API documentation

Data handling

What Stonewake ingests, stores, and serves, on one page. The research base is registers, courts, regulators, tenders, filings and the trade press; your workspace data stays yours.

Sources and citations

  • The research base is public data only: official company registers and gazettes, court and insolvency publications, regulatory filings, the LEI system, public procurement records, official statistics, licensed reference datasets, and reputable press.
  • Findings carry citations to their public origin, down to the quoted passage, so every claim can be checked at its source.
  • Scores apply to organizations and countries, never to natural persons.

Retention

  • Workspace data is retained while your arrangement is active. Bank-instructed screenings are stamped at creation with the retention horizon agreed with your bank, enforced by a daily purge; absent an agreed horizon they are kept until erased, and every screening is erasable on demand.
  • Database backups are encrypted, held apart from the production server, and kept for a defined retention window; restore procedures have been exercised.
  • On offboarding you export your reports and data during a wind-down period; workspace data is then deleted, and identifier-only entries of the audit ledger are retained after the arrangement ends. The API security page carries the same posture for the programmatic surface.
  • The GDPR basis for each processing purpose is set out in the privacy policy; public-register facts follow the public records notice.
  • Stored product data is processed on infrastructure in the EU and the UK; search queries and fetched public text are processed by search and AI providers as described in the privacy policy, sections 7 and 8. The full processor list and the Article 32 measures are part of the data processing agreement provided to customer banks.
  • Your workspace records are stored on our infrastructure and are never used to train models.

Related: Security overview, Terms of use.