Crystal Intelligence
Crystal Intelligence is a blockchain analytics and compliance platform operated by Crystal Blockchain B.V. of Amsterdam, begun inside the Bitfury Group in 2015 and released publicly on 30 January 2018. The flagship product, Crystal Expert, covers more than 330 blockchains and over 10,000 digital assets and combines automated address clustering with human verified attribution across a database the company reports at more than 120,000 verified entities.
Around it sit Crystal for Compliance for sanctions screening and transaction monitoring, Crystal for Investigations for case work and cross chain visualisation, and Crystal Foresight, a stablecoin prediction product launched in 2025. An AI analyst named Ask Crystal was announced in August 2026. Three access commitments run alongside the commercial line: a free Open Block Explorer that returns entity connections and a risk score without any licence, free Crystal Expert licences for university research and teaching, and Scam Alert, a public scam reporting service acquired in 2025 whose off chain data also feeds the attribution set.
Services include training and certification, investigative work and regulatory advisory. Navin Gupta, formerly of Ripple, was appointed chief executive in 2024, when the company rebranded from Crystal Blockchain to Crystal Intelligence. Tether made a strategic investment in 2025. The DIFC Courts approved the platform as an official blockchain intelligence provider for digital asset litigation.
Capability Axes
Capability grades
15 of 15 axes rated · 11 graded A or B
The removal test lands where it does for most of this lane. Strip the models and what remains is not nothing: more than 120,000 verified entities across more than 330 blockchains, assembled over a decade through investigations, exchange relationships and law enforcement work, plus off chain material from Scam Alert and what the company calls ground level intelligence from high risk jurisdictions. That attribution set is the asset.
The company states plainly that clustering is automated but attribution is human verified, an unusual admission that confirms where the value sits. Real machine learning does run underneath, in the proprietary entity clustering and in risk scoring, and two components are explicitly artificial intelligence: Crystal Foresight, a stablecoin prediction product launched in 2025, and Ask Crystal, an AI analyst announced on 4 August 2026. Both are too recent to carry the grade. The moat is data and human verification rather than models.
Two things pull in opposite directions. On the data side there is a real and published human control: the company states that clustering is automated but attribution is human verified, which puts a person between the model and the label that determines a customer's outcome, and that is a stronger oversight construction than most of this lane describes. On the product side the direction runs the other way.
Screening and monitoring are automated with configurable alerts, the marketing promises compliance automated at scale, and Ask Crystal, announced on 4 August 2026, is presented as an AI analyst working around the clock. Nothing published states what Ask Crystal is permitted to conclude unaided, what a human must approve, what threshold triggers review, or how an analyst overrides it. A named human verification step on one side and an unspecified agent on the other.
No accuracy figure, clustering precision measure, validation report or model documentation was located for any component. Three partial mechanisms exist and none substitutes for one. The quality management system is stated to align with ISO 9001:2015 and to cover development and delivery of the forensic software, which is process assurance rather than model assurance. Human verification of attribution is a real control on output quality but its criteria are unpublished.
The DIFC Courts approval is external scrutiny of an unusually demanding kind, since a court satisfying itself that output is fit for litigation is a higher bar than a procurement review, but the court's reasoning is not published and an approval is not an error profile. One published false positive rate would be worth more to a model risk reviewer than all three together.
The named counterparty list is dense and spans every category a buyer would want to test. Banking and financial infrastructure: The Provident Bank, which took Crystal for cryptocurrency AML compliance in 2019, alongside Magnetiq Bank, Clear Junction, Avaloq and Grant Thornton.
Exchanges and custodians: WhiteBIT, ChangeNOW and Wallex Custody, and in a 2021 CoinDesk interview then chief executive Marina Khaustova named Upbit, Coinspaid and Rain among a base she put at more than 1,900 customers. Government and law enforcement: the Ukrainian Cyber Police from 2021, a contract with the Ukrainian government signed after the 2022 invasion, the Finance Ministry of Ukraine, Dubai Police under a 2024 memorandum, Politie Belgium, and the European Central Bank.
Journalism: the ICIJ Coin Laundry investigation in 2025. The company also claims its Ukrainian work helped close more than half of that country's open crypto fraud cases, which is its own figure and is not independently verified here. Awards are named with the bodies awarding them, the FSTech RegTech Award in 2024 and Best Blockchain Analytics at the Regulation Asia Awards in 2025.
The boundary is written down, and written into a contract rather than a marketing page. The Data Processing Addendum limits Crystal to retaining, using or disclosing personal data for three purposes only, confines access to employees with a need to know, requires confidentiality undertakings, and subjects the arrangement to customer audit. Against that sits the second of those three permitted purposes, to improve the services generally, which is open ended and undefined.
That clause is where the network effect question lives, because Crystal states its intelligence is continuously updated from real time threat signals and off chain data, and nothing describes whether a customer's own enquiry activity feeds the shared attribution set, whether such contribution can be declined, or how one institution's searches are separated from what another institution can see. Disclosed and bounded, but not governed at the point that decides the answer.
The Data Processing Addendum, last revised 19 May 2026, is the most complete privacy artifact located in the blockchain analytics lane, and it is published rather than gated behind diligence. It names the competent supervisory authority, the Autoriteit Persoonsgegevens at Hoge Nieuwstraat 8 in The Hague. It names every subprocessor with purpose and address: Hetzner in Gunzenhausen for hosting, Refinitiv in London for KYC verification, DocuSign and HubSpot in Dublin.
It incorporates the standard contractual clauses at Commission Implementing Decision (EU) 2021/914 for restricted transfers. It commits to breach notification within twenty four hours, deletion or return of data on termination with flow down to subprocessors, notification of subprocessor changes with a right to object, and audit rights including data protection inspections by the customer or an auditor the customer mandates.
Most tellingly it allocates GDPR roles across three distinct data categories and accepts controller status for Crystal Data, the attribution set carrying names and sanctions or enforcement markings. No retention schedule appears, which is the single gap.
Crystal was awarded ISO 27001:2022 in September 2024 following an independent audit by the British Standards Institute, which the company names as the certifying body, and Nicholas Smart, its Director of Intelligence, is quoted on the record announcing it. That clears the credential test on three of four points: there is a verb, a named auditor and a version with a date. The fourth is missing.
No ISMS scope statement, certificate number, Statement of Applicability or downloadable certificate was located across two dedicated passes, so a buyer cannot tell which systems, entities or product lines the certificate actually covers, and for a company running a separate investigative services arm and a acquired consumer property that boundary matters.
Beyond the certificate the security annex to the processing addendum enumerates controls: encryption at rest and in transit with key management, role based access on least privilege with access monitored and logged, intrusion detection and prevention, regular vulnerability assessment and penetration testing, backup to a secure facility, and security training for all employees.
Because that annex also serves as an annex under the standard contractual clauses those controls are contractually operative rather than promotional. Two further standards are cited honestly as alignment rather than certification, ISO 9001:2015 for quality management and ISO 22301:2012 for business continuity. No trust centre, SOC 2 report or penetration test summary exists. A published scope statement is the one artifact that would move this to A, and nothing short of it will.
Standing is evidenced through named institutions rather than claimed in general terms. The DIFC Courts approved Crystal as an official blockchain intelligence provider for digital asset litigation, which is a judicial body accepting the platform's output in its own proceedings and is the strongest form this axis can take for a technology supplier. The European Central Bank is named as a 2024 partner.
A contract with the Ukrainian government followed the 2022 invasion and the company's team received medals from Ukraine's National Police. Four industry bodies are named together with the company's role in each: CryptoUK on national compliance strategy, Global Digital Finance on AML and KYC standards, the International Association for Trusted Blockchain Applications on EU policy alignment, and the Global Blockchain Business Council on regulatory working groups.
A memorandum with Vietnam's GOE Alliance was signed at Davos in 2026. The Dutch data supervisor is named in the processing addendum. Crystal holds no financial licence itself, which is correct for a technology supplier and is not a deduction.
One genuine disclosure, then silence. The company publishes its definition of an entity, describing it as a cluster of addresses determined through data analysis and attribution methods to belong to the same controlling party, which concedes in the vendor's own words that an entity is an inference rather than an observation. Little in this lane says that out loud. Nothing follows it.
No error rate, no attribution confidence measure, no false positive figure, no statement of which chains or regions are better or worse covered, and no discussion of how proximity based risk scoring treats a person who received funds several hops from a flagged source without any knowledge of it. The human verification step is asserted but its standard is not published, so a reader cannot tell what verification consists of or what proportion of attributions receive it.
A person wrongly attributed here has a route, which is uncommon in this lane. Because the processing addendum makes Crystal the data controller for Crystal Data, the category it defines as names and inclusion on sanctions lists or enforcement actions for persons marked as such by Crystal, the attribution set falls under GDPR with Crystal answerable for it.
The addendum enumerates all six data subject rights including rectification of inaccurate data, erasure, restriction of processing and objection, and it names the authority to complain to, the Autoriteit Persoonsgegevens. That is a checkable path to challenge a label. Two things hold the grade down.
Clause 15 assigns responsibility for handling data subject requests to the customer rather than to Crystal, with Crystal only assisting, which puts the institution that acted on the label in charge of reviewing it. And the indemnity covers data protection failures rather than attribution error: there is no accuracy guarantee, no service level on correction time, and nothing stating how a corrected attribution propagates to customers who already acted on the original.
Disclosure runs deeper here than the lane norm and reaches the layer that actually decides outcomes. Every subprocessor appears with purpose and address in the published addendum: Hetzner for hosting, Refinitiv for KYC verification, DocuSign for document processing, HubSpot for relationship management. Naming Refinitiv is substantive, since it identifies the third party identity data feeding verification rather than leaving it unnamed.
On the intelligence side the company identifies its inputs, stating the entity set is updated from proprietary threat signals, off chain data from Scam Alert which Crystal acquired in 2025, and hyperlocal intelligence gathered from high risk jurisdictions.
Most importantly, attribution provenance is exposed per record rather than in aggregate: Crystal states that where an address has been linked to an entity it records the source of that link, including web mentions with the original reference, so a customer can inspect the basis for an individual attribution. Its entity directory carries type, risk score, registration and legal details and supervising authorities for each entity.
What is still undisclosed is how competing sources are weighted, what standard the human verification step applies, and whether any third party or foundation model sits behind Crystal Foresight or Ask Crystal, which is the gap between this and an A.
Delivery is a web application and an API, with authentication and access management described in the processing addendum. Integration partners are named rather than gestured at, which is what separates this from the lane norm. FICO integrated Crystal blockchain risk data into its anti financial crime solutions in 2020, placing the intelligence inside a decisioning platform banks already run.
Avaloq and Clear Junction appear as partners, reaching wealth management and payments infrastructure respectively. Sumsub appears alongside, connecting on chain risk to identity verification. A travel rule partner programme covers the messaging layer that screening alone cannot satisfy.
What is absent is any named core banking or case management connector and any published integration documentation, so the depth rests on one substantial platform integration and a partner roster rather than on a catalogue a buyer can inspect.
The residency position is specific and contractually binding, which is rare in this lane. Hosting is named as Hetzner at Industriestrasse 25 in Gunzenhausen, Germany, so the processing location is a street address rather than a region. The processing addendum states that data sits in an ISO 27001 certified data centre on dedicated servers on a separate rack, logically and physically isolated from other data in that facility.
Restricted transfers outside the European Economic Area run on the standard contractual clauses and the Dutch supervisory authority is named. What is absent is any customer selectable region, any documented multi region option and any current on premise offering.
One passage of the binding security annex reads that no redundant infrastructure is maintained across multiple geographic locations while the sentences on either side of it describe redundancy and failover, and a buyer should raise that directly, because the annex is the operative document rather than a brochure.
No rate, tier or list price appears anywhere, confirmed across two dedicated passes. The second pass turned up a movement worth recording: a licence comparison page at crystalintelligence.com/license carried three named segment tiers as recently as August 2025, distinguishing compliance teams, high volume financial organisations and occasional case by case users, with support terms stated per tier. That URL now redirects to a demo request form.
The tier structure was withdrawn from public view, and it carried no figures even when it stood. Discovering that URL live again would not move this grade unless it carries a rate. What holds the grade above the floor is three separate access commitments, published and maintained rather than announced once.
The Open Block Explorer is free to any user and returns entity connections and a Crystal calculated risk score on an address, which is the substantive compliance check rather than a block lookup. Free Crystal Expert licences have been offered to universities for research and teaching since 2023. Scam Alert is a public scam reporting service that costs nothing to use. Three commitments of that kind is a stronger position than any single free tier, and it is what this axis recognises where no rate is disclosed.
Institution types run wide: banks and payment providers, crypto exchanges and wallet services, virtual asset service providers, custodians, stablecoin issuers, law enforcement, financial regulators, a central bank, universities and auditors. Geographic evidence is concrete rather than asserted, with named engagements in the Netherlands, the United Kingdom, Ukraine, the United Arab Emirates, Belgium and Vietnam, and a stated emphasis on the Middle East and North Africa.
Product coverage spans screening, monitoring, investigation, stablecoin prediction and travel rule, backed by training, investigative and advisory services. What holds this below the top grade is that the named evidence clusters in Europe, Ukraine and the Gulf rather than demonstrating the global spread the marketing describes.
Alternatives to Crystal Intelligence
The closest documented capability profiles to Crystal Intelligence in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Stronger documented coverage on Institution and Segment Coverage and Core Systems and Integration Depth
Stronger documented coverage on Institution and Segment Coverage and Core Systems and Integration Depth
Documents Autonomy and Oversight Model and Model Risk Management and Transparency where Crystal Intelligence does not
Documents AI Centrality and Autonomy and Oversight Model, among others where Crystal Intelligence does not
Documents AI Centrality and Autonomy and Oversight Model, among others where Crystal Intelligence does not
Documents Autonomy and Oversight Model where Crystal Intelligence does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | Data Protection Terms | Implementation | Source |
|---|---|---|---|---|
|
Not published. Every commercial tier is quote only through a demo request. A free Open Block Explorer, a free Crystal Expert licence for university research and teaching, and the free Scam Alert reporting service sit outside the commercial line.
|
Quote only, negotiated per customer. The vendor publishes no unit of sale, so a buyer cannot tell whether pricing keys to seats, screened addresses, monitored wallets, API calls, chains covered or entity database access. Product tiering is real, since Crystal Expert, Crystal for Compliance, Crystal for Investigations and Crystal Foresight are packaged separately and a Crystal Lite tier is referenced outside the vendor's own material, but the commercial relationship between those packages is not disclosed. | A Data Processing Addendum is published in full and self executing: it states that it automatically becomes part of any contractual arrangement between Crystal and a customer wherever personal data processing is involved, and that it prevails over the underlying agreement in the event of conflict. It names four subprocessors with purpose and address, names the Autoriteit Persoonsgegevens as the competent supervisory authority, incorporates the standard contractual clauses at Commission Implementing Decision (EU) 2021/914, commits to breach notification within twenty four hours, and grants the customer audit and data protection inspection rights. A buyer therefore knows the data protection terms before contact rather than after diligence, which is unusual in this lane. | Not published. No setup, onboarding, training or data migration fee appears anywhere, and none is disclaimed either. Training and certification, investigative services and advisory services are sold as named service lines alongside the software, so implementation and expert work are evidently chargeable, but no rate card, day rate or engagement minimum was located for any of them across two passes. | Vendor Published |
Two dedicated passes returned no figure from any source, vendor or third party. The pass worth recording is a withdrawal rather than an absence. A licence comparison page at crystalintelligence.com/license was live as recently as August 2025 carrying three named segment tiers, compliance teams such as hedge funds, high frequency firms, family offices, money transmitters, investigators, law enforcement and supervisory bodies; high transaction volume financial organisations such as exchanges, payment processors and trading services; and occasional case by case use for AML and CFT screening.
Support terms were stated per tier. That URL now redirects to the demo request form and the tier structure is no longer public. It carried no prices even when it stood, so the withdrawal removed segmentation rather than rates. Pre emptive negative finding: a third party review site or a reseller listing quoting a Crystal figure should not be treated as a published rate, because the vendor has never published one and has actively retired the page that came closest.