What this is
Bonafi receives daily position, transaction and cash files from private banks on behalf of their clients, under a signed authorisation per bank and client. This page gives a bank what it needs to set that up: how we connect, which addresses to allowlist, which keys to trust, how we handle the data, and who to contact.
A printable version is at /sheet.
How we connect
- SFTP over SSH-2 only.
- Public-key authentication only; no password fallback.
- We pin your host key. We do not accept a key on first use.
- Read-only on your server: we never write, rename or delete.
- One concurrent session.
- We log in twice a day, also on days without files.
- FTPS on request. We do not accept unencrypted FTP.
- PGP-encrypted and signed files are accepted on request.
Algorithms we enable
- Key exchange
- mlkem768x25519-sha256 curve25519-sha256 curve25519-sha256@libssh.org ecdh-sha2-nistp256 ecdh-sha2-nistp384 ecdh-sha2-nistp521 diffie-hellman-group16-sha512 diffie-hellman-group14-sha256 diffie-hellman-group-exchange-sha256
- Ciphers
- chacha20-poly1305@openssh.com aes256-gcm@openssh.com aes128-gcm@openssh.com aes256-ctr aes192-ctr aes128-ctr
- MACs
- hmac-sha2-256-etm@openssh.com hmac-sha2-512-etm@openssh.com hmac-sha2-256 hmac-sha2-512
- Host key algorithms
- ssh-ed25519 rsa-sha2-512 rsa-sha2-256 ecdsa-sha2-nistp256 ecdsa-sha2-nistp384 ecdsa-sha2-nistp521
Our addresses
Our connections leave from static addresses. We publish two per environment; allowlist both, so a failover changes nothing on your side.
- Test
- 34.7.15.242 34.7.160.221
- Production
- 34.32.224.212 34.6.5.2
Our SSH public key (Test environment)
- Algorithm
- RSA 4096
- Public key
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDIx51RKXCgYpYZnCPwHxh4wKs538KX+Xgfk5SXKXe/pIIVU1O2s87R07VN0Jv+6mhexT002o1iGEajyuQYairP1o7FwvkJbtnXsEH+J19TmOo1ZZaTnqnafg0W4Qki9MgQFZhO0awD2Pbv4C0l9eMaLqy6mZ6Acut3J4H6oPYWbslNLBySNkA+k9FWSHLuYIRDstcvX8+scHAfyejZnMUbUKvEKW5a1yQOKouWPWKUv8IkOJx+7/fUX5ciHWmdnNM4Xjw0QN5UtEbXME/1u0cVMCWGNyGWwEn2brVtkaC1yhkcdBykDl7TFihFn+7xbsGuokbhIGLK84n9xPprFZChiZ97RCNPiheZUvvceKOBbTYmTCOLjhYYHvL6+EgjSfISTQoBXdeByE+qalRY0s9QWlsDhMHogdxrC1sTwKIkJx0wQElKraOZgl0AWZ923g8OsJNyvVsNKZDoj3KjPyw8MANiBnE8+jbgnbyjSgviesNDH3AIFVbd+YdEanl9F8/nBrYGvX2V/+0HAg4HEu2J9kc3I2RNBVbAS2bIkJzj/wWffwXdVdl51EZnVPrF7QTKAfKUGhECSdIr5qoyi0HRbtDaTYFBvsxhWjFNenezOgxdjFSgg6ui7TahpAgTCUXm/hE3LVfqeIZ9hehmpzfFI+FMXh/ZhbRs/Wpa/oxW8Q== bonafi bank feeds test
- SHA256 fingerprint
- SHA256:T/3H/XrvA0qJsM2dj/C61+ii42LPZ5vwIyjpOWWaLwc
- Ed25519 is available on request.
- Production keys are generated per bank inside the production environment and published before the first production feed.
Our PGP public key (Test environment)
- Fingerprint
- 1039 9FB2 8C1A 5D46 2514 2675 DF5A 15B4 5F33 A7E0
- Expires
- 2028-10-09
- Download
- /bonafi-bank-feeds-test.asc
Schedule
- Pickup windows are agreed per bank.
- Our default is from 08:15 CET on delivery days, with retries until 10:30.
- Two keep-alive logins per day, twelve hours apart.
Data handling
- All processing and storage in the EU: Google Cloud europe-west4, Netherlands.
- Files are archived unchanged under a bucket retention policy that refuses deletion; every pickup is logged.
- Bonafi acts as processor for the account holder under the client's data processing agreement; the bank delivers on the client's instruction.
- This page is served by Vercel and Cloudflare; no bank data passes through it.
- Incidents are notified to the client without undue delay.
Sub-processors for bank data
| Provider | Service | Location |
|---|---|---|
| Google Cloud | Compute, storage and secrets | EU, region europe-west4 (Netherlands) |
| Temporal Technologies | Temporal Cloud, workflow scheduling | EU, Frankfurt region |
Certification
- Standards
- ISO/IEC 27001:2022, including ISO/IEC 27017 and ISO/IEC 27018
- Certification body
- Prescient Security
- Scope
The scope of the ISO/IEC 27001:2022, ISO/IEC 27017:2015 and ISO/IEC 27018:2019 certification is the Information Security Management System (ISMS) of Bonafi B.V., supporting the design, development, operation and support of Bonafi's AI-first software platform that supports wealth management for high-net-worth individuals in the Netherlands, including the client-data database, the AI/LLM processing pipeline and supporting SaaS tooling. The scope includes infrastructure hosted on Google Cloud (GCP). The ISMS scope also includes the following departments: Software Development & Engineering, Operations & Cloud Infrastructure, Information Security & Compliance & Management & Governance.
- Certificate
- Certificate (PDF)
- This service
- Bank-file delivery runs on the platform's Google Cloud infrastructure, which this scope includes; the service entered the ISMS risk register in October 2026 and is reviewed at the next surveillance audit.
Key lifecycle
- SSH keys are rotated yearly; PGP keys every 18 months with a 90-day overlap.
- Banks are notified before a rotation.
- Emergency re-keying within one business day.
- A change of your host key is confirmed with you out of band before we accept it.
If a pickup fails
- We alert internally within the hour.
- After two missed delivery days we contact you.
- Backfill requests go to the technical contact.
Contacts
- Commercial and mandates
- Cecé de Boon, founder, partners@bonafi.ai
- Technical
- partners@bonafi.ai
- Security
- info@bonafi.ai (from security.txt)
What we ask every bank
- Direction: do we pull from your server, or do you push to ours?
- Host, port and accepted key types.
- Whether our IP addresses must be allowlisted.
- PGP: whether files are encrypted or signed, and with which key.
- Format, file names, character set; full or delta files.
- Delivery time, and how long files stay on your side.
- Test environment and sample files.
- Agreement or form, cost and lead time.
- If you offer only FTP: is SFTP or FTPS possible?
- Your server's IP addresses, for our egress allowlist.
- Whether files are written under a temporary name first.
- Your business-day calendar.