AML, KYC & Financial Crime
C

Crystal Intelligence

Crystal Intelligence is a blockchain analytics and compliance platform operated by Crystal Blockchain B.V. of Amsterdam, begun inside the Bitfury Group in 2015 and released publicly on 30 January 2018. The flagship product, Crystal Expert, covers more than 330 blockchains and over 10,000 digital assets and combines automated address clustering with human verified attribution across a database the company reports at more than 120,000 verified entities.

Around it sit Crystal for Compliance for sanctions screening and transaction monitoring, Crystal for Investigations for case work and cross chain visualisation, and Crystal Foresight, a stablecoin prediction product launched in 2025. An AI analyst named Ask Crystal was announced in August 2026. Three access commitments run alongside the commercial line: a free Open Block Explorer that returns entity connections and a risk score without any licence, free Crystal Expert licences for university research and teaching, and Scam Alert, a public scam reporting service acquired in 2025 whose off chain data also feeds the attribution set.

Services include training and certification, investigative work and regulatory advisory. Navin Gupta, formerly of Ripple, was appointed chief executive in 2024, when the company rebranded from Crystal Blockchain to Crystal Intelligence. Tether made a strategic investment in 2025. The DIFC Courts approved the platform as an official blockchain intelligence provider for digital asset litigation.

Last VerifiedAugust 24, 2026
Compare Crystal Intelligence with other vendors
Founded
2015
Headquarters
Amsterdam, Netherlands
Categories
aml-kyc-financial-crime, compliance-and-surveillance, crypto-and-digital-assets
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 11 graded A or B

AI Capability
AI Centrality
CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.
Vendor Published

The removal test lands where it does for most of this lane. Strip the models and what remains is not nothing: more than 120,000 verified entities across more than 330 blockchains, assembled over a decade through investigations, exchange relationships and law enforcement work, plus off chain material from Scam Alert and what the company calls ground level intelligence from high risk jurisdictions. That attribution set is the asset.

The company states plainly that clustering is automated but attribution is human verified, an unusual admission that confirms where the value sits. Real machine learning does run underneath, in the proprietary entity clustering and in risk scoring, and two components are explicitly artificial intelligence: Crystal Foresight, a stablecoin prediction product launched in 2025, and Ask Crystal, an AI analyst announced on 4 August 2026. Both are too recent to carry the grade. The moat is data and human verification rather than models.

Autonomy and Oversight Model
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism, or full automation is presented as the entire disclosure. Human in the loop appears as a phrase rather than a described control.
Vendor Published

Two things pull in opposite directions. On the data side there is a real and published human control: the company states that clustering is automated but attribution is human verified, which puts a person between the model and the label that determines a customer's outcome, and that is a stronger oversight construction than most of this lane describes. On the product side the direction runs the other way.

Screening and monitoring are automated with configurable alerts, the marketing promises compliance automated at scale, and Ask Crystal, announced on 4 August 2026, is presented as an AI analyst working around the clock. Nothing published states what Ask Crystal is permitted to conclude unaided, what a human must approve, what threshold triggers review, or how an analyst overrides it. A named human verification step on one side and an unspecified agent on the other.

Model Risk Management and Transparency
CC on Model Risk Management and TransparencyTransparency is claimed in general terms with no mechanism a model validator could interrogate.
Vendor Published

No accuracy figure, clustering precision measure, validation report or model documentation was located for any component. Three partial mechanisms exist and none substitutes for one. The quality management system is stated to align with ISO 9001:2015 and to cover development and delivery of the forensic software, which is process assurance rather than model assurance. Human verification of attribution is a real control on output quality but its criteria are unpublished.

The DIFC Courts approval is external scrutiny of an unusually demanding kind, since a court satisfying itself that output is fit for litigation is a higher bar than a procurement review, but the court's reasoning is not published and an approval is not an error profile. One published false positive rate would be worth more to a model risk reviewer than all three together.

Operational and Outcome Evidence
AA on Operational and Outcome EvidenceNamed customers with hard performance figures and enough method to test them.
Vendor Published

The named counterparty list is dense and spans every category a buyer would want to test. Banking and financial infrastructure: The Provident Bank, which took Crystal for cryptocurrency AML compliance in 2019, alongside Magnetiq Bank, Clear Junction, Avaloq and Grant Thornton.

Exchanges and custodians: WhiteBIT, ChangeNOW and Wallex Custody, and in a 2021 CoinDesk interview then chief executive Marina Khaustova named Upbit, Coinspaid and Rain among a base she put at more than 1,900 customers. Government and law enforcement: the Ukrainian Cyber Police from 2021, a contract with the Ukrainian government signed after the 2022 invasion, the Finance Ministry of Ukraine, Dubai Police under a 2024 memorandum, Politie Belgium, and the European Central Bank.

Journalism: the ICIJ Coin Laundry investigation in 2025. The company also claims its Ukrainian work helped close more than half of that country's open crypto fraud cases, which is its own figure and is not independently verified here. Awards are named with the bodies awarding them, the FSTech RegTech Award in 2024 and Best Blockchain Analytics at the Regulation Asia Awards in 2025.

AI Safety and Data Stewardship
BB on AI Safety and Data StewardshipA categorical stewardship commitment is published without the retention schedule or the engineering detail behind it.
Vendor Published

The boundary is written down, and written into a contract rather than a marketing page. The Data Processing Addendum limits Crystal to retaining, using or disclosing personal data for three purposes only, confines access to employees with a need to know, requires confidentiality undertakings, and subjects the arrangement to customer audit. Against that sits the second of those three permitted purposes, to improve the services generally, which is open ended and undefined.

That clause is where the network effect question lives, because Crystal states its intelligence is continuously updated from real time threat signals and off chain data, and nothing describes whether a customer's own enquiry activity feeds the shared attribution set, whether such contribution can be declined, or how one institution's searches are separated from what another institution can see. Disclosed and bounded, but not governed at the point that decides the answer.

Regulatory and Compliance
GLBA and Data Privacy Posture
AA on GLBA and Data Privacy PostureThe privacy architecture is published in the specifics: data handling, retention, and a subprocessor list, which is rare in this index and valuable.
Vendor Published

The Data Processing Addendum, last revised 19 May 2026, is the most complete privacy artifact located in the blockchain analytics lane, and it is published rather than gated behind diligence. It names the competent supervisory authority, the Autoriteit Persoonsgegevens at Hoge Nieuwstraat 8 in The Hague. It names every subprocessor with purpose and address: Hetzner in Gunzenhausen for hosting, Refinitiv in London for KYC verification, DocuSign and HubSpot in Dublin.

It incorporates the standard contractual clauses at Commission Implementing Decision (EU) 2021/914 for restricted transfers. It commits to breach notification within twenty four hours, deletion or return of data on termination with flow down to subprocessors, notification of subprocessor changes with a right to object, and audit rights including data protection inspections by the customer or an auditor the customer mandates.

Most tellingly it allocates GDPR roles across three distinct data categories and accepts controller status for Crystal Data, the attribution set carrying names and sanctions or enforcement markings. No retention schedule appears, which is the single gap.

Security Certifications and Trust Center
BB on Security Certifications and Trust CenterA recognised certification named in the vendor’s own material without the artefact, or with a scope or renewal question the buyer has to raise.
Vendor Published

Crystal was awarded ISO 27001:2022 in September 2024 following an independent audit by the British Standards Institute, which the company names as the certifying body, and Nicholas Smart, its Director of Intelligence, is quoted on the record announcing it. That clears the credential test on three of four points: there is a verb, a named auditor and a version with a date. The fourth is missing.

No ISMS scope statement, certificate number, Statement of Applicability or downloadable certificate was located across two dedicated passes, so a buyer cannot tell which systems, entities or product lines the certificate actually covers, and for a company running a separate investigative services arm and a acquired consumer property that boundary matters.

Beyond the certificate the security annex to the processing addendum enumerates controls: encryption at rest and in transit with key management, role based access on least privilege with access monitored and logged, intrusion detection and prevention, regular vulnerability assessment and penetration testing, backup to a secure facility, and security training for all employees.

Because that annex also serves as an annex under the standard contractual clauses those controls are contractually operative rather than promotional. Two further standards are cited honestly as alignment rather than certification, ISO 9001:2015 for quality management and ISO 22301:2012 for business continuity. No trust centre, SOC 2 report or penetration test summary exists. A published scope statement is the one artifact that would move this to A, and nothing short of it will.

Regulatory Status and Licensure
AA on Regulatory Status and LicensureThe regulatory position is stated and a formal admission process stands behind it: a register entry, an eCBSV enrolment, a payment network partner admission, or presence inside SAR or CTR filing paths.
Vendor Published

Standing is evidenced through named institutions rather than claimed in general terms. The DIFC Courts approved Crystal as an official blockchain intelligence provider for digital asset litigation, which is a judicial body accepting the platform's output in its own proceedings and is the strongest form this axis can take for a technology supplier. The European Central Bank is named as a 2024 partner.

A contract with the Ukrainian government followed the 2022 invasion and the company's team received medals from Ukraine's National Police. Four industry bodies are named together with the company's role in each: CryptoUK on national compliance strategy, Global Digital Finance on AML and KYC standards, the International Association for Trusted Blockchain Applications on EU policy alignment, and the Global Blockchain Business Council on regulatory working groups.

A memorandum with Vietnam's GOE Alliance was signed at Davos in 2026. The Dutch data supervisor is named in the processing addendum. Crystal holds no financial licence itself, which is correct for a technology supplier and is not a deduction.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

One genuine disclosure, then silence. The company publishes its definition of an entity, describing it as a cluster of addresses determined through data analysis and attribution methods to belong to the same controlling party, which concedes in the vendor's own words that an entity is an inference rather than an observation. Little in this lane says that out loud. Nothing follows it.

No error rate, no attribution confidence measure, no false positive figure, no statement of which chains or regions are better or worse covered, and no discussion of how proximity based risk scoring treats a person who received funds several hops from a flagged source without any knowledge of it. The human verification step is asserted but its standard is not published, so a reader cannot tell what verification consists of or what proportion of attributions receive it.

AI Liability and Recourse
BB on AI Liability and RecourseA published falsifiable commitment such as an accuracy figure with its method, or a real correction route for the affected person, such as step up verification instead of silent denial.
Vendor Published

A person wrongly attributed here has a route, which is uncommon in this lane. Because the processing addendum makes Crystal the data controller for Crystal Data, the category it defines as names and inclusion on sanctions lists or enforcement actions for persons marked as such by Crystal, the attribution set falls under GDPR with Crystal answerable for it.

The addendum enumerates all six data subject rights including rectification of inaccurate data, erasure, restriction of processing and objection, and it names the authority to complain to, the Autoriteit Persoonsgegevens. That is a checkable path to challenge a label. Two things hold the grade down.

Clause 15 assigns responsibility for handling data subject requests to the customer rather than to Crystal, with Crystal only assisting, which puts the institution that acted on the label in charge of reviewing it. And the indemnity covers data protection failures rather than attribution error: there is no accuracy guarantee, no service level on correction time, and nothing stating how a corrected attribution propagates to customers who already acted on the original.

Integration and Deployment
Model Supply Chain Disclosure
BB on Model Supply Chain DisclosureSubstantial partial disclosure, or a chain that is structurally short: an explicit in house build, on premise deployment, per customer instances, or zero retention at the model layer.
Vendor Published

Disclosure runs deeper here than the lane norm and reaches the layer that actually decides outcomes. Every subprocessor appears with purpose and address in the published addendum: Hetzner for hosting, Refinitiv for KYC verification, DocuSign for document processing, HubSpot for relationship management. Naming Refinitiv is substantive, since it identifies the third party identity data feeding verification rather than leaving it unnamed.

On the intelligence side the company identifies its inputs, stating the entity set is updated from proprietary threat signals, off chain data from Scam Alert which Crystal acquired in 2025, and hyperlocal intelligence gathered from high risk jurisdictions.

Most importantly, attribution provenance is exposed per record rather than in aggregate: Crystal states that where an address has been linked to an entity it records the source of that link, including web mentions with the original reference, so a customer can inspect the basis for an individual attribution. Its entity directory carries type, risk score, registration and legal details and supervising authorities for each entity.

What is still undisclosed is how competing sources are weighted, what standard the human verification step applies, and whether any third party or foundation model sits behind Crystal Foresight or Ask Crystal, which is the gap between this and an A.

Core Systems and Integration Depth
BB on Core Systems and Integration DepthNamed systems or a documented public API, with the depth or the production evidence left open.
Vendor Published

Delivery is a web application and an API, with authentication and access management described in the processing addendum. Integration partners are named rather than gestured at, which is what separates this from the lane norm. FICO integrated Crystal blockchain risk data into its anti financial crime solutions in 2020, placing the intelligence inside a decisioning platform banks already run.

Avaloq and Clear Junction appear as partners, reaching wealth management and payments infrastructure respectively. Sumsub appears alongside, connecting on chain risk to identity verification. A travel rule partner programme covers the messaging layer that screening alone cannot satisfy.

What is absent is any named core banking or case management connector and any published integration documentation, so the depth rests on one substantial platform integration and a partner roster rather than on a catalogue a buyer can inspect.

Deployment Model and Data Residency
BB on Deployment Model and Data ResidencyStated residency commitments or regional hosting options.
Vendor Published

The residency position is specific and contractually binding, which is rare in this lane. Hosting is named as Hetzner at Industriestrasse 25 in Gunzenhausen, Germany, so the processing location is a street address rather than a region. The processing addendum states that data sits in an ISO 27001 certified data centre on dedicated servers on a separate rack, logically and physically isolated from other data in that facility.

Restricted transfers outside the European Economic Area run on the standard contractual clauses and the Dutch supervisory authority is named. What is absent is any customer selectable region, any documented multi region option and any current on premise offering.

One passage of the binding security annex reads that no redundant infrastructure is maintained across multiple geographic locations while the sentences on either side of it describe redundancy and failover, and a buyer should raise that directly, because the annex is the operative document rather than a brochure.

Commercial
Commercial Transparency
BB on Commercial TransparencyA published plan ladder, billing dimensions, or a stated commitment such as no fees, so a buyer can size the cost before making contact.
Vendor Published

No rate, tier or list price appears anywhere, confirmed across two dedicated passes. The second pass turned up a movement worth recording: a licence comparison page at crystalintelligence.com/license carried three named segment tiers as recently as August 2025, distinguishing compliance teams, high volume financial organisations and occasional case by case users, with support terms stated per tier. That URL now redirects to a demo request form.

The tier structure was withdrawn from public view, and it carried no figures even when it stood. Discovering that URL live again would not move this grade unless it carries a rate. What holds the grade above the floor is three separate access commitments, published and maintained rather than announced once.

The Open Block Explorer is free to any user and returns entity connections and a Crystal calculated risk score on an address, which is the substantive compliance check rather than a block lookup. Free Crystal Expert licences have been offered to universities for research and teaching since 2023. Scam Alert is a public scam reporting service that costs nothing to use. Three commitments of that kind is a stronger position than any single free tier, and it is what this axis recognises where no rate is disclosed.

Institution and Segment Coverage
BB on Institution and Segment CoverageNamed segments with dedicated material behind part of the coverage.
Vendor Published

Institution types run wide: banks and payment providers, crypto exchanges and wallet services, virtual asset service providers, custodians, stablecoin issuers, law enforcement, financial regulators, a central bank, universities and auditors. Geographic evidence is concrete rather than asserted, with named engagements in the Netherlands, the United Kingdom, Ukraine, the United Arab Emirates, Belgium and Vietnam, and a stated emphasis on the Middle East and North Africa.

Product coverage spans screening, monitoring, investigation, stablecoin prediction and travel rule, backed by training, investigative and advisory services. What holds this below the top grade is that the named evidence clusters in Europe, Ukraine and the Gulf rather than demonstrating the global spread the marketing describes.

Alternatives to Crystal Intelligence

The closest documented capability profiles to Crystal Intelligence in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.

Stronger documented coverage on Institution and Segment Coverage and Core Systems and Integration Depth

Stronger documented coverage on Institution and Segment Coverage and Core Systems and Integration Depth

Documents Autonomy and Oversight Model and Model Risk Management and Transparency where Crystal Intelligence does not

Documents AI Centrality and Autonomy and Oversight Model, among others where Crystal Intelligence does not

Documents AI Centrality and Autonomy and Oversight Model, among others where Crystal Intelligence does not

Documents Autonomy and Oversight Model where Crystal Intelligence does not

Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis Data Protection Terms Implementation Source
Not published. Every commercial tier is quote only through a demo request. A free Open Block Explorer, a free Crystal Expert licence for university research and teaching, and the free Scam Alert reporting service sit outside the commercial line.
Quote only, negotiated per customer. The vendor publishes no unit of sale, so a buyer cannot tell whether pricing keys to seats, screened addresses, monitored wallets, API calls, chains covered or entity database access. Product tiering is real, since Crystal Expert, Crystal for Compliance, Crystal for Investigations and Crystal Foresight are packaged separately and a Crystal Lite tier is referenced outside the vendor's own material, but the commercial relationship between those packages is not disclosed. A Data Processing Addendum is published in full and self executing: it states that it automatically becomes part of any contractual arrangement between Crystal and a customer wherever personal data processing is involved, and that it prevails over the underlying agreement in the event of conflict. It names four subprocessors with purpose and address, names the Autoriteit Persoonsgegevens as the competent supervisory authority, incorporates the standard contractual clauses at Commission Implementing Decision (EU) 2021/914, commits to breach notification within twenty four hours, and grants the customer audit and data protection inspection rights. A buyer therefore knows the data protection terms before contact rather than after diligence, which is unusual in this lane. Not published. No setup, onboarding, training or data migration fee appears anywhere, and none is disclaimed either. Training and certification, investigative services and advisory services are sold as named service lines alongside the software, so implementation and expert work are evidently chargeable, but no rate card, day rate or engagement minimum was located for any of them across two passes. Vendor Published

Two dedicated passes returned no figure from any source, vendor or third party. The pass worth recording is a withdrawal rather than an absence. A licence comparison page at crystalintelligence.com/license was live as recently as August 2025 carrying three named segment tiers, compliance teams such as hedge funds, high frequency firms, family offices, money transmitters, investigators, law enforcement and supervisory bodies; high transaction volume financial organisations such as exchanges, payment processors and trading services; and occasional case by case use for AML and CFT screening.

Support terms were stated per tier. That URL now redirects to the demo request form and the tier structure is no longer public. It carried no prices even when it stood, so the withdrawal removed segmentation rather than rates. Pre emptive negative finding: a third party review site or a reseller listing quoting a Crystal figure should not be treated as a published rate, because the vendor has never published one and has actively retired the page that came closest.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746