Trust and Identity squad

AI crypto AML screening with custody controls tracked

Cypher Knox, Lead AI Crypto Custody Architect, an AI agent by FluxForceCypher Knox — Lead AI Crypto Custody Architect

Cypher Knox is an AI agent for virtual asset firms. He screens blockchain transfers for AML risk, checks that travel rule information arrives with each transfer, and tracks the custody controls on your wallets and keys. Anything risky goes to your compliance team with the on-chain evidence attached. Your MLRO makes the call.

Cypher Knox
Cypher Knox, Lead AI Crypto Custody Architect, an AI agent by FluxForce
Withdrawal #VA-55107 screened
IllustrativeSent to analyst
AML risk 0.77 · high
Flag explained
“Two hops from a sanctioned address, beneficiary data missing.”
FATF R.16VARA
REPORTS TO
Your MLRO
Shadow mode first
How Cypher works with your team
Shadow mode
first: nothing acts until you say so
3 bands
of autonomy you configure
Every decision
has a replayable record
1 per agent
kill switch
SaaS · on-prem · hybrid
deployment
Product controls, not performance claims. Performance is measured on your data, in shadow mode.
The problem

The crypto compliance problem your MLRO carries

Virtual asset transfers settle fast and cross borders by default. Your compliance team has to screen counterparties it can't see by name, collect travel rule data from other providers, and show a regulator how keys are controlled. Much of that still runs on spreadsheets and separate tools.

ON-CHAIN QUEUE
Minutes

for a transfer to settle

Review queues run on business days.

Pseudonymous risk

No name on the address

A wallet address doesn't say who owns it. Exposure to sanctioned or illicit addresses can sit a few hops back, out of sight of a simple list check.

Travel rule gaps

Data that doesn't arrive

FATF R.16 expects originator and beneficiary information to travel with transfers. Counterparty providers send it late, incomplete or not at all.

Custody evidence

Who can move the funds

Regulators ask how keys are created, stored, rotated and used. If the answer lives in a wiki page and an engineer's memory, it isn't evidence.

Job description

What Cypher Knox does Job description

Cypher Knox is a Lead AI Crypto Custody Architect. He sits beside your wallet infrastructure and compliance tools, screens transfers for AML risk, checks travel rule data and keeps a record of custody controls.

AI AGENT · TRUST AND IDENTITY SQUAD
Cypher Knox, Lead AI Crypto Custody Architect, an AI agent by FluxForce
CYPHER KNOX
Lead AI Crypto Custody Architect
REPORTS TO
Your MLRO or Head of Compliance
WORKS WITH
Your wallet platform, blockchain analytics provider and case management system
DEPLOYED
Shadow mode first, then the autonomy you set
KEY RESPONSIBILITIES
01Screen incoming and outgoing transfers for exposure to sanctioned, high-risk or illicit addresses
02Check that originator and beneficiary information is present for transfers that need it
03Track key lifecycle events, such as creation, rotation, access and signing, against your custody policy
04Flag custody actions that break policy, such as a signing request outside approved roles
05Prepare cases for your analyst with the on-chain path and travel rule status attached
AUTONOMY MODEL
Low risk
Can close clear transfers with a reason, if you allow it
LOW
Medium risk
Goes to an analyst by default
MEDIUM
High risk
Always goes to an analyst
HIGH
You set the threshold per rule.
Kill switch: Turn Cypher off at any time
Shadow mode

What to measure in shadow mode on your own data

We don't publish detection numbers from our own tests. Run Cypher Knox beside your current crypto compliance process and measure what he finds on your transfers before he acts on anything.

01
Analyst agreement
How often your analyst's decision matches Cypher's recommendation, by risk band.
02
Missed-risk review
Every transfer your team later confirmed as suspicious that Cypher scored low. Read this number first.
03
Travel rule completeness
Share of in-scope transfers with full originator and beneficiary data.
04
Indirect exposure found
Transfers linked to risky addresses through intermediate hops, and how many your team confirms.
05
Custody policy breaks
Key and signing events that fall outside your custody policy.
06
Time to case-ready
Minutes from transfer to a case file an analyst can decide on.
07
Screening latency
Time to screen a transfer at your volumes, on your infrastructure.
08
Decisions with evidence
Share of decisions with a replayable record. The target is all of them.
Shadow mode results belong to you. We agree the metrics, the time window and who reviews the closures before the trial starts.
How it works

How AI crypto AML screening works with Cypher Knox

Cypher Knox connects to your wallet platform and analytics provider through APIs. Your custody setup stays where it is.

01

Ingest

Transfer requests, deposits, wallet addresses and travel rule messages arrive from your wallet platform and travel rule provider. Key management events arrive from your custody system.

02

Screen

Cypher checks each counterparty address and its on-chain path against sanctions and risk data from your analytics provider, and checks whether the required travel rule information is present.

03

Route

Your autonomy settings decide what happens next. Clear transfers can close with a reason if you allow it. Medium risk goes to an analyst by default. High risk always goes to an analyst.

04

Record

Every result comes with a plain-English reason, the on-chain path and the travel rule status. The decision, its inputs and the person who approved it go into tamper-evident evidence storage.

Want to see this on your data?

Run Cypher Knox in shadow mode on your live transfers. He screens, explains and opens cases, while your team keeps making every call. Compare his calls with your analysts' before you switch anything on.

Request a shadow mode trial
Compliance and regulatory mapping

Regulatory frameworks Cypher Knox supports

Cypher doesn't make you compliant. He produces the evidence these frameworks expect a virtual asset firm to keep.

FATF Recommendation 15
Virtual asset service providers are expected to apply AML/CFT measures. Cypher prepares the screening evidence your MLRO reviews.
FATF Recommendation 16
The travel rule calls for originator and beneficiary information on transfers. Cypher flags transfers where it's missing.
EU Transfer of Funds Regulation 2023/1113
Applies the travel rule to crypto transfers in the EU. Cypher records travel rule status for each transfer.
MiCA (Regulation 2023/1114)
Sets the EU framework for crypto-asset service providers, including custody. Cypher keeps a record of key and signing events against your policy.
VARA
Dubai's Virtual Assets Regulatory Authority supervises virtual asset firms in Dubai. Cypher prepares evidence for your VARA compliance reviews.
OFAC sanctions (SDN list)
The SDN list includes some digital currency addresses. Cypher screens counterparties and the paths behind them.
Analyst view

What your crypto compliance analyst sees

Each risky transfer arrives with its on-chain path and travel rule status.

BEFORE CYPHER KNOX
Address checks against a single list
Travel rule gaps found at audit
Key events tracked in spreadsheets
On-chain paths traced by hand
Decision reasons scattered across tools
AFTER CYPHER KNOX
Indirect exposure shown hop by hop
Missing travel rule data flagged per transfer
Key and signing events checked against policy
Cases opened with the path already traced
Every decision replayable for an examiner
Options

How the options compare

CRITERIA Analytics tool and manual reviewCustody platform alerts Cypher Knox, Lead AI Crypto Custody Architect, an AI agent by FluxForceCypher Knox
Time to first results Already in placeAlready in place Shadow mode on your live transfers
Who decides AnalystPlatform rule, then your team Analyst, inside risk bands you set
Travel rule checks Separate tool and processNot usually Checked with each transfer
Custody evidence Not coveredPlatform logs Key events checked against your policy
Why a transfer was flagged Risk score from the toolRule ID Plain-English reason with the on-chain path
Where it's weaker Analyst time grows with volumeSees the wallet, not the AML picture Relies on your analytics provider's address data, and isn't a custody platform
Trust Builders

Built for Regulated Financial Institutions

01

Configurable autonomy

Low risk can run on its own if you allow it. Medium risk goes to a person by default. High risk always goes to a person. You set the bands per rule, channel and transaction type.

02

Kill switch

Turn Cypher off without touching the other agents or your core systems. The switch, and who used it, is stamped on the record.

03

Shadow mode

Run Cypher on live data with nothing blocked or closed. Compare the calls with your team's before anything changes.

04

Explainability

Every decision answers why, in plain English, with the signals and the rule or policy behind it.

05

Audit trail

Each decision is stored with its inputs, its reasoning and the person who approved it, in tamper-evident evidence storage.

06

No migration

Agents connect beside your systems through APIs. Your core banking, screening and case tools stay where they are.

Questions? We Have Answers

Frequently Asked Questions

FluxForce

Still have questions?

Talk to the people who build the agents. We'll answer per capability, yes or no.

For a virtual asset firm, it screens transfers for AML risk, checks travel rule data and tracks the controls around wallets and keys. Cypher Knox explains each flag with the on-chain path and routes cases by the risk bands your team sets. Your MLRO makes the call on anything that isn't clearly low risk.

Your team does. Cypher can close clear transfers with a recorded reason only where you allow it. Medium risk goes to an analyst by default and high risk always does. A kill switch turns Cypher off without touching your wallets.

No. He doesn't hold keys or move funds. He reads key and signing events from your custody system and checks them against your policy, so you have evidence of how custody is controlled.

No. Cypher uses your provider's address data and adds travel rule checks, custody evidence and case preparation on top.

Cypher screens your live transfers and opens cases, but nothing is held or closed. Your analysts keep working as they do today, and you compare Cypher's calls with theirs. You decide whether, and where, to switch on any autonomy afterwards.

Transfer and deposit records with addresses, amounts and timestamps, travel rule messages, and key management events from your custody system. Past analyst decisions help him learn what your team treats as acceptable risk.

FluxForce runs as SaaS, on-premise or hybrid, built on Microsoft Azure. We agree data residency and which components run inside your environment during deployment design, before any data moves.

Shadow mode trial

See Cypher on your data before anything changes

Run Cypher Knox beside your current process. He works on your live data and records every call, and nothing is blocked, closed or sent until you decide.

  • Runs in shadow mode on your own data, next to your team
  • You agree the metrics, the time window and who reviews the results
  • Kill switch and a replayable record of every decision from day one
  • SaaS, on-premise or hybrid, with data residency agreed up front

Shadow mode results belong to you.

Take the first step

AI agents that prepare the case. Your team makes the call.

Start with one workflow in shadow mode, then decide how much each agent does on its own.

How we start
Discovery and scoping
Integration beside your systems
Shadow mode
Controlled autonomy
Govern and improve