KLOOM
Book a demo
PLATFORM
Morphic Identity EngineImmutable Evidence APIPoint-in-Time InvestigationsAgent Identity Layer
SOLUTIONS — BY INDUSTRY
National Security & IntelFinancial Intelligence & BankingCrypto & Web3 Compliance
BY MISSION
Sanctions & SDN ScreeningAdverse Media MonitoringOSINT Subject ResolutionContinuous Due Diligence & KYC
COMPANY
CareersContact
Book a demo
Solutions / Crypto & Web3 Compliance
By industry

Tie on-chain activity to off-chain identity.

Resolve pseudonymous handles, exchange-disclosed KYC names, and conflicting attribution sources to a single evidence-backed cluster — and feed the result, with its citable basis, directly into your transaction-monitoring pipeline.

Book a technical walkthrough
transaction attribution · graph v1.8.2
TRANSACTION
0x7f3a…8b2c 0x4e9d…1a7f 42.7 BTC
COUNTERPARTY ATTRIBUTION — 4 SOURCES
Alexei Morozov Latin KYC disclosure
attr. 0.88
Morozov_A Latin exchange handle
attr. 0.82
А. Морозов Cyrillic adverse media
attr. 0.74
alexm1992 Latin on-chain label
attr. 0.61
RESOLVED CLUSTER
Alexei Morozov
PERSON · 4 attributions · 18 mentions
conf.0.77
likely
SDN MATCH · confidence 0.77 · coherence: likely
blocking evidence: OFAC SDN #SDN-03421
01 · Where incumbent stacks break

Pseudonymous is not anonymous.
But treating it like one source is wrong.

Crypto compliance operates on partial information, contested attribution, and adversarial naming. Three failure modes compound in practice.

01

Attribution is contested by design

No canonical source controls who owns an address. Multiple analytics firms disagree. Exchange KYC names conflict with on-chain labels. The question isn’t which attribution has the highest score — it’s which attribution’s evidence disqualifies the others.

owner: disputed // sources: 4 // agreement: 0
02

Adversarial handle variation

"Morozov_A", "А. Морозов", "alexm1992". Possibly the same entity across two scripts and a pseudonym. Traditional string matching returns zero cross-script candidates. Translation at index time introduces ambiguity rather than resolving it.

"А. Морозов" → 0 results (script mismatch)
03

Flagged transactions with no citable basis

A transaction-monitoring system flags an address. The alert contains a score and a verdict. No source, no passage, no evidence. The analyst cannot assess the flag. The customer cannot dispute it. The regulator cannot audit it.

alert: "SDN_MATCH" // evidence: null
02 · What Kloom provides

Four capabilities.
From attribution to adjudication.

Handle & name resolution across scripts

Latin, Cyrillic, Arabic, CJK and more — original-script storage, transliteration, nickname, and spelling-variant tolerance. Resolve "Morozov_A", "А. Морозов", and "Alexei Morozov" as candidates for the same entity — with confidence and coherence reported independently, without normalising at index time.

Latin, Cyrillic, Arabic, CJK + spelling & transliteration tolerance cross-script retrieval

Cluster-level uncertainty for contested attribution

When analytics firms disagree on a wallet’s owner, Kloom holds the disagreement as structured uncertainty rather than forcing a verdict. Confidence (numeric) reports how strongly the evidence supports the merge; coherence (qualitative: certain / likely / possible / unlikely / excluded) reports the resulting epistemic state; blocking_evidence carries the specific conflicts when a merge is contested. Three signals, not one collapsed verdict.

structured uncertainty confidence + coherence blocking_evidence surfaced

Standing queries into transaction monitoring

Register a standing query against a counterparty cluster at onboarding. When the underlying graph evolves — new sanctions designations, new adverse-media mentions, new attribution signals — the query re-evaluates automatically and fires into your monitoring pipeline.

standing queries alert-on-change tx monitoring feed

Evidence-backed transaction flags

Every flagged transaction comes with the citable mentions that produced the flag — source, passage, confidence, and the per-component scores. An analyst can assess it. A customer can dispute it. A regulator can audit it.

citable evidence per flag per-mention provenance auditable
03 · Transaction monitoring

An alert that ships with its evidence.

A standing query registered at onboarding re-evaluates automatically as the underlying graph evolves — new sanctions designations, new adverse-media mentions, new attribution signals from analytics providers.

When a transaction fires against a cluster that has crossed the confidence threshold, the alert carries the full evidence payload. Not just a score — the sources, passages, and per-component breakdown an analyst needs to act.

differentiation

"A flagged transaction comes with the citable basis for the flag — not a score the analyst has to trust blindly."

Day 0 · 14:03 registered

Attribution cluster created

Wallet 0x7f3a…8b2c submitted during customer onboarding. Four attribution sources ingested. Cluster confidence: 0.54 · coherence: possible — below alert threshold. Standing query #CRY-8821 registered against SDN, PEP, and adverse-media corpora.

query #CRY-8821 · confidence 0.54 · coherence: possible (below alert threshold)
Day 7 · 09:31 attribution

New attribution signal arrives

On-chain analytics firm submits updated attribution: 0x7f3a…8b2c linked to "Alexei Morozov" at 0.82 confidence. Cluster confidence updates from 0.54 to 0.71. Still below the 0.75 alert threshold.

attribution source 5 · confidence 0.54 → 0.71
Day 11 · 03:18 sanctions update

SDN entry processed

OFAC SDN list updated. New entry: "Alexei Morozov". Cluster re-evaluated against the updated graph — confidence crosses 0.77. Alert threshold (0.75) exceeded. Standing query fires.

OFAC SDN #SDN-03421 · confidence 0.71 → 0.77 · coherence crosses to likely
Day 11 · 11:44 tx alert

Transaction alert fired with evidence

Inbound transaction detected from 0x7f3a…8b2c. Alert #CRY-ALT-0514 delivered to transaction monitoring pipeline. Evidence payload included: 5 attribution sources, OFAC citation, confidence 0.77, coherence: likely, blocking_evidence: OFAC SDN #SDN-03421.

alert #CRY-ALT-0514 · evidence payload attached
04 · Deployment posture

Evidence first.
In every flag, in every audit.

Crypto compliance operates under the same regulatory pressure as traditional finance — and the evidence standard is the same. Kloom is built so every output in the system is citable, and every decision is reproducible.

Evidence-backed flags

Every alert ships with the citable mentions that produced it — source, passage, confidence, and per-component scores. An analyst can assess it. A customer can dispute it. A regulator can audit it.

Cluster-level uncertainty, preserved

When attribution is contested, the cluster state holds the disagreement as structured uncertainty. Confidence and coherence reported as two independent signals — not collapsed to a binary verdict that destroys the signal.

Integrator-controlled data flows

Kloom runs inside your perimeter. The PKG ships as a single binary you operate; Name Intelligence additionally ships as a standalone library for teams that want screening without the graph above it. Either way, wallet addresses, KYC data, and attribution signals never leave your trust boundary.

Original-script handle storage

Handles and names stored in the script and language in which they arrive. Cross-script matching — Cyrillic pseudonyms against Latin KYC names — is a retrieval-time concern, not an index-time normalisation that destroys the original.

Security posture Compliance & regulatory
Platform

Relevant platform capabilities

Name Intelligence

Parse–retrieve–rerank pipeline for handles and names. 19 scripts, adversarial spelling, cross-script retrieval.

standalone library
Read the page

Immutable Evidence API

Append-only record of every attribution and mention. Blocking evidence in the response envelope — citable per flag.

Read the page

Agent Identity Layer

Structured uncertainty surface for automated pipelines. Agents consume coherence, certainty, and blocking evidence — not just a verdict.

Read the page

Morphic Identity Engine

Continuous reshaping as attribution signals arrive. Cluster state evolves — no destructive merges, every state reproducible.

Read the page
Ready when you are

Book a technical walkthrough.

A demo runs against a representative set of wallet addresses or counterparty data from your environment and returns attributed entities you can audit end to end.

Book a demo