For Analytics Platforms · Surikata-X Darknet Intelligence
We're not a blockchain analytics company. We're what sits upstream of one.
You derive risk from the ledger. We collect it from the darknet — inside operators' own payment pages, usually before an address has received a single transaction. Run us as a second source behind your own attribution, and pay only when we return something your data didn't have. If we never surface anything new to you, you never pay us anything.
A second source that only bills for the delta.
You call us after your own attribution comes back empty. So every hit we return is, by construction, something your data did not already contain — and that is the only thing we charge for.
Your customer screens an address
An exchange, PSP or bank asks your platform about a destination before funds move.
your stack, as todayYour attribution runs first
If you already have the address, you answer and we are never involved. Nothing changes and nothing is owed.
no call to usEmpty? Query DarkScout
Only addresses your data could not attribute reach us. The query itself is free, so there is no reason to ration it.
query: freeHit, or nothing
We return the attribution, the entity type and the source evidence — or we return nothing. You pay per positive hit, and never for a miss.
pay per positive hitThere is no revenue to attribute and nothing for finance to model in advance. A hit is a counted API response that both sides can see.
Where our data sits relative to yours.
Chain analysis needs history — a first transaction, then co-spends, then clusters. We collect the address when it is published on the operator's payment page, which is usually before any of that exists. The gap between the two is lead time your customers can act in.
Collected at the source. Measured continuously.
Live operating figures from the Surikata-X collection engine.
Categories we collect — by operator site
Most darknet payment intelligence in the market today is sourced from child-protection organisations, whose charter stops at child protection. Carding, markets, counterfeit documents, fraud infrastructure and mixers sit outside it. We run one collection engine across all of them. See the full breakdown, by site and by address.
Gateway Monitoring — a product your platform can resell.
Every darknet storefront needs a way to take payment, and most use an ordinary crypto payment processor opened under a clean merchant identity. Which processor sits behind a given checkout exists only in the checkout page itself — it never touches the blockchain, so no amount of chain analysis recovers it. We walk those funnels, fingerprint the processor, capture the address it issues, and preserve the page as evidence.
Payment service providers are already in your customer base. This is not a new market for you — it is a new line into an existing book, sold to people who already take your calls. It also moves you upstream of your own exchange customers, because the processor is where their exposure originates.
A hosted processor holds merchant accounts, takes a percentage of volume, and has an acceptable-use policy its criminal merchants are breaching — along with the contractual right to terminate them. What it does not have is any way to find them. We have reviewed the terms of several major processors: the enforcement rights exist, the detection capability doesn't.
Priced to you wholesale, per monitored processor. You set the retail price and keep the margin — a discrete product with a discrete price, straightforward to put through your own pricing and comp plans.
What a hit actually contains.
The operator entity, its type, and the chains it transacts on — collected inside the darknet, upstream of the heuristics you already run.
The content-filtered source page that establishes each address — suitable for risk-committee review or law-enforcement referral. See an example.
No donation wallets, no "hacked wallet for sale" listings already attributed to someone else. Every collected address is checked against existing clustering before it is delivered. How we keep it clean.
Take nothing on faith. Two ways to test it.
Both cost you nothing, and both produce a result you can judge without taking a meeting first.
Name a payment processor
Tell us one processor your customers deal with, and we will tell you which criminal merchants are running checkouts through it. One day of work on our side, nothing on yours.
Run live queries behind your attribution
Route the addresses your own data can't attribute to us. Both sides log everything. At the end you have your real hit rate, your real lead times, and a price built on your measured volume rather than a guess from either of us.