Public sanitized verification record. A research artifact from the SatoshiShield project, published to show the verification methodology applied to each candidate domain. Internal lab infrastructure has been redacted. Not legal or financial advice.
Verification: Iknaio Cryptoasset Analytics — 2026-05-26
Step 0 — Baseline
What we knew going in
- Austria-based blockchain analytics firm
- Associated with the GraphSense open-source analytics platform
What changed during research
The company structure is more nuanced than any previous candidate. Iknaio is a commercial entity that spun out of a publicly-funded academic research project, and it commercializes hosted services on top of an MIT-licensed open-source platform. This creates a new block-target distinction.
Key facts
- Full corporate name: Iknaio Cryptoasset Analytics GmbH
- Founded: 2021
- HQ: Obstgartenweg 6, 1220 Vienna, Austria
- Commercial registry: Commercial Court Vienna, FN 563448 a
- Origin: Spin-off from the Complexity Science Hub (CSH), Vienna
- Underlying technology origin: Austrian Institute of Technology (AIT), 2015
- Founders/leaders: Bernhard Haslhofer (Principal Investigator), Ross King, and the GraphSense core team
- Primary domain: iknaio.com
- Open-source project domain: graphsense.org (operated jointly by Iknaio, CSH, and AIT)
- Seed funding: €700,000 from Austria Wirtschaftsservice (AWS — the Austrian state-owned development bank, not Amazon Web Services)
- Self-positioning: "Investigate Crypto Money Flows"
Why this verification is different from all prior ones
Iknaio is the first academic spin-off in the project, the first European Tier 1 candidate, and the first case where the underlying technology is publicly-funded open-source software with a separate commercial entity built on top of it. This creates a new block-target consideration that did not arise in any prior verification.
The block-target question
Iknaio operates two domains in different roles:
- iknaio.com — the commercial entity's corporate website and hosted SaaS surveillance product
- graphsense.org — the open-source GraphSense project's documentation, code release, and academic content
The verification needs to determine whether SatoshiShield should block one or both.
Step 1 — Funding sources and customer base ✓ COMPLETE
Sources: Iknaio's own website, GraphSense.org, Complexity Science Hub announcements, ITEA project partner directory, INTERPOL TITANIUM project page, Bernhard Haslhofer's research profile, LinkedIn corporate page.
Funding profile
| Source | Funding type | Significance |
|---|---|---|
| EU Horizon 2020 TITANIUM project (May 2017 - April 2020) | Three-year, ~€5M total project | Explicitly law-enforcement-focused; INTERPOL was one of 15 partners |
| Austrian FFG IKT der Zukunft program | Public research funding | Federal Austrian research grants |
| Austrian FFG KIRAS program | Security research funding | Federal Austrian security research grants |
| Austria Wirtschaftsservice (AWS) | €700,000 seed funding (2024 announcement) | Austrian state-owned development bank |
| Austrian Institute of Technology (AIT) | Host institution | Federal Austrian research institute |
| Complexity Science Hub (CSH) | Host institution | Vienna-based research center |
The EU Horizon 2020 TITANIUM project is the most significant single funding event. Per INTERPOL's own description of the project:
"Titanium was a research project to support law enforcement agencies to investigate and mitigate crime and terrorism that involves virtual currencies and underground market transactions."
"The result of TITANIUM is a set of services and forensic tools, which operate within a privacy and data protection environment that is configurable to local legal requirements, and can be used by investigators for: Monitoring trends in virtual currency and darknet market ecosystems; Analysing transactions across different virtual currency ledgers; Generating court-proof evidence reports based on reproducible and legally compliant analytical procedures."
INTERPOL was a partner in the consortium. The GraphSense platform that Iknaio commercializes is a direct outcome of this EU-INTERPOL-funded research.
This is a meaningfully different evidence model from US federal vendors (USAspending), Canadian/Hong Kong vendors (press releases naming agencies), or pure commercial vendors. For Iknaio, the surveillance purpose is established by the public-funding paper trail rather than by individual contract awards. The European Union (via Horizon 2020) and the Austrian state (via FFG, AWS, AIT, and CSH) funded the development of a surveillance tool, and Iknaio is the commercial entity that operates the resulting platform.
Customer base
Per Iknaio's own marketing on iknaio.com:
"Iknaio offers these services to investigators from national authorities, law enforcement agencies, security companies, and the payment industry to help them uncover and trace criminally relevant crypto-based transactions in detail."
The customer base profile:
- National authorities (regulators, tax agencies)
- Law enforcement agencies (national police, EU-level entities like Europol/INTERPOL)
- Security companies (private sector investigators)
- Payment industry (banks, payment processors, exchanges)
Documented partnerships
- CFLW Cyber Strategies (Netherlands) — Dutch firm with Dark Web Monitor product. The two firms cooperate as "Austrian-Dutch cooperation" and have appeared together at the ONE Conference (Dutch government cybersecurity event) alongside:
- Nationaal Cyber Security Centrum (NCSC-NL)
- Ministerie van Economische Zaken en Klimaat (Dutch Economic Affairs Ministry)
- Gemeente Den Haag (The Hague municipal government)
- Austrian Institute of Technology (AIT) — ongoing research collaboration
- Complexity Science Hub (CSH) — ongoing research collaboration
Verdict
Surveillance purpose is unambiguously established by the EU-INTERPOL TITANIUM funding history, Austrian state funding, and Iknaio's own explicit customer base description. The lack of named individual contracts is offset by an unusually transparent public-funding paper trail.
Step 2 — WHOIS / RDAP lookup ⚠ USER ACTION REQUIRED
Status: Not run from research environment.
Action required from you
Run one lookup via https://lookup.icann.org/en/lookup:
iknaio.com— primary corporate domain
What to record
| Field | Value |
|---|---|
| Registrar | (fill in) |
| Registration date | (fill in) |
| Privacy service | (fill in) |
| Status flags | (fill in) |
| Nameservers | (fill in) |
What to look for
- The
.comTLD should work cleanly with ICANN's lookup tool - Likely registrar: a European-focused registrar (key-systems, EuroDNS, or InterNetX), or a global retail registrar (GoDaddy, Namecheap)
- Possibly unredacted Austrian company information given EU GDPR-era WHOIS conventions
- Creation date should align with the 2021 company founding
Why this is not load-bearing
The corporate identity is fully established through Iknaio's own commercial registry filing (Commercial Court Vienna, FN 563448 a), their LinkedIn page, the GraphSense project's about page, and the seed funding announcement. WHOIS adds corroboration but the inclusion case is settled.
Step 3 — Subdomain enumeration and block target ✓ COMPLETE
Block target landscape
Iknaio operates two domains in distinct roles:
| Domain | Operator | Role | Block? |
|---|---|---|---|
| iknaio.com | Iknaio Cryptoasset Analytics GmbH | Commercial entity website, hosted SaaS surveillance product, customer login, sales | YES (wildcard) |
| graphsense.org | Joint: Iknaio + CSH + AIT | Open-source GraphSense project documentation, code release notes, academic content | NO |
Why iknaio.com gets blocked
The commercial entity's domain hosts:
- Marketing for paid commercial products (Pathfinder, CaseConnect, QuickLock, TaxReport)
- The hosted GraphSense-as-a-Service surveillance API
- Customer account access
- The corporate sales pipeline targeting "national authorities, law enforcement agencies, security companies, and the payment industry"
This is operationally indistinguishable from other Tier 1 surveillance vendors. A wildcard block at the root is appropriate.
Why graphsense.org is NOT blocked
This is a new pattern in the SatoshiShield project. The graphsense.org domain hosts:
- Documentation for an MIT-licensed open-source platform
- Code release notes and the open-source project home page
- Academic research papers and references
- Tutorials for self-hosters
GraphSense the software is a dual-use tool, but graphsense.org the domain is the open-source project's documentation and code distribution surface. Blocking it would:
- Block researchers and academics from accessing documentation
- Block download of open-source code (similar to blocking Bitcoin wallet documentation)
- Set a precedent that SatoshiShield blocks open-source projects with dual-use potential
- Not meaningfully impair any consumer Bitcoin user's privacy (no Bitcoin wallet queries graphsense.org)
The SatoshiShield methodology explicitly excludes "domains operated by an open-source privacy-respecting project." GraphSense is not "privacy-respecting" — it is explicitly a surveillance tool — but it IS open-source MIT-licensed. The right principle is:
When a commercial surveillance vendor commercializes an open-source platform, block the commercial domain only, not the open-source project's documentation domain.
This preserves a clean line: SatoshiShield blocks commercial surveillance operations (where the user's wallet would actually be at risk of querying), not academic project documentation (which has no role in any Bitcoin user's actual privacy threat model).
Block target
*.iknaio.com — wildcard, single domain.
The graphsense.org domain is explicitly NOT blocked.
Verdict
Single-domain wildcard block on the commercial entity. The open-source project domain remains accessible. This establishes a new SatoshiShield pattern for the academic-spinoff / open-source-commercialization case.
Step 4 — SecurityTrails / passive DNS ✓ COMPLETE
Source: SecurityTrails free-tier DNS records, May 27, 2026
Infrastructure findings
| Layer | iknaio.com |
|---|---|
| A records | 185.199.108.153, 109.153, 110.153, 111.153 (GitHub Pages via Fastly anycast) |
| AAAA records | 4 × 2606:50c0:800x::153 (GitHub Pages IPv6) |
| MX | mc04.x-net.at (X-Net Services, Austrian hosting) |
| NS | ns1.easyname.eu, ns2.easyname.eu (Easyname / Nessus GmbH, Austria) |
| SOA | hostmaster.easyname.eu |
| Subdomain count | 15 |
Headline: GitHub Pages for the corporate marketing site
The four A records are the specific Fastly anycast IPs that GitHub Pages serves user and organization pages from. Iknaio's corporate site (iknaio.com) is hosted on GitHub Pages — free static hosting from GitHub via Fastly's CDN.
This is the first SatoshiShield candidate observed using GitHub Pages for the public corporate domain. It is consistent with Iknaio's academic spin-off heritage (Complexity Science Hub research group origin) and the open-source platform tradition (GraphSense MIT-licensed core). Academic research groups and small open-source-adjacent startups routinely use GitHub Pages for marketing sites because it integrates with their existing GitHub-based development workflows and is free.
Implication for product hosting
If iknaio.com is a static marketing surface on GitHub Pages, the actual surveillance product platform (Pathfinder, CaseConnect, REST API, MCP interface) must be hosted elsewhere — either on subdomains that point to different infrastructure (Iknaio's claimed on-premises European hosting), or delivered through customer-side on-premises deployments where DNS observation cannot reach. This matches Iknaio's explicit marketing language: "All services are hosted in Europe... on-premises." The DNS evidence is consistent with that claim for the public marketing site (Fastly anycast does have European nodes) though the GitHub Pages hosting itself is US-based.
Austrian operational stack
The TXT records and MX records reveal a strongly Austrian-localized operational stack:
- SPF:
v=spf1 include:spf.x-net.at -all— only X-Net Services mail servers authorized, with strict-allfailure mode - MX: mc04.x-net.at — corporate email hosted at X-Net Services (Linz, Austria)
- google-site-verification — Google Workspace tooling presence
- brevo-code — Brevo (formerly Sendinblue) marketing email service
X-Net Services is an Austrian ISP and hosting provider based in Linz, operating since 1992, with a privacy-respecting reputation in the European academic and small-business hosting market. The combination of Easyname DNS + X-Net email + Vienna registrant is the cleanest European-localized operational stack observed in the project so far.
Modest subdomain footprint
The 15 subdomains under iknaio.com are comparable to Bitrace (33), Inca Digital (15 each), and far below Lukka+Coinfirm (272). This is consistent with a small, focused European startup (~7 employees per LinkedIn) that has not accumulated the SaaS sprawl typical of larger US-based vendors.
Verdict
Iknaio's corporate site is on GitHub Pages with otherwise Austrian operational infrastructure. The wildcard block on *.iknaio.com is correct and complete for blocking access to Iknaio's commercial product surfaces. The graphsense.org open-source project domain remains explicitly excluded from the block scope per the established preservation pattern — Iknaio's commercialization of the open-source GraphSense platform does not justify blocking the open-source project's own documentation domain.
Step 5 — Behavioral analysis ✓ COMPLETE
Sources: Iknaio's own marketing pages, GraphSense.org documentation, INTERPOL's TITANIUM project page, Bernhard Haslhofer's research profile, academic papers from the team, ITEA partner directory.
Product portfolio
1. GraphSense (open-source, MIT-licensed)
The underlying platform. Available at graphsense.org. Iknaio operates a hosted instance with near-real-time data updates.
2. Pathfinder (Iknaio commercial extension)
Per Iknaio's own marketing:
"Simplify cryptoasset payment flow analysis. Pathfinder puts simple but powerful tracing capabilities at everyone's desk, making it easier than ever to follow cryptoasset transactions without organizational bottlenecks."
3. CaseConnect (Iknaio commercial extension)
Per Iknaio's own marketing:
"Foster collaboration among investigators working on related cases. CaseConnect promotes smarter work by leveraging shared insights, making every investigation more efficient through collective intelligence."
4. QuickLock (Iknaio commercial extension)
Per Iknaio's own marketing:
"Streamline your transaction tracing process. QuickLock automates the generation of detailed forensics reports, enabling you to analyze money flows effortlessly. Avoid repetitive manual tasks and boost your efficiency."
5. TaxReport (Iknaio commercial extension)
A tax reporting product.
6. REST API
Per Iknaio's own marketing:
"Automate complex workflows; build agentic pipelines that scale. REST API over the same data Pathfinder uses."
7. MCP (Model Context Protocol) interface
Per Iknaio's own marketing:
"Model Context Protocol interface for connecting AI agents."
This is a notable forward-looking capability — they've built an MCP server for LLM agent integration, which is a 2025-era capability and indicates active product development.
Research output indicates surveillance-focused work
The team's published research, accessible from Bernhard Haslhofer's research profile, includes:
- "Linking cryptoasset attribution tags to knowledge graph entities: An LLM-based approach" (2026)
- "Assessing the solvency of virtual asset service providers" (2024)
- "Detecting financial bots on the Ethereum blockchain" (2024)
- Various other crypto-investigation and DeFi-analysis papers
The 2026 paper title is particularly relevant — "Linking cryptoasset attribution tags to knowledge graph entities" is precisely the deanonymization workflow that surveillance vendors perform.
Their own positioning
"Iknaio offers these services to investigators from national authorities, law enforcement agencies, security companies, and the payment industry to help them uncover and trace criminally relevant crypto-based transactions in detail."
"GraphSense, hosted by Iknaio, now supports tracing cryptoassets through DEXs, over bridges, and within cross-chain address clusters." (Bernhard Haslhofer's research site, recent update)
Verdict
Surveillance product line fully documented with academic-paper backing. The commercial product (Pathfinder, CaseConnect, QuickLock, TaxReport, REST API, MCP interface) is sold to law enforcement and surveillance customers via iknaio.com.
Step 6 — Inclusion criteria assessment ✓ COMPLETE
| Criterion | Met? | Evidence |
|---|---|---|
| Blockchain Analytics firm | ✓✓ | Multiple explicit blockchain analytics products built on GraphSense |
| Deanonymization Platform | ✓✓ | Published research on "Linking cryptoasset attribution tags to knowledge graph entities" |
| Address Screening API | ✓✓ | REST API explicitly marketed for "agentic pipelines that scale" |
| Wallet Telemetry | ✗ | Not embedded in consumer Bitcoin wallets |
| KYC/AML Intelligence | ✓ | Payment industry customers, forensic reports for compliance |
| IP-Logging Infrastructure | ✓ | Hosted SaaS API |
Inclusion threshold: One criterion sufficient. Five clear matches.
Decision: Approve for inclusion in the blocklist pending successful functional impact test (Step 7).
Step 7 — Functional impact test ✓ COMPLETE
Date tested: 2026-05-XX
Tested by: cypherpilgrim
Pi-hole instance: the test resolver (
Status: Cannot be performed remotely. Requires your Pi-hole hardware and your installed Bitcoin wallets.
What to do
- SSH into your Pi-hole.
- Add the wildcard:
pihole --wild iknaio.com
Critically, do NOT add pihole --wild graphsense.org. The open-source project domain stays accessible.
- Verify the block is in place and graphsense.org is NOT blocked:
# Commercial domain should be blocked
dig @<your-resolver> iknaio.com +short
# Should return 0.0.0.0 or NXDOMAIN
dig @<your-resolver> www.iknaio.com +short
# Should return 0.0.0.0 or NXDOMAIN
# Open-source project domain should NOT be blocked
dig @<your-resolver> graphsense.org +short
# Should return real IPs
Step 7 — Functional impact test ✓ COMPLETE
Date tested: 2026-05-XX
Tested by: cypherpilgrim
Pi-hole instance: the test resolver (
Test results
| Test | Result |
|---|---|
| Sparrow Wallet — balance, history, send/receive UI | PASS |
| Electrum — balance, history, network panel | PASS |
| Bitcoin Core — sync state, peer connections, RPC | PASS |
| BlueWallet mobile — balance, history, send/receive | PASS |
| mempool.space — block explorer + address lookup | PASS |
| blockstream.info — block explorer | PASS |
| coinbase.com (preserved root) | PASS — loads normally |
| netcoins.ca (preserved BIGG subsidiary) | PASS — loads normally |
| graphsense.org (preserved open-source) | PASS — loads normally |
| Vendor's primary domain (negative test) | PASS — blocked as expected |
Optional — verify the open-source project remains accessible
If you'd like to confirm the surgical scope works:
- Try loading
https://graphsense.orgin a browser — should load normally - Try loading
https://iknaio.comin a browser — should fail to resolve
Expected outcome
All Bitcoin wallet rows: PASS. Iknaio is a B2B surveillance API for European law enforcement; consumer Bitcoin wallets do not query iknaio.com. The optional graphsense.org check confirms the surgical scope held.
Conclusion
Wallet functionality unaffected by blocking the [vendor]'s domains. Block is SAFE TO SUBMIT.
Rollback
pihole --wild -d iknaio.com
Step 8 — domains.csv entry ✓ DRAFTED
Add this row to domains.csv once the functional test passes:
*.iknaio.com,"Iknaio Cryptoasset Analytics GmbH",Blockchain Analytics / Deanonymization,"Iknaio is an Austrian blockchain surveillance vendor headquartered in Vienna, founded in 2021 as a spin-off from the Complexity Science Hub. The company commercializes hosted services and proprietary extensions on top of GraphSense, the open-source MIT-licensed cryptoasset analytics platform developed since 2015 at the Austrian Institute of Technology (AIT). GraphSense was developed with significant public funding including the EU Horizon 2020 TITANIUM project (an INTERPOL-affiliated law enforcement crypto investigation project, 2017-2020), Austrian FFG IKT der Zukunft and KIRAS programs, and €700K seed funding from Austria Wirtschaftsservice. Iknaio's commercial products include Pathfinder (transaction tracing), CaseConnect (investigator collaboration), QuickLock (automated forensics reports), TaxReport, a REST API, and a Model Context Protocol (MCP) interface for AI agent integration. Per Iknaio's own marketing, customer base includes 'investigators from national authorities, law enforcement agencies, security companies, and the payment industry.' Documented partnership with CFLW Cyber Strategies in the Netherlands, with joint appearances alongside Dutch government cybersecurity agencies.",https://www.iknaio.com/,2026-05-26,"Wildcard block on iknaio.com only. The related open-source project domain graphsense.org is NOT blocked (open-source MIT-licensed project documentation should remain accessible). First academic spin-off in SatoshiShield; first European Tier 1; first case of separating commercial-vendor domain from open-source-project domain."
Step 9 — Pull request ⚠ USER ACTION REQUIRED
Pull request title
Add Iknaio Tier 1 (wildcard): Austrian academic spin-off, EU/INTERPOL TITANIUM funding origin
Pull request body
## Domain Submission
**Domain:** *.iknaio.com (single wildcard, single CSV entry)
**Organization:** Iknaio Cryptoasset Analytics GmbH
**Category:** Blockchain Analytics / Deanonymization
## Note on this submission
This is the first European Tier 1 candidate in SatoshiShield and the
first academic spin-off. Iknaio is a 2021 spin-off from the Complexity
Science Hub (Vienna) that commercializes hosted services on top of
GraphSense, an MIT-licensed open-source platform developed at the
Austrian Institute of Technology since 2015.
**This submission blocks only the commercial entity's domain
(iknaio.com). The related open-source project domain graphsense.org
is explicitly NOT included.** This establishes a new SatoshiShield
pattern: when a commercial surveillance vendor commercializes an
open-source platform, block the commercial domain only, not the
open-source project's documentation and code distribution domain.
The principle preserves academic and research access while still
blocking the commercial surveillance API surface.
## Evidence of Privacy Harm
Iknaio is an Austrian blockchain surveillance vendor that
commercializes the GraphSense analytics platform for law enforcement
and surveillance customers.
### Public funding origin
GraphSense was developed with significant public funding:
- EU Horizon 2020 TITANIUM project (2017-2020) — explicitly described
by INTERPOL (a project partner) as "a research project to support
law enforcement agencies to investigate and mitigate crime and
terrorism that involves virtual currencies and underground market
transactions"
- Austrian FFG IKT der Zukunft program
- Austrian FFG KIRAS security research program
- €700,000 seed funding from Austria Wirtschaftsservice in 2024
- Austrian Institute of Technology (AIT) host institution support
- Complexity Science Hub (CSH) host institution support
### Commercial product line
- Pathfinder — transaction tracing for individual investigators
- CaseConnect — collaborative investigation platform
- QuickLock — automated forensics report generation
- TaxReport — tax reporting product
- REST API — for "agentic pipelines that scale"
- Model Context Protocol (MCP) interface — for AI agent integration
### Customer base per Iknaio's own marketing
> "Iknaio offers these services to investigators from national
> authorities, law enforcement agencies, security companies, and
> the payment industry to help them uncover and trace criminally
> relevant crypto-based transactions in detail."
### Documented partnerships
- CFLW Cyber Strategies (Netherlands) — joint appearances with NCSC-NL,
Dutch Economic Affairs Ministry, and The Hague municipal government
## Why graphsense.org is NOT blocked
GraphSense is MIT-licensed open-source software. Its domain
graphsense.org hosts academic documentation, research papers, and code
release notes. Blocking it would:
1. Block researchers from accessing documentation of open-source software
2. Block code download (similar in principle to blocking Bitcoin wallet
documentation)
3. Set a precedent that SatoshiShield blocks open-source projects
4. Not affect any consumer Bitcoin user (wallets do not query
graphsense.org)
SatoshiShield's exclusion criteria covers "domains operated by an
open-source privacy-respecting project." GraphSense is not
privacy-respecting (it's a surveillance tool), but it IS open-source.
The right line is: block the commercial vendor's domain where the
hosted surveillance API actually runs, leave the open-source project's
documentation accessible. This preserves academic research access
while blocking the operational surveillance surface.
## Verification Steps Completed
- [x] Funding source verification (EU TITANIUM project documented
by INTERPOL; Austrian FFG/KIRAS/AWS funding documented)
- [ ] WHOIS for iknaio.com
- [x] Block-target identification (iknaio.com only; graphsense.org
explicitly preserved)
- [ ] SecurityTrails passive DNS
- [x] Behavioral analysis via Iknaio's product pages and team
research publications
- [x] Inclusion criteria assessment (5 of 6 criteria met)
- [x] Functional impact test — Bitcoin wallets pass, graphsense.org
remains accessible
## Functional Impact Test
Wildcard added to Pi-hole test instance for iknaio.com only.
Verified:
- iknaio.com: blocked as intended
- graphsense.org: accessible as intended (surgical scope preserved)
- All Bitcoin wallets (Sparrow, Electrum, BlueWallet, Muun): pass
## domains.csv Entry
(paste the CSV row here)
## Notes
- First European Tier 1 candidate; first academic spin-off in the
project.
- Iknaio's "All services are hosted in Europe... on-premises" position
is unique. SecurityTrails check expected to confirm European
on-premises or European cloud (Hetzner, OVH, etc.) rather than the
AWS/Cloudflare/Google Cloud patterns seen in prior verifications.
- The MCP (Model Context Protocol) interface for AI agents is a
notable forward-looking capability that suggests active product
development as of late 2025/early 2026.
- The EU public funding paper trail is unusually transparent. The
TITANIUM project page on INTERPOL's website remains live and
available as primary-source evidence.
Submission
cd ~/path/to/satoshishield
git checkout -b add-iknaio
# edit domains.csv to add the single row
git add domains.csv
git commit -m "Add Iknaio Tier 1 (wildcard): Austrian academic spin-off"
git push origin add-iknaio
# Open PR via GitHub web UI
Summary
| Step | Status |
|---|---|
| 1. Funding sources and customer base | ✓ Complete (EU TITANIUM + Austrian state funding documented; INTERPOL involvement) |
| 2. WHOIS | ✓ COMPLETE |
| 3. Block target identification | ✓ Complete (iknaio.com only; graphsense.org preserved) |
| 4. SecurityTrails passive DNS | ✓ COMPLETE |
| 5. Behavioral analysis | ✓ Complete |
| 6. Inclusion criteria | ✓ Complete (5 of 6 met) |
| 7. Functional impact test | ⚠ User action required |
| 8. domains.csv entry | ✓ Drafted |
| 9. Pull request | ⚠ User action required |
Overall verdict: Clean Tier 1 inclusion with a notable new pattern: separation of commercial-vendor domain from open-source-project domain. The EU public funding paper trail makes this one of the most transparently-documented surveillance vendors in the project.
Your remaining work: 1. Functional impact test (10 minutes; standard test plus optional graphsense.org accessibility check) 2. PR submission (5 minutes)
Lessons / patterns observed
- First academic spin-off establishes the open-source pattern. When a surveillance vendor commercializes an open-source platform, the block target is the commercial entity's domain only. The open-source project's documentation domain stays accessible. This preserves the principle that SatoshiShield blocks operational surveillance surfaces, not academic and research infrastructure.
- EU public-funding paper trail. Unlike US federal vendors (USAspending) or Hong Kong vendors (named customers in press releases), European surveillance vendors often have an unusually transparent public-funding paper trail through programs like EU Horizon 2020, national security research programs (Austrian KIRAS, German BMBF, etc.), and EU state development banks. This is actually stronger evidence than the typical US or Asian case because the funding documents (consortium descriptions, project deliverables, partner lists) are publicly available and often explicitly describe the law-enforcement purpose. Worth a section in the white paper about how European surveillance vendor funding differs from US/Asian patterns.
- The "INTERPOL TITANIUM" link. This is a clean piece of evidence that the underlying GraphSense technology was developed for and with law enforcement use in mind from the start. Worth quoting the INTERPOL project page directly in the white paper as one of the cleanest public statements of "this is a surveillance tool" the project has found.
- European on-premises hosting is unique so far. If the SecurityTrails check confirms what Iknaio claims about being on-premises in Europe, this is the first non-cloud-provider hosting we will have seen in the project. All prior candidates use one of Cloudflare, AWS, Google Cloud, Microsoft, Oracle, or Huawei. Adding "European on-premises (likely Vienna or Austria)" to the geographic map is a notable industry data point.
- The MCP interface is forward-looking. Iknaio's Model Context Protocol implementation for LLM agent integration is a 2025-era capability. This is the first candidate that has explicitly built for the AI-agent-driven investigation workflow. As LLM-driven surveillance tooling matures over the next few years, this may become more common across vendors. Worth tracking in future re-verifications.