. These reports are compiled using internet and open-source information using the latest AI technologies to produce a comprehensive and fast report.
The service is cloud-based and can be run at any time by the user.

Features

  • Comprehensive reports in 5-10 minutes
  • Real time and up to the minute up to date
  • Sanctions, PEPs & Watchlist screening, international media covered
  • As simple to run as Google search
  • Risk highlighted & summarised
  • International Corporate records of over 140 Jurisdictions covered
  • Multi-lingual coverage with translation of over 100 languages & charactersets

Benefits

  • Time saving - 7-days of manual effort in 7-minutes
  • Cost saving - improving the efficiency of any analyst team
  • Deeper research provides better protection
  • Support compliance with AML / KYC & due diligence
  • Onboard customers quicker
  • Consistency across the team

Pricing

£50 a unit

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at dan@xapien.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 13

Service ID

4 2 6 7 6 7 5 9 1 1 4 1 2 4 1

Contact

Xapien Daniel Secretan
Telephone: 0203 332 2018
Email: dan@xapien.com

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
No
System requirements
  • Internet Connection
  • Up to date Safari, Chrome or Firefox browser

User support

Email or online ticketing support
Email or online ticketing
Support response times
Email support provided.
Response times within 4 hours, Monday - Friday 9am-5pm London time
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
1 level of support -
Account manager for all account enquiries
Customer Success team provide email response within 4 hours of a ticket during working hours.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
User account created by customer success team
20 minute on-boarding session run with every user over video conf
Online training and user documentation provided
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
All reports created by users can be exported as PDFs and saved on users systems.
End-of-contract process
Reports remain available on our systems for 60 days after the end of a contract at no additional cost.
Support provided to export all data and reports via PDF at no extra cost.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
No
Service interface
No
User support accessibility
WCAG 2.1 A
API
Yes
What users can and can't do using the API
Users can call our service to kick off the automated research process.
The API can be called from a workflow solution, or other, to automatically generate a background due diligence report

The API will return a URL that can be embedded in the system and allows the user to open that report from a browser or within another system.
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Enterprise customers can white-label the service.

Scaling

Independence of resources
Xapien is architected as a cloud native solution.
Cloud resources are provisioned for the running of each report. This means that as more reports are requested, our solution automatically scales the AWS infrastructure required so users are not affected by the demand of other users.

Analytics

Service usage metrics
Yes
Metrics types
Number of users, number of reports run per user.
Stats provided monthly as standard, but can be more frequent should the client require
Reporting types
  • Regular reports
  • Reports on request

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Up to Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
Other locations
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v3.0
  • Physical access control, complying with SSAE-16 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Data sanitisation type
  • Explicit overwriting of storage before reallocation
  • Deleted data can’t be directly accessed
Equipment disposal approach
A third-party destruction service

Data importing and exporting

Data export approach
They export the reports to PDF format and save the files locally.
Data export formats
Other
Other data export formats
Pdf
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
99.9% availability guaranteed.
Service credits are applicable (rounded to the nearest minute of downtime) and refunds provided against the next invoice
Approach to resilience
Datacentres are provided by AWS who have a number of principles underpinning their resilient architecture.

More information on AWS resilience can be found at:
https://docs.aws.amazon.com/whitepapers/latest/aws-operational-resilience/how-aws-maintains-operational-resilience-and-continuity-of-service.html

More information on how Xapien's takes advantage and builds on this resilience is available on request.
Outage reporting
EMail alerts

Identity and authentication

User authentication needed
Yes
User authentication
  • 2-factor authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
The entire system requires authentication to use, we do not currently provide a management portal to customers.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • 2-factor authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
You control when users can access audit information
How long user audit data is stored for
Between 6 months and 12 months
Access to supplier activity audit information
You control when users can access audit information
How long supplier audit data is stored for
Between 6 months and 12 months
How long system logs are stored for
Between 6 months and 12 months

Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber essentials plus
No
Other security certifications
No

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
We are actively working towards achieving the ISO/IEC 27001 certification.
Information security policies and processes
We have an Information Security policy which dictates the required access controls for IT assets and what they may be used for. All employees must accept this policy before using IT assets or working on the platform.

Operational security

Configuration and change management standard
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Configuration and change management approach
We make use of GitHub for code version control, releases are made through AWS CodePipeline which requires manual approval from select individuals within the organisation before being delivered to production. Vulnerability scanning is performed as part of the pipeline.
Vulnerability management type
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Vulnerability management approach
We perform vulnerability scanning on our system as part of our build pipelines. In the event that a vulnerability is discovered, we will patch the SaaS platform and audit logs for indicators of compromise (IOC's). Where required we will responsibly disclose vulnerabilities in upstream systems and libraries.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We log all interactions with the system, and store these in a AWS provided central logging system. We regularly perform custom queries against this system, searching for indicators of compromise (IOC's).
Incident management type
Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
Incident management approach
Users are able to report incidents through our support email. Incidents are investigated internally and where needed, reported through the correct channels, in compliance with ISO27035:2011 and UK GDPR.

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Social Value

Fighting climate change

Fighting climate change

Xapien enables our customers to vet their suppliers not only for criminal, judicial and regulatory risk, but the depth of the platform also highlights Environmental, Social and Governance (ESG) risks.

Xapien highlights all Environmental concerns, accusations and historic activities of a potential supplier. This critical information allows our customers to choose their partners based on their environmental credentials and also to put pressure on to work towards net zero greenhouse gas emissions.

Although not part of this question, but critical given the current state of global affairs, Xapien can also highlight links to Sanctioned, Russian and Belarussian organisations and individuals. As many Western organisations choose not to do business in Russia, so they must also look to their supply chain and Xapien is unique in being able to give this insight at such a critical time.
Covid-19 recovery

Covid-19 recovery

Xapien plans to create over 100 jobs in the high-tech Artificial Intelligence area over the next 2 years. We offer formal and on the job training to candidates and welcome applications from those left unemployed by COVID-19, particularly new opportunities in high growth sectors.

Xapien has already improved workplace conditions to support the COVID-19 recovery effort. This includes remote working, flexible hours and working from a local serviced office to reduce travel.

Xapien is also helping our customers work better remotely by enabling them to do comprehensive background checks on their customers, suppliers and employees without meeting them face to face, but retaining the confidence of who they are doing business with.
Tackling economic inequality

Tackling economic inequality

Xapien is working hard to increase supply chain resilience and capacity by allowing our customers to review, vet and on-board more suppliers in a timely and efficient manner. This is allowing them to create a diverse supply chain including new businesses and entrepreneurs.

Our innovative and disruptive technologies can vet suppliers for ESG and traditional due diligence comprehensively and rapidly. This is improving the onboarding times, helping delivering lower cost goods and services in a fair, transparent and responsible manner.

The Xapien solution allows our customers to identify and manage cyber security risks of their own and in the supply chain.

Pricing

Price
£50 a unit
Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Free access to the full version of the platform. There are no limits to the functionality of the platform.
Trials usually last for 1 week for up to 5 users and a maximum of 25 reports.
Link to free trial
Email:sales@xapien.com

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at dan@xapien.com. Tell them what format you need. It will help if you say what assistive technology you use.