Every verdict
shows its work.
Enterprise AML tools hand you a score and ask you to trust it. A regulator won't accept “the vendor said so”. So every Helix signal carries its source, its weight, and a link — the evidence you'd put in an audit file.
Sanctions lists are re-ingested daily. Freshness is the moat, so we make it inspectable — these numbers are live.
OFAC SDN · EU CFSP · UN Security Council · UK OFSI sanctions lists, plus Chainabuse scam reports and Helix-curated mixer / verified-DEX labels. (Live counts load when the API is reachable.)
Direct hit short-circuits everything
If the address itself is on a sanctions list, the verdict is CRITICAL and pinned to 100 — no heuristic can talk it down. Sanctions are strict liability; we treat them that way.
Counterparty exposure is weighted, not binary
One hop out, each labeled counterparty contributes a weight adjusted for volume, recency, and concentration. A wallet that sent 300 ETH to a mixer last week scores higher than one that touched it once, years ago. The multipliers are printed in the evidence.
Behavioral patterns are flagged for review, not auto-blocked
Consolidator, sweeper, peel-chain, MEV and fresh-funded patterns each add a bounded signal. Some legitimate businesses look like this — so these raise a verdict for an analyst to confirm, they don't silently block.
Verified contracts pull the score down
Known DEX routers and verified DeFi carry negative weight, so routine on-chain activity doesn't read as risk. False positives cost a compliance team as much as false negatives.
Ethereum and Tron mainnet today — Tron because USDT-TRC20 is the single largest sanctions-evasion rail and most enterprise tools under-serve it. Bitcoin and major L2s are on the roadmap. If a chain isn't supported, we tell you at screen time rather than returning a misleading “clean”.