Trust & Security

How our AML engine works

Every scan runs an 8-category composite risk model against live on-chain data and a continuously updated sanctions / label registry. No black box — here's exactly what we check.

Risk categories & weights

CategoryWeightWhat we look for
Sanctions30OFAC SDN, UN, EU, UK HMT and OpenSanctions matches against the queried address and its counterparties.
Mixer / Privacy18Direct interaction with Tornado Cash pools, Wasabi/Samourai CoinJoin clusters, Railgun and ChainFlip-style obfuscators.
Scam / Phishing12Drainer kits, approval-phishing operators, fake airdrops and impersonation wallets reported to our registry.
Darknet Market12Hot wallets and deposit addresses tied to known darknet marketplaces.
Ransomware10Payment addresses associated with active ransomware families.
Theft / Exploit8Wallets receiving stolen funds from bridge hacks, protocol exploits and rug-pulls.
Exchange Exposure5Hot/deposit wallets of major CEXs — neutral signal, used for source-of-funds attribution.
Smart Contract5Contract heuristics (age, verification, proxy patterns) for token / contract addresses.

Data sources

OFAC SDN list

U.S. Treasury sanctions for crypto wallets.

EU / UK / UN sanctions

Cross-jurisdiction screening.

OpenSanctions

Aggregated global watchlists and PEPs.

Blockscout / Etherscan / Blockstream / mempool.space

Live on-chain telemetry for balances, txs and counterparties.

Solana RPC + Helius

Solana account, signature and token data.

TronGrid

Tron account and TRC-20 activity.

Curated registry

Internal label set for exchanges, mixers, scam operators and bridges.

Scoring methodology

  1. Fetch live on-chain state — balance, tx count, age, recent counterparties from public node APIs.
  2. Label every counterparty against our registry + sanctions lists.
  3. Score each of 8 categories from 0–100 based on hits, direction, recency and volume.
  4. Composite the weighted sum into a 0–100 risk index, capped per category and clamped to a level (Low / Caution / High / Severe).
  5. Cache the result so repeat lookups are deterministic and reviewable.

Security & data handling

  • Read-only. We never request signing or wallet permissions.
  • Public data only. All chain data is queried from public node APIs.
  • Row-level security. User watchlists and alerts are isolated per account.
  • Transport security. All traffic is served over HTTPS.
  • No PII required. An email is the only identifier needed to use the product.

Compliance roadmap

We're working toward independent attestation of our security program. Status reflects work amlcryptocheck is doing today — not a certification.

SOC 2 Type I

In progress

Readiness assessment underway. Controls inventory, access reviews and policy framework being finalized.

SOC 2 Type II

Planned

Observation window begins after Type I report. Target: 6-month observation following Type I.

ISO/IEC 27001

In progress

ISMS scoping and Statement of Applicability in draft. Stage 1 audit planned alongside SOC 2 work.

GDPR & data residency

Live

DPA available on request. EU-hosted infrastructure and data subject request workflow already in place.

Statuses are maintained by amlcryptocheck and are not an independent attestation. Need our current security questionnaire or DPA? Contact compliance.

Not a substitute for formal KYT

amlcryptocheck is a forensic intelligence tool. For regulated compliance workflows it should sit alongside, not replace, a licensed KYT provider.

Talk to compliance