generated: '2026-08-27' method: probed source: >- live probes of the Chainalysis API estate + https://www.chainalysis.com/legal/ + https://trust.chainalysis.com/ description: >- Cross-cutting and domain-standard conformance assertions for Chainalysis. Every entry is backed by an observation on a live host or a published Chainalysis document. Where the evidence is gated, the entry records `conforms: unknown` rather than guessing. standards: - id: oauth2 name: OAuth 2.0 conforms: false evidence: >- No oauth2 security scheme, no authorization or token endpoint, and no /.well-known/oauth-authorization-server on any host (404 on www.chainalysis.com; SPA shell on reactor.chainalysis.com). All surfaces use a static API key header. - id: oidc name: OpenID Connect conforms: false evidence: No /.well-known/openid-configuration served on any Chainalysis host. - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false evidence: >- No endpoint returns application/problem+json. Three proprietary JSON error envelopes are in production. See errors/chainalysis-problem-types.yml. - id: rfc9116 name: RFC 9116 security.txt conforms: false evidence: >- No /.well-known/security.txt on any host, despite a published vulnerability disclosure policy at https://www.chainalysis.com/vulnerability-disclosure-policy/. - id: rfc8594 name: RFC 8594 Sunset HTTP Header conforms: false evidence: >- No Sunset or Deprecation header observed. The Entities sunset is signalled with a 410 Gone plus a plaintext migration pointer instead. - id: rfc8615 name: RFC 8615 Well-Known URIs conforms: false evidence: No /.well-known document served on any host. - id: openapi name: OpenAPI conforms: unknown evidence: >- An OpenAPI document exists but is auth-gated: developers.chainalysis.com/openapi.json returns HTTP 401 {"error":"Unauthorized"}. Its version and content cannot be assessed anonymously. - id: asyncapi name: AsyncAPI conforms: false evidence: No AsyncAPI document or anonymously readable event catalog found. - id: mcp name: Model Context Protocol conforms: false evidence: >- No first-party MCP server. mcp.chainalysis.com does not resolve; api.chainalysis.com/mcp returns 410; www.chainalysis.com/mcp returns 404. Third-party Chainalysis-branded MCP servers exist on public registries but are not published by Chainalysis. - id: a2a name: A2A Agent Card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json return 404 on www.chainalysis.com and 404 on reactor.chainalysis.com. - id: idempotency name: Idempotent write semantics conforms: unknown evidence: >- KYT is a write API but no Idempotency-Key header or replay guarantee is publicly documented; the reference is behind the customer login. - id: pagination name: Documented pagination conforms: unknown evidence: Not observable without a credential; reference is gated. - id: tls name: TLS 1.3 + HSTS conforms: true evidence: >- TLSv1.3 with HSTS max-age 31622400 on www.chainalysis.com and go.chainalysis.com. See security/chainalysis-domain-security.yml. - id: dmarc name: DMARC enforcement conforms: true evidence: chainalysis.com publishes DMARC with policy p=reject, plus SPF and CAA records. - id: dnssec name: DNSSEC conforms: false evidence: chainalysis.com is not DNSSEC-signed. domain_standards: note: >- REWARD-ONLY. Chainalysis operates in crypto-asset AML/sanctions compliance. The domain standards that matter in this market are the FATF Travel Rule messaging standards (IVMS101, TRP, OpenVASP), sanctions-list identifier schemes (OFAC SDN), and ISO 20022 for fiat-rail interoperability. NONE of these could be confirmed as declared BY THE CONTRACT, because the contract is not anonymously readable - so none is asserted. candidates: - id: ofac-sdn name: OFAC Specially Designated Nationals list declared_in_contract: unknown conforms: unknown evidence: >- Chainalysis's free sanctions screening product is explicitly built on OFAC, EU and UN sanctions designations, and its blog documents SDN entries with identified crypto addresses in detail. That is a PRODUCT claim on a marketing/editorial surface, not a schema declaration in a machine-readable contract, so it does not satisfy domain_standard_conformance as defined. Confirming whether the API returns a structured OFAC identifier (e.g. an SDN entity id) would require an authenticated read of the gated reference. - id: ivms101 name: IVMS101 (interVASP Messaging Standard, FATF Travel Rule) declared_in_contract: unknown conforms: unknown evidence: >- No IVMS101 schema reference found on any anonymously readable Chainalysis surface. Chainalysis is not primarily a Travel Rule messaging vendor; it supplies the risk and attribution data such systems consume. - id: iso20022 name: ISO 20022 declared_in_contract: false conforms: false evidence: No ISO 20022 message type referenced on any readable surface. asserted: [] asserted_note: >- No domain standard is asserted. The market has real standards, but Chainalysis does not declare one in a contract we can read, and inventing a conformance to fill the slot is forbidden. compliance_program: published: true basis: >- Chainalysis publishes a maintained sub-processor list, a Data Processing Addendum, regional privacy disclosures (EEA/UK, California), an Acceptable Use Policy, a Global Code of Business Conduct, a Transfer Impact Assessment white paper, and operates a Vanta Trust Center at trust.chainalysis.com (HTTP 200). certifications_verified: [] note: >- The Compliance pointer in apis.yml is backed by the published DPA / sub-processor / privacy document set and the live trust center - NOT by any verified certification. No SOC 2 or ISO 27001 attestation was readable anonymously. See security/chainalysis-trust-center.yml.