Public sanitized verification record. A research artifact from the SatoshiShield project, published to show the verification methodology applied to each candidate domain. Internal lab infrastructure has been redacted. Not legal or financial advice.
21 Analytics — Verification Record
VERDICT: EXCLUDED FROM BLOCKLIST.
21 Analytics is a Swiss Travel Rule compliance vendor headquartered in Zug. Their main product (21 Travel Rule) is delivered as on-premises software with zero telemetry running inside customer (VASP) data centers. There is no cloud surveillance API surface that user-side devices could query, and the firm's own product page explicitly markets "100% On-Premise. Zero telemetry, ensuring you retain absolute data sovereignty."
This is the Whitestream pattern: surveillance-adjacent in the broader compliance ecosystem, but no direct user-layer privacy harm that DNS-level blocking can prevent.
Why it was evaluated
21 Analytics surfaced as a Tier 2 candidate during research into the Travel Rule / VASP-to-VASP compliance ecosystem. Several characteristics made the firm worth investigating:
- Compliance vendor with explicit FATF Travel Rule positioning
- Partners with confirmed Tier 1 firms (Coinfirm/Lukka, Global Ledger) for blockchain analytics integration
- VASP-facing product for transaction screening
- Two active domains (
21analytics.ch,21analytics.co)
Step 1 — WHOIS lookup — ✓ Complete
Tool used: whois CLI; Swiss registry browser form for .ch (CLI-blocked)
Findings per domain:
| Domain | Created | Registrar | Nameservers | Registrant geo | Lock status |
|---|---|---|---|---|---|
| 21analytics.co | 2025-12-22 | Cloudflare, Inc. | agustin.ns.cloudflare.com jill.ns.cloudflare.com |
CH (Zug) — Cloudflare privacy proxy | clientTransferProhibited |
| 21analytics.ch | n/a — CLI blocked by SWITCH registry | — (use https://www.nic.ch/whois/ to complete) | — | — | — |
Notes:
- 21analytics.co is a recent secondary domain — registered December 22, 2025, only ~5 months before this verification. The firm was founded April 2020, so 21analytics.ch is the original primary domain. The .co hosts marketing and blog content; .ch hosts the corporate primary.
- 21analytics.ch WHOIS via CLI returns only TLD-level metadata; the SWITCH registry restricts CLI WHOIS access. Domain-specific lookup requires the browser form at https://www.nic.ch/whois/. Completion of this lookup is optional given the EXCLUDED verdict reached at Step 6.
- Geography: registrant country CH, state Zug — consistent with the Step 4 corporate identity statement.
- Privacy redaction: standard Cloudflare privacy proxy pattern; not a surveillance signal.
- DNSSEC: signedDelegation on .co.
Conclusion: No new surveillance signal from registration metadata. Findings reinforce the Step 4 corporate identity and do not alter the EXCLUDED verdict.
Step 2 — SSL Certificate — ✓ Complete
Tool used: openssl s_client for live cert inspection. crt.sh historical CT enumeration deferred — crt.sh returned 502 during verification window. Can be backfilled in a future audit cycle if material new subdomains are suspected.
Findings per domain:
| Domain | Subject CN | Issuer | DNS SANs |
|---|---|---|---|
| 21analytics.co | 21analytics.co | C=US, O=Google Trust Services, CN=WE1 | 21analytics.co |
| 21analytics.ch | 21analytics.ch | C=US, O=Google Trust Services, CN=WE1 | 21analytics.ch, *.21analytics.ch |
Notes:
- Both certs issued by Google Trust Services (WE1) — Google's commercial CA, typically used by sites on Google Cloud Platform or via Google Workspace integrations. Notable because the WHOIS shows Cloudflare as registrar and nameserver: this means Cloudflare provides DNS only, with actual web hosting on Google Cloud infrastructure. Standard split for European startups; not a surveillance signal.
- 21analytics.ch carries a wildcard SAN (
*.21analytics.ch) authorizing any subdomain under the same cert. Normal for an established corporate site with marketing/blog subdomains. - 21analytics.co has no wildcard, only the root in SANs. Consistent with the newer (Dec 2025) registration — less subdomain sprawl yet.
- No surveillance-product-shaped subdomains in either cert's SANs. No
api.*,screening.*,monitor.*,data.*,customer.*, orapp.*. This is the key check, and it passes cleanly: the on-premises product model from Step 4 is corroborated by the cert SAN structure.
Conclusion: Findings reinforce the EXCLUDED verdict. No cloud surveillance API surface detected via live cert inspection. The Google Trust Services + Cloudflare DNS pattern is routine European-startup infrastructure, not surveillance-vendor-shaped.
Step 3 — SecurityTrails / Passive DNS — ✓ Complete
Tool used: dig CLI for current DNS records (A, AAAA, MX, NS). SecurityTrails historical lookup deferred — free tier locked behind login as of May 2026; not material to the EXCLUDED verdict.
Findings per domain:
| Domain | A records | AAAA records | MX | NS |
|---|---|---|---|---|
| 21analytics.co | 172.67.149.24, 104.21.33.195 | 2606:4700:3034::ac43:9518, 2606:4700:3032::6815:21c3 | 1 smtp.google.com | agustin.ns.cloudflare.com, jill.ns.cloudflare.com |
| 21analytics.ch | 104.21.79.17, 172.67.140.9 | 2606:4700:3035::ac43:8c09, 2606:4700:3036::6815:4f11 | Full Google Workspace set (aspmx.l + alt1-4) | jill.ns.cloudflare.com, agustin.ns.cloudflare.com |
Notes:
- Both domains are fully proxied through Cloudflare — A records resolve to Cloudflare anycast (172.67.0.0/16, 104.21.0.0/16) and AAAA records to Cloudflare's IPv6 anycast (2606:4700::/32). Origin server IPs are not directly observable from external DNS.
- Cloudflare + Google Trust Services cert pattern explained. The Step 2 finding (Google Trust Services issuer) is consistent with Cloudflare-proxied hosting: Cloudflare uses Google Trust Services as one of their Universal SSL CA partners. The certs are issued at Cloudflare's edge, not from a separately-hosted Google Cloud origin.
- Email infrastructure: Google Workspace for both domains. 21analytics.co has a minimal single-MX setup (
smtp.google.com); 21analytics.ch has the full Google Workspace MX configuration (priority 1, 5, 5, 10, 10). The simpler .co setup is consistent with its recent registration date (Dec 2025) and lighter operational use. - No shared infrastructure with known surveillance vendors. Cloudflare anycast is shared with millions of sites globally so this is not a meaningful signal; what would be a meaningful signal — surveillance-vendor nameservers, or unusual MX providers — is absent.
- Operational profile confirmed. Modern Swiss startup using Google Workspace + Cloudflare DNS/proxy. Routine infrastructure choices, not surveillance-vendor-shaped.
Conclusion: Findings reinforce the EXCLUDED verdict. No production cloud surveillance API surface visible at the DNS layer.
Step 4 — Behavioral Evidence — COMPLETE (vendor documentation route)
Per Contributor Guide v1.4 §4.4, vendor-documentation route applied. Evidence:
Product architecture (from 21analytics.co):
"Because 21 Travel Rule is a on-premise solution, our security program is focused on delivering verifiable, tamper-proof, and resilient software to your infrastructure." "Privacy by Design: 100% On-Premise. Zero telemetry, ensuring you retain absolute data sovereignty."
Self-positioning (from same source):
"21 Analytics is the only provider giving VASPs full control over their Travel Rule data and compliance program."
Corporate origins (from blog and AOPP history page):
"Founded by Bitcoiners who have been working in the blockchain industry since 2014, 21 Analytics leverages its experience to advance the idea of combining compliance with data protection."
Pro-privacy product origin (AOPP):
"When Switzerland first enforced the Travel Rule, we realised that proving wallet ownership would become a major usability challenge for both CASPs and customers. We built AOPP to make this process as seamless and privacy-preserving as possible, staying true to Bitcoin's values while ensuring compliance." — Lucas Betschart, COO & Co-Founder
AOPP (Address Ownership Proof Protocol) is the only standardized self-hosted wallet verification method that does not require Satoshi-Test on-chain transactions or visual proof manual review. It is implemented in many privacy-respecting wallets (including BlueWallet, Sparrow, Wasabi historically) and is a pro-privacy contribution to the ecosystem.
Corporate identity: - HQ: Zug, Switzerland (Crypto Valley) - Founded: April 2020 - CEO: Lucas Betschart (also Co-Founder) - COO: Lucas Betschart (and Co-Founder) - Domains: 21analytics.ch (primary), 21analytics.co (secondary) - ISO 27001:2022 Certified
Step 5 — Privacy Harm Assessment
There is no documented user-layer privacy harm that DNS-level blocking would mitigate. The firm's product runs in VASP data centers, not on 21analytics.* cloud endpoints. When a Bitcoin user transacts with a VASP using 21 Travel Rule:
- The Travel Rule data exchange happens between two VASPs' on-premises 21 Analytics instances
- The user's device never queries
21analytics.chor21analytics.co - 21 Analytics the company never sees the transaction data — it stays in the customers' infrastructure
Blocking 21analytics.ch or 21analytics.co at the DNS layer would prevent visits to the corporate website (marketing/documentation) but would NOT prevent any surveillance event involving the user's transactions.
Step 6 — Inclusion Criteria — DOES NOT MEET
Applying the six SatoshiShield inclusion criteria:
- [ ] Blockchain Analytics firm — primary business is on-premises Travel Rule compliance software, not blockchain analytics
- [ ] Address Screening API — no cloud screening API; product runs on customer infrastructure
- [ ] IP-Logging Infrastructure — explicit "Zero telemetry" marketing claim; no documented IP logging
- [ ] KYC/AML Intelligence — does provide AML-related software but as on-premises tools, not as cloud intelligence service
- [ ] Wallet Telemetry — no consumer wallet integration; B2B VASP product
- [ ] Deanonymization Platform — opposite positioning; created AOPP for privacy-preserving wallet verification
Zero of six criteria met. Surveillance-adjacent positioning (Travel Rule is fundamentally a KYC mechanism) is real, but does not translate to user-layer privacy harm that DNS blocking addresses.
Step 7 — Functional Impact Test — NOT REQUIRED
The conclusion is reached at Step 6 without requiring functional impact testing. The firm has no surveillance API surface to test against.
Pattern observations
21 Analytics establishes a second exclusion pattern distinct from the Whitestream pattern:
- Whitestream pattern (training vendor): firm operates in the surveillance ecosystem but their product is training and methodology dissemination, not surveillance infrastructure
- 21 Analytics pattern (on-premises software): firm operates surveillance-adjacent software but delivers it as on-premises product with zero telemetry, removing any direct user-layer query surface
Both patterns warrant exclusion from the blocklist under the criteria-first reading.
Future candidates in the Travel Rule / on-premises compliance space (e.g., Notabene, depending on architecture) should be evaluated against this pattern.
Verification status
| Step | Status | Outcome |
|---|---|---|
| 1. WHOIS | ✓ Complete | EXCLUDE reached at Step 6 |
| 2. SSL certificate | ✓ Complete | EXCLUDE reached at Step 6 |
| 3. SecurityTrails | ✓ Complete | EXCLUDE reached at Step 6 |
| 4. Behavioral evidence | ✓ Complete | Vendor self-documentation establishes on-premises model |
| 5. Privacy harm | ✓ Complete | No user-layer query surface |
| 6. Inclusion criteria | ✓ Complete | MEETS 0 of 6 CRITERIA — EXCLUDE |
| 7. Functional impact test | — Not required | — |
Final verdict: EXCLUDED FROM BLOCKLIST. Record preserved as historical research artifact under the on-premises-software exclusion pattern.