N

Nominis

Nominis argues that the established blockchain analytics firms were built for law enforcement and forensic casework, and that virtual asset service providers inherited tools shaped for a different job, carrying complexity, cost and integration timelines they did not need. Its answer is a platform combining wallet screening, know your transaction monitoring and forensic investigation, with a custom risk policy builder so an institution writes its own logic rather than accepting the vendor's.

The technical claim is multi dimensional data rather than volume alone. Where most competitors reason from the chain, Nominis fuses on chain activity with off chain intelligence drawn from the open, deep and dark web, behavioural analytics and geo location signals, arguing that legacy tools miss the dark web mention, the leaked credential or the behavioural break that would have made a call obvious. Coverage spans more than 70 blockchains and over a billion clustered wallets, with more than 100,000 new wallets scanned daily and screening responses stated under 500 milliseconds so a risky flow can be blocked before settlement rather than flagged afterwards.

Its distinguishing asset is a curated attribution database of wallets linked to terror financing, which the company describes as the largest known, covering state sponsored actors, proxy entities, facilitators and brokers. That focus is reflected in its published research, including joint work with a national security think tank tracing how networks converted smuggled gold into crypto and moved the proceeds through apparently innocent wallets.

Buyers are named by category rather than by name, spanning exchanges, payment gateways, custodial services, decentralised finance protocols, banks, payment processors and law enforcement agencies. The company states it has exclusively flagged 10 billion dollars in illicit crypto and reports an 80 percent reduction in investigation and decision time.

Operating as Xplorisk Ltd, Nominis was founded in June 2023 by Snir Levi in Tel Aviv, with seed backing from Hyperwise Ventures and an innovation lab jointly run by a global card network, whose accelerator programme it has also joined.

Last VerifiedAugust 25, 2026
Compare Nominis with other vendors
Founded
2023
Headquarters
Tel Aviv, Israel
Website
www.nominis.io
Categories
crypto-and-digital-assets, aml-kyc-financial-crime
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 2 graded A or B

AI Capability
AI Centrality
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a rules or workflow system.
Vendor Published

The load bearing work here is inference rather than lookup, which places it above most of this lane. Clustering more than a billion wallets into entities is an attribution problem solved by learned heuristics rather than by a register, and scanning more than 100,000 new wallets daily means that attribution is continuously recomputed rather than curated by hand.

The stated fusion of on chain activity with off chain intelligence from open, deep and dark web sources, behavioural analytics and geo location is a multi modal inference problem, and the company's own framing depends on it, since detecting a behavioural break that legacy tools miss is by definition a model judgement rather than a rule. References to supporting more explainable compliance decisions imply outputs that require explanation. Two things hold it out of the top band.

The flagship differentiator, the terror financing attribution database, is a curated dataset rather than a model. And across two passes nothing published names a technique, architecture or learned component anywhere.

Autonomy and Oversight Model
BB on Autonomy and Oversight ModelA written commitment that the models work alongside human judgment, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

The institution writes the logic and the workflow is built around an investigator. A custom risk policy builder lets each firm design rules reflecting its own risk profile and jurisdiction rather than inheriting the vendor's thresholds, which places the substantive decisions with the customer, and the company presents that configurability as a central differentiator rather than an advanced option.

The investigative surface reinforces it, with tools for mapping fund trails, inspecting complex flows through mixers and bridges and supporting regulator queries, all of which describe a person examining evidence. Stated emphasis on explainable compliance decisions implies outputs a human is expected to interrogate rather than accept. What is not published is a boundary.

Real time blocking of risky flows before settlement is offered, which is machine action on money movement, and nothing states what threshold governs it, whether any category of block requires review, or what a wrongly blocked counterparty is told.

Model Risk Management and Transparency
CC on Model Risk Management and TransparencyTransparency is claimed in general terms with no mechanism a model validator could interrogate.
Vendor Published

Volume and speed are quantified, accuracy is not. Published figures describe throughput and coverage rather than performance: more than 70 blockchains, over a billion clustered wallets, more than 100,000 new wallets scanned daily, screening responses under 500 milliseconds, and an 80 percent reduction in investigation and decision time. Those tell a buyer the platform is fast and broad, not that it is right.

The one competitive performance claim, that the company has exclusively flagged 10 billion dollars in illicit crypto, asserts detection that named competitors missed, which is a strong assertion carrying no methodology, no sample, no definition of exclusivity and no way to verify.

Across two passes no false positive rate, no attribution accuracy measure, no recall against a known illicit set, no validation methodology and no drift or coverage change disclosure was located, which matters for a product whose clustering is recomputed continuously as new services appear.

Operational and Outcome Evidence
CC on Operational and Outcome EvidenceUnnamed case studies, customer logos, or claims without numbers. Prestige is not measurement: the calibre of the client list describes the buyer rather than the product, and coverage statistics are not adoption statistics.
Vendor Published

Genuine institutional corroboration of capability, and no customer evidence at all. The corroboration is unusual and checkable: the company publishes joint research with a national security think tank tracing how a designated network converted smuggled gold into cryptocurrency and moved the proceeds through apparently innocent wallets, which is original investigative work validated by an institution with no commercial interest in the platform.

Backing from an innovation lab jointly operated by a global card network, participation in that network's accelerator, and recognition from a national innovation authority add further external assessment of the business. Against that, across two passes no customer is named anywhere, no customer count is published, and the claim of being trusted by law enforcement agencies identifies no agency.

The published figures are vendor stated and mostly volumetric: 10 billion dollars in illicit crypto exclusively flagged, more than a billion clustered wallets, 100,000 new wallets daily, an 80 percent reduction in investigation time. The company was founded in June 2023 and employs on the order of ten to fifty people.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

One genuine public interest contribution and no safety documentation. The contribution is the published research with a national security institute, which puts investigative findings into the public domain rather than reserving them for customers, and the company's stated emphasis on explainable compliance decisions points in the right direction on interpretability. Beyond that the record is empty.

Across two passes no model card, evaluation methodology, red team result, incident disclosure or acceptable use boundary was located. The acceptable use gap is the notable one here rather than a routine omission, because the same platform is sold to commercial compliance teams and to law enforcement agencies, and a proprietary attribution database identifying state sponsored actors, proxy entities and facilitators is dual use by construction. Nothing published describes what uses the company declines, how it handles requests from state actors, or what separates a commercial screening deployment from an investigative targeting one.

Regulatory and Compliance
GLBA and Data Privacy Posture
CC on GLBA and Data Privacy PostureA standard privacy policy that covers the website rather than the service, or silence on a product that touches limited consumer data.
Vendor Published

Nothing is published, and the architecture makes that absence weigh more than it would at a chain only analytics vendor. Across two passes no privacy policy content, data processing description, retention schedule or subprocessor list was located. The specific exposure follows from the product's central claim. Analysing the public ledger involves data that is by definition public.

This platform goes deliberately further, fusing on chain activity with intelligence gathered from open, deep and dark web sources, behavioural signals and geo location, in order to link pseudonymous addresses to real world identity and place. That is assembly of profiles about people from material they never published and cannot see, sourced in part from criminal marketplaces and breach data, and applied to decisions that block their transactions. Nothing published describes what off chain material is retained, how long, how it is verified before it affects a score, or what rights a profiled individual has.

Security Certifications and Trust Center
DD on Security Certifications and Trust CenterNothing published at all on security posture.
Vendor Published

Nothing was located. Across two passes no certification, attestation report, trust centre, security page, penetration test summary, subprocessor list or security contact appears on any surface, and no framework is named anywhere in the published material. This is complete absence rather than thin or stale disclosure.

The mitigating inference available at larger vendors does not apply, because it depends on named supervised customers having run third party assessments, and this company names no customer at all. Its association with an innovation lab operated by a global card network and participation in that network's accelerator do involve external diligence, but that is commercial and product assessment rather than an information security examination, and neither is presented as the latter. The gap matters in proportion to what the platform holds, which includes off chain intelligence and behavioural profiles linking wallet addresses to identifiable people.

Regulatory Status and Licensure
CC on Regulatory Status and LicensureThe regulatory position is unstated. Most vendors in this index are technology suppliers and being unlicensed is the correct posture, so this grade records silence about the posture, not a missing licence.
Vendor Published

An unregulated supplier with unusually specific regulatory literacy for its size. Published material engages named regimes rather than gesturing at compliance: the Australian regulator's 2026 crypto anti money laundering framework and what it changes for monitoring, New York state supervisory guidance and its virtual currency licence, the international standard setter's travel rule recommendation, and European requirements, each addressed with practical guidance rather than a mention.

For a company founded in 2023 with a small team, that depth of jurisdictional coverage is real work. It confers no standing. The company holds no authorisation and claims none, and across two passes no supervisory examination outcome, regulatory review or accreditation was located. Its position inside an innovation lab jointly operated by a global card network is commercial sponsorship rather than regulatory recognition. No position on the European artificial intelligence regulation was located, despite the platform producing risk determinations about identifiable people.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

This platform makes the most consequential determination in the crypto lane and publishes nothing about how it is governed. The flagship asset is a curated database attributing wallets to terror financing, covering state sponsored actors, proxy entities, facilitators and brokers, assembled partly from open, deep and dark web sources, and applied to block transactions before settlement.

Being wrongly included carries consequences well beyond a declined deposit, since a terror financing attribution can mean funds frozen, an account closed and a report filed to authorities, and the subject is never notified and is not the vendor's customer. Two governance questions follow and neither is addressed. What evidentiary standard admits an entity to the database, who reviews additions, and how is an error corrected.

And how are jurisdictional differences handled, given that designations of who constitutes a terror financier differ between governments, so an attribution reflecting one jurisdiction's view is applied to customers operating under others. Across two passes no methodology, review process, accuracy measure, appeal route or fairness analysis was located.

AI Liability and Recourse
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.
Vendor Published

No commercial instrument is published and the third party exposure is the starkest in this lane. Across two passes no terms of service, master agreement, warranty, indemnity, liability cap or service level was located, and nothing states what a customer is owed if a screening result proves wrong in either direction. The uncovered party is not the customer.

Someone wrongly attributed in a terror financing database, or wrongly clustered into an entity through an attribution error, has no relationship with this company, receives no notice, and has no published route to correction, while the consequence they experience is a blocked transaction, a frozen balance or a report to authorities.

The company's own model makes this concrete, since it markets blocking risky flows before settlement, which means the affected party learns only that a transfer failed. No appeal process, correction procedure or contact route for a mis attributed subject was located.

Integration and Deployment
Model Supply Chain Disclosure
CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

The categories of input are disclosed more candidly than most competitors manage, and no supplier is identified. On the candour side, the company states plainly that its determinations draw on off chain intelligence from open, deep and dark web sources alongside behavioural analytics and geo location, and admitting that dark web material feeds a compliance score is disclosure many vendors would prefer to leave implicit.

The terror financing attribution database is presented as proprietary and curated in house, so a buyer knows the differentiating asset is owned rather than licensed. What is absent is specificity of a kind that matters here more than usual. Deep and dark web is a description of where material comes from, not who supplies it or how it is verified, and the reliability of intelligence sourced from criminal marketplaces and breach dumps depends entirely on that. No data supplier, intelligence partner, technique or model provider is named anywhere.

Core Systems and Integration Depth
CC on Core Systems and Integration DepthIntegration claimed through standards or connectors with no system named and nothing to verify.
Vendor Published

Integration is a stated differentiator with nothing published to inspect. The company positions itself explicitly against competitors whose integration timelines run in quarters rather than days, offers both a secure interface and a visual dashboard so a firm can adopt either as a screen or as an embedded check, and describes embedding transaction checks into smart contract flows and running them before settlement rather than after.

The stated response time under 500 milliseconds is a genuine integration relevant specification, since a check that fast can sit inline in a deposit or withdrawal path without the user waiting. Chain coverage above 70 networks with dedicated material per asset means a buyer can check whether their own mix is supported. What is missing is anything an engineer can evaluate before contact.

Across two passes no public interface documentation, developer portal, sandbox or code repository was located, and no exchange, custody platform, wallet provider or compliance system is named as a supported integration.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

A hosted service with the placement questions unaddressed, in a company whose data footprint makes them pointed. Across two passes no hosting provider, region list, tenancy description or residency commitment was located, and no customer hosted option is described. Two factors sharpen the question.

The platform accumulates off chain intelligence, behavioural profiles and geo location signals about identifiable people alongside chain data, so what rests with the vendor is materially more sensitive than a ledger index. And the company is Israeli incorporated and headquartered while selling to virtual asset service providers under Australian, New York state and European supervision, several of which impose expectations on where regulated data is processed and which authorities may compel access to it. A regulated buyer would need those answers before onboarding and none is discoverable publicly.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

Pricing accessibility is a published argument and the price is not published, which is a tension worth naming. The company's competitive case rests partly on commercial terms: it criticises established providers for quoting enterprise contracts to virtual asset service providers before those firms have enterprise revenue, and for integration timelines that run in quarters rather than days, positioning itself as the accessible alternative for fast growing crypto businesses.

Having made cost and accessibility the differentiator, it publishes no rate, unit, tier or contract term anywhere across two passes, so a buyer cannot verify the claim that this will be cheaper or check the shape of the commitment before entering a sales process. The estate spans wallet screening, transaction monitoring, forensic investigation and a policy builder, which could plausibly be charged by screened addresses, monitored transactions, seats or subscription, and nothing narrows it. The published entry route is a demonstration request.

Institution and Segment Coverage
CC on Institution and Segment CoverageSegments claimed broadly, banks, fintechs, credit unions, without evidence any of them has its own maintained surface.
Vendor Published

Buyer types named by category across a genuinely wide span, with nobody named inside any of them. The stated clientele reaches beyond crypto native firms to banks, payment processors and law enforcement agencies, alongside exchanges, payment gateways, custodial services and decentralised finance protocols, and the company addresses both operational compliance and investigative casework as distinct jobs.

Chain coverage is the strongest concrete dimension, at more than 70 blockchains with dedicated material for individual assets rather than a single generic page. Regulatory coverage is similarly specific, engaging the Australian regulator's 2026 crypto rules, New York state guidance and its licensing regime, and the international travel rule standard, which indicates real jurisdictional breadth.

What is missing is evidence: no institution is named in any segment, no customer count is published, and the company is small and recently founded, so the breadth described is addressable market rather than demonstrated footprint.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis Data Protection Terms Implementation Source
Not published. No price, unit of billing, tier or contract term appears on any vendor surface
Not published on any vendor surface. The estate covers wallet screening, real time transaction monitoring, forensic investigation tooling and a custom risk policy builder, delivered through an interface and a dashboard across more than 70 blockchains, with no published indication of whether charging follows screened addresses, monitored transactions, chains enabled, seats, investigations or a platform subscription. The company's positioning toward fast growing crypto businesses that cannot absorb enterprise contracts implies a lower entry commitment than established competitors without stating one, and the published entry route is a demonstration request. No tiered data protection terms are published, and across two passes no privacy policy content, data processing agreement, retention schedule, subprocessor list, hosting location or security credential was located on any surface. The platform accumulates off chain intelligence gathered from open, deep and dark web sources, behavioural profiles and geo location signals linking pseudonymous addresses to identifiable people, alongside a proprietary attribution database, and nothing published describes what is retained, for how long, how it is verified before affecting a determination, or what rights a profiled subject holds. No implementation, integration or professional services fee is published. Integration speed is nonetheless central to the company's positioning, since it presents fast deployment as the answer to competitors whose timelines it characterises as running in quarters rather than days, and the product design supports that claim in principle through an interface first architecture, an alternative visual dashboard requiring no engineering work, and a stated screening response under 500 milliseconds allowing inline placement in a deposit or withdrawal path. A custom risk policy builder is presented as configurable by the compliance team rather than requiring vendor services, which if accurate removes a recurring cost most platforms in this category charge for. None of that is quantified: no implementation timeline, onboarding scope, trial, sandbox or public documentation was located across two passes, so a buyer cannot scope the work independently. Vendor Published

Two passes across the company's site, its product and insight pages, its per chain material and third party directories produced no rate, unit or tier. The absence is more notable here than at a typical enterprise vendor because commercial accessibility is part of the company's published argument: it criticises established providers for quoting enterprise contracts to virtual asset service providers before those firms have enterprise revenue, and contrasts its own approach with integration timelines running in quarters.

A vendor making affordability and speed its differentiator, then publishing neither a price nor an implementation term, leaves a buyer unable to test either claim before entering a sales process. Two further unknowns matter for this estate. Nothing indicates whether investigation and forensic tooling is licensed separately from operational screening, which are different jobs bought by different teams. And nothing states whether access to the terror financing attribution database, the stated differentiator, is included or separately licensed.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746