Security & Compliance

Every claim has a document behind it. Our data protection, regulatory alignment, and model governance — in one place.

Blacklisted addresses

3.2M+

Whitelisted services

14.6M

Known mixers

57K+

Model governance

Public model card

Certifications & attestations

Independent audits, self-assessments, and framework alignments. Status badges reflect the current state — no claim is made beyond it.
SOC 2 Type IIProgram underway
Independent audit of our security, availability, and confidentiality controls under the AICPA Trust Services Criteria is in preparation. The report will be shared under NDA once issued.
Certified InfrastructureActive
Riskora is hosted on AWS and Supabase, whose infrastructure is certified SOC 2 Type II and ISO/IEC 27001. Provider attestation reports are available under NDA.
GDPRActive
We act as a Data Processor under Article 28. Our Data Processing Agreement, Technical and Organisational Measures, and subprocessor list are public documents.View DPA
CSA CAIQActive
Our completed Cloud Security Alliance Consensus Assessments Initiative Questionnaire (CAIQ v4) self-assessment answers the standard enterprise security questionnaire and is available on request.
OWASP ASVS · NIST CSF 2.0 · CIS v8Aligned
Our application-security and operations controls are aligned with the OWASP Application Security Verification Standard, the NIST Cybersecurity Framework 2.0, and CIS Critical Security Controls v8.
EU AI ActActive
Our scoring model is a proprietary, narrowly-scoped classifier with a documented minimal-risk self-assessment. Training data, calibration, and performance are published in our model card.View model card

Sanctions screening & regulatory alignment

Riskora is a data and analytics provider. Our screening supports the AML due-diligence obligations of VASPs and CASPs — final compliance decisions remain with your team.
    OFAC SDN screening
    Every address is checked against the U.S. Treasury OFAC Specially Designated Nationals list, updated on an ongoing basis through a dedicated update path.
    EU, UN & UK sanctions screening
    Every address is also checked against the EU Consolidated Financial Sanctions list (FSD), the UN Security Council Consolidated list, and the UK OFSI Consolidated list, updated on an ongoing basis.
    Proprietary threat-intelligence blacklist
    3.2M+ addresses aggregated from multiple intelligence sources — including Elliptic++, BABD-13, Real-CATS, JetQe, and CryptoScamDB — covering sanctioned entities, scams, ransomware, darknet markets, phishing, and other illicit categories. Continuously maintained.
    Whitelist of known services
    14.6M exchange and mining-pool wallets. Exposure to legitimate services deflates scores instead of inflating them; the blacklist always takes precedence.
    FATF Recommendation 16 (Travel Rule)
    Counterparty wallet risk data supporting Travel Rule due-diligence workflows for VASPs and CASPs.
    EU TFR (2023/1113) · AMLR (2024/1624) · MiCA (2023/1114)
    Wallet screening built for the EU framework: TFR originator and beneficiary risk assessment, the incoming AML Single Rulebook, and MiCA transaction-monitoring requirements.
How lists are maintained

Lists are refreshed on a rolling basis through a two-stage pipeline — source collection, then merge and reload — with the sanctions list on their own dedicated update path.

Mixer and coinjoin detection covers 57K+ known mixer addresses plus behavioral coinjoin heuristics, with multi-hop taint analysis across the transaction graph.

Claims on this page always reflect the currently deployed lists.

How Riskora fits your AML program

From first alert to filed evidence — one flow.
1Screen
Check any BTC address against OFAC SDN and our 3.2M+ proprietary blacklist, with 14.6M known services whitelisted out of your way.
2Score
A calibrated 0–100 risk score with documented reasons — deterministic and reproducible for the same on-chain state.
3Explain
AI-generated narratives turn the score into a case summary analysts can review and attach to alerts.
4Evidence
Every scan is stored as a reproducible audit record, shareable by link — ready for internal reviews and FIU requests.

Data protection

What we store, how we protect it, and how long we keep it.
Encryption at rest — AES-256
All stored data is encrypted at rest with 256-bit AES, managed by our database and infrastructure providers.
Encryption in transit — TLS 1.2+
Every API call and dashboard session is encrypted in transit over TLS 1.2 or higher.
Hashed API keys
API keys are shown once at creation and stored only as SHA-256 hashes. We can never recover or leak a plaintext key.
Session security
Short-lived JWT access tokens with refresh tokens in httpOnly cookies, never exposed to JavaScript.
Data minimization
Only pseudonymous wallet addresses and scan metadata are sent to our AI provider for narrative generation — never account data or user PII.
Retention & deletion
Scan records are retained as a reproducible audit trail while your account is active. Erasure requests are honored via privacy@riskora.co.

Vulnerability disclosure

We welcome good-faith security research. Report vulnerabilities to security@riskora.co — machine-readable contacts at /.well-known/security.txt.
Our commitments
  • Acknowledge your report within 72 hours
  • Provide a remediation timeline within 14 days of triage
  • Notify you when the issue is resolved
  • No legal action against good-faith research conducted within this policy
Ground rules
  • Do not access, modify, or delete data belonging to other users
  • Do not perform denial-of-service testing or degrade the service
  • Do not use social engineering against our staff or providers
  • Give us reasonable time to remediate before public disclosure

Security FAQ

The same answers we send to enterprise security teams. Anything else: security@riskora.co.

Request the Trust Pack

Every document on this page, sent the same business day. Enterprise security teams can additionally request infrastructure attestation reports under NDA.
  • Data Processing Agreement (DPA) with Annex I & II (TOMs)
  • Subprocessor list
  • CSA CAIQ v4 self-assessment
  • Infrastructure attestation reports — AWS / Supabase (under NDA)
  • Public model card with held-out performance metrics
  • Vulnerability disclosure policy and security contacts