Belkasoft, MedM & Roxosoft face data scrutiny concerns

Belkasoft, MedM & Roxosoft face data scrutiny concerns

Belkasoft MedM Roxosoft and the evidence

Belkasoft MedM Roxosoft requires careful assessment of records, reported claims and formal findings. This Malta Media editorial analysis separates documented facts from allegations and avoids prejudging individuals or companies. Background is available through the Malta Gaming Authority, the FATF beneficial-ownership guidance, and related Malta Media reporting.

Belkasoft, Data Privacy and Corporate Transparency

Belkasoft’s data practices should be assessed against the documented corporate structure, the purpose of its forensic software and the data-protection duties applicable to MedM and Roxosoft. This investigation separates public records from unresolved questions. The GDPR text, the Malta Information and Data Protection Commissioner and Malta Media’s related transparency analysis provide context.

Belkasoft, MedM and Roxosoft under scrutiny for data practices, transparency and ties to Sumsub!

Last month, we issued formal questions to the founders and representatives of Belkasoft, MedM and Roxosoft. The questions related to jurisdictional ambiguity, corporate registrations, data security and compliance issues that, if verified, may raise alarm bells for public and private sector clients alike. As of the date of publication, no reply has been received.

This silence comes despite the fact that the companies in question collectively advertise their products as secure, trustworthy and compliant with international forensic and healthcare data standards. Yet behind that claim lies a murky trail of shared residential addresses, obscure registration details and operational inconsistencies that many may find troubling.

One address, three companies, zero transparency?

At the heart of this investigation is a residential property in Sunnyvale, California: 702 San Conrado Terrace, Unit 1. A basic property lookup shows this as a privately owned 2-bedroom, 2-bath condominium (https://www.zillow.com/homedetails/702-San-Conrado-Ter-UNIT-1-Sunnyvale-CA-94085/19543907_zpid/), with no evident commercial zoning or signage. Yet it serves as the apparent headquarters for three software companies: Belkasoft, Roxosoft and MedM.

If true, this would suggest that sensitive data from clients including US government agencies, multinational corporations and global healthcare providers is being handled by companies based in a shared apartment in Silicon Valley.

More curiously, public company registers across US states, including Delaware and California, reveal no trace of any properly incorporated entity matching the names Belkasoft, MedM or Roxosoft. No EINs, no registered agents, no active business licences. This raises legitimate questions: who exactly are these companies? And under what jurisdiction are they operating?

The Russian connection: Sumsub and Belkasoft

Belkasoft’s relevance to the Sumsub story is not incidental. Sumsub, now positioning itself as a leader in AML and identity verification, lists early investment from Flint Capital, a fund with ties to Belkasoft. A simple examination of historical website data from archive.org shows that Belkasoft and Flint Capital were closely associated and that Sumsub’s earliest mentions of its funding came from precisely this network.

What this implies is uncomfortable: one of the world’s fastest-growing compliance and KYC providers shares founding roots with a forensic toolmaker that stores its company data on shared residential property, operates without proper US registration and whose main development team appears to be based not in Silicon Valley, but in Tbilisi, Georgia.

If Sumsub’s credibility was already under pressure due to concerns about its founders' origins, this latest connection may further complicate the company’s narrative of being a “trusted” global provider.

Serious clients, serious questions

A review of Belkasoft’s own marketing materials reveals a list of clients that would make any compliance expert pause. These include:

  • US Department of Transportation
  • DoD Cyber Crime Center
  • NYPD
  • KPMG, EY, Deloitte and PwC
  • Disney and other Fortune 500 entities

Yet in June 2023, a technical review by the US Department of Homeland Security (DHS) and the National Institute of Standards and Technology (NIST) found multiple deficiencies in Belkasoft Evidence Center X, the company’s flagship forensic product. These included:

  • Failure to identify SQLite journal modes
  • Incorrect presentation of deleted rows
  • Inability to show source filenames and offsets
  • Lack of support for reading BLOB file content

Such findings, if not corrected and clearly disclosed, could result in forensic evidence being rendered inadmissible in court. The legal consequences could be severe, particularly in cases involving serious crimes.

Despite this, there is no public record that Belkasoft has proactively informed its clients of these issues. Nor has it issued any clarification or correction in response to the DHS/NIST findings.

Belkasoft in Georgia, not California?

While the companies list a California address, the bulk of their staff appears to be based in Tbilisi, Georgia. This includes developers, marketing personnel and what appears to be senior management. On LinkedIn, the total headcount for Belkasoft remains below 40 people, with most profiles indicating Georgian residency.

This geographic discrepancy raises compliance red flags, particularly in light of the companies’ promises to adhere to EU GDPR and US HIPAA data protection rules. If customer data, including sensitive law enforcement files or medical device telemetry, is being processed in Georgia or other non-GDPR jurisdictions, then clients may be exposed to liability without their knowledge.

MedM’s GDPR compliance claims under the microscope

This concern is even more pronounced with MedM, a healthcare software provider whose products process telemetry data from highly sensitive medical devices, including blood glucose monitors, cardiac sensors and remote patient care tools. MedM advertises broad European compatibility, including data integrations with Android and iOS systems and lists several enterprise clients across healthcare and elder care sectors.

To comply with EU data protection laws, non-EU companies processing the personal data of EU citizens are legally required to appoint a representative based within the European Union and ensure proper cross-border transfer mechanisms are in place. In this context, MedM has named Denis Khitrov as its “EU representative”, listing him as being based in Aschaffenburg, Germany.

However, public records searches in Germany have revealed no legal entity formally registered under the MedM name. The lack of incorporation raises questions as to whether Mr Khitrov’s role meets the legal standard required by Article 27 of the General Data Protection Regulation (GDPR), which mandates that an EU representative must be explicitly authorised in writing and should serve as a point of contact for data subjects and supervisory authorities.

Moreover, MedM has not published any documentation on its website concerning Standard Contractual Clauses (SCCs), Data Processing Agreements (DPAs) or a list of subprocessors, all of which are standard requirements for GDPR-compliant data transfers from the EU to third countries.

Without such documentation, customers may be unaware that their medical telemetry data could be processed in jurisdictions such as Georgia, Armenia or Kazakhstan, where data protection standards differ markedly from those in the EU.

Roxosoft’s opaque footprint and data concerns

Roxosoft, the third company linked to the San Conrado Terrace address, appears even less transparent than its counterparts. Public-facing information about Roxosoft is sparse and the company maintains no functional website, no stated headquarters outside of the shared California apartment and no formal incorporation data available in the United States or the European Union.

Despite this, Roxosoft has developed or contributed to various software applications in the fields of database analysis and automation and appears to operate in parallel with Belkasoft, often sharing technical personnel, email domains and infrastructure.

The overlapping identities raise serious concerns about operational independence and legal separation between the entities.

The named individuals associated with Roxosoft, Igor Barchevskii and Misha Zolotov, have published no formal documentation outlining the legal registration of the company, nor have they responded to direct inquiries regarding Roxosoft’s business activity, staff structure or client portfolio.

As with Belkasoft and MedM, LinkedIn analysis and domain infrastructure tools suggest that Roxosoft’s development operations are based not in the United States but in Tbilisi, Georgia and possibly other former CIS jurisdictions.

Given that some of Roxosoft’s tools appear to interact with large datasets, potentially including personal or business information, the lack of clarity on where data is processed or stored may constitute a breach of international data handling norms, especially for clients based in the UK or EU.

Furthermore, no privacy policy, data protection statement or terms of service are publicly available for Roxosoft.

This absence makes it impossible for prospective clients, partners or regulators to assess what safeguards, if any, are in place regarding data security, audit trails or liability.

In combination with the use of a residential California address and the apparent lack of regulatory filings, Roxosoft's operational model raises fundamental questions about legal accountability, corporate responsibility and fitness to handle sensitive or regulated data.

Misrepresentation by omission?

None of the companies publish their legal incorporation data, their tax numbers, nor any physical presence beyond the Sunnyvale apartment. A search across European company registers yields no results. Furthermore, many of their product pages and customer claims are ambiguous at best, misleading at worst.

The decision to co-locate three supposedly unrelated tech companies in a single residential address already stretches credibility. But when paired with missing company registrations, offshore staff, ignored government findings and a failure to respond to journalistic requests, the picture becomes harder to ignore.

This is not a matter of tone, rivalry or regional bias. It is a question of regulatory oversight and customer safety. In what other sector would a forensic software company handling data for federal clients be permitted to operate in this manner?

A recurring pattern: From Sumsub to Belkasoft and back again

For those who have followed the ongoing scrutiny surrounding Sumsub, the structural parallels emerging in this investigation are difficult to ignore. Sumsub’s founding story has long raised eyebrows among compliance professionals and regulators, particularly in light of its opaque jurisdictional structure and developer footprint. While officially incorporated in Cyprus, the company was founded by a group of four:

  • Andrew Sever, originally from Israel, Andrey graduated from St. Petersburg State University, where he received a degree in theoretical physics.
  • His twin brothers, Jacob and Peter, both with backgrounds in animation and computer graphics
  • And Vyacheslav Zholudev, a solution architect holding a PhD in computer science

Despite presenting itself as a European data processor, Sumsub’s development and core technical operations have historically been rooted in Moscow, a fact corroborated by both LinkedIn data and archived corporate materials. The company received early-stage venture funding from Flint Capital, a firm with deep ties to other software ventures operating out of the post-Soviet region.

One of the earliest and most notable of these links is Belkasoft, which received similar investment from Flint Capital and appears to share overlapping infrastructure, investor relationships and operational characteristics.

Archived versions of Belkasoft’s website list Flint among its early backers and company registry data suggests personnel have moved between the two organisations. These connections take on greater significance when viewed alongside Belkasoft’s current business model: operating from a shared residential apartment in Sunnyvale, California, while conducting software development in Tbilisi, Georgia and offering forensic products to US law enforcement and international clients.

As with Sumsub, Belkasoft presents itself as a secure, globally recognised technology company. But both entities show significant gaps in legal structure, registration transparency and jurisdictional accountability.

Their apparent reliance on loosely defined offshore development teams, absence of clear corporate documentation and Russian-language operational roots raises critical questions for data protection and compliance.

The involvement of the founders, engineers and capital in companies handling personal identity documents, biometric data, forensic evidence and medical telemetry creates a landscape of regulatory exposure that is difficult to ignore.

While nationality itself is not a proxy for risk, it becomes material when combined with undisclosed data processing locations, unclear legal entities and non-response to lawful journalistic inquiries.

What is most troubling is the growing pattern this appears to represent. Build a technology platform. Register in Cyprus or the US using a residential address. Staff it with an offshore team. Obscure legal ownership. Then pursue contracts in high-stakes industries like law enforcement, healthcare or finance under the appearance of GDPR or HIPAA compliance.

As regulators in the US, UK and EU move to close loopholes in data protection enforcement, such operating models may come under increasing scrutiny. Products like forensic software and digital identity verification tools are no longer niche; they sit at the core of criminal justice, financial compliance and state-level security.

In this context, the operating profiles of Sumsub, Belkasoft, MedM and Roxosoft merit immediate and detailed review. The repeated features across these entities – unregistered jurisdictions, unclear data flows, minimal public accountability – suggest this may not be an anomaly, but rather a systemic design.

It's a world where speed and investor appeal take priority over legal and ethical standards. One where transparency is optional.

Final remarks

The pattern revealed across Belkasoft, MedM and Roxosoft is not just one of administrative oversight or start-up chaos. It is one that raises foundational questions about how companies that handle highly sensitive personal and forensic data can operate outside the visible boundaries of regulatory control. What began as a residential address anomaly has evolved into a broader investigation of opaque legal structures, unverified corporate registrations and silent development pipelines running through jurisdictions known for limited data protection enforcement.

This article does not assert criminal wrongdoing. But it does show, through verified public sources, that each of these entities presents inconsistencies that clients, regulators and investors should scrutinise. From the shared Sunnyvale address to the undeclared Georgian development teams and from missing GDPR-required documentation to the failure to respond to formal questions, the picture is one of a sector operating on the margins of transparency.

When companies present themselves as compliant, secure and internationally recognised, they assume a responsibility to ensure that claim is grounded in verifiable facts. That includes being clear about where data is processed, who owns and operates the company, under which jurisdiction they are accountable and whether they meet the standards legally required by the industries they serve. This is especially true when the clients include state agencies, hospitals or audit firms.

At the centre of this story is not simply a concern about shared addresses or registration gaps. It is a concern about misalignment between the image projected and the reality on the ground. As regulatory attention intensifies globally, the tolerance for vague legal structures, offshore development without disclosure and data handling without robust governance is quickly shrinking.

The silence from Belkasoft, MedM and Roxosoft cannot be interpreted in isolation. It must be viewed alongside broader industry trends where unregulated or lightly regulated companies present themselves as fully compliant solutions in sectors requiring the highest levels of accountability. Whether these companies are deliberately avoiding regulatory obligations or simply failing to meet them due to resource constraints, the result is the same: increased risk for clients, users and regulatory bodies.

In the coming weeks, our next articles will examine the corporate and financial architecture of Flint Capital, including its early investment in Sumsub, Belkasoft and other entities that share these characteristics. It will continue to ask whether what we are witnessing is a fragmented coincidence, or the outline of a deliberate model built to obscure rather than clarify.

FAQs

What is the core concern regarding Belkasoft, MedM, and Roxosoft?
These companies are under scrutiny for lacking clear corporate registration, transparency, and compliance with international data protection regulations, despite claiming high standards.

Why is the shared address in Sunnyvale, California significant?
All three companies list a single residential condominium as their headquarters, raising concerns about the legitimacy and independence of their operations.

Are these companies legally registered in the US?
No formal registration has been found for Belkasoft, MedM, or Roxosoft in US state or federal corporate databases, which is unusual given their claims of serving high-profile clients.

What data protection laws are potentially being violated?
There are concerns regarding non-compliance with the EU’s GDPR and the US’s HIPAA, particularly around data transfers and lack of required documentation or EU representation.

How is Sumsub connected to Belkasoft?
Sumsub received early investment from Flint Capital, which has ties to Belkasoft. Archived data shows shared infrastructure and personnel movement between the two entities.

Has Belkasoft’s software been evaluated by US authorities?
Yes. In June 2023, the DHS and NIST found multiple technical flaws in Belkasoft’s forensic software, which could compromise legal proceedings if left unaddressed.

Where are the companies’ development teams actually based?
Despite claiming US headquarters, LinkedIn and infrastructure data suggest their staff are mostly based in Tbilisi, Georgia and possibly other former Soviet states.

Is there any public record of GDPR compliance by MedM?
MedM lists a German-based EU representative but lacks official incorporation in Germany and fails to publish required GDPR compliance documents like DPAs or SCCs.

What is known about Roxosoft’s operations?
Roxosoft appears the least transparent of the three, with no website, unclear registration, and overlapping staff and infrastructure with Belkasoft.

Why is this investigation important for clients and regulators?
These companies handle sensitive forensic and medical data. Their lack of transparency, unclear jurisdiction, and silence on regulatory questions pose serious risks to clients and public trust.

Share

Michael Schmitt is the founder of TRIDER.UK and Editor of Malta Media. He writes about iGaming, gambling regulation, corporate structures, financial services and market integrity, combining investigative journalism with nearly three decades of experience in corporate services and international business.