FAQ - Account access - Reports - Billing - Privacy

Frequently asked questions.

Straightforward answers about how SanctionIQ handles account access, report requests, credits, billing, delivery fallbacks and privacy-first report handling.

Privacy-first Full report content is delivered on demand and is not retained long term by the platform.
3 channels Reports can be requested from the dashboard, authorised email addresses or the API.
Owner control The main account owner controls billing, account details and linked user access.
Fallbacks If delivery fails, SanctionIQ uses safe fallback delivery where possible.

How to run reports

SanctionIQ supports report requests through email, the portal and the API.

Via email

To request a report by email, send an email to report@sanctioniq.io.

Enter the name and country of the person or company you wish to search in the subject line. No text is required in the body of the email unless you want to pass your own additional parameters, which are then returned in the response.

Example email subjects:

  • John Smith from Gibraltar
  • John Smith from Spain, CEO of CompanyX
  • John Smith from UK, DOB: 04/04/1979, CEO of CompanyX

For companies, simply replace the individual's name with the company name.

Multi-lingual reports: SanctionIQ supports over 30 languages. Add LANGUAGE after a hyphen as an additional subject parameter. If no language is provided, the report defaults to English.

Example: John Smith from Gibraltar - LANGUAGE:SPANISH

Via portal

To request a report from the portal, log in to your SanctionIQ dashboard and use the report request form.

Enter the subject details, choose the required report format and submit the request. Reports normally return to the portal within approximately 2 to 3 minutes.

Choosing a report format:

  • HTML: This is usually the most common and easiest format for most users. It displays the report in a clean, readable layout inside the portal and can be exported neatly to PDF once the results arrive.
  • JSON: This is a structured data format mainly used by technical teams, developers or systems that need to read the report automatically. It is useful for integrations, but it is not designed to be read like a normal document.
  • Text: This provides the report as plain text only, without styling or layout. It can be useful when you need a simple copy-and-paste version of the findings.
Recommended for most portal users: Choose HTML if you want the report to be easy to read on screen and export nicely to PDF from the portal.

For the smoothest experience, keep the browser window open while the report is being generated. If you close the browser or the report is not collected through the portal, SanctionIQ can send the completed report to you by email as a fallback.

Via API

API access is available to Enterprise accounts and to Professional accounts with the optional API add-on.

For API request formats, authentication, live endpoints and test endpoints, please read the API documentation: https://sanctioniq.io/documentation.html

How much detail should I provide?

The more detail you provide, the more accurately SanctionIQ can identify the correct person or company. Useful additional details include country, date of birth, current role, employer, company name, nationality or other identifiers.

However, very specific details can sometimes narrow the search too much. For example, adding a role or location may help distinguish between people with similar names, but it may also limit broader discovery if the public records use different wording.

Best practice: provide enough detail to identify the subject clearly, but avoid overloading the request with assumptions unless you are confident they are correct.
What is Strict Search?

Strict Search is an optional setting that tells SanctionIQ to treat supplied identifying details as stronger matching filters. These may include date of birth, country, nationality, company name, role, address, registration number or other identifiers.

When Strict Search is enabled, SanctionIQ is more cautious about linking results to the searched person or company. This can reduce false matches involving similarly named individuals or entities, but it may also return fewer report details.

When Strict Search is not enabled, SanctionIQ uses the broader default search mode. This may return more possible matches and wider OSINT context, but users should review similar-name results carefully.

Best practice: use Strict Search when you have reliable identifiers such as a date of birth, company name, address, registration number or exact country. Leave it off when you want broader discovery and are comfortable reviewing possible similar-name matches.

Portal: Strict Search can be enabled by ticking the Strict search checkbox on the dashboard report form. If left unticked, the report runs in the broader default mode.

Email: add STRICT:TRUE to the email subject or body. If you do not include it, Strict Search defaults to off.

Example email subjects:

  • John Smith from Gibraltar - DOB: 04/04/1979 - STRICT:TRUE
  • John Smith from Gibraltar - LANGUAGE:SPANISH - STRICT:TRUE
  • CompanyX from Spain - registration number 123456 - STRICT:TRUE

API: include the optional strict parameter in the request payload. If omitted, it defaults to false.

API example:
"strict": true

Account access

Who can manage what inside the portal.

Who can edit the account or company details?

Only the main account owner can edit account-level details, including company details or the main individual account record.

Linked users can edit their own profile details, but they cannot edit the commercial account, company profile, billing settings or owner-level details.

Main owner: account editing Linked user: profile only
Who can manage billing, plans and add-ons?

Only the main account owner can manage billing. This includes upgrades, downgrades, billing cadence changes, token packs, recurring extra seats and API add-ons.

Linked users can use the platform according to the account permissions and available credits, but they cannot purchase or modify subscriptions.

Can linked users access the dashboard?

Yes, active linked users can access the dashboard if they have been invited and activated. Disabled users cannot log in or request reports.

Report requests

How reports can be requested and whether channels differ.

How can a report be requested?

Reports can be requested through three channels:

  • Dashboard: users submit a request from the portal and wait for the result.
  • Email: authorised active users can send a report request from their registered email address.
  • API: authorised accounts with API access can submit report requests programmatically.
Is there any difference between dashboard, email and API reports?

The underlying report flow is designed to be consistent across all channels. The main difference is delivery format and how the request is submitted.

Dashboard requests return to the portal, email requests return by email, and API requests can return to a callback URL or use the configured response format.

Who is allowed to request reports?

Only active users linked to the account can request reports. This applies to dashboard, email and API requests.

If a linked user is disabled, their report requests are blocked and no report is generated.

Active linked user: allowed Disabled user: blocked
Does a report request always deduct a token?

A token is deducted only when a report request is accepted for processing. If the request is blocked due to access, billing status, unavailable credits or invalid permissions, no token should be deducted.

Data and privacy

What SanctionIQ stores and what it deliberately avoids storing.

Does SanctionIQ store full report content?

No. SanctionIQ is designed around a privacy-first model. Full report content is generated and delivered to the user, but it is not retained as a long-term archive by the platform.

The system may temporarily hold report content only as needed for delivery, fallback delivery or short-lived dashboard retrieval.

What information is recorded?

SanctionIQ records operational metadata needed to run the service, such as account details, authorised users, usage counts, billing status, API key metadata, report IDs, request status and delivery status.

The platform is designed to avoid storing the full report content as a permanent record.

Why does SanctionIQ keep metadata?

Metadata is required for access control, usage tracking, billing, troubleshooting, delivery confirmation, auditability and support.

Example: SanctionIQ may know that a report was requested and delivered, but it is not designed to keep the full report content indefinitely.
Can a user choose whether a report is stored?

The current privacy-first approach does not retain full reports by default. A future version may allow paid users to choose per report whether a report should be stored, but that would be explicit and user-controlled.

Credits and billing

How tokens, plans and payment status affect report access.

What happens if I run out of tokens?

If the account has no available report tokens, new report requests are blocked until more tokens become available.

Depending on the plan, this may happen when the next billing period begins or when the main account owner purchases a token pack or upgrades the plan.

Do purchased token packs roll over?

Yes. Purchased token packs/top-ups roll over until consumed. Subscription plan tokens reset each billing period and do not roll over.

What happens if a subscription payment fails?

If a subscription payment fails, the account enters a grace period. During the grace period, users can continue generating reports as long as credits remain available.

If the payment is not resolved before the grace period ends, report generation is suspended until payment succeeds.

Grace period: limited continued access Expired grace: reports blocked Recovered payment: access restored
Who can buy token packs or change plans?

Only the main account owner can purchase token packs, upgrade, downgrade, change billing cadence, add extra seats or manage API add-ons.

Delivery and failures

What happens if a report cannot be delivered normally.

What happens if a dashboard report is ready but I close the browser?

If a dashboard report is generated successfully but is not collected through the portal, SanctionIQ can use fallback email delivery so the report is not lost.

What happens if API callback delivery fails?

If an API report is generated successfully but cannot be delivered to the callback URL, SanctionIQ can fall back to email delivery where possible.

Because the report was successfully generated, callback delivery failure does not automatically mean the token is refunded. The priority is to safely deliver the result by an alternative route.

What happens if report generation itself fails?

If report generation fails before a usable report is produced, the system is designed to handle the failure, notify the user where appropriate and avoid charging unfairly.

Users and seats

How linked users, disabled users and seat limits work.

What is a linked user?

A linked user is an additional user attached to the main account. Linked users can request reports if they are active and the account has available credits and access rights.

Do disabled users count towards seat usage?

Disabled users do not consume an active seat. If a disabled user is re-enabled, they will consume a seat again.

Can the main owner re-enable a disabled user?

Yes, provided the account has available seat capacity. If all available seats are already in use, the user cannot be re-enabled until a seat is freed, an extra seat is added or the plan is upgraded.

Can the main owner disable or remove linked users?

Yes. The main account owner can disable or remove linked users, but the primary account owner cannot disable themselves.

API and email access

How authorised users can request reports outside the portal.

Can any linked user request a report by email?

Any active user linked to the account can request a report by email from their registered email address, provided the account has available credits and report access is not suspended.

If a disabled or unauthorised user sends a request, the system can reply explaining that they are not authorised to request reports.

Can any linked user request a report through the API?

API access is account-based. If the account has API access, an API request can be attributed to any active linked user on that account, provided the submitted user email belongs to an active linked user.

Can disabled users still use old sessions, email or API?

No. Report generation requires the user to be active at the time of request. Disabled users are blocked across dashboard, email and API report flows.

Support

Where to go if something looks wrong.

What should I do if a report looks incorrect?

Review the sources and the extended findings carefully. SanctionIQ reports are designed to assist compliance review, but the final assessment should always be reviewed by a qualified person.

If something appears wrong, contact support with the report ID and a clear explanation of the issue.

What should I include in a support request?

Include the report ID, account email, approximate request time, request channel used and a short description of the issue. Do not send unnecessary sensitive personal data unless requested.

Are SanctionIQ reports final legal or compliance advice?

No. SanctionIQ provides AI-assisted compliance report outputs to support human review. Reports should be assessed alongside your organisation's policies, regulatory obligations and professional judgement.

Development and testing

Testing your integration without consuming live tokens.

Is there a way to test the API without using live tokens?

Yes. SanctionIQ provides a development/test API route that allows you to integrate and test your implementation without consuming live report tokens.

This route returns mock or controlled responses designed specifically for integration testing.

Important: The development endpoint is rate-limited and intended for testing only.
Dev endpoint: available Monthly limit: 25 requests No live tokens consumed

Once your integration is complete, you can switch to the live endpoint to begin generating real reports.

Full API details, including authentication, endpoints and usage examples, are available in the documentation: https://sanctioniq.io/documentation.html