Bonafi

Bonafi B.V. · Bank connectivity

Last updated

What this is

Bonafi receives daily position, transaction and cash files from private banks on behalf of their clients, under a signed authorisation per bank and client. This page gives a bank what it needs to set that up: how we connect, which addresses to allowlist, which keys to trust, how we handle the data, and who to contact.

A printable version is at /sheet.

How we connect

  • SFTP over SSH-2 only.
  • Public-key authentication only; no password fallback.
  • We pin your host key. We do not accept a key on first use.
  • Read-only on your server: we never write, rename or delete.
  • One concurrent session.
  • We log in twice a day, also on days without files.
  • FTPS on request. We do not accept unencrypted FTP.
  • PGP-encrypted and signed files are accepted on request.

Algorithms we enable

Key exchange
mlkem768x25519-sha256 curve25519-sha256 curve25519-sha256@libssh.org ecdh-sha2-nistp256 ecdh-sha2-nistp384 ecdh-sha2-nistp521 diffie-hellman-group16-sha512 diffie-hellman-group14-sha256 diffie-hellman-group-exchange-sha256
Ciphers
chacha20-poly1305@openssh.com aes256-gcm@openssh.com aes128-gcm@openssh.com aes256-ctr aes192-ctr aes128-ctr
MACs
hmac-sha2-256-etm@openssh.com hmac-sha2-512-etm@openssh.com hmac-sha2-256 hmac-sha2-512
Host key algorithms
ssh-ed25519 rsa-sha2-512 rsa-sha2-256 ecdsa-sha2-nistp256 ecdsa-sha2-nistp384 ecdsa-sha2-nistp521

Our addresses

Our connections leave from static addresses. We publish two per environment; allowlist both, so a failover changes nothing on your side.

Test
34.7.15.242 34.7.160.221
Production
34.32.224.212 34.6.5.2

Our SSH public key (Test environment)

Algorithm
RSA 4096
Public key
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDIx51RKXCgYpYZnCPwHxh4wKs538KX+Xgfk5SXKXe/pIIVU1O2s87R07VN0Jv+6mhexT002o1iGEajyuQYairP1o7FwvkJbtnXsEH+J19TmOo1ZZaTnqnafg0W4Qki9MgQFZhO0awD2Pbv4C0l9eMaLqy6mZ6Acut3J4H6oPYWbslNLBySNkA+k9FWSHLuYIRDstcvX8+scHAfyejZnMUbUKvEKW5a1yQOKouWPWKUv8IkOJx+7/fUX5ciHWmdnNM4Xjw0QN5UtEbXME/1u0cVMCWGNyGWwEn2brVtkaC1yhkcdBykDl7TFihFn+7xbsGuokbhIGLK84n9xPprFZChiZ97RCNPiheZUvvceKOBbTYmTCOLjhYYHvL6+EgjSfISTQoBXdeByE+qalRY0s9QWlsDhMHogdxrC1sTwKIkJx0wQElKraOZgl0AWZ923g8OsJNyvVsNKZDoj3KjPyw8MANiBnE8+jbgnbyjSgviesNDH3AIFVbd+YdEanl9F8/nBrYGvX2V/+0HAg4HEu2J9kc3I2RNBVbAS2bIkJzj/wWffwXdVdl51EZnVPrF7QTKAfKUGhECSdIr5qoyi0HRbtDaTYFBvsxhWjFNenezOgxdjFSgg6ui7TahpAgTCUXm/hE3LVfqeIZ9hehmpzfFI+FMXh/ZhbRs/Wpa/oxW8Q== bonafi bank feeds test
SHA256 fingerprint
SHA256:T/3H/XrvA0qJsM2dj/C61+ii42LPZ5vwIyjpOWWaLwc
  • Ed25519 is available on request.
  • Production keys are generated per bank inside the production environment and published before the first production feed.

Our PGP public key (Test environment)

Fingerprint
1039 9FB2 8C1A 5D46 2514 2675 DF5A 15B4 5F33 A7E0
Expires
2028-10-09

Schedule

  • Pickup windows are agreed per bank.
  • Our default is from 08:15 CET on delivery days, with retries until 10:30.
  • Two keep-alive logins per day, twelve hours apart.

Data handling

  • All processing and storage in the EU: Google Cloud europe-west4, Netherlands.
  • Files are archived unchanged under a bucket retention policy that refuses deletion; every pickup is logged.
  • Bonafi acts as processor for the account holder under the client's data processing agreement; the bank delivers on the client's instruction.
  • This page is served by Vercel and Cloudflare; no bank data passes through it.
  • Incidents are notified to the client without undue delay.

Sub-processors for bank data

ProviderServiceLocation
Google CloudCompute, storage and secretsEU, region europe-west4 (Netherlands)
Temporal TechnologiesTemporal Cloud, workflow schedulingEU, Frankfurt region

Certification

Standards
ISO/IEC 27001:2022, including ISO/IEC 27017 and ISO/IEC 27018
Certification body
Prescient Security
Scope

The scope of the ISO/IEC 27001:2022, ISO/IEC 27017:2015 and ISO/IEC 27018:2019 certification is the Information Security Management System (ISMS) of Bonafi B.V., supporting the design, development, operation and support of Bonafi's AI-first software platform that supports wealth management for high-net-worth individuals in the Netherlands, including the client-data database, the AI/LLM processing pipeline and supporting SaaS tooling. The scope includes infrastructure hosted on Google Cloud (GCP). The ISMS scope also includes the following departments: Software Development & Engineering, Operations & Cloud Infrastructure, Information Security & Compliance & Management & Governance.

This service
Bank-file delivery runs on the platform's Google Cloud infrastructure, which this scope includes; the service entered the ISMS risk register in October 2026 and is reviewed at the next surveillance audit.

Key lifecycle

  • SSH keys are rotated yearly; PGP keys every 18 months with a 90-day overlap.
  • Banks are notified before a rotation.
  • Emergency re-keying within one business day.
  • A change of your host key is confirmed with you out of band before we accept it.

If a pickup fails

  • We alert internally within the hour.
  • After two missed delivery days we contact you.
  • Backfill requests go to the technical contact.

Contacts

Commercial and mandates
Cecé de Boon, founder, partners@bonafi.ai

What we ask every bank

  1. Direction: do we pull from your server, or do you push to ours?
  2. Host, port and accepted key types.
  3. Whether our IP addresses must be allowlisted.
  4. PGP: whether files are encrypted or signed, and with which key.
  5. Format, file names, character set; full or delta files.
  6. Delivery time, and how long files stay on your side.
  7. Test environment and sample files.
  8. Agreement or form, cost and lead time.
  9. If you offer only FTP: is SFTP or FTPS possible?
  10. Your server's IP addresses, for our egress allowlist.
  11. Whether files are written under a temporary name first.
  12. Your business-day calendar.