Global Ledger
Global Ledger is a Swiss blockchain analytics company trading as GLO Services AG from Zug, founded in 2019 by Lex Fisun and Dimitrii Bilokon and running a team of around forty. Three products carry the line: Know Your Transaction for real time risk scoring, monitoring and alerting, Know Your Business for entity level exposure reporting against a database of more than 92,000 crypto entities, and sanctions screening.
Around them sit an investigations toolset with visual tracing, case management, automated tracing of tainted assets and a Chrome extension that surfaces wallet risk on any web page, plus asset recovery, counterparty risk work and a compliance officer certification programme built against FATF requirements. The company states a database of more than 700 million attributed addresses updated daily and an average response time of 500 milliseconds. Its scoring output, the GL Score, runs 0 to 100 and is derived from the assessed riskiness of the sources contributing to a given address or transaction, with the calculation approach published rather than withheld.
Packaging is unusually open for this lane, with four tiers published against request quotas and seat counts alongside named add on modules including on premise installation and a support agreement carrying a 99.8 percent availability guarantee, though no rate appears against any of them. Integration with IBM Digital Asset Haven is documented in IBM's own product documentation. The company runs law enforcement training with the United Nations Office on Drugs and Crime and belongs to the Global Coalition to Fight Financial Crime, CryptoUK and Global Digital Finance.
Published figures are internally inconsistent in places: digital asset coverage appears as both 700,000 and over 2,000, and daily checks as both 500,000 and 250,000, across the same site and in one case the same page.
Capability Axes
Capability grades
15 of 15 axes rated · 7 graded A or B
The artificial intelligence language is thinner than the marketing suggests, and the vendor's own methodology page is what shows it. AI appears as a label on features, a Risk Report marked plus AI, real time AI powered alerts, AI driven prioritisation credited with cutting compliance time and cost by up to eighty percent.
But the one place the company explains how its scoring actually works describes something else: the GL Score is stated to be derived by an algorithm that analyses incoming transactions, assesses the risk of the identified sources contributing to an address, and propagates that into a number from 0 to 100. That is deterministic source risk propagation, not a learned model, and the company describes it that way itself.
What does carry the grade is the attribution layer underneath, since a database of more than 700 million attributed addresses and 92,000 entities cannot be assembled at that scale without clustering and entity resolution, which are genuine machine learning even where the vendor never says so. The moat is the address database and the investigations team behind it. Strip the models and the propagation logic still runs; strip the database and nothing does.
The oversight construction here is better assembled than most in this lane, and all four components are published on the pricing page rather than asserted in marketing. Custom Scoring Profiles let a customer set and apply their own risk scores for any type or tag in place of the default system scores so the output aligns with internal policy, which is an explicit published override of the vendor's own judgement and implicitly concedes that the defaults are a starting position rather than a finding.
KYT Lab is a sandbox for testing new alert rules and thresholds against historical transactions without touching live systems or consuming request quota, so a change can be validated before it reaches production, and the company frames it as letting a team see projected alert volume and balance regulatory requirements against frozen client liquidity. An audit log records user actions and configuration changes for traceability.
Role based access with structured permission levels is sold as part of the seat model. Nothing in the product acts on funds: Auto Tracing monitors tainted assets from a starting address and alerts when they move or reach a known service, and monitoring assigns scores and alerts compliance teams, but the decision stays with a person throughout. What is absent is any published threshold, escalation path or review requirement around the alerts themselves.
Two things point up and one points down hard. Upward, the GL Score calculation method is published rather than withheld, with a dedicated article on the risk based approach behind it, and KYT Lab gives a reviewer something rare in this lane, the ability to run proposed rules and thresholds against historical transactions before they go live and see the projected alert volume, which is a validation affordance even though the vendor sells it as workload planning.
Downward, no accuracy figure, precision measure, false positive rate, validation report or model documentation was located for any component. The specific problem for a model risk reviewer is that the published figures do not reconcile with each other. Digital asset coverage is stated as 700,000 in the company mission and as over 2,000 in the FAQ. Daily checks appear as 500,000 in one place and 250,000 in another, in at least one instance on the same page.
Supported chains are described as all blockchains in the packaging table while the FAQ on that page enumerates fourteen. None of those gaps is fatal on its own, but a reviewer asked to rely on a vendor's numbers has to be able to rely on the ones it publishes about itself first.
Named evidence exists and two pieces of it are verifiable outside the vendor's own site, which is what separates this from a testimonial page. IBM documents the Global Ledger integration in its own product documentation for Digital Asset Haven, describing real time risk scoring for transaction screening.
ARGOS Identity, itself indexed here, posted a client review on Clutch covering an engagement running from April 2024 with a minimum project size above ten thousand dollars, describing onboarding, transaction monitoring and API work. On the vendor's own surface, named customers speak on the record rather than anonymously: Konstantin Anissimov, chief executive of Currency.com, Roman Bieda, head of investigations at Token Recovery, and Bryan Noller of ARGOS Identity.
Institutional relationships are named with the counterparty: a 2022 training course for law enforcement, financial intelligence units and supervisors run with the United Nations Office on Drugs and Crime, a Council of Europe partnership, work with Panama's Chamber of Digital Commerce and Blockchain quoted by its board director Rodrigo Icaza, and OSCE training. Che Sidanius, vice chair of the Global Coalition to Fight Financial Crime, is quoted on the company's membership.
Investigative output is concrete, including analyst tracking of 16.54 billion dollars processed through the sanctioned Grinex exchange, and collaborations with Reuters, the Financial Times, the Wall Street Journal and Forbes. What is missing for a higher grade is a named bank, a named regulator as a paying customer, and any outcome figure for funds frozen or recovered.
One genuine control exists and it is sold rather than granted. The on premise installation add on is described as keeping all labels and wallet monitoring requests on the customer's own private server, limiting access to approved users, keeping anti money laundering information fully isolated, and maintaining total privacy without outside data access. That is a real and specific boundary, and stating it in those terms concedes what the default arrangement is not.
For the hosted default nothing is documented. No statement describes whether a customer's screening queries feed the shared attribution database, whether that contribution can be declined, or how one institution's enquiry activity is separated from another's, and the privacy policy that would normally govern it excludes platform data by its own scope.
Data sourcing is disclosed only in categories, naming publicly available information, open blockchain data, the company's own investigations, and data purchased from unnamed vendors. A stewardship posture that a customer has to buy their way into is better than none, and it is not the same as one that is documented for everybody.
The only privacy artifact published is scoped to the wrong thing. The privacy policy states in its opening line that it covers privacy on Global Ledger websites and marketing initiatives, and everything in it follows that scope: newsletter signups, event registrations, IP addresses, browser type, CRM records and marketing preferences.
It says nothing about the platform, which is where the sensitive processing actually happens, and no data processing addendum, subprocessor list or platform retention schedule was located across two passes. One sentence shows the mismatch plainly, stating the company will not collect any information about criminal convictions and offences, which is true of the website and could not be true of a product whose function is attributing addresses to criminal activity.
What it does do well is name things: the Federal Data Protection and Information Commissioner at Feldeggweg 1 in Berne is given with full address as the authority to complain to, all six data subject rights are enumerated with a one month response commitment, and processing principles are quoted against Article 5 of the GDPR.
Against that, the international transfers clause asks the reader to consent to processing on servers in many countries around the world including outside the European Economic Area, with standard contractual clauses stated to apply only between group companies. The document carries an effective date of 25 August 2022 and a publication date of 2 February 2023.
Two dedicated passes found nothing to credit. There is no security page in the site navigation, where the Policies section holds only a privacy policy and a cookie policy, no trust centre, no certification of any kind, no attestation, no penetration test summary and no enumerated control framework.
The entire published security position is one paragraph inside the website privacy policy, stating that personal information is stored on secure servers accessible to select personnel, encrypted to prevent unauthorised access, with procedures in place to handle a breach and notify where legally required. That paragraph is scoped to website and marketing data by the document containing it, so it does not even purport to cover the platform.
The only quantified commitment anywhere is a 99.8 percent availability guarantee, which is sold as a paid support add on and measures uptime rather than security. The company runs a standing alert about a website impersonating it, which shows operational awareness but is not assurance a buyer can rely on. Pre emptive negative finding: a future blog announcement of ISO 27001 or SOC 2 should not move this grade on its own. It needs a verb, a named certifying body and a scope statement, the same bar applied everywhere in this lane.
Standing rests on named institutional relationships rather than on any licence, which is correct for a technology supplier and not a deduction. The United Nations Office on Drugs and Crime is named as the partner on a 2022 training course built for law enforcement, financial intelligence units, supervisors and other government agencies.
The Council of Europe is named as a 2024 partner alongside work with Panama, quoted on the record by Rodrigo Icaza of that country's Chamber of Digital Commerce and Blockchain, describing training that reached Panamanian judges. Membership is dated and named: the Global Coalition to Fight Financial Crime and CryptoUK in 2024, Global Digital Finance in 2025, with the coalition's vice chair Che Sidanius quoted. OSCE training and European Union consultations are claimed.
The Swiss Federal Data Protection and Information Commissioner is named as the supervisory authority in the privacy policy. What separates this from the top of the axis is that the court admissibility claim, which the company makes in absolute terms, is not attached to any named court, tribunal or ruling that has accepted its output, and no regulator appears as a named customer.
There is a real methodological disclosure here, which is more than most of this lane offers, and it stops well short of governance. The GL Score is explained in the vendor's own FAQ: a 0 to 100 scale with green, yellow and red bands, derived from the assessed riskiness of the sources contributing to a requested address or transaction, calculated by an algorithm that analyses incoming transactions and evaluates identified sources, with a linked blog article on the risk based approach and the calculation itself.
Publishing the shape of the scoring logic lets a reviewer reason about what the number means. Nothing else follows. No error rate, false positive rate, confidence measure or coverage statement appears, and there is no discussion of the central fairness question for source based propagation, which is how many hops of separation from a flagged source still taint an address and what happens to a recipient who had no way to know.
The Custom Scoring Profiles feature quietly concedes the issue by letting institutions replace the defaults wholesale, but that is a commercial escape hatch rather than a disclosure, and it moves the judgement rather than examining it.
The institution is served and the subject of a score is not. For the customer there is one falsifiable commitment, a 99.8 percent availability guarantee under the paid support agreement, with incidents prioritised and standard resolution procedures supplied. That is uptime rather than accuracy, and no guarantee, indemnity or correction commitment attaches to the GL Score itself.
Custom Scoring Profiles give an institution a genuine corrective, since it can override the default score for any type or tag where it disagrees with the vendor, and that is more than most of this lane offers. For a person or business whose address carries a high GL Score the position is worse than silence.
The privacy policy enumerates all six data subject rights and names the Swiss Federal Data Protection and Information Commissioner as the authority to complain to, but that document scopes itself to websites and marketing initiatives, so the rights it grants do not reach the attribution database where the consequential judgement lives. Nothing published describes who reviews a disputed attribution, how long a correction takes, or whether a correction propagates to customers who already acted on the original score.
The chain is described in categories and named nowhere, which is precisely the pattern this axis exists to catch. The company states that its team collects and analyses publicly available information, uses open data from top blockchains, replenishes its internal base through its own investigations, and buys data from reliable vendors.
That last clause is the whole problem: an unnamed commercial supplier feeds an attribution database of more than 700 million addresses that determines whether a customer's funds are treated as tainted, and a buyer cannot identify it, assess it, or check whether it is already in their own supply chain elsewhere. No subprocessor list exists in any document. No hosting provider is named. No model or foundation model provider is named for any component carrying an AI label.
The only third party named anywhere in the delivery chain is IBM, and that is a downstream integration consuming Global Ledger data rather than a supplier feeding it. Reliable vendors is an adjective standing where a name should be.
The strongest integration evidence sits on somebody else's website, which is what makes it worth something. IBM documents the Global Ledger integration in its own product documentation for Digital Asset Haven, describing the platform as supplying anti money laundering compliance and Know Your Transaction capability with real time risk scoring for transaction screening.
That places the risk data inside an enterprise digital asset custody and settlement stack rather than beside it, and IBM's documentation is a primary source rather than a vendor claim. Public API documentation is served at common.glprotocol.com and API access is bundled into every published tier rather than reserved for enterprise. Monitoring and alerts carry their own API.
A Chrome extension, GL-Lens, pushes wallet risk indicators onto any web page on hover, which is a distribution surface as much as an integration. ARGOS Identity, itself indexed here, describes onboarding, transaction monitoring and API work delivered alongside its identity verification service.
What is not present is any named core banking, case management or transaction monitoring platform connector, so the depth is one substantial enterprise integration plus an open API rather than a connector catalogue.
The deployment half of this axis is answered well and the residency half is answered against the buyer. On premise installation is a published, purchasable add on rather than a sales conversation, and the company states its purpose plainly: keep blockchain and operational data on the customer's own infrastructure, run unlimited requests without restriction, stay compliant with local data storage regulations, and receive regular secure updates with full database access.
Naming local data storage regulation as the reason is the useful part, because it tells a regulated buyer the option exists precisely for them. Private server deployment is referenced consistently across the product material. For the hosted default the position is the opposite of a commitment.
The privacy policy states that the company processes information on servers in many countries around the world and asks the reader to consent to processing outside their own country and outside the European Economic Area, with standard contractual clauses stated to cover transfers between group companies. No hosting provider, data centre, region or country is named anywhere across two passes. A Swiss registered company selling to European regulated institutions has the strongest possible reason to publish a residency position and has not.
The packaging is published in full and the rates are not, which is an unusual split and better than it sounds. Four tiers appear on a public pricing page with the unit of sale stated outright: KYT Essentials at 10,000 requests and one seat, KYT Advanced at 50,000 requests and three seats, All in one at 250,000 requests and five seats, and Unlimited at unlimited requests and twenty seats.
A full comparison matrix names what each tier includes down to individual modules, and six add ons are named separately, including on premise installation, additional seats, a KYT testing sandbox and a support agreement carrying a stated 99.8 percent availability guarantee. A buyer can therefore work out what they need and how consumption will scale before speaking to anyone, which is the harder half of the problem.
Every tier then routes to a Request Pricing button and no figure appears anywhere on the vendor's own material. Third party listings at SoftwareSuggest and Slashdot quote a starting point above ten thousand dollars calculated per request and training from five thousand dollars for a group of ten, dated December 2024 and not sourced to the vendor, so they are recorded as estimate rather than published rate.
Four buyer types are addressed with their own material: centralised exchanges, over the counter desks, financial institutions and law enforcement, with virtual asset service providers, regulators and blockchain startups covered alongside.
Geographic reach is stated concretely rather than asserted, with named staff and contact details published for eleven countries covering Switzerland, the United States, the United Arab Emirates, Spain, Kenya, Ukraine, Poland, Kazakhstan, Bulgaria, Serbia and Cyprus, and market entry claimed across Europe, Africa, the Middle East, the United States and Latin America.
Services extend the reach past software into asset recovery, counterparty risk and a compliance officer certification programme. The constraint is chain coverage, which is where the marketing and the disclosure diverge. Every package states all blockchains included and the comparison table lists Bitcoin, Ethereum, Tron, Binance Coin, Solana, XRP, Stellar and Toncoin among others, while the FAQ on that same page enumerates fourteen supported chains and includes neither XRP nor Stellar. The company offers to add a missing chain within two weeks, which is a real commitment and also an admission that coverage is narrower than the headline.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | Data Protection Terms | Implementation | Source |
|---|---|---|---|---|
|
Not published. Four tiers are named with quotas and seat counts but every one routes to a Request Pricing button. Third party listings estimate a starting point above ten thousand dollars calculated per request, unverified against the vendor.
|
Subscription against a request quota with a bundled seat count, published as four tiers. KYT Essentials covers 10,000 requests and one user and is positioned for over the counter desks and financial institutions wanting monitoring and risk reporting without tracing. KYT Advanced covers 50,000 requests and three users and adds the visual tracing tool, case management, auto tracing and the GL-Lens Chrome extension. All in one covers 250,000 requests and five users and adds the entity database, entity report and DeFi report. Unlimited covers unlimited requests and twenty users. Every tier states all blockchains included. Six add ons extend any tier: KYT Lab for testing rules against historical transactions without consuming quota, an investigations module, a KYB module reaching a database of more than 92,000 crypto entities, additional users, a 24 hour support agreement carrying a 99.8 percent availability guarantee, and on premise installation which removes the request limit entirely by moving the platform onto customer infrastructure. The unit of sale is therefore requests plus seats, disclosed plainly, with the on premise route breaking the metering model altogether. | No data processing addendum, subprocessor list or platform data protection terms were located across two passes. The only privacy document published is a website and marketing privacy policy carrying an effective date of 25 August 2022 and a publication date of 2 February 2023, which excludes platform data by its own opening scope. It names the Swiss Federal Data Protection and Information Commissioner as the supervisory authority and enumerates the six GDPR data subject rights with a one month response commitment, but its international transfers clause asks the reader to consent to processing on servers in many countries including outside the European Economic Area, with standard contractual clauses stated to apply only between group companies. A regulated buyer will need to negotiate platform data terms from scratch rather than review them in advance. | Not published and not disclaimed. No setup, onboarding, migration or configuration fee appears anywhere. On premise installation is sold as a named add on without a figure, and it is the one line item where an implementation cost would be expected, since it involves standing up the platform and the address database on customer infrastructure with ongoing secure updates. The compliance officer certification and training programme is a separate paid service line, estimated by a third party listing at five thousand dollars for a group of ten and carrying no published rate from the vendor. Asset recovery, counterparty risk and investigative services are sold as engagements with no rate, day rate or minimum published. | Vendor Published |
Two dedicated passes. The finding is that structure is published and price is not, which is the reverse of the usual failure in this lane and materially more useful to a buyer than a bare contact form. A prospective customer can determine the unit of sale, the consumption quota at each tier, the seat count, the exact module list per tier and the available add ons before any contact, and can therefore size the purchase and model how cost will scale with volume.
What they cannot determine is any rate. Third party listings quote a starting point above ten thousand dollars calculated per request, and training from five thousand dollars for a group of ten, appearing on SoftwareSuggest and Slashdot and dated December 2024. Those are recorded here as third party estimate and were not treated as evidence of a published rate, since neither is sourced to the vendor and the vendor publishes no figure anywhere.
Pre emptive negative finding: a reseller or review site quoting a Global Ledger figure should not move the commercial transparency grade, because the absence here is deliberate and consistent across every tier and add on rather than an oversight on one page.