Sanctuary Intelligence Team

Most wallet screening products rely on a narrow evidence view. That creates blind spots: sanctions lists cover authority designations but miss many fraud typologies, on-chain analytics can miss off-chain incident context, and community reports need governance before they become defensible evidence.
The result: a narrow screening system can return "clean" for addresses that deserve review under another evidence class. Buyers should ask how coverage limits are shown, not just how many feeds a vendor claims.
Sanctuary presents wallet checks as controlled risk verdicts built from governed evidence classes:
1. Authority and issuer records: sanctions, law-enforcement, and stablecoin issuer actions are treated as hard evidence when they match the checked wallet.
2. Entity context: service profiles help separate exchange, bridge, protocol, merchant, and user-wallet context.
3. Community and incident intelligence: scam, phishing, exploit, and ransomware reports are normalized into customer-facing risk categories.
4. Graph and behavioural evidence: on-chain relationships, exposure direction, wallet age, and repeated movement patterns add context for review.
5. OSINT intelligence: open-source incident and threat intelligence can support enhanced due diligence when it is source-governed and fresh.
The product vocabulary focuses on evidence classes, confidence posture, limitations, and decision context.
Raw source aggregation is not enough. Cross-validation is what turns multi-source data into reliable risk assessment:
1. Corroboration: When independent evidence families point to the same risk category, the review posture becomes stronger.
2. Contradiction resolution: When evidence conflicts, the system separates current authority records, historical records, weak OSINT hints, and analyst-reviewed attributions instead of flattening them into one label.
3. Coverage gap detection: If a check has limited data, the result carries lower confidence and clear degraded-coverage guidance.
4. Temporal validation: Fresh incident intelligence, historical designations, and stale community reports are not treated the same way. Recency and source governance affect confidence before a user sees the verdict.
The difference between narrow screening and governed evidence coverage shows up in daily operations:
- Stronger review posture when independent evidence classes point to the same risk category - Fewer unsupported decisions when contradictory or stale records are separated instead of flattened - Better audit answers because limitations are shown next to the verdict - Wider typology coverage across sanctions, mixers, scams, phishing, DeFi exploits, ransomware, darknet markets, restricted services, and fraud
For compliance officers, evidence governance is an audit defense. When a partner asks "how do you screen deposits?", the useful answer is not a feed count — it is a repeatable policy, evidence categories, and documented limitations.
Scam alerts, new sanctions, and investigation techniques. One email per week. Unsubscribe anytime.