The architecture

Eight modules, three layers.

Every module draws on the same foundation. Intelligence flows up from every chain and data source, into an explainable scoring engine, into autonomous agents that work the case, with your team in control at the top.

01
Foundation
The intelligence layer

Every major chain, read directly and normalized into one feed: balances, transfers, DeFi positions, plus the sanctions, threat, and identity signals that give each address context. Vendor-neutral, so no single source is a blind spot.

10+ blockchains RPC DeFi positions Balances & transfers Sanctions & watchlists Threat intelligence Token security Off-chain identity Device fingerprint
02
Engine
Explainable risk scoring

Hard-veto, then capped per-source layers, then an ML modifier, then Identity Hub context, with taint inherited across chains. Every point of the score traces back to the source that produced it. No black box.

Hard-veto Per-source caps ML ensemble Identity Hub Cross-chain taint Full audit trail
03
Agentic AI
Agents that work the case

Autonomous agents triage alerts, investigate end to end across on-chain and off-chain signals, and draft the regulatory filing with citations. Every file / freeze / block passes through a human-in-the-loop gate.

Triage agent Investigation agent Monitoring agent SAR drafting Human-in-the-loop MCP tools
Signal flows up · explanations flow back down
Core · 01

Real-time transaction monitoring.

The core engine. Every payment, transfer, and authorization gets scored against learned baselines as it happens. Cross-chain and off-chain transactions go through the same pipeline. The decision comes back with the full signal trail your audit team can defend.

Sub-200ms scoring at production load
Block, step-up, or release decisions with human-readable explanations
Unified context across cards, ACH, SEPA, wires, and on-chain transfers
Per-tenant model isolation, no data leakage between customers
See it in your environment
blockevt_9f4a2b71 · ATO velocity€ 12,400
passevt_9f4a2b70 · clean€ 89.50
step-upevt_9f4a2b6f · location€ 3,200
blockevt_9f4a2b6e · synth ID€ 5,700
passevt_9f4a2b6d · clean€ 245.00
passevt_9f4a2b6c · recurring€ 47.80
02 · Onboarding

Synthetic identity defense.

Fake IDs are no longer hand-made. They're generated, blended, and tested at scale. We catch them at signup, before they touch your card issuer, your KYC partner, your customer support. Liveness, document forensics, and behavioral signals combined into a single score.

Liveness verification resistant to deepfake video
Document tampering and forgery detection
Cross-application identity correlation
Synthetic identity scoring with confidence interval
See it in your environment
Application #4892flagged
Document typeRO passport
Liveness score0.31 (low)
Document forensicspassed
Identity correlation3 similar
Synth score0.83
→ RECOMMENDED: block + manual review
03 · Access

Account takeover defense.

A stolen credential is the cheapest fraud vector in 2026. We watch the session itself, not just the login. Typing cadence, device posture, navigation path, network telemetry. The intruder behaves differently than the rightful owner, and we score that difference in real time.

Credential stuffing detection at the edge
Session hijacking and SIM swap signals
Behavioral biometrics without intrusive UX
Step-up authentication triggers integrated with your auth provider
See it in your environment
SESSION INTEGRITY
typing cadence ✓
device posture ✓
network telemetry ✓
04 · Cyber

Bot & agentic defense.

Bots used to be scripts. Now they're autonomous agents with goals, memory, and the ability to adapt mid-session. Telling them apart from human users is no longer optional, especially as agentic commerce scales. We classify every session as human, bot, or autonomous agent, with confidence.

Headless browser and emulator detection
Agentic AI classification (LLM-driven sessions)
Coordinated botnet pattern recognition
Allowlist for sanctioned AI agents (your own bots)
See it in your environment
SESSION CLASSIFICATION · LAST HOUR
human bot agent
05 · Network

Fraud ring detection.

A single fraudulent transaction is hard to catch. A coordinated ring is easier to see. We build a graph of relationships between accounts, devices, IPs, payment methods, and counterparties. When the same device fingerprint opens fifty accounts across three days, you see it before they drain anything.

Device fingerprint clustering across customer accounts
Mule network identification through transfer patterns
Cross-platform correlation (off-chain to on-chain)
Interactive investigation graph for your fraud team
See it in your environment
HUB
06 · On-chain

On-chain forensics.

Score any wallet, then follow the money. Vector traces where funds came from and where they're going, propagates taint upstream and downstream, and tags every counterparty by exchange, VASP, mixer, or sanctions exposure. One investigation surface across every chain you touch, with a scoring trail your compliance team can defend line by line.

Explainable wallet risk scoring: every source and factor shown, no black box
Fund-flow provenance: trace tainted value upstream and downstream across hops
Transaction ledger with VASP, sanctions, and mixer tags on each counterparty
Cross-chain taint inheritance across Bitcoin, EVM chains, and Solana
See it in your environment
PROVENANCE TRACE · 0x9c4f…a71b
taintedsource · sanctioned mixer18.4 ETH
hop 1peel chain · 4 wallets17.9 ETH
hop 2bridge · EVM → Solana16.1 ETH
cash-outVASP · KYC exchange15.8 ETH
→ 86% of inflow traces to tainted origin
07 · Prevention

Pre-send protection.

The best fraud response is the payment that never leaves. Address-poisoning and look-alike drainer attacks seed a victim's history with a wallet that mimics a trusted counterparty, matching its first and last characters, so the next copy-paste sends funds to the attacker. Our verify-recipient API checks the destination against the payer's real transaction history in real time and returns allow, warn, or block before the transaction is ever signed.

Look-alike and address-poisoning detection on prefix + suffix collisions
Verify-recipient API returns allow / warn / block at the send screen
Counterparty history and counterfeit-token bait detection
Grounded in peer-reviewed on-chain phishing research (arXiv:2501.16681)
See it in your environment
Verify recipientblock
Sending to0x441c…9c7e
Looks like0x441c…3fdf
Recipient history2 tx · fresh
Paid beforenever
→ look-alike of a wallet you trust · do not send
08 · Agentic AI

Agentic AI analysts.

ISOFORT doesn't just score events, it works them. Autonomous AI agents triage alerts, investigate cases end to end across on-chain and off-chain signals, and draft the regulatory filing with citations back to the evidence. Every action that touches a regulated decision (file, freeze, block) passes through a human-in-the-loop gate, so your team stays in control and the audit trail stays clean.

Triage, investigation, and monitoring agents that run continuously
One-click SAR narrative drafting, cited back to the underlying signals
Human-in-the-loop approval on every file / freeze / block action
Model Context Protocol (MCP) tools to wire agents into your own stack
See it in your environment
INVESTIGATION AGENT · case_4f2a
donepulled 1,284 transfers · 4 chains
donetraced taint to sanctioned origin
donedrafted SAR narrative · 6 citations
waithuman approval · freeze request
→ awaiting analyst sign-off
Integrations

Plugs into the stack you already run.

SDKs for every major platform, REST and gRPC APIs, real-time webhooks, native connectors for payment rails and chains.

Stripe
Adyen
Bitcoin
EVM chains
Solana
SEPA
SWIFT
AWS
GCP
Azure
REST API
Webhooks
Get started

See the platform
in your environment.

30 minutes, no slides. We bring your real attack vectors and walk through the response.