SatoshiShield
Verification record

Public sanitized verification record. A research artifact from the SatoshiShield project, published to show the verification methodology applied to each candidate domain. Internal lab infrastructure has been redacted. Not legal or financial advice.

21 Analytics — Verification Record

VERDICT: EXCLUDED FROM BLOCKLIST.

21 Analytics is a Swiss Travel Rule compliance vendor headquartered in Zug. Their main product (21 Travel Rule) is delivered as on-premises software with zero telemetry running inside customer (VASP) data centers. There is no cloud surveillance API surface that user-side devices could query, and the firm's own product page explicitly markets "100% On-Premise. Zero telemetry, ensuring you retain absolute data sovereignty."

This is the Whitestream pattern: surveillance-adjacent in the broader compliance ecosystem, but no direct user-layer privacy harm that DNS-level blocking can prevent.

Why it was evaluated

21 Analytics surfaced as a Tier 2 candidate during research into the Travel Rule / VASP-to-VASP compliance ecosystem. Several characteristics made the firm worth investigating:

  • Compliance vendor with explicit FATF Travel Rule positioning
  • Partners with confirmed Tier 1 firms (Coinfirm/Lukka, Global Ledger) for blockchain analytics integration
  • VASP-facing product for transaction screening
  • Two active domains (21analytics.ch, 21analytics.co)

Step 1 — WHOIS lookup — ✓ Complete

Tool used: whois CLI; Swiss registry browser form for .ch (CLI-blocked)

Findings per domain:

Domain Created Registrar Nameservers Registrant geo Lock status
21analytics.co 2025-12-22 Cloudflare, Inc. agustin.ns.cloudflare.com
jill.ns.cloudflare.com
CH (Zug) — Cloudflare privacy proxy clientTransferProhibited
21analytics.ch n/a — CLI blocked by SWITCH registry — (use https://www.nic.ch/whois/ to complete)

Notes:

  • 21analytics.co is a recent secondary domain — registered December 22, 2025, only ~5 months before this verification. The firm was founded April 2020, so 21analytics.ch is the original primary domain. The .co hosts marketing and blog content; .ch hosts the corporate primary.
  • 21analytics.ch WHOIS via CLI returns only TLD-level metadata; the SWITCH registry restricts CLI WHOIS access. Domain-specific lookup requires the browser form at https://www.nic.ch/whois/. Completion of this lookup is optional given the EXCLUDED verdict reached at Step 6.
  • Geography: registrant country CH, state Zug — consistent with the Step 4 corporate identity statement.
  • Privacy redaction: standard Cloudflare privacy proxy pattern; not a surveillance signal.
  • DNSSEC: signedDelegation on .co.

Conclusion: No new surveillance signal from registration metadata. Findings reinforce the Step 4 corporate identity and do not alter the EXCLUDED verdict.


Step 2 — SSL Certificate — ✓ Complete

Tool used: openssl s_client for live cert inspection. crt.sh historical CT enumeration deferred — crt.sh returned 502 during verification window. Can be backfilled in a future audit cycle if material new subdomains are suspected.

Findings per domain:

Domain Subject CN Issuer DNS SANs
21analytics.co 21analytics.co C=US, O=Google Trust Services, CN=WE1 21analytics.co
21analytics.ch 21analytics.ch C=US, O=Google Trust Services, CN=WE1 21analytics.ch, *.21analytics.ch

Notes:

  • Both certs issued by Google Trust Services (WE1) — Google's commercial CA, typically used by sites on Google Cloud Platform or via Google Workspace integrations. Notable because the WHOIS shows Cloudflare as registrar and nameserver: this means Cloudflare provides DNS only, with actual web hosting on Google Cloud infrastructure. Standard split for European startups; not a surveillance signal.
  • 21analytics.ch carries a wildcard SAN (*.21analytics.ch) authorizing any subdomain under the same cert. Normal for an established corporate site with marketing/blog subdomains.
  • 21analytics.co has no wildcard, only the root in SANs. Consistent with the newer (Dec 2025) registration — less subdomain sprawl yet.
  • No surveillance-product-shaped subdomains in either cert's SANs. No api.*, screening.*, monitor.*, data.*, customer.*, or app.*. This is the key check, and it passes cleanly: the on-premises product model from Step 4 is corroborated by the cert SAN structure.

Conclusion: Findings reinforce the EXCLUDED verdict. No cloud surveillance API surface detected via live cert inspection. The Google Trust Services + Cloudflare DNS pattern is routine European-startup infrastructure, not surveillance-vendor-shaped.


Step 3 — SecurityTrails / Passive DNS — ✓ Complete

Tool used: dig CLI for current DNS records (A, AAAA, MX, NS). SecurityTrails historical lookup deferred — free tier locked behind login as of May 2026; not material to the EXCLUDED verdict.

Findings per domain:

Domain A records AAAA records MX NS
21analytics.co 172.67.149.24, 104.21.33.195 2606:4700:3034::ac43:9518, 2606:4700:3032::6815:21c3 1 smtp.google.com agustin.ns.cloudflare.com, jill.ns.cloudflare.com
21analytics.ch 104.21.79.17, 172.67.140.9 2606:4700:3035::ac43:8c09, 2606:4700:3036::6815:4f11 Full Google Workspace set (aspmx.l + alt1-4) jill.ns.cloudflare.com, agustin.ns.cloudflare.com

Notes:

  • Both domains are fully proxied through Cloudflare — A records resolve to Cloudflare anycast (172.67.0.0/16, 104.21.0.0/16) and AAAA records to Cloudflare's IPv6 anycast (2606:4700::/32). Origin server IPs are not directly observable from external DNS.
  • Cloudflare + Google Trust Services cert pattern explained. The Step 2 finding (Google Trust Services issuer) is consistent with Cloudflare-proxied hosting: Cloudflare uses Google Trust Services as one of their Universal SSL CA partners. The certs are issued at Cloudflare's edge, not from a separately-hosted Google Cloud origin.
  • Email infrastructure: Google Workspace for both domains. 21analytics.co has a minimal single-MX setup (smtp.google.com); 21analytics.ch has the full Google Workspace MX configuration (priority 1, 5, 5, 10, 10). The simpler .co setup is consistent with its recent registration date (Dec 2025) and lighter operational use.
  • No shared infrastructure with known surveillance vendors. Cloudflare anycast is shared with millions of sites globally so this is not a meaningful signal; what would be a meaningful signal — surveillance-vendor nameservers, or unusual MX providers — is absent.
  • Operational profile confirmed. Modern Swiss startup using Google Workspace + Cloudflare DNS/proxy. Routine infrastructure choices, not surveillance-vendor-shaped.

Conclusion: Findings reinforce the EXCLUDED verdict. No production cloud surveillance API surface visible at the DNS layer.


Step 4 — Behavioral Evidence — COMPLETE (vendor documentation route)

Per Contributor Guide v1.4 §4.4, vendor-documentation route applied. Evidence:

Product architecture (from 21analytics.co):

"Because 21 Travel Rule is a on-premise solution, our security program is focused on delivering verifiable, tamper-proof, and resilient software to your infrastructure." "Privacy by Design: 100% On-Premise. Zero telemetry, ensuring you retain absolute data sovereignty."

Self-positioning (from same source):

"21 Analytics is the only provider giving VASPs full control over their Travel Rule data and compliance program."

Corporate origins (from blog and AOPP history page):

"Founded by Bitcoiners who have been working in the blockchain industry since 2014, 21 Analytics leverages its experience to advance the idea of combining compliance with data protection."

Pro-privacy product origin (AOPP):

"When Switzerland first enforced the Travel Rule, we realised that proving wallet ownership would become a major usability challenge for both CASPs and customers. We built AOPP to make this process as seamless and privacy-preserving as possible, staying true to Bitcoin's values while ensuring compliance." — Lucas Betschart, COO & Co-Founder

AOPP (Address Ownership Proof Protocol) is the only standardized self-hosted wallet verification method that does not require Satoshi-Test on-chain transactions or visual proof manual review. It is implemented in many privacy-respecting wallets (including BlueWallet, Sparrow, Wasabi historically) and is a pro-privacy contribution to the ecosystem.

Corporate identity: - HQ: Zug, Switzerland (Crypto Valley) - Founded: April 2020 - CEO: Lucas Betschart (also Co-Founder) - COO: Lucas Betschart (and Co-Founder) - Domains: 21analytics.ch (primary), 21analytics.co (secondary) - ISO 27001:2022 Certified

Step 5 — Privacy Harm Assessment

There is no documented user-layer privacy harm that DNS-level blocking would mitigate. The firm's product runs in VASP data centers, not on 21analytics.* cloud endpoints. When a Bitcoin user transacts with a VASP using 21 Travel Rule:

  1. The Travel Rule data exchange happens between two VASPs' on-premises 21 Analytics instances
  2. The user's device never queries 21analytics.ch or 21analytics.co
  3. 21 Analytics the company never sees the transaction data — it stays in the customers' infrastructure

Blocking 21analytics.ch or 21analytics.co at the DNS layer would prevent visits to the corporate website (marketing/documentation) but would NOT prevent any surveillance event involving the user's transactions.

Step 6 — Inclusion Criteria — DOES NOT MEET

Applying the six SatoshiShield inclusion criteria:

  • [ ] Blockchain Analytics firm — primary business is on-premises Travel Rule compliance software, not blockchain analytics
  • [ ] Address Screening API — no cloud screening API; product runs on customer infrastructure
  • [ ] IP-Logging Infrastructure — explicit "Zero telemetry" marketing claim; no documented IP logging
  • [ ] KYC/AML Intelligence — does provide AML-related software but as on-premises tools, not as cloud intelligence service
  • [ ] Wallet Telemetry — no consumer wallet integration; B2B VASP product
  • [ ] Deanonymization Platform — opposite positioning; created AOPP for privacy-preserving wallet verification

Zero of six criteria met. Surveillance-adjacent positioning (Travel Rule is fundamentally a KYC mechanism) is real, but does not translate to user-layer privacy harm that DNS blocking addresses.

Step 7 — Functional Impact Test — NOT REQUIRED

The conclusion is reached at Step 6 without requiring functional impact testing. The firm has no surveillance API surface to test against.

Pattern observations

21 Analytics establishes a second exclusion pattern distinct from the Whitestream pattern:

  • Whitestream pattern (training vendor): firm operates in the surveillance ecosystem but their product is training and methodology dissemination, not surveillance infrastructure
  • 21 Analytics pattern (on-premises software): firm operates surveillance-adjacent software but delivers it as on-premises product with zero telemetry, removing any direct user-layer query surface

Both patterns warrant exclusion from the blocklist under the criteria-first reading.

Future candidates in the Travel Rule / on-premises compliance space (e.g., Notabene, depending on architecture) should be evaluated against this pattern.

Verification status

Step Status Outcome
1. WHOIS ✓ Complete EXCLUDE reached at Step 6
2. SSL certificate ✓ Complete EXCLUDE reached at Step 6
3. SecurityTrails ✓ Complete EXCLUDE reached at Step 6
4. Behavioral evidence ✓ Complete Vendor self-documentation establishes on-premises model
5. Privacy harm ✓ Complete No user-layer query surface
6. Inclusion criteria ✓ Complete MEETS 0 of 6 CRITERIA — EXCLUDE
7. Functional impact test — Not required

Final verdict: EXCLUDED FROM BLOCKLIST. Record preserved as historical research artifact under the on-premises-software exclusion pattern.