What you receive
Beneficial owners
GET /entities/{id}/ubos returns only individual owners, and only these fields:
Document requests
GET .../document-requests returns the status of a collection, never the
documents:
What you never receive
These are withheld unconditionally:amlScreeningData— the raw Sumsub case blob, including hit names, source watchlists, and media titles.verifiedDateOfBirth— full date of birth.verifiedAddress— full street address.kycRejectionReason— free-text rejection reason (often contains sensitive moderator notes).kycVerificationModeratorNote/addressVerificationModeratorNote— internal moderator notes.sumsubApplicantId— the underlying Sumsub identifier.- Any document ids, image URLs, or file references.
- A beneficial owner’s
onboardingToken— their live verification-link token. The link is returned only from the explicitPOST .../ubos/{uboId}/kycaction, never from a read. - The contents of any collected document — the document endpoints expose status only. A file key, file name, or download URL never crosses the API, even for a request you created. Uploads travel browser → S3 directly; the API server never proxies the bytes.
Why
- Regulatory minimisation. Sharing only what a downstream integrator needs to act keeps our and your AML obligations clean.
- Breach blast radius. A leaked API key cannot exfiltrate document images or detailed AML hit data even if it has every scope.
- Vendor-neutrality. Integrators receive a stable shape — not raw vendor (Sumsub) payloads that can change without notice.

