Averholm is a tool for regulated professionals, and it's built like one. Here is plainly how your data is held, who controls it, and how the things a supervisor asks about are answered in the architecture rather than in a promise.
Every action — a login, a review, an export, a decision — is written once and never rewritten. It's enforced at the database with a restricted runtime role, not just promised in code.
Your data and every sub-processor stay in the EU. No third-country transfer happens without being assessed and disclosed to you first.
Each customer's data is fenced off at the database layer, and integration tests prove one tenant can't read another. Your client list is yours alone.
Passwords are hashed; a login email in the audit trail is stored only as a one-way hash. We minimise what's kept, and keep no secret it doesn't need.
A deterministic core does the detection. AI only drafts and summarises at the edges — always labelled, always reviewed by a person before it counts.
The audit trail keeps ids, outcomes and hashes — not free text or names where an id will do. Less personal data held means less at risk.
For the client data you run through Averholm, you are the data controller — you decide the purpose, under your own anti-money-laundering obligation. Averholm acts as your processor, handling that data on your instruction under a data-processing agreement. For our own operational data — your account, security and audit logs — we are the controller.
Your AML obligation stays with you; a tool can't assume it. That's not a limitation — it's the honest, defensible position, and it's why Averholm surfaces, drafts and assists, but never decides, files or clears on its own.
What you'll get for your file: a data-processing agreement, a record of the sub-processors we use, and a clear statement of what data Averholm holds, on what basis, and for how long — the paperwork your DPO or supervisor will expect.
Luxembourg's beneficial-ownership register is not open to vendors. Professional access is bound to the professional who holds it, so a service provider cannot lawfully sit outside that access and re-serve the data to you.
Averholm therefore operates inside your own professional access, as your processor: it orchestrates the lookups you are entitled to make, records what you were shown, and monitors it for change. Where a chain is reconstructed from the company register rather than the RBE, it is labelled as exactly that, so nothing in a file claims a provenance it does not have.
If a vendor offers you bulk Luxembourg beneficial-ownership data, ask them on what basis they hold it. It is a short conversation, and it is worth having before their answer becomes your finding.
The audit trail is split into two horizons so nothing is kept longer than it needs to be: activity that supports your AML record-keeping obligation is held to that horizon, and pure security events (logins, IP addresses) are kept for a shorter, proportionate window. When the obligation lapses, a scheduled, self-auditing purge removes what's past its retention.
An append-only trail can't be quietly edited — that's the point. If something recorded is wrong, the correction is appended: a new entry that references the original and states what's right. The history stays intact, and the correction is on the record too. It's how rectification works on an evidence trail you can trust.
The parts of Averholm that decide anything — change detection, screening matches, risk logic — are deterministic and testable. Language models are used only to summarise and draft at the edges: an impact brief, a suspicious-activity-report narrative. Those outputs are marked as drafts and reviewed by a person before they count. No customer data is used to train models, and no consequential decision is automated.
Averholm is built on official, openly-reusable sources where it can be — the company register, legal-entity identifiers, the public sanctions lists, the official gazette. Where a source carries its own licence (certain PEP feeds, commercial financial data) it's a clearly-labelled part of your plan, not something quietly re-sold. And where a register sits behind an access control, we use the lawful route — your own access, or an official channel — rather than scraping it.
AMLR — the EU's single AML regulation — applies from 10 July 2027, with the new authority AMLA behind it. Averholm's perpetual-KYC model, harmonised CDD/EDD case files and goAML-format reporting are shaped for that regime, so adopting it now is a step toward the new standard rather than something to redo.
We're happy to walk through the data flows, the DPA and the audit model in detail.