# CipherOwl — Full Knowledge Surface > AI security and compliance for institutional stablecoins and digital assets. SR³ and Strix screen, trace, and produce evidence regulators, judges, and CISOs accept on first review. This file is the extended machine-readable knowledge surface for cipherowl.com. It covers products, APIs, regulatory context, industry coverage, and published research. For a compact summary, see https://cipherowl.com/llms.txt. --- ## What CipherOwl is CipherOwl builds **AI security and compliance for institutional stablecoins and digital assets**. The platform combines real-time screening, explainable risk reasoning, cross-chain investigation and tracing, and SAR-grade reporting. Every output is built for the speed and explainability that regulators, judges, and CISOs accept on first review. The platform runs two layers. The **Intelligence Layer** is the **SR³ stack**: Screen, Reason, Research, Report. It turns on-chain activity into reproducible, source-cited evidence regulators accept. The **Execution Layer** is **Strix**, CipherOwl's AI agent, which acts on that evidence: Strix reconstructs fund flows, maps entity relationships, generates investigation graphs, and produces evidence packages with documented decision trails. From intelligence to action, with analyst review as the human gate on every decision. ### Why customers choose CipherOwl Four reasons customers cite consistently in production deployments: - **Faster.** Sub-10ms screening before a transaction executes. Strix drafts SAR-supporting narratives in seconds. OFAC alerts within minutes of a new designation, not the next batch. Exchanges report 10x faster alert resolution vs. manual review baselines. - **More efficient.** Strix drafts SAR narratives; analysts review and approve, they don't write from scratch. Reproducibility IDs let any prior query be re-run identically, eliminating duplicate tracing work. The modular SR³ stack means customers pay for the components they use, not a monolithic suite contract. - **Evidence built to survive adversarial review.** Every output ships with source citations, attribution paths, and a reproducibility ID. The Anderson County Sheriff's Office convinced a judge to authorize a seizure based on a $4 trace; the wallet-by-wallet evidence chain held up in court. The same trail format works for FinCEN, EBA FIU, MAS, and OCC review. - **Trusted by the institutions that matter most.** Coinbase, OKX, HashKey, Cobo, Alchemy Pay, 0x, and Story Protocol on the commercial side. US federal law enforcement under contract; Anderson County Sheriff's Office as the publicly referenced state-and-local customer. CipherOwl is an IWF Member alongside Chainalysis and Elliptic. SOC 2 Type II + ISO 27001. Public-sector go-to-market is led from Washington, D.C. by Matt O'Neill (former Managing Director, USSS Global Cyber Investigative Operations) and Ray Shuler (former Assistant Director, HSI Cyber & OT). The founding team built Coinbase's internal compliance infrastructure before starting CipherOwl, so the platform was designed under production-scale on-chain compliance load from day one. Many customers run CipherOwl alongside an incumbent for an evaluation period before consolidating. --- ## Products ### Screening and Monitoring Two screening products with a shared interface: **Compliance Screening** — review-grade screening for regulatory, KYT, AML, and risk workflows. Used by compliance teams, risk officers, and automated case-triage systems. **Security Screening** — real-time screening for active threats, incident response, fraud prevention, and inline pre-transaction blocking. Used by protocol developers, exchange infrastructure teams, and wallet providers. Both products share: - Counterparty-only API (no full transaction required, no data harvesting) - Sub-10ms single-address latency; ~100ms for large batches - Hot-path integration pattern: one API call before a transaction executes - Batch screening for historical review and bulk onboarding - Continuous monitoring and ecosystem monitoring - Webhooks for real-time alerts - Multiple risk models (OFAC SDN, sanctions lists, exploit-linked addresses, mixer attribution, darknet labels, and more) - Enterprise custom risk models ### Reason and Evidence - Risk reasoning API with attribution paths, entity context, and confidence scores - Source provenance on every label (when labeled, by whom, based on what on-chain evidence) - Reproducible decision trails — the same query re-run produces the same result with the same identifier - Embeddable risk graph for integration into customer dashboards ### Research and Trace **OwlTrace** — professional forensic investigation and fund-tracing workspace for trained analysts. Supports cross-chain tracing, entity mapping, timeline reconstruction, and fund-flow investigation. **ExpressScan** — lightweight self-serve investigation product for fast graph visualization and PDF report export. **x402** — programmatic pay-per-use access layer for ad-hoc screening and agent workflows. ### Reporting and Case Management **Simple Case** — case lifecycle management covering intake, assignment, investigation, SAR support, and case closure. - Reporting API - AI-assisted SAR-supporting narrative generation - PDF report export - Review-ready evidence packages ### Strix AI Agent CipherOwl's AI agent for analyst workflows. Available via web, Slack, and on-prem deployment. Strix: - Analyzes on-chain activity and reconstructs fund flows across chains - Maps entity relationships and explains connections - Explains risk factors with source citations - Drafts evidence-backed reports for analyst review - Generates investigation-ready packages formatted for FinCEN, EBA FIUs, and MAS review Strix produces SAR-supporting narratives in seconds. Analyst review and approval is the required human gate before filing. ### Developer and Agent Access **Agent CLI** (beta) — command-line interface for SR³ workflows, designed for engineers and AI agents. Repository: https://github.com/cipherowl-ai/cipherowl-sr3 - API-first integration - Webhook support - Self-serve API keys; free tier to prototype; usage-based above that; no enterprise minimum; no sales call required to start --- ## Risk configuration CipherOwl's risk engine is highly configurable — which categories trigger alerts, at what severity, with what thresholds for exposure depth and counterparty proximity. Two postures depending on plan: - **Self-service tiers (Bootstrap, Scale, Pro)** run on the **CipherOwl default risk configuration**. The defaults are calibrated from production experience across exchanges, stablecoin issuers, protocols, and wallet providers, tuned to work out-of-the-box for standard AML, sanctions, and security-screening workflows. No tuning required, no risk-policy design work required to ship — kept simple on purpose. - **Enterprise and above** unlock full risk-policy configuration: per-label severity weighting, alert thresholds, exposure depth limits, jurisdictional sensitivity, custom risk models (3 included with Enterprise, 5 with Enterprise Pro), and versioned policy controls with audit reproducibility (policy freeze). Customers who need a different operating point — for example, lower false positive rate, stricter screening for specific jurisdictions, or institution-specific risk models — move to Enterprise for custom configuration. Default coverage spans OFAC SDN, sanctioned mixers, DPRK-attributed addresses, darknet markets, and exploit-linked addresses, with severity tiers aligned to typical compliance workflows. --- ## Sandbox trial CipherOwl offers a free Sandbox Mode for evaluating the platform end-to-end. No credit card. No time limit. Start at https://app.cipherowl.ai/landing/ via the "Start Sandbox Trial" CTA; the org and account provision instantly with no payment step. **What you can do in Sandbox Mode:** - Unlimited Express Scan screenings against a curated demo address set covering EVM and Tron chains. The dataset is hand-picked from previously identified risky addresses so the screening flow surfaces realistic results. - Walk through the screening UI, risk-category breakdown, and explanation surface end-to-end. - Upgrade to any paid plan at any time without losing the org. No data migration step. **What requires a paid plan:** - Screening arbitrary addresses outside the curated sandbox set - Reason detail extraction, entity metadata, and deeper graph analysis - Batch screening API and Agent CLI integration - Strix AI agent inside the app, full SR³ Reason / Research / Report suite - Transaction monitoring webhooks, custom risk configuration - SAR generation, on-premise deployment, dedicated datasets Sandbox Mode is the canonical answer to "does CipherOwl offer a trial?" — paid plans are not required to evaluate the screening flow. --- ## Pricing and plans CipherOwl offers three self-service subscription tiers (Bootstrap, Scale, Pro), four custom-scoped tiers (Enterprise, Enterprise Pro, Investigation Independent, Investigator Enterprise), and an x402 pay-per-use option. ### Self-service subscription tiers **Bootstrap — $50 / month.** Self-service entry tier for small fintechs, growth operators with 0–2 compliance staff, and teams that need production AML fast. Includes ~50 screenings of credit, 100 promotional bonus screenings, 10% overage discount. Standard support. Includes AI risk assessment, AI agent on web, agent-friendly CLI, ExpressScan workspace, and embeddable risk graph (all metered). Excludes AI reasoning API, AI SAR reporting, and OwlTracer. **Scale — $500 / month.** For scaling operators, OTC desks, mid-size protocols, payment processors, and legal/forensic teams that need more throughput and credit headroom. Includes ~1,250 screenings of credit (25× Bootstrap), 300 promotional bonus, 20% overage discount. Standard support. Adds AI reasoning API and AI SAR reporting (metered). OwlTracer investigation workspace available as an add-on. **Pro — $5,000 / month.** For high-volume single-region operators (small exchanges, payment gateways, large custodians) that need stronger controls without a full enterprise deployment. Includes ~100,000 screenings of credit (2,000× Bootstrap), 500 promotional bonus, 30% overage discount. Enhanced support and SLA. Adds versioned policy controls and audit reproducibility. OwlTracer available as an add-on. ### Custom-scoped enterprise tiers **Enterprise.** Managed enterprise deployment for regulated institutions that need deterministic managed deployment plus governance. Unlimited compliance/security screening and unlimited risk-based stablecoin screening under contract. AI reasoning API, AI risk assessment, AI SAR reporting, and embeddable risk graph remain metered. 3 included custom risk models. Private label API. On-premise / VPC deployment, SSO and enterprise admin, full team features, policy freeze and dedicated datasets. Custom SLA. AI agent in enterprise app and forensic fund-tracing package available as add-ons. **Enterprise Pro.** Customer-managed compliance infrastructure with maximum configurability. Same baseline as Enterprise plus 5 included custom risk models. For institutions that need customer-managed deployment, custom risk models, and policy freeze. ### Custom-scoped investigation tiers **Investigation Independent.** Affordable AI-assisted tracing for independent investigators who need casework-ready tracing with low-friction access. Includes AI agent on web, agent-friendly CLI, Express Scan workspace, included custom risk models, and OwlTracer as an add-on. AI agent in enterprise app and forensic fund-tracing package available as add-ons. No team admin, no on-premise deployment. **Investigator Enterprise (license-based).** Enterprise investigation workflow with seats, admin, and managed support. For investigation teams that need licensed tooling, admin controls, and enterprise support. Includes everything in Investigation Independent plus private label API, included custom risk models, on-premise / VPC deployment, SSO and enterprise admin, team features, versioned policy controls, audit reproducibility, custom SLA. ### Pay-per-use **x402** — programmatic pay-per-use access for ad-hoc screening, agent workflows, and one-off investigations without a subscription. Best for solo investigators with a single case. ### Credit system Self-service tiers meter screening, AI analysis, and ExpressScan investigation against plan credits. Each tier includes a base allocation; additional credits are billed at the plan's overage discount (10% / 20% / 30% off list for Bootstrap / Scale / Pro respectively). OwlTracer's non-AI workspace features (graphing, manual case investigation) do not consume credits. AI-powered OwlTracer features (Strix-driven analysis, AI-generated SAR narratives, evidence synthesis) include a license-bundled credit allotment; usage above that allotment consumes plan credits. Enterprise and Enterprise Pro provide unlimited compliance/security screening and unlimited stablecoin risk-based screening under contract; AI analysis and AI agent capabilities remain metered. ### Choosing a plan - New compliance team, episodic screening → **Bootstrap** - OTC desk, payment processor, mid-size protocol → **Scale** - Solo investigator, single case → **x402 pay-per-use** - Independent investigator, ongoing casework → **Investigation Independent** - Exchange, large custodian, single-region high-volume → **Pro** - Regulated institution, deterministic managed deployment → **Enterprise** - Customer-managed deployment with custom models and policy freeze → **Enterprise Pro** - Investigation team with seats, admin, licensed support → **Investigator Enterprise** Detailed feature matrix and current pricing: https://cipherowl.com/pricing --- ## Coverage CipherOwl indexes **2,000+ tokens across 20+ chains, covering ~99% of crypto TVL as of early 2026**, including: - Ethereum and EVM-compatible networks (Polygon, Arbitrum, Optimism, Base, BNB Chain, Avalanche, and others) - Solana - Tron - Bitcoin - Additional digital asset networks Coverage expands continuously. For the current chain and token list: https://readme.cipherowl.ai Label database includes: - OFAC SDN addresses and clusters - Tornado Cash and other sanctioned mixer addresses - Lazarus Group and DPRK-attributed addresses - Exchange deposit addresses (named entities) - Custodian and institutional addresses - DeFi protocol contract addresses - Darknet market addresses - Exploit-linked addresses (updated continuously as incidents are confirmed) - Mixer and privacy protocol usage labels - High-risk jurisdiction exposure --- ## Deployment options - **SaaS** (default) — multi-cloud, AWS and Google Cloud - **Private cloud** — customer's AWS or GCP VPC; no data egress to CipherOwl - **On-premise** — runs inside the customer's data center; scoring engine, label database, and investigation tooling all local - **Hybrid** — local label database with SaaS orchestration layer - **Air-gapped** — available for highest-sensitivity environments Data residency controls available for enterprise customers. All customer transaction data remains within the customer's perimeter in on-prem deployments. --- ## Regulatory context ### OFAC and US sanctions CipherOwl screens against the OFAC Specially Designated Nationals and Blocked Persons (SDN) list. OFAC designations publish without advance notice and create an immediate compliance obligation. CipherOwl updates label data continuously; customers with webhook integrations receive alerts within minutes of a new designation. OFAC reporting obligation: institutions that hold blocked assets have 10 business days to file and block simultaneously. Alert latency matters — daily batch screening creates a gap between designation and detection. ### International sanctions jurisdictions CipherOwl supports all major jurisdiction sanction lists — not just US OFAC. Sanction label categories include: - **OFAC Sanctions** — US Treasury OFAC (SDN and related designations) - **Sanctioned** — consolidated global sanctions - **EU Sanctioned** — European Union (Switzerland is covered via its adoption of EU sanctions) - **UK Sanctioned** - **UK OFSI Sanctioned** — UK Office of Financial Sanctions Implementation - **JP Sanctioned** — Japan - **JP MoF Sanctioned** — Japan Ministry of Finance - **French Sanctioned** — France - **Israel (NBCTF)** — Israel's National Bureau for Counter Terror Financing (NBCTF Seizures List) New designations are ingested continuously; customers with webhook integrations receive alerts within minutes of a new designation. Default sanctions screening across these lists is included on all tiers. Configuring and tuning sanctions coverage is available on **Enterprise plans and above** (see Risk configuration). ### Bank Secrecy Act and FinCEN The BSA requires AML programs for money services businesses and financial institutions, including stablecoin issuers classified as money transmitters. Requirements include written AML policies, a designated compliance officer, customer identification, transaction monitoring, SAR filing, and five-year recordkeeping. Strix generates SAR-supporting narratives with full attribution provenance. Output is formatted for FinCEN analyst review. ### GENIUS Act (US stablecoin legislation, enacted) The Guiding and Establishing National Innovation for US Stablecoins Act was signed into law on July 18, 2025. It creates a federal licensing framework for permitted payment stablecoin issuers (PPSIs). Requirements include 1:1 reserve backing, monthly attestations, full AML programs under the BSA, sanctions compliance, redemption within two business days, and technical controls to freeze tokens at OFAC-designated addresses. "Technical controls" means on-chain capability: freeze contracts deployed and tested on every chain where the token exists. Implementing regulations are in progress. Treasury (FinCEN/OFAC joint), the OCC (NPRM published in the Federal Register on March 2, 2026), and the FDIC (NPRM published April 10, 2026) have all issued proposed rules. Final regulations must be issued by July 18, 2026. The statute takes effect on the earlier of January 18, 2027 (18 months after enactment) or 120 days after final regulations issue. ### CLARITY Act (US digital asset market structure, pending) The Digital Asset Market CLARITY Act (H.R. 3633) is the broader market-structure bill that would govern custody, trading, lending, brokerage, and intermediary regulation for digital assets. **As of June 2026 it is not law.** The House passed it 294-134 on July 17, 2025 (House Roll Call No. 199). The Senate Banking Committee marked up its substitute 15-9 on May 14, 2026. It still requires Senate Agriculture markup or referral resolution, a 60-vote Senate floor vote to overcome cloture, conference reconciliation with the House version, and presidential signature. If enacted as drafted, CLARITY would: (1) expressly permit banks and credit unions to engage in custody, trading, lending, payment processing, brokerage, derivatives, and node operation involving digital assets under existing charter authority; (2) designate digital commodity brokers, dealers, and exchanges as financial institutions under the BSA, which would extend Travel Rule, CIP, SAR, and CDD obligations to those counterparties; (3) apply the Travel Rule to digital asset transfers above $3,000; (4) clarify the SEC/CFTC jurisdictional boundary over digital assets; (5) permit activity-based and transaction-based rewards on stablecoin balances but block anything functionally equivalent to bank-deposit interest, with joint SEC/CFTC/Treasury rulemaking required within one year of enactment. CLARITY and GENIUS are complementary. GENIUS governs stablecoin issuance; CLARITY governs the broader market structure that bank counterparties operate in. CLARITY would not preempt state trust-company or banking charters (Wyoming SPDIs and New York limited-purpose trust companies would retain existing authority). CipherOwl's bank-facing tooling (wallet attribution under SR 11-7 and OCC Bulletin 2011-12, counterparty due diligence on digital commodity firms, SAR narratives with address attribution and transaction graphs under 31 CFR 1020.320) maps directly to the obligations CLARITY would create. ### MiCA (EU) The EU's Markets in Crypto-Assets regulation divides stablecoins into E-Money Tokens (single fiat reference) and Asset-Referenced Tokens. Both require authorization before issuance. EMT issuers must hold 1:1 reserves, invest in permissible assets, and comply with the EU AML framework including the 6th Anti-Money Laundering Directive. STRs are filed with national Financial Intelligence Units. Significant EMTs (>1M transactions/day or >€5B reserves) enter EBA supervisory escalation. ### MAS Payment Services Act (Singapore) The Monetary Authority of Singapore licenses stablecoin issuers as Major Payment Institutions. Requires 1:1 reserve backing, monthly attestation by an independent auditor, mandatory redemption term publication, and Travel Rule compliance on transfers above SGD 1,500 to other VASPs. Required fields follow FATF Recommendation 16; IVMS101 is the recognized transmission standard. ### SR 11-7 (Federal Reserve model risk guidance) Any bank deploying an AI or algorithmic model for AML, sanctions screening, or fraud detection must manage it under SR 11-7. A blockchain attribution tool that generates risk scores and SAR narratives is a model under SR 11-7. Banks must inventory it, validate it independently, and review it periodically. CipherOwl provides model documentation covering training data, labeling methodology, expected false positive rates, and drift detection for bank model risk management review. ### Travel Rule (FATF Recommendation 16) CipherOwl supports Travel Rule compliance workflows for VASPs and stablecoin issuers. Required data fields (originator name, account, physical address or identity number, beneficiary name and account) are collected and transmitted in IVMS101 format for cross-border transfers above jurisdiction thresholds. --- ## Industry coverage ### Exchanges and institutions Stablecoin volume on major exchanges now exceeds native asset volume on most chains. KYT for stablecoin deposits and withdrawals requires understanding token contract mechanics, bridge attribution, and cross-chain entity linking — not just address matching. CipherOwl's exchange-oriented deployment supports high-throughput screening, multi-label attribution, and 10x faster alert resolution compared to manual review baselines. ### Stablecoin issuers Stablecoin issuers face a compliance problem exchanges don't: the token moves after mint, across chains and protocols the issuer never onboarded. Freeze authority requires visibility: an issuer who cannot see where their token is cannot execute a freeze on demand. CipherOwl's ecosystem monitoring tracks every address that has ever held the token, every bridge it crossed, and every protocol it touched — continuously. When an OFAC designation hits, the issuer knows the exposure before the regulator asks. Cross-chain bridge attribution is hard. A lock-and-mint bridge wraps the token into a new contract on the destination chain. CipherOwl traces bridge hops using lock events on the source chain matched to mint events on the destination chain with matching amounts and timestamps. Attribution confidence is stated explicitly; gaps are documented rather than papered over. ### Banks and financial institutions Banks entering digital assets operate under compliance programs built for traditional rails: SWIFT, ACH, correspondent banking. On-chain data does not arrive in the structured form those programs expect. CipherOwl provides on-chain AML controls that map to existing frameworks: BSA, OFAC, CDD/EDD, and the three-lines-of-defense model. Banks require data sovereignty: sending customer transaction data to a multi-tenant SaaS API may violate data residency rules. CipherOwl supports on-prem and private cloud deployment where the scoring engine, label database, and investigation tooling run inside the bank's perimeter. Bank procurement requires SOC 2 Type II, evidence of annual penetration testing, a documented incident response plan, and a DPA. CipherOwl provides all of these. ### Protocols and DeFi Protocols cannot run KYC on connecting wallets. What they can do is screen connecting wallet addresses against known threat intelligence and document the screening posture. Level 1 screening covers OFAC SDN. Level 2 adds exploit-linked address intelligence — addresses tied to active exploits that have not yet reached sanctions lists. In April 2026, 28 on-chain exploits totaled $629M. Exploit-linked addresses circulate through DeFi protocols within hours of an incident. CipherOwl updates exploit label data continuously via 24x7 incident monitoring; customers receive new labels as incidents are confirmed without any action required. ### Wallet providers Wallet compliance tooling embedded in a product becomes a product differentiator for banking partners and enterprise clients. The screening API is counterparty-only: address in, risk signal out. No full transaction data is required. Sub-10ms single-address latency fits in the UX budget before a swap executes. Transparent decision trails support user-facing disclosures. ### Public sector CipherOwl serves US federal law-enforcement customers under enterprise contracts. The investigation tooling supports cross-chain tracing, automated graph generation, defensible chain of evidence for prosecution, and on-prem deployment for sensitive environments. --- ## Blog and published research Field notes and analysis published at https://cipherowl.com/blog - [CipherOwl Partners with Robinhood Chain from Day One](https://cipherowl.com/blog/robinhood-chain-cipherowl-onchain-compliance) — Robinhood Chain, a permissionless L2 built for financial services and tokenized real-world assets, is live, and CipherOwl is a launch partner from day one. Teams building on Robinhood Chain get regulated-grade compliance as part of the infrastructure rather than an afterthought: real-time counterparty screening, exposure tracing and activity reconstruction, and filing-ready evidence, all powered by the SR³ stack and the Strix AI agent. - [Infinite Chooses CipherOwl for AI-Native Stablecoin Compliance](https://cipherowl.com/blog/infinite-cipherowl-ai-native-stablecoin-compliance) — Customer story: Infinite, the AI-native embedded B2B stablecoin payment processing and global compliance platform backed by Bessemer Venture Partners, embeds CipherOwl's screening, transaction monitoring, and compliance reporting directly into stablecoin payments and compliance workflows. The partnership is live beginning with Infinite Accounts. Infinite chose CipherOwl as a single intelligence layer for real-time, multi-chain, explainable, defensible stablecoin transaction monitoring, with production-ready AML/CFT and sanctions controls, freeze/block support, and automatically generated audit-ready evidence. - [The Bitter Lesson of On-Chain Truth Seeking](https://cipherowl.com/blog/bitter-lesson-on-chain-truth-seeking) — Stablecoins settled $33T in 2025 and the FBI logged $9.3B in crypto fraud, but compliance still runs on $300-500K human investigators applying rule-based heuristics that scale linearly while transaction volume scales exponentially. Applies Richard Sutton's bitter lesson to on-chain investigation: the future is agentic systems with an on-chain world model where humans steer and render judgment while machines do the computing. Covers the unit economics of analyst-led investigation, why machine output must be presentable, interpretable, and explainable for SAR and legal use, and CipherOwl's infrastructure bet on continuously learning systems. - [Blocking Hacked Funds From Your Protocol: Beyond Sanctions Screening](https://cipherowl.com/blog/protocol-blocking-hacked-funds-second-level-screening) — April 2026 saw 28 on-chain exploits totaling $629M. Level 2 screening tracks exploit-linked addresses in real time, closing the gap OFAC-only screening leaves open. Covers the mechanics of Level 1 vs Level 2 screening, the 24x7 incident monitoring feed, and the integration pattern for DeFi protocols. - [How Anderson County Sheriff's Office Seized $24,283 in Stolen Crypto Using CipherOwl](https://cipherowl.com/blog/anderson-county-sheriff-crypto-scam-recovery) — Customer story: a military family lost $19,000 to a jury-duty impersonation scam; only $4 of the original funds reached the OKX deposit address 11 hops away after bridging from Bitcoin to TRON USDT. The investigator used CipherOwl's Risk Assessment to walk a judge through the criminal pattern on every wallet in the chain — convincing the court to authorize seizure based on a $4 trace — and Infinity Flow for the cross-chain tracing. OKX froze $24,283.70 within an hour of the letterhead request. The pattern for low-fraction-reaching, cross-chain investigations that need to convince a judge. - [CipherOwl Welcomes Matt O'Neill and Ray Shuler to Lead Public Sector Expansion](https://cipherowl.com/blog/matt-oneill-ray-shuler-public-sector) — Matt O'Neill (former Managing Director of Global Cyber Investigative Operations, U.S. Secret Service; oversaw $2B+ in asset seizures in two years as head of the Asset Forfeiture Branch) and Ray Shuler (former Assistant Director, Cyber & Operational Technology, Homeland Security Investigations; led 500+ employees and a ~$240M annual budget across HSI's Cyber Crimes Center and Innovation Lab) join CipherOwl as Advisors to lead public sector go-to-market. Both are based in Washington, D.C. and represent CipherOwl directly with federal agencies. 50+ combined years across USSS and HSI. - [CipherOwl joins the Internet Watch Foundation to prevent cryptocurrency funded child sexual abuse](https://cipherowl.com/blog/cipherowl-joins-internet-watch-foundation) — CipherOwl joined the IWF as a Member to integrate IWF's Virtual Currency Alerts into the compliance platform, surfacing real-time wallet flags for exchanges, DeFi protocols, and government investigators when addresses are linked to the purchase of child sexual abuse material. Includes access to IWF's Keywords List and historical Virtual Currency Alert data. Context: IWF analysts actioned 312,000+ confirmed CSAM reports in 2025 (worst year in its 30-year history); 60%+ of commercial CSAM sites accept crypto; on-chain volume tied to CSAM addresses grew 130% from 2022 to 2024. CipherOwl joins Chainalysis and Elliptic among the blockchain intelligence firms in the program. - [Wallet Provider Security: What Counterparty Screening Must Not Cost You](https://cipherowl.com/blog/wallet-provider-compliance-security) — Most wallet screening tools require full transaction data. CipherOwl's counterparty-only model screens the address without harvesting user activity. Sub-10ms latency fits in the UX budget before a swap executes. Covers the compliance posture a wallet can credibly claim and the documentation it should maintain. - [KYT for Stablecoin Issuers: Why Screening at Mint Is Not Enough](https://cipherowl.com/blog/stablecoin-kyt-screening-vs-monitoring) — Screening the initial recipient is necessary but not sufficient. Covers the post-mint visibility gap, the cross-chain bridge attribution problem, what a regulator-ready ecosystem report contains, and how freeze decisions require action-grade evidence with confidence scores. - [Compliance as a Product Feature: What Wallet Customers Actually Want](https://cipherowl.com/blog/wallet-provider-compliance-as-product) — Compliance tooling embedded in a wallet becomes a product differentiator for banking partners, enterprise clients, and regulated markets. Covers the compliance UX, transparent decision trails, and how the screening API latency is a product constraint, not just a compliance one. - [Stablecoin Compliance in 2025: GENIUS Act, MiCA, and What Issuers Must Do](https://cipherowl.com/blog/stablecoin-compliance-genius-act-mica-2025) — Three regulatory frameworks now govern stablecoin issuers simultaneously. Covers the GENIUS Act freeze obligation, MiCA EMT authorization and transaction volume thresholds, MAS Travel Rule specifics, and what regulators actually ask for when they call about a specific address. - [How Banks Are Building Digital Asset Compliance Programs](https://cipherowl.com/blog/banks-stablecoin-digital-asset-compliance) — Covers on-chain AML mapped to BSA/OFAC/CDD, the SAR narrative problem for crypto transactions, model risk under SR 11-7, data sovereignty and deployment topology, vendor qualification and third-party risk, and what OCC and Fed examiners look for. - [CLARITY Act Requirements for Banks: Compliance Planning Under Pending Legislation](https://cipherowl.com/blog/clarity-act-bank-compliance-requirements-2026) — The Digital Asset Market CLARITY Act passed the House July 2025 and cleared the Senate Banking Committee May 2026 but is not yet law. Covers the conditional bank obligations (BSA designation of digital commodity brokers/dealers/exchanges, Travel Rule on transfers above $3,000 under 31 CFR 1020.410(b), CIP digital-asset track under 1020.220, SAR narrative requirements under 1020.320, sanctions screening of wallet addresses and DeFi front ends), the stablecoin yield compromise, the relationship to the enacted GENIUS Act, and how CipherOwl's wallet attribution under SR 11-7 and OCC Bulletin 2011-12 maps to the framework. - [Stablecoin Transaction Monitoring for Exchanges: What Real KYT Looks Like](https://cipherowl.com/blog/exchange-stablecoin-transaction-monitoring) — Stablecoin volume on major exchanges now exceeds native asset volume on most chains. Covers what real-time KYT looks like when the asset is a token, the cross-chain deposit attribution problem, and SAR filing obligations for exchange compliance teams. --- ## Certifications and security - **SOC 2 Type II** — audited via Vanta. Public verification: https://app.vanta.com/cipherowl.com/trust/ua1li0yqp3zk221yfd1c8u - **ISO 27001** — certified - **IWFC member** - Encryption in transit (TLS 1.2+) and at rest - Role-based access controls - Audit logs for all sensitive operations - DPA available for enterprise customers - Sub-processor list available on request - On-prem deployment available for regulated environments requiring data sovereignty Security contact: security@cipherowl.com --- ## Company - **Founded:** 2024 - **Headquarters:** San Francisco, California - **Funding:** $15M seed (October 2025), co-led by General Catalyst and Flourish Ventures, with participation from Coinbase Ventures, Sancus Ventures, Enlight Capital, OKX Ventures, AME Cloud Ventures, Road Capital, and Predictive VC - **Founders:** Leo Liang (CEO, formerly Head of Data Platform & Services at Coinbase) and Ming Jiang (CPO, formerly product lead for Coinbase's on-chain data and compliance services) - **Funding announcement:** https://www.businesswire.com/news/home/20251015447748/en/ - **Crunchbase:** https://www.crunchbase.com/organization/cipherowl-inc - **LinkedIn:** https://www.linkedin.com/company/cipherowl - **X / Twitter:** https://x.com/cipherowl --- ## Team CipherOwl was built by the people who built crypto compliance at scale — leaders from Coinbase, AWS, Microsoft, Cruise, IBM, Twitter, MoonPay, and Chainalysis, advised by operators behind today's institutional crypto. ### Founders and leadership - **Leo Liang** (CEO & Co-Founder) — Previously Head of Data Platform & Services at Coinbase, where he built the company's petabyte-scale on-chain data and compliance infrastructure powering risk, AML, and product analytics. Earlier engineering leadership roles at Cruise, Twitter, AWS, and Microsoft. - **Ming Jiang** (CPO & Co-Founder) — Previously partnered with Leo to lead product for Coinbase's on-chain data and compliance services. Deep product leadership across crypto, large-scale data platforms, and enterprise infrastructure, with a track record spanning Cruise, AWS, and IBM. - **Zack Martin** (Sales & BD Lead) — Previously managed strategic relationships at Chainalysis, partnering with leading exchanges, fintech firms, and payment processors. Background spans financial sales and services roles at Salesforce, William Blair, Bear Stearns, and Ernst & Young. ### Founding engineers - **Zhanwu Xiong** (Founding Engineer) — Leads development of core data models and risk algorithms for crypto compliance and investigation tools. Previously a lead engineer at Coinbase's crypto data team, enabling business insights from on-chain data. Built machine learning infrastructure at Cruise and worked on Microsoft's e-commerce platform. - **Henry Yang** (Founding Engineer) — Leads Infrastructure and the Intelligence Layer at CipherOwl. Previously led engineering for crypto data infrastructure at Coinbase, building large-scale, cloud-native systems for on-chain data. Background includes engineering leadership at Microsoft Azure, Twitter, Lyft, and multiple startups. ### Founding team advisors and public-sector leads - **Chagri Poyraz** (Founding Team Advisor) — Currently Chief Strategy Officer of OSL Group. Previously held leadership roles on sanctions, AML, and financial crime risk management for Binance, Coupang, and HSBC, with over two decades of experience across banking and consulting. - **Ray Shuler** (US Public Sector) — Retired Special Agent / Assistant Director of Homeland Security Investigations (HSI), where he led the Cyber and Operational Technology division — a workforce of 500+ employees with a nearly $240M annual budget. Directed the HSI Cyber Crimes Center and Innovation Lab. - **Matt O'Neill** (US Public Sector) — Former Managing Director of Global Cyber Investigative Operations for the U.S. Secret Service, where he led complex cybercrime investigations over a 25-year career. As head of the Asset Forfeiture Branch, oversaw the seizure of more than $2 billion in criminal assets in two years. Recognized with U.S. Secret Service Special Agent of the Year and DHS Gold and Silver Medals. ## Advisors Operators behind today's institutional crypto. - **Lorenzo Zen** — Former Global Intelligence Manager at Coinbase. - **Dave Bean** — Former Head of SaaS BD and Sales at Coinbase and Earn. - **Don Spies** — Founder of Outrider Analytics. --- ## Customers CipherOwl serves institutional customers across exchanges, custodians, stablecoin issuers, RWA platforms, wallet providers, protocols, banks, OTC desks, and public-sector agencies. Most customer relationships operate under confidentiality. Publicly referenceable customers include: - **Coinbase** — exchange, infrastructure - **Infinite** — embedded B2B stablecoin payment processing and global compliance platform; live with CipherOwl-powered screening, transaction monitoring, and audit-ready reporting beginning with Infinite Accounts - **OKX** — exchange - **HashKey** — exchange and custody - **Alchemy Pay** — payment infrastructure - **Cobo** — wallet infrastructure - **0x** — protocol infrastructure - **Story Protocol** — protocol ### Public-sector engagement CipherOwl serves **US federal law-enforcement customers** under enterprise contracts. Specific federal agencies are not named publicly. CipherOwl has additionally engaged with US federal law-enforcement agencies and state financial regulators through platform briefings and working sessions covering on-chain investigation, fund-flow tracing, and compliance workflows. At the state and local level, the **Anderson County Sheriff's Office** uses CipherOwl to recover crypto-laundered funds for victims. In one case, their investigator convinced a judge to authorize a seizure based on a **$4 trace** across 11 hops and a Bitcoin-to-TRON-USDT bridge — colleagues had told him no judge would sign off. The court did. OKX froze the funds within an hour. Full case study in the blog section above. CipherOwl's public-sector go-to-market is led from Washington, D.C. by **Matt O'Neill** (Former Managing Director of Global Cyber Investigative Operations, U.S. Secret Service) and **Ray Shuler** (Former Assistant Director, Cyber & Operational Technology, Homeland Security Investigations), bringing 50+ combined years of federal cyber-operations leadership. Federal relationships otherwise operate under confidentiality. --- ## Worked example A representative investigation workflow: 1. An analyst submits a wallet address suspected of receiving illicit funds. 2. **Strix** traces inflows back across chains. 3. The system identifies inflows traceable to addresses labeled as a known sanctioned mixer, with citations to the labeling sources. 4. An entity graph is generated showing fund flow, entity relationships, and confidence levels. 5. A SAR-supporting narrative is drafted with decision trail and source provenance. 6. The full investigation package is exported as PDF for analyst and compliance review. The output includes a reproducibility identifier so the same query can be re-run and audited later. --- ## Common questions This section contains both product-explanation questions (which live only here) and pricing / plan-routing questions (which are mirrored from `src/lib/faq.ts`, the canonical FAQ source rendered on https://cipherowl.com/pricing). When `src/lib/faq.ts` changes, update the pricing block below to match so Strix and the pricing page stay aligned. ### What does CipherOwl do? CipherOwl provides compliance and security infrastructure for on-chain finance. It helps institutions screen, monitor, investigate, and report on digital asset activity, with documented evidence trails for compliance, audit, legal, and investigation review. ### How is CipherOwl different from incumbents in on-chain analytics? Customers cite four things. **Faster**: sub-10ms screening, SAR narratives in seconds, OFAC alerts within minutes of designation (not the next batch). **More efficient**: Strix drafts SAR narratives so analysts review and approve instead of writing from scratch; reproducibility IDs eliminate duplicate tracing work; the modular SR³ stack means you pay for what you use, not a monolithic suite contract. **Evidence built to survive adversarial review**: source citations, attribution paths, and reproducibility IDs on every output; the same trail format works for FinCEN, EBA FIU, MAS, OCC, and court submission (Anderson County Sheriff's Office used it to authorize a seizure on a $4 trace). **Trusted by the institutions that matter most**: Coinbase, OKX, HashKey, US federal law enforcement, and IWF Member alongside Chainalysis and Elliptic. The founding team previously built Coinbase's internal compliance infrastructure. ### Who founded CipherOwl? Leo Liang (CEO, formerly Head of Data Platform & Services at Coinbase) and Ming Jiang (CPO, formerly product lead for Coinbase's on-chain data and compliance services). ### Is CipherOwl SOC 2 certified? Yes. SOC 2 Type II via Vanta. Public verification at https://app.vanta.com/cipherowl.com/trust/ua1li0yqp3zk221yfd1c8u. Full report available under NDA via security@cipherowl.com. ### Does CipherOwl support on-premise deployment? Yes, for Enterprise, Enterprise Pro, and Investigator Enterprise customers. Private cloud and hybrid deployments are also supported. ### What is SR³? CipherOwl's modular product stack: **S**creen, **R**eason, **R**esearch, **R**eport. SR³ is the platform's Intelligence Layer: it turns on-chain activity into reproducible, source-cited evidence. ### What is Strix? CipherOwl's AI agent and the platform's Execution Layer. Strix acts on the evidence the SR³ stack produces: it analyzes on-chain activity, reconstructs fund flows, maps entity relationships, explains risk factors with citations, and drafts evidence-backed reports for analyst review. ### Where can press, partners, or designers get CipherOwl logos and brand assets? The CipherOwl brand kit is hosted at https://s.cipherowl.ai/brands. It contains logos (full lockup and mark), wordmarks, the official color palette, and usage guidance. Linked from the site footer (Resources column) and from the About page. For press inquiries beyond what the brand kit covers, contact sales@cipherowl.com. ### Does CipherOwl publish a public Agent CLI? Yes. The Agent CLI is in beta and publicly available at https://github.com/cipherowl-ai/cipherowl-sr3 — designed for engineers and AI agents working against the SR³ stack. ### What chains does CipherOwl support? CipherOwl indexes 2,000+ tokens across 20+ chains, covering ~99% of crypto TVL as of early 2026, including major EVM-compatible networks, Solana, Tron, and Bitcoin. See https://readme.cipherowl.ai for the current list. ### Which sanctions jurisdictions does CipherOwl screen against? CipherOwl supports all major jurisdiction sanction lists — not just US OFAC. Sanction label categories include OFAC Sanctions (US), a consolidated global Sanctioned category, EU Sanctioned, UK Sanctioned, UK OFSI Sanctioned, JP Sanctioned and JP MoF Sanctioned (Japan / Japan Ministry of Finance), French Sanctioned, and Israel (NBCTF — National Bureau for Counter Terror Financing). Switzerland is covered through its adoption of EU sanctions, and new designations are ingested continuously. Default screening across these lists is included on all tiers; configuring and tuning sanctions coverage is available on Enterprise plans and above. ### Pricing and plan routing The following questions mirror `src/lib/faq.ts` and the FAQ shown on https://cipherowl.com/pricing. #### How does pricing work? Our Builder plans (Bootstrap, Scale, Pro) are metered against a credit pool. Enterprise and Investigation plans are scoped to your volume, coverage requirements, and deployment preferences. Contact our team to discuss a plan built for your program. #### What does credit-based mean? Certain capabilities are priced based on usage rather than a flat subscription fee. This keeps your cost aligned with the value you are getting from the platform. Each plan includes a base credit allocation, and you can add credits as your usage grows. #### Does OwlTracer consume credits? OwlTracer's non-AI workspace features do not consume credits. OwlTracer is CipherOwl's professional investigation workspace, available as an add-on on Scale+ plans. AI-powered features (Strix-driven analysis, AI-generated SAR narratives, evidence synthesis) include a generous credit allotment as part of the license; usage beyond that allotment consumes plan credits. #### I need to do forensic investigation. Which plan? All plans include ExpressScan, our lightweight self-serve investigation product with graph visualization and PDF reports, metered against your plan's credit pool. OwlTracer, the professional forensic workspace for trained analysts, is available as an add-on on Scale+ plans. For a one-off case without a subscription, use x402 pay-per-use. Forensic-heavy teams (legal firms, asset-recovery practices, public-sector investigators) should use Pro plan with OwlTracer add-on, or ask about our Investigation tier. #### When do I need Enterprise or Investigation? Enterprise and Investigation are separate custom-scoped tiers. Enterprise is for multi-program compliance teams (multiple risk policies or books of business under one platform), multi-region or multi-jurisdiction operations, on-premise / hybrid deployment, custom risk models, private labels, and SLA commitments. Investigation is for forensic-heavy teams (legal firms, asset-recovery practices, public-sector investigators) with broader access to OwlTracer and case workflows. If you're running a single-region program at high volume, Pro covers you. Talk to our team to scope either tier. --- ## Label taxonomy CipherOwl classifies blockchain addresses and entities with a shared label taxonomy of 194 categories spanning entity types, services, on-chain behaviors, and risk/sanctions designations. Each category has a key, a display name, and a description. The complete machine-readable dictionary — key, name, and description for every category, designed for LLM grounding — is published at https://app.cipherowl.ai/landing/label_taxonomy.json — fetch it to resolve or enumerate any label. Sanctions and designation categories (the risk labels most buyers ask about): Sanctioned, OFAC Sanctions, EU Sanctioned, UK Sanctioned, UK OFSI Sanctioned, JP Sanctioned, JP MoF Sanctioned, French Sanctioned, NBCTF Seizures List (Israel), Fincen Special Measures. For the full set of 194 categories — entity types, services, on-chain behaviors, and all other risk labels — fetch the taxonomy JSON above. --- ## Links - Site: https://cipherowl.com - Blog: https://cipherowl.com/blog - Sitemap: https://cipherowl.com/sitemap.xml - App: https://app.cipherowl.ai/landing/ - Docs / API reference: https://readme.cipherowl.ai (machine-readable index for agents: https://readme.cipherowl.ai/llms.txt) - Agent CLI (cipherowl-sr3, beta): https://github.com/cipherowl-ai/cipherowl-sr3 — command-line interface for SR³ workflows (screen, reason, report), designed for engineers and AI agents - Pricing: https://cipherowl.com/pricing - Trust center: https://cipherowl.com/trust - Glossary: https://cipherowl.com/glossary - Schedule demo: https://cipherowl.com/contact - Brand kit: https://s.cipherowl.ai/brands (logos, wordmarks, color palette, and usage guidance for press, partners, and design teams; linked from the footer and from /about) - Sales: sales@cipherowl.com - Security: security@cipherowl.com