Public sanitized verification record. A research artifact from the SatoshiShield project, published to show the verification methodology applied to each candidate domain. Internal lab infrastructure has been redacted. Not legal or financial advice.
Allium — Verification Record
VERDICT: EXCLUDED FROM BLOCKLIST.
Allium (Allium Labs, Inc.) is a US-based enterprise blockchain data infrastructure firm founded late 2021 by ex-Primer and ex-Meta engineers. The primary product is a blockchain data warehouse delivered into customers' Snowflake, BigQuery, or Databricks instances — not a cloud surveillance API queried by user-side devices. Customers include Visa, Stripe, Phantom, Coinbase, Uniswap, and Paradigm.
There is surveillance-adjacent functionality (Allium Datastreams power "fraud detection and monitoring"), but the architecture means no direct user-layer privacy harm that DNS-level blocking can mitigate. This is a variant of the 21 Analytics / Whitestream exclusion pattern.
Why it was evaluated
Allium surfaced as a Tier 2 candidate during research into the enterprise blockchain data ecosystem. Several characteristics made the firm worth investigating:
- Real-time blockchain data infrastructure with surveillance use cases marketed
- Customer base includes major payment and exchange firms (Visa, Stripe, Coinbase)
- Datastreams product explicitly markets fraud detection capabilities
- Active funding ($21.5M raised) and rapid growth — likely to become more prominent
Step 1 — WHOIS Lookup — ✓ Complete
Tool used: whois CLI
Findings:
| Field | Value |
|---|---|
| Registrar | NameCheap Inc. (US, Phoenix AZ) |
| Creation date | 2022-03-03 |
| Expiry | 2027-03-03 |
| Last updated | 2026-02-01 |
| Registrant | Redacted — Privacy service via Withheld for Privacy ehf (Reykjavik, Iceland) |
| Nameservers | arya.ns.cloudflare.com, sage.ns.cloudflare.com |
| DNSSEC | unsigned |
| TLD | .SO (Somalia ccTLD — used for branding, not jurisdictional signal) |
Notes:
- Registrant is privacy-shielded via Withheld for Privacy ehf, NameCheap's default Iceland-based privacy proxy. WHOIS does not directly identify Allium Labs Inc. as the operator. Corporate identity must come from the SSL certificate (Step 2) and public records, not WHOIS.
- Domain age 4+ years — registered March 2022, a few months after the company's reported late-2021 founding. Consistent with a startup acquiring a branded domain shortly after incorporation. Not a recently-registered domain (which would be a higher signal of infrastructure rotation).
- Infrastructure pattern is routine US startup — NameCheap registrar + Cloudflare DNS + privacy proxy is the default stack for tech startups in 2022-2026. Same overall shape as 21 Analytics, with a different Cloudflare NS pair (
arya,sage) — normal, since Cloudflare assigns NS pairs from a pool. - .SO TLD is a branding choice, not a jurisdictional one. "allium.so" parses as a clean four-letter brand on a short ccTLD. The company is publicly reported as NYC-based.
Conclusion: WHOIS findings are consistent with the EXCLUDED verdict. No surprise corporate registration, no surveillance-vendor pattern. Privacy proxy is standard for startups and not itself a signal of concealment.
Step 2 — SSL Certificate Inspection — ✓ Complete
Tool used: openssl s_client for live certificate inspection. crt.sh historical lookup deferred — crt.sh was returning 502 errors at the time of verification; not material to the EXCLUDED verdict.
Findings:
| Field | Value |
|---|---|
| Issuer | C=US, O=Google Trust Services, CN=WE1 |
| Subject | CN=allium.so |
| Subject Alternative Names | allium.so, www.allium.so |
| Not After | 2026-08-13 |
Notes:
- CA: Google Trust Services, same pattern as 21 Analytics. Consistent with Cloudflare-proxied hosting — Cloudflare uses Google Trust Services as one of their Universal SSL CA partners. The cert is provisioned at Cloudflare's edge, not from a separately-hosted Google Cloud origin.
- No corporate identity in cert. Subject is the bare
CN=allium.sowith noO=field for "Allium Labs Inc." Normal for Cloudflare-proxied sites; edge certs typically don't carry the customer's organization name. - No surveillance-product subdomains in SANs. The cert covers only the apex and
www— noapi.*,screening.*,monitor.*,data.*,compliance.*, orcustomer.*subdomain pattern that would indicate a public surveillance API surface. This is consistent with Allium's product delivery model: data is pushed into customer-controlled cloud data warehouses (Snowflake/BigQuery/Databricks/ClickHouse), not exposed via a public scoring or screening endpoint. - No wildcard in the cert. Cloudflare Universal SSL provisions per-hostname certs by default, so the absence of
*.allium.sois expected. Other hostnames (e.g. internal app/console) would have separate certs not visible from this query.
Conclusion: SSL findings reinforce the EXCLUDED verdict. The cert reveals no public surveillance API surface — consistent with Allium's documented data-warehouse delivery model, which does not require operating a hosted screening/scoring/attribution endpoint.
Step 3 — SecurityTrails / Passive DNS — ✓ Complete
Tool used: dig CLI for current DNS records (A, AAAA, MX). NS records already captured in Step 1 WHOIS. SecurityTrails historical lookup deferred — free tier locked behind login as of May 2026; not material to the EXCLUDED verdict.
Findings:
| Record | Value |
|---|---|
| A | 104.18.12.30, 104.18.13.30 |
| AAAA | 2606:4700::6812:d1e, 2606:4700::6812:c1e |
| MX | 1 aspmx.l.google.com; 5 alt1/alt2.aspmx.l.google.com; 10 aspmx2/aspmx3.googlemail.com |
| NS | arya.ns.cloudflare.com, sage.ns.cloudflare.com (from Step 1) |
Notes:
- Fully Cloudflare-proxied. A records resolve to Cloudflare anycast (104.18.0.0/16) and AAAA to Cloudflare's IPv6 anycast (2606:4700::/32). Origin server IPs are not directly observable from external DNS. Same proxy pattern as 21 Analytics, with different IP allocations from Cloudflare's anycast pool — not a meaningful difference.
- Email infrastructure: Google Workspace. Full standard MX setup with primary
aspmx.l.google.com(priority 1),alt1/alt2secondaries (priority 5), andaspmx2/aspmx3.googlemail.comtertiaries (priority 10). Thegooglemail.comsecondaries are the older Google Workspace MX pattern, consistent with a domain set up some years ago (matches the 2022 registration date). - No shared infrastructure with known surveillance vendors. Cloudflare anycast and Google Workspace MX are shared with millions of sites globally and are not meaningful signals. What would be a meaningful signal — surveillance-vendor nameservers, unusual MX providers, or co-resolution with known surveillance firm IPs — is absent.
- Operational profile confirmed. US-based data-warehouse startup using Cloudflare DNS/proxy + Google Workspace. Standard infrastructure stack for a venture-backed B2B tech company, not surveillance-vendor-shaped.
Conclusion: Findings reinforce the EXCLUDED verdict. No production cloud surveillance API surface visible at the DNS layer. Infrastructure is fully consistent with the B2B-data-infrastructure exclusion pattern (data delivered into customer-controlled warehouses, not via a hosted screening/attribution endpoint).
Step 4 — Behavioral Evidence — COMPLETE (vendor documentation route)
Per Contributor Guide v1.4 §4.4, vendor-documentation route applied.
Product architecture (from allium.so and partner documentation):
"Allium delivers blockchain data into Snowflake, BigQuery, and Databricks." (Confluent partner page) "Allium Datashares is a direct data warehouse integration that streams on-chain data directly into organizations' internal Snowflake, BigQuery, or Databricks environments for complete control and flexibility." (Allium blog) "Three product lines as of 2026: Allium Data (warehouse drops, batch), Allium Datastreams (real-time event streams), and Allium Explorer (a hosted UI for ad-hoc queries, the closest thing to Dune in their stack)."
Customer pattern (from allium.so/about-us):
"Today, we power analytics and mission-critical infrastructure for teams like Visa, Stripe, Phantom, Coinbase, Uniswap, and Grayscale, turning blockchain's raw exhaust into usable, trustworthy records of economic activity."
Surveillance-adjacent positioning (from product page):
"Allium Datastreams deliver enriched blockchain events that power real-time monitoring and fraud detection across wallets, exchanges, and DeFi platforms. Teams use Allium to flag suspicious transfers, detect compromised accounts, and track abnormal trading patterns with instant alerts and reliable data feeds."
Corporate identity: - HQ: New York City; team in Singapore and remote - Founded: late 2021 - Founders: Ethan (ex-Primer ML/analytics lead), Cheng Han (ex-Meta payments, ex-Poynt) - Funding: $21.5M raised (Kleiner Perkins, Bain Capital Crypto, Theory Ventures) - Team size: 50+ - Legal entity: Allium Labs, Inc.
Step 5 — Privacy Harm Assessment
The user-layer privacy harm analysis turns on whether end-user devices query allium.so directly.
Architecture analysis:
When a Bitcoin user interacts with one of Allium's customers (e.g., Phantom wallet, Coinbase, Uniswap), the user's device queries the customer's product (e.g., Phantom's backend). The customer's backend may then query Allium internally. The DNS path from user device → Allium does not exist in this flow.
The only direct user-side queries to allium.so would be:
1. Developer visiting allium.so to read documentation (not a typical Bitcoin user)
2. Customer staff using Allium Explorer (web UI for ad-hoc queries)
3. Some hypothetical wallet that embeds Allium SDK directly (not documented)
None of these represent the standard Tier 1 IP-logging pattern. The surveillance event (Phantom logging user activity) happens at the wallet operator, not via Allium.
Step 6 — Inclusion Criteria — DOES NOT MEET CLEARLY
Applying the six SatoshiShield inclusion criteria:
- [ ] Blockchain Analytics firm — primary product is data infrastructure (warehouse + streams), not analytics
- [ ] Address Screening API — Developer API exists but is SQL/batch oriented, not real-time screening
- [ ] IP-Logging Infrastructure — API exists but enterprise-focused; not consumer-facing
- [ ] KYC/AML Intelligence — not a compliance product
- [ ] Wallet Telemetry — not a wallet integration target
- [ ] Deanonymization Platform — not positioned as identity attribution
Zero of six criteria clearly met. The closest match is "Blockchain Analytics" via the fraud-detection positioning of Datastreams, but the architecture (delivery into customer warehouses) means no direct user-layer query surface.
Step 7 — Functional Impact Test — NOT REQUIRED
Conclusion reached at Step 6 without requiring functional testing. No expected user-side queries to allium.so to test against.
Pattern observations
Allium establishes a third exclusion pattern distinct from Whitestream and 21 Analytics:
- Whitestream pattern (training vendor): surveillance-adjacent but the product is methodology dissemination
- 21 Analytics pattern (on-premises software): surveillance-adjacent but delivered as on-premises product with zero telemetry
- Allium pattern (B2B data infrastructure): surveillance-adjacent but delivered as data warehouse drops into customer-owned analytics infrastructure
Future candidates in the enterprise blockchain data infrastructure space (Dune Analytics, Coin Metrics, Kaiko, etc.) should be evaluated against this pattern.
Verification status
| Step | Status | Outcome |
|---|---|---|
| 1. WHOIS | ✓ Complete | EXCLUDE reached at Step 6 |
| 2. SSL certificate | ✓ Complete | EXCLUDE reached at Step 6 |
| 3. SecurityTrails | ✓ Complete | EXCLUDE reached at Step 6 |
| 4. Behavioral evidence | ✓ Complete | Vendor self-documentation establishes B2B data warehouse architecture |
| 5. Privacy harm | ✓ Complete | No direct user-layer query surface |
| 6. Inclusion criteria | ✓ Complete | MEETS 0 of 6 CRITERIA — EXCLUDE |
| 7. Functional impact test | — Not required | — |
Final verdict: EXCLUDED FROM BLOCKLIST. Record preserved as historical research artifact under the B2B-data-infrastructure exclusion pattern.