Bonafi B.V. · Connectivity sheet

Version

Supersedes: none, first issue. The current sheet is always at connect.bonafi.ai/sheet.

Protocol

SFTP over SSH-2 only. Public-key authentication only, no password fallback. We pin the bank's host key and do not accept a key on first use. Read-only on the bank's server; we never write, rename or delete. One concurrent session. Two logins per day, also on days without files. FTPS on request; no unencrypted FTP. PGP-encrypted and signed files on request.

Algorithms

Key exchange
mlkem768x25519-sha256, curve25519-sha256, curve25519-sha256@libssh.org, ecdh-sha2-nistp256, ecdh-sha2-nistp384, ecdh-sha2-nistp521, diffie-hellman-group16-sha512, diffie-hellman-group14-sha256, diffie-hellman-group-exchange-sha256
Ciphers
chacha20-poly1305@openssh.com, aes256-gcm@openssh.com, aes128-gcm@openssh.com, aes256-ctr, aes192-ctr, aes128-ctr
MACs
hmac-sha2-256-etm@openssh.com, hmac-sha2-512-etm@openssh.com, hmac-sha2-256, hmac-sha2-512
Host key algorithms
ssh-ed25519, rsa-sha2-512, rsa-sha2-256, ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, ecdsa-sha2-nistp521

Source addresses to allowlist

Test
34.7.15.242, 34.7.160.221
Production
34.32.224.212, 34.6.5.2

Keys (Test environment)

SSH algorithm
RSA 4096
SSH public key
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDIx51RKXCgYpYZnCPwHxh4wKs538KX+Xgfk5SXKXe/pIIVU1O2s87R07VN0Jv+6mhexT002o1iGEajyuQYairP1o7FwvkJbtnXsEH+J19TmOo1ZZaTnqnafg0W4Qki9MgQFZhO0awD2Pbv4C0l9eMaLqy6mZ6Acut3J4H6oPYWbslNLBySNkA+k9FWSHLuYIRDstcvX8+scHAfyejZnMUbUKvEKW5a1yQOKouWPWKUv8IkOJx+7/fUX5ciHWmdnNM4Xjw0QN5UtEbXME/1u0cVMCWGNyGWwEn2brVtkaC1yhkcdBykDl7TFihFn+7xbsGuokbhIGLK84n9xPprFZChiZ97RCNPiheZUvvceKOBbTYmTCOLjhYYHvL6+EgjSfISTQoBXdeByE+qalRY0s9QWlsDhMHogdxrC1sTwKIkJx0wQElKraOZgl0AWZ923g8OsJNyvVsNKZDoj3KjPyw8MANiBnE8+jbgnbyjSgviesNDH3AIFVbd+YdEanl9F8/nBrYGvX2V/+0HAg4HEu2J9kc3I2RNBVbAS2bIkJzj/wWffwXdVdl51EZnVPrF7QTKAfKUGhECSdIr5qoyi0HRbtDaTYFBvsxhWjFNenezOgxdjFSgg6ui7TahpAgTCUXm/hE3LVfqeIZ9hehmpzfFI+FMXh/ZhbRs/Wpa/oxW8Q== bonafi bank feeds test
SSH SHA256
SHA256:T/3H/XrvA0qJsM2dj/C61+ii42LPZ5vwIyjpOWWaLwc
PGP fingerprint
1039 9FB2 8C1A 5D46 2514 2675 DF5A 15B4 5F33 A7E0
PGP expires
2028-10-09
PGP key file
connect.bonafi.ai/bonafi-bank-feeds-test.asc

Schedule, data and keys

Pickup windows agreed per bank; default from 08:15 CET on delivery days with retries until 10:30; two keep-alive logins per day, twelve hours apart. Processing and storage in the EU (Google Cloud europe-west4, Netherlands); files archived unchanged under a retention policy that refuses deletion; every pickup logged. Bonafi is processor for the account holder. SSH keys rotated yearly, PGP keys every 18 months with a 90-day overlap, notice before rotation, emergency re-keying within one business day. A bank host-key change is confirmed out of band before acceptance. Pickup failures: internal alert within the hour; after two missed delivery days we contact the bank.

Certification

Standards
ISO/IEC 27001:2022, including ISO/IEC 27017 and ISO/IEC 27018
Body
Prescient Security
Scope
The scope of the ISO/IEC 27001:2022, ISO/IEC 27017:2015 and ISO/IEC 27018:2019 certification is the Information Security Management System (ISMS) of Bonafi B.V., supporting the design, development, operation and support of Bonafi's AI-first software platform that supports wealth management for high-net-worth individuals in the Netherlands, including the client-data database, the AI/LLM processing pipeline and supporting SaaS tooling. The scope includes infrastructure hosted on Google Cloud (GCP). The ISMS scope also includes the following departments: Software Development & Engineering, Operations & Cloud Infrastructure, Information Security & Compliance & Management & Governance.
This service
Bank-file delivery runs on the platform's Google Cloud infrastructure, which this scope includes; the service entered the ISMS risk register in October 2026 and is reviewed at the next surveillance audit.

Contacts

Commercial
Cecé de Boon, founder, partners@bonafi.ai
Technical
partners@bonafi.ai
Security
info@bonafi.ai