Sanctions & Counterparty Due Diligence

Know who you're dealing with before you deal with them. This screens a domain, address, or network against sanctions lists and assesses the counterparty's hosting, true owner, jurisdiction, and reputation — the external due-diligence pass for compliance teams, crypto-AML checks, and vetting an acquisition or an exchange before you transact.

How it uses the graph

Traverses the threat-intel, WHOIS, GeoIP, BGP layers of the graph, in 7 steps:

How it walks the graph7 steps
01Threat verdict

Scoring the indicator across every threat dimension…

threat-intelWHOISGeoIPBGP
02Sanctions & threat-feed listings

Checking every feed the hosting IPs are listed in…

threat-intelWHOISGeoIPBGP
03Hosting & jurisdiction

Resolving the hosting network and country…

threat-intelWHOISGeoIPBGP
04Registrant

Reading the WHOIS registrant…

threat-intelWHOISGeoIPBGP
05Geographic footprint & jurisdiction

Geographic footprint & jurisdiction…

threat-intelWHOISGeoIPBGP
06Related entities

Related entities…

threat-intelWHOISGeoIPBGP
07Infrastructure estate size

Infrastructure estate size…

threat-intelWHOISGeoIPBGP

Why each step runs

  1. 01Threat verdict. One-call verdict (score, level, factors, sources) — the sanctions/reputation headline.
  2. 02Sanctions & threat-feed listings. OFAC SDN is among the ~43 feeds; a feed/category naming OFAC or sanctions is the sanctions signal.
  3. 03Hosting & jurisdiction. Hosting reputation + jurisdiction — sanctions screening needs the where and the who.
  4. 04Registrant. Registrant org/email pivots — sanctioned entities often reuse registration identities.
  5. 05Geographic footprint & jurisdiction. Shows the counterparty's hosting country and city with how many IPs sit in each, so the compliance frame and multi-region spread are visible at a glance.
  6. 06Related entities. Surfaces sister companies and consolidated entities tied to the registrant, widening the due-diligence picture beyond the single owner.
  7. 07Infrastructure estate size. Counts subdomains under the domain as a fast proxy for the counterparty's infrastructure maturity and scale.