AMLBot
AMLBot sells crypto compliance to the businesses that cannot afford to build it, and it is unusually direct about what that buys them. The platform covers know your transaction monitoring and wallet screening, customer and business identity verification spanning more than 4,000 document types across 240 countries with face and liveness checks, sanctions and politically exposed person screening and ultimate beneficial owner verification, and an investigation product called Tracer that traces and de anonymises flows across blockchains, bridges and swaps including mixer and darknet exposure for major stablecoins. Behavioural alerts detect structuring and threshold evasion across multiple transactions. Asset recovery support and consulting on licences and anti money laundering procedures sit alongside the software.
The scoring method is described more plainly than most in this category. The company states that it identifies links from a screened address to other users on chain, each carrying its own conditional risk score, and that the overall score is the average of the components found, drawn from three data sources it does not name. That mechanism is worth understanding before buying, because it means an address inherits risk from what it has touched.
What distinguishes the record is a published limitation. The company states that it does not clean funds and does not guarantee that screened deposits will never trigger an exchange hold, and that what it provides is the data, workflow support and documentation allowing a business to make an informed risk based decision. Vendors in this segment routinely imply the opposite.
External validation comes from casework rather than logos: the company contributes to a major exchange's stolen asset bounty programme, working alongside that exchange's blockchain risk team to trace illicit flows and support freezing, and it publishes original threat research that has been picked up by crypto press. It holds an ISO 27001 certification. Customers are crypto native throughout, spanning exchanges, over the counter desks, trading platforms and decentralised finance businesses, with support offered around the clock through Telegram.
Capability Axes
Capability grades
15 of 15 axes rated · 3 graded A or B
The published method is arithmetic rather than learned, and the company says so itself. It states that it identifies links from a screened address to other users on chain, each carrying a conditional risk score, and that the overall score is the average of the components found, drawn from three data sources. An average of sourced component scores is aggregation, not inference.
Two capabilities in the estate plainly involve the kind of work usually done with models, since tracing and de anonymising flows across blockchains, bridges and swaps requires address clustering and attribution, and detecting structuring and threshold evasion across multiple transactions requires pattern recognition rather than a single threshold.
But across two passes nothing published names a model, a technique, a learned component or artificial intelligence at all in describing how any of it works. Strip the models and what remains is a multi source risk data aggregator with a configurable alerting layer and an investigation interface, which is most of what is described.
The human is written into the workflow explicitly, including into the record. The customer sets its own risk thresholds and tolerance levels to match its risk appetite, alerts are reviewed, prioritised or dismissed by a person in a dashboard rather than disposed of automatically, and the company's published guidance on documentation lists what an audit trail must contain: the date and time of screening, the sender address, the risk score and exposure categories identified, the decision taken, who approved it, and any supporting correspondence.
Naming the approver as a required field is a clear statement that a person is expected to decide. The limitation statement reinforces the same position from the other direction, since a tool that disclaims any guarantee about outcomes is telling the customer it cannot be relied on unattended. What is missing is a vendor position on the boundary itself, since nothing states what should not be automated or whether a customer may configure automatic acceptance or rejection.
The mechanism is disclosed and the performance is not. Publishing that the overall risk score is the average of conditional component scores attached to linked addresses is more method transparency than most of this segment offers, and it lets a compliance officer reason about why a particular address scored as it did rather than treating the number as an oracle.
Against that sits a figure that cannot be assessed: risk scoring is claimed to ensure 99.5 percent data accuracy from three reliable sources, with no definition of what accuracy means here, no identification of the three sources, no sample, no observation period and no method.
Across two passes no false positive rate, no recall against a known illicit set, no validation methodology, no benchmark against competing providers and no drift or coverage change disclosure was located, which matters in a category where chain coverage and attribution quality change continuously as new services appear.
Real casework evidence, no named customer, and scale claims that contradict each other. The casework is the strongest part and is externally corroborated rather than asserted: the company contributes to a major exchange's stolen asset bounty programme, working alongside that exchange's own blockchain risk control team to trace illicit flows and support the freezing of stolen funds, and it publishes original threat research, including a quantified finding on wallets compromised through a specific permissions vulnerability, that has been picked up by crypto press.
That is verifiable work product. Against it, across two passes no customer is named anywhere, and the scale figures do not reconcile: the current site states more than 300 crypto enterprises across 25 jurisdictions, while a company controlled channel elsewhere claims more than 5,000 crypto companies and over 220,000 active users. Those may count different things, and nothing published explains which. A major software review platform carries a single review.
One published statement here does more for a buyer than most safety pages in this index, because it disclaims rather than promises. The company states plainly that it does not clean funds and does not guarantee that screened deposits will never trigger an exchange hold, and that what it supplies is data, workflow support and documentation enabling the business to make an informed risk based decision.
In a segment where the implied promise is that a green result makes funds safe to accept, telling customers the opposite is a meaningful act of restraint, and it correctly locates the residual risk with the business rather than the tool.
Alongside it, the company publishes original threat research identifying specific attack vectors with quantified impact, contributing to industry response rather than only marketing, and holds a certification under the international information security management standard. Absent across two passes: model card, evaluation methodology, red team result, incident disclosure about its own systems, and any acceptable use boundary.
A certified security management system and nothing published about privacy. The company states it holds a certification under the international standard for information security management systems, which is a real credential and bears on data handling, but information security and data protection are different disciplines and one does not stand in for the other.
Across two passes no privacy policy content, data processing description, retention schedule, subprocessor list or reference to the European or any other data protection regime was located. The gap weighs more than it would at a pure analytics vendor because of what the identity component handles: document images, facial biometrics and liveness captures, proof of address and beneficial ownership records, collected across 240 countries, which is among the most sensitive categories of personal data and is subject to heightened protection in several of the jurisdictions the company operates in. Nothing published states how long that material is kept or who processes it.
One real credential named correctly, with nothing obtainable behind it. The company states it has attained certification under the international standard for information security management systems, and uses the right word, since that standard does produce a certificate, a distinction several larger vendors in this index get wrong.
What is missing is everything that would let a buyer act on the claim: no certificate document, no certification body named, no revision year, no statement of applicability and therefore no way to read whether the screening pipeline and the identity verification store sit inside the certified boundary. No trust centre exists, no service organisation control report was located, and no penetration test summary or subprocessor list is published.
A third party procurement assessment additionally records that no public status page, historical uptime figure or availability commitment could be found, so operational security cannot be assessed either.
An unregulated supplier with a services line that touches regulation directly. Product material engages named regimes rather than gesturing at compliance generally, referencing the international standard setter's recommendations, the United Kingdom conduct regulator's requirements and European anti money laundering standards, and building the transfer of originator and beneficiary information into the workflow.
Beyond software the company offers consulting to help crypto businesses obtain licences, open banking relationships, draft anti money laundering procedures and conduct staff training, which places it inside its customers' regulatory preparation rather than beside it. None of that confers standing on the company itself.
Across two passes no authorisation, registration, supervisory examination outcome or regulatory review was located, and no position was found on the European artificial intelligence regulation despite the platform producing risk determinations about people within that jurisdiction.
The scoring method is guilt by association, stated openly, and its consequences are not addressed. The company describes identifying links from a screened address to other users on chain, each carrying a conditional risk score, with the overall score being the average of the components found.
Under that mechanism a person who received funds from a counterparty with a tainted history carries a portion of that taint themselves, through no act of their own, and the resulting score can mean a deposit refused or an account restricted. The company acknowledges the downstream effect exists when it notes that screening cannot guarantee against exchange holds.
What is not published is anything about how that falls: no false positive rate, no analysis of whether scores distribute differently by jurisdiction or by the chains and services common in particular regions, no remediation path for an address scored wrongly, and no appeal available to the person whose funds are affected but who is not the customer.
No commercial instrument is published, and the one relevant statement runs the other way. Across two passes no terms of service, master agreement, warranty, indemnity, liability cap or service level was located, and a third party procurement assessment separately records that availability commitments backed by a service level are not disclosed.
The company's clearest published statement on outcomes is an explicit disclaimer rather than a remedy: it does not clean funds and does not guarantee that screened deposits will never trigger an exchange hold. That honesty is creditable and is recorded as such on the stewardship axis, but on this axis it confirms the position, since a vendor that disclaims any guarantee has by definition allocated the consequence to the customer.
Nothing published states what a business is owed if a screening result proves wrong in either direction, and nothing addresses the person whose funds are refused, who is not the customer and has no route to the vendor at all.
The dependency is admitted in outline and left unnamed. The company states that its risk scoring draws on three data sources, and separately describes proprietary data supporting its investigation product, so a buyer knows the output is a blend of owned and sourced material rather than being led to believe it is wholly proprietary. Acknowledging a multi source dependency at all is more than several competitors do.
Naming none of the three is the gap, and it is consequential in this category specifically, because in blockchain analytics the identity of the attribution provider determines chain coverage, label quality and how quickly new illicit services are recognised, and those differ materially between providers. Several plausible suppliers are themselves vendors in this index, so a buyer could be paying separately for a dataset it is already receiving through this platform, and cannot tell. On the model side no technique, framework or provider is named anywhere.
Interface first delivery with public documentation and an unusual commitment about who does the work. Reference documentation for the transaction monitoring interface is published and reachable, integration is offered across the estate through a single access point, and the company states that it handles the integration itself so the customer's developers stay on their own priorities, with identity verification set up in a day.
For the buyer this product targets, a crypto business with no compliance team and often a very small engineering team, a vendor absorbing the integration effort is a more meaningful form of accessibility than a well documented interface would be on its own. Coverage is broad on chain, spanning multiple blockchains, bridges, swaps and major stablecoins, and support runs continuously through a messaging channel rather than a ticket queue. Holding it below the top band: across two passes no connector catalogue was located and no exchange, custody platform or wallet provider is named as a supported integration.
A hosted service with nothing published about where it runs. Across two passes no hosting provider, region list, tenancy description or data residency commitment was located, and no customer hosted or in perimeter option is described. Two things make the silence weigh more here than it might elsewhere.
The identity verification component collects document images, facial biometrics and liveness captures across 240 countries, and where biometric material is processed and stored is a regulated question in several of the jurisdictions the company claims to serve, not a preference. And the company's origins and operations span multiple countries in a way the public record describes only loosely, so a buyer cannot establish which entity processes their data or under which legal regime.
A third party procurement assessment separately notes that no public status page or historical availability figure could be found, which compounds the difficulty of assessing the hosting arrangement from outside.
No rate card, unit or tier was located across two passes, and the published entry route is a conversation with the team. The positioning is explicitly affordability led, aimed at businesses that cannot staff a compliance function, and one concrete free offer is published: an address can be verified once and then monitored with continuing free checks, which gives a small operator a genuine no cost entry point rather than a demonstration. That is unusual and worth crediting.
What is absent is the shape of a paying relationship. Nothing indicates whether charging follows screened addresses, transactions, monitored wallets, verified customers, seats or a subscription, and the estate spans transaction monitoring, wallet screening, identity verification, investigation tooling and consulting, which would ordinarily price very differently. A third party procurement assessment of this category flags pricing models that conceal alert volume or data coverage costs as a standing risk, and nothing published here resolves it either way.
Crypto native throughout, deliberately so, and narrow as a consequence. The published buyer set covers exchanges, over the counter desks, crypto trading platforms, decentralised and centralised finance businesses and virtual asset service providers, with material addressed specifically to teams too small to build an in house compliance function from day one, which is a coherent and honestly stated position rather than an attempt to appear enterprise ready.
Jurisdictional reach is claimed at 25 markets, and the identity verification component covers 240 countries and more than 4,000 document types, which is genuine international breadth on that one capability. What is absent is any presence in the segments where crypto compliance increasingly matters most.
No bank, payment institution, custodian or regulated financial institution is named or addressed, no institution count is published for any segment, and nothing indicates whether the platform is used by anyone outside crypto native businesses.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | Data Protection Terms | Implementation | Source |
|---|---|---|---|---|
|
Not published. No price, unit of billing, tier or contract term appears on any vendor surface; a free lifetime address monitoring offer is published
|
Not published on any vendor surface. The estate covers transaction monitoring and wallet screening, customer and business identity verification, an investigation and tracing product, asset recovery support, and consulting on licences and compliance procedures, with no published indication of whether charging follows addresses screened, transactions monitored, customers verified, seats, or a platform subscription, nor whether the components are licensed separately. Positioning is explicitly affordability led toward crypto businesses without in house compliance teams, and a free continuing monitoring tier is published for a single verified address, which suggests a usage based model above that threshold without confirming one. | No tiered data protection terms are published. The company states it holds a certification under the international standard for information security management systems, with no certificate, certification body, revision year or scope statement obtainable. Across two passes no privacy policy content, data processing agreement, retention schedule, subprocessor list or hosting location was located. That gap matters most for the identity verification component, which collects document images, facial biometrics and liveness captures across 240 countries, and for which no retention or processing location is described. | No implementation, integration or professional services fee is published, and the company makes an explicit commitment about the work itself rather than its price: it states that it handles integration so that the customer's developers are freed for their own priorities, and puts identity verification setup at one day. For the target buyer, a crypto business with little or no engineering capacity, a vendor absorbing integration effort is a material part of the offer. Separately the company sells consulting that sits outside software entirely, covering preparation of documents for crypto licences, opening banking relationships, drafting anti money laundering procedures and delivering staff training, none of it priced publicly and all of it plainly a services engagement rather than a product feature. Support is provided continuously through a messaging channel rather than a ticketing system, which suits the segment and carries no published service level. | Vendor Published |
Two passes across the company's site, its product pages, its blog and third party directories produced no rate card, unit or tier for any part of the estate. One genuinely useful free offer is published rather than merely promised: an address can be verified once and then monitored on a continuing basis at no charge, which lets a small operator or an individual use the core screening capability without a commercial relationship at all.
That is a real accessibility feature and consistent with the company's stated positioning toward businesses that cannot staff compliance. What a paying buyer still cannot establish is the shape of the commitment. The estate spans transaction monitoring, wallet screening, identity verification, investigation tooling, asset recovery support and licensing consultancy, which would ordinarily carry four or five different commercial models, and nothing published indicates which applies to which or how they combine. A third party procurement assessment of this category flags alert volume and data coverage costs as a standing risk.