AML, KYC & Financial Crime
A

AnChain.AI

AnChain.AI is a San Francisco company founded in 2018 and led by Dr. Victor Fang, selling AI native blockchain intelligence to investigators, compliance teams and government agencies. Three products carry the line: CISO, a blockchain forensics, analysis and case management platform built around a patented Auto-Trace capability and agents that trace money flows and generate reports; a Data API and Model Context Protocol server delivering crypto intelligence with structured outputs designed for large language model tool calling; and SCREEN for smart contract due diligence and risk monitoring.

Around them sit a crypto tracing and expert witness service used in litigation, an agentic AI advisory practice, and AnChain.AI University, which runs four self paced courses and instructor led training leading to Certified Web3 Investigator and Certified Smart Contract Investigator credentials. The company enumerates sixteen machine learning and language models publicly, naming the technique behind each, marking six as patented, and citing external academic provenance for several including a Kyoto University paper on bytecode similarity, an MIT and Berkeley paper on NFT wash trading detection and Berkeley DataX material on bot behaviour detection.

Stated figures include more than 870 million dollars in asset seizures and recoveries, a trillion transactions processed, coverage of more than 41 blockchains, over a billion address labels, 100 millisecond API latency and 99.99 percent uptime. Developer access is unusually open: the API and MCP server are published open source on GitHub, the Python client ships on PyPI as crypto-aml, a JavaScript package ships on npm, and both a free API key with a thousand credits and free platform access are offered without a procurement cycle. SOC 2 Type II was completed in October 2024. Forbes reported an SEC engagement to investigate DeFi transactions in 2021.

Last VerifiedAugust 24, 2026
Compare AnChain.AI with other vendors
Founded
2018
Headquarters
San Francisco, California, United States
Website
www.anchain.ai
Categories
aml-kyc-financial-crime, compliance-and-surveillance, crypto-and-digital-assets
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 9 graded A or B

AI Capability
AI Centrality
AA on AI CentralityThe artificial intelligence is the product. Remove the models and there is nothing left to sell.
Vendor Published

The removal test is unusually easy here because the company answers it itself. AnChain.AI publishes an inventory of sixteen models with the technique named for each: two patented Auto-Trace graph heuristic search engines, one for UTXO chains and one for smart contract EVM chains; a generative pretrained transformer that interprets smart contract functions; a fine tuned large language model with retrieval augmented generation for financial crime; Tornado Cash demixing heuristics; patented regression models for risk scoring on UTXO and externally owned account transactions and for smart contract vulnerability; wallet clustering on cryptographic and behavioural patterns; bytecode similarity search and bytecode reverse engineering through vector database embedding; NFT wash trading detection; bot behaviour detection; patented peel chain and passthrough detection; exchange behaviour classification; DeFi behaviour classification; and cross chain bridge demixing.

Strip those and there is no product left, because the billion labels the platform serves are themselves model output rather than a hand assembled directory. The commercial structure confirms it: agentic AI advisory is sold as its own service line, the data product exists to feed other people's agents through a Model Context Protocol server, and the outputs are shaped as structured JSON for tool calling. This is a modelling company selling models, not a data company with a model on top.

Autonomy and Oversight Model
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism, or full automation is presented as the entire disclosure. Human in the loop appears as a phrase rather than a described control.
Vendor Published

This is the axis where the company's strength becomes its exposure, and the gap is the widest on this record. The products are explicitly agentic: an agentic AML workflow automation suite is sold to streamline sanction screening, Auto-Trace and what the company calls Auto Report to financial regulators, and the platform is described as using AI agents to analyse blockchains, trace money flows and auto generate reports.

Automatically generating a filing to a financial regulator is among the more consequential acts software can perform in this domain, because a report once filed cannot be recalled and carries legal weight for the institution that filed it. One thing points the right way: explainability is claimed repeatedly as a product property, with outputs described as explainable risk signals and structured for audit, which is the correct design intent for a reviewable agent.

But nothing published states what an agent may conclude unaided, what a human must approve before a report leaves, what threshold escalates to review, or how an analyst overrides an agent's finding. The most autonomous product in this lane carries the least documented oversight around it.

Model Risk Management and Transparency
BB on Model Risk Management and TransparencyReal transparency mechanisms are published, such as per alert explainability, confidence scoring or split testing, without the validation package or supervisory mapping behind them.
Vendor Published

The model inventory is the most complete published by any vendor in the blockchain analytics lane and it is what carries this grade. Sixteen components are named individually with the technique behind each, distinguishing heuristic graph search from regression scoring from classification from language model work, and marking which are patented.

Three carry external academic provenance a reviewer can go and read: a Kyoto University paper behind bytecode similarity search, an MIT and Berkeley paper behind NFT wash trading detection, and Berkeley DataX material behind bot behaviour detection. Naming the method and its published source is precisely what lets a model risk function form its own view rather than accept a vendor's summary. Outputs are described as explainable and structured for audit.

What is missing is the other half of the discipline. No accuracy figure, precision or recall measure, false positive rate, validation report, benchmark result or monitoring statement was located for any of the sixteen. The one quantified customer figure, a 96.66 percent reduction in analysis time reported by VAAS, measures throughput rather than correctness. A model risk reviewer here can see exactly what is running and nothing about how well it runs.

Operational and Outcome Evidence
AA on Operational and Outcome EvidenceNamed customers with hard performance figures and enough method to test them.
Vendor Published

Named counterparties, named individuals speaking on the record, and one independently reported engagement. Jarod Koopman, Executive Director for Cyber and Forensic Services at IRS Criminal Investigation, is quoted describing the agency's use of the technology against DeFi financial crime.

Forbes reported in August 2021, under Steven Ehrlich's byline, that the Securities and Exchange Commission signed a deal with the company to investigate DeFi transactions, which is third party reporting rather than a vendor claim. David Cass, managing director and chief information security officer at GSR, states the platform let a small security team operate effectively and saved several full time equivalents.

Gustavo Tremel, chief executive of VAAS, gives the one quantified customer outcome located anywhere in this lane: analysis time falling from fifteen minutes to thirty seconds, a 96.66 percent reduction, across more than a million transactions. Institutional logos name Ripple, PwC, DBS Bank, MetaMask, Solana, Sui, Amber, Provenance, Japan's Financial Services Agency and Dubai's Virtual Assets Regulatory Authority.

The payment screening extension is stated to reach more than 17,000 MetaMask users. Company figures claim 870 million dollars in asset seizures and recoveries and a trillion transactions processed. Awards are named with their bodies: the FinTech Innovation Lab, the RSA Conference Innovation Sandbox and CNBC.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

One genuine and unusual control exists: the Data API and Model Context Protocol server are published as open source on the company's GitHub repository, so the layer that carries intelligence out to a customer's own agents is inspectable rather than a black box, and a security team can read what it sends before deploying it. That is real and rare. Everything else is undocumented.

Nothing states whether a customer's screening queries or investigative case material feed the shared label set, whether contribution can be declined, how one agency's enquiries are separated from another's, or how long anything is retained.

The exposure is sharper here than for a screening only vendor because the platform holds active investigative case files from law enforcement alongside commercial customer traffic on the same infrastructure, and no published statement addresses the boundary between them. Open sourcing the transport does not answer what happens to what travels through it.

Regulatory and Compliance
GLBA and Data Privacy Posture
CC on GLBA and Data Privacy PostureA standard privacy policy that covers the website rather than the service, or silence on a product that touches limited consumer data.
Vendor Published

A privacy policy is published and linked from the footer, and nothing else on the privacy side was located. No data processing addendum, no subprocessor list, no retention schedule, no named supervisory authority and no standard contractual clause provision were found.

That gap matters more than usual given what this company handles: it takes investigative case material from tax and securities enforcement agencies, litigation evidence prepared for court, and screening queries from payment firms, all categories where the customer carries its own confidentiality obligations and would normally require documented processing terms before signing.

The AWS GovCloud badge implies a US government aligned handling posture for at least part of the estate, but no scope, region or applicability statement accompanies it. The company publishes its models in exhaustive detail and its data handling barely at all, which is a consistent pattern across this record rather than an oversight on one page.

Security Certifications and Trust Center
BB on Security Certifications and Trust CenterA recognised certification named in the vendor’s own material without the artefact, or with a scope or renewal question the buyer has to raise.
Vendor Published

SOC 2 Type II is held and the announcement clears most of the credential test. There is a verb, the company announced successful completion of the certification in a release dated 29 October 2024. The type is stated and it is the stronger one, Type II being an evaluation of controls operating over a period rather than at a point in time. The standard's author is named, the American Institute of Certified Public Accountants, and the evaluation is described as a third party audit.

Dr. Victor Fang, chief executive, is quoted on the record. What is missing is the scope and the auditor. No certifying firm is named, unlike peers in this lane who name theirs, no trust services criteria are enumerated so a buyer cannot tell whether the report covers only security or extends to availability, confidentiality, processing integrity or privacy, and no report or bridge letter is available to request.

AWS GovCloud availability adds an inherited control environment for part of the estate. There is no trust centre, no penetration test summary and no ISO certification. Pre emptive negative finding: a renewed SOC 2 announcement will not move this grade on its own. Naming the audit firm and the trust services criteria in scope is what would.

Regulatory Status and Licensure
BB on Regulatory Status and LicensureThe regulatory position is clearly stated and appropriate to the product, with part of the verification left to the buyer.
Vendor Published

The strongest item is real and independently reported but ageing. Forbes reported in August 2021 that the Securities and Exchange Commission signed a deal with the company to investigate DeFi transactions, and the company still links that article from its public sector material, but no current status, renewal or scope is stated anywhere. IRS Criminal Investigation is evidenced better, through a named executive, Jarod Koopman, speaking on the record about the agency's use of the technology.

The AWS GovCloud badge indicates availability in the US government cloud region, which carries its own federal handling requirements. Japan's Financial Services Agency, Dubai's Virtual Assets Regulatory Authority and the Financial Action Task Force all appear as logos with no engagement described, and a standards body like FATF does not purchase software, so those carry little weight.

Alignment is claimed against the GENIUS Act, MiCA, the FATF Travel Rule, OFAC, FinCEN and ESMA, which is a readiness statement rather than a supervisory relationship. The company holds no licence itself, which is correct for a technology supplier and not a deduction.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

The published model inventory is genuine transparency and it is credited on the model risk and supply chain axes where it belongs. It is not governance, and crediting it here would be counting one artifact three times. What this axis asks for is absent. No error rate, false positive rate or confidence measure is published for any of the sixteen models. No bias statement, fairness testing, disparate impact analysis or coverage disclosure appears.

Nothing describes how the risk scoring regression models treat an address that received funds several hops from a flagged source without knowledge of it, which is the central fairness question for propagated crypto risk. Nothing describes who governs model changes, how a retrain is approved, or what review a new model passes before it reaches a customer.

The explainability claim is asserted as a product property rather than described as a method, so a reviewer cannot tell whether it means feature attribution, a natural language rationale generated by the language model, or a citation back to the underlying transaction graph.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

One structural feature points the right way and it is unusual in this lane. The company sells crypto tracing as litigation support with expert witness services and court ready forensics reporting, and claims proven success in major lawsuits.

A vendor that puts its analysts in a witness box has accepted that its methodology will be cross examined by an opposing expert, which is a stronger accountability posture than any commercial guarantee, and the explainability claimed for the outputs is the property that makes such testimony possible. That is where it stops. No accuracy guarantee, indemnity, service level on correction or falsifiable commitment attaches to any risk score.

Nothing describes who reviews a disputed attribution, how long a correction takes, or whether a correction reaches customers who already acted on the original. For the subject of a finding the position is worse. A person or business screened by the payment API and refused has no described route to see the evidence, challenge the score or reach the company, and no supervisory authority is named anywhere that they could complain to instead.

Integration and Deployment
Model Supply Chain Disclosure
AA on Model Supply Chain DisclosureEvery party between the customer’s data and the output is enumerated by name, canonically through a public subprocessor list naming the model providers.
Vendor Published

This is the most complete supply chain disclosure located in the blockchain analytics lane, and almost all of it is checkable by a reader without contacting the company. Sixteen models are named individually rather than as a capability, each with its technique stated, so a reviewer can distinguish patented heuristic graph search from regression scoring from behavioural classification from generative language work. Six are marked patented, which points at a public filing.

Three cite external academic provenance by institution: a Kyoto University paper behind smart contract bytecode similarity search, an MIT and Berkeley paper behind NFT wash trading detection, and Berkeley DataX lecture material behind bot behaviour detection. Infrastructure suppliers are named, Amazon Web Services and NVIDIA.

The delivery chain is published rather than described: the API and Model Context Protocol server source sits in a public GitHub repository, the Python client is a named PyPI package and a JavaScript package ships on npm, so the code carrying the intelligence can be read. Two gaps remain and both matter.

No foundation model provider is named for the fine tuned large language model and retrieval augmented generation component, so the base model behind the financial crime reasoning is unidentified. And no subprocessor list exists in any document.

Core Systems and Integration Depth
AA on Core Systems and Integration DepthNamed integrations with the systems of record, core banking, policy administration, custodial or contact center platforms, verifiable in marketplace listings or public API documentation.
Vendor Published

The integration surface is the most inspectable in this lane and almost all of it can be verified without contacting the company. The Data API and Model Context Protocol server are published open source on GitHub under AnChainAI, so an engineer can read the integration layer before adopting it.

The Python client is distributed on the Python Package Index as crypto-aml and installs with a single command, and a JavaScript package is distributed on npm, meaning the vendor ships through the package registries its buyers already use rather than through a partner portal.

The REST API states 100 millisecond latency on most endpoints and 99.99 percent uptime, and delivers structured JSON explicitly shaped for large language model tool calling and agentic workflows, which makes the product a component other systems build on rather than a destination. MetaMask carries the payment screening capability to a stated 17,000 plus users. Amazon Web Services and NVIDIA are named as infrastructure partners and AWS GovCloud availability is indicated.

Agentic AI advisory is sold alongside to handle deployment. What is absent is any named core banking, case management or transaction monitoring connector, so the depth is developer led rather than enterprise stack led.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

Delivery is hosted software plus an API, with 99.99 percent uptime stated and 100 millisecond latency claimed on most endpoints. Amazon Web Services is named as an infrastructure partner and an AWS GovCloud badge appears on the home page, which is the only residency signal anywhere and which matters because GovCloud is a physically separate US region operated under federal handling requirements. That badge is where it stops.

No statement describes which products run in GovCloud and which do not, whether a commercial customer can request it, what region a non government customer lands in, or whether any region choice exists at all. No data centre, country or residency commitment is published, no on premise or private deployment option was located across two passes, and no standard contractual clause or transfer mechanism appears for customers outside the United States. A badge asserting availability in a government region, without a described deployment option or scope around it, is a marketing signal rather than a residency position a buyer can rely on.

Commercial
Commercial Transparency
BB on Commercial TransparencyA published plan ladder, billing dimensions, or a stated commitment such as no fees, so a buyer can size the cost before making contact.
Vendor Published

No rate card, tier table or price appears anywhere across two dedicated passes, and the company describes its own pricing only as flexible. What earns the grade is that the barrier to first use is genuinely removed rather than merely lowered.

A developer can obtain a free API key carrying a thousand credits without contact, install the Python client from PyPI with pip install crypto-aml, take the JavaScript package from npm, or read the API and Model Context Protocol server source on the company's public GitHub repository. Investigators can request free access to the CISO platform.

The company states plainly in its own comparison FAQ that this is meant to avoid a lengthy procurement cycle, positioning free access against Chainalysis, TRM Labs and Elliptic by name. Publishing working code and a free tier is a substantive commitment a buyer can act on today, and it is what this axis recognises where no rate exists. It is not the same as publishing what the paid tier costs, which nothing here does.

Institution and Segment Coverage
BB on Institution and Segment CoverageNamed segments with dedicated material behind part of the coverage.
Vendor Published

Three buyer segments are addressed with their own material and named references in each. Public sector covers crypto tracing, DeFi exploit investigation, ransomware response, sanctions enforcement and tax evasion detection, evidenced by IRS Criminal Investigation and the reported SEC engagement. Law firms and accountants cover forensic accounting, litigation support and expert witness work, with a published Big Four accounting case study and case studies on probate and estate disputes.

Virtual asset service providers and crypto payment firms cover real time screening and agentic AML workflows, evidenced by GSR, Amber, Ripple and MetaMask. Coverage extends across more than 41 blockchains and into layer one protocols themselves through Solana and Sui. Regulatory framework alignment is claimed for FATF, the GENIUS Act, MiCA, the Travel Rule, OFAC, FinCEN and ESMA.

What holds this below the top grade is delivery capacity against breadth: this is a company of roughly twenty one people addressing government, Big Four, tier one banking, payments and protocol segments simultaneously, and the geographic evidence is thinner than the logo strip implies.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis Data Protection Terms Implementation Source
Not published. Free API key with 1,000 credits and free CISO platform access are available without contact; every paid tier routes to a demo request with no rate stated anywhere.
Undisclosed. The company describes its own pricing only as flexible and no unit of sale, tier structure, quota or seat model is published for any of the three products. What is published is the entry point: a free API key carrying 1,000 credits, free access to the CISO platform on request, an open source API and Model Context Protocol server on GitHub, a Python client on PyPI as crypto-aml and a JavaScript package on npm. Credits are therefore the metering unit for the data API at minimum, since the free allocation is denominated in them, but no credit price, refill rate or overage behaviour is stated and nothing indicates how CISO platform access, the investigation service or the advisory practice are priced. Three separate commercial motions sit behind one demo request form. No data processing addendum, subprocessor list or negotiated data protection terms were located. A single privacy policy is linked from the site footer and nothing further. No supervisory authority is named, no standard contractual clauses or transfer mechanism is published for customers outside the United States, and no retention schedule appears. A buyer taking this platform for investigative case material, litigation evidence or payment screening traffic will be negotiating data protection terms from a blank sheet, which is a notable position for a vendor whose named references include a tax enforcement agency and a Big Four accounting firm. Not published and not disclaimed. The company sells agentic AI advisory as a distinct service line for enterprises, financial services and government, describing it as building production grade solutions and prototyping a first use case, which is professional services work that would normally carry a day rate or engagement minimum, and none is published. Crypto tracing, asset recovery, litigation support and expert witness services are sold as engagements with no rate, minimum or basis stated. AnChain.AI University runs four self paced courses and instructor led training toward Certified Web3 Investigator and Certified Smart Contract Investigator credentials, and no course or certification fee was located. Self serve onboarding for the API carries no fee because it requires no human contact at all. Vendor Published

Two dedicated passes returned no figure from the vendor or from any third party listing. The finding is that the free tier is real and unusually substantive rather than a lead capture device, which is why the commercial transparency grade sits above the floor despite the total absence of rates.

A developer can obtain a working API key with a thousand credits, install a client from PyPI or npm, and read the API and MCP server source on GitHub without ever contacting the company, and an investigator can request free platform access on the same basis. The company positions this explicitly against Chainalysis, TRM Labs and Elliptic by name in its own comparison FAQ, arguing that speed to first use is its advantage over a procurement cycle.

What that leaves unanswered is everything past the free tier. The word the company uses for its own pricing is flexible, which is not a model, and no unit of sale is disclosed anywhere: a buyer cannot tell whether the paid product meters on API calls, credits, seats, cases, monitored addresses or chains.

Pre emptive negative finding: publishing a credit pack price for the data API alone would not resolve this, because the platform, the investigation service and the advisory practice are three separate commercial motions and none carries a published rate.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746