Methodology
How the verdict is made — and where it stops
Every signal carries a source and a confidence, and every gap is reported honestly. We never emit a fake GREEN, and a single seed label never becomes a fake RED.
Wallet AML analysis
We reconstruct the on-chain neighbourhood of a subject wallet or transaction under available coverage. Findings describe what the graph shows; gaps are reported as UNKNOWN rather than filled with assumptions.
Source of funds
Inbound flow is traced to identify originating services and exposure paths. Where a path cannot be resolved within coverage, the result is INSUFFICIENT DATA — not an implied clean origin.
Sanctions exposure
Direct and indirect exposure to sanctioned entities is measured against provider-backed lists. Exposure is reported with the path and its confidence; absence of a match is not a certification of compliance.
Risk scoring
Signals are combined into a redacted risk band for triage. A band is a prioritisation aid, not a legal conclusion — high-risk bands are flagged as requiring analyst review before any decision.
Seed labels
Curated seed labels anchor known entities. A seed label attributes an entity; it does not, on its own, produce a RED verdict for everything one hop away. Seed-derived inferences are marked NEEDS VALIDATION.
External attribution
Third-party attribution (exchanges, services, sanctioned entities) is attached with its provider source and confidence. Unattributed subjects remain UNKNOWN; we do not invent identities.
Limitations
Coverage is partial and time-bound. Chain reorganisation, privacy tooling, new addresses, and provider lag all constrain results. Every report states what it covers so findings are read in context.
What we will never do
- Call a wallet “clean” or “safe” — verdicts are scoped to coverage, not guarantees.
- Emit a GREEN result to fill a data gap. Missing data is UNKNOWN or INSUFFICIENT DATA.
- Turn a single seed label into a definitive RED for adjacent wallets without validation.