> ## Documentation Index
> Fetch the complete documentation index at: https://docs.compliapi.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Introduction

> Real-time sanctions and financial-crime screening for developers

CompliAPI screens entities against multiple sanctions and financial-crime lists:

* **Onchain addresses** — crypto wallet addresses across ETH, BTC, XMR, USDT, and more (ENS names supported)
* **Email addresses** associated with sanctioned entities
* **Websites and domains** operated by sanctioned entities
* **Government-issued IDs** — passports, tax IDs, registration numbers (fuzzy matching)
* **Countries and regions** subject to comprehensive, targeted, or military sanctions
* **VPN detection** and **IP geolocation** with sanctioned-country flagging

## Source lists

| List | Publisher | Refresh |
| - | - | - |
| `ofac` | US Treasury OFAC SDN list | every 15 minutes |
| `ofac_consolidated` | US Treasury OFAC Consolidated (non-SDN) list — SSI, NS-MBS, NS-CMIC, NS-PLC and other non-SDN programs | every 15 minutes |
| `us_fbi_lazarus_crypto` | FBI — Lazarus Group crypto addresses (Stake.com theft) | static, reconciled daily |
| `il_mod_crypto` | Israel NBCTF administrative seizure orders | curated, reconciled daily |
| `fr_tresor` | French Trésor national asset-freeze register | daily |
| `jp_mof_sanctions` | Japan Ministry of Finance sanctions list | daily |
| `eu_fsf` | EU consolidated financial sanctions list | daily |
| `uk_fcdo_sanctions` | UK Sanctions List (FCDO) — the sole UK designation list since January 2026 | daily |
| `ransomwhere` | ransomwhe.re ransomware payment addresses (crime intelligence, not sanctions) | weekly |
| `tornado_cash` | Tornado Cash depositors & withdrawal relayers, extracted from Ethereum mainnet events (risk exposure, not sanctions) | daily on-chain crawl |
| `tornado_cash_recipients` | Tornado Cash withdrawal recipients (weak signal, disabled by default — see below) | daily on-chain crawl |

The [screening endpoints](/api/screen) (`/api/v1/screen/*`) check every enabled list in one call and name the list behind each match; `GET /api/v1/screen/lists` reports what's live.

A match on a **sanctions** list sets `sanctioned: true`. A match on a **crime** list (ransomwhe.re) or a **risk** list (Tornado Cash association) sets only `flagged: true` — it signals risk, not a government designation.

Ransomware payment data comes from [Ransomwhere](https://ransomwhe.re/) by Jack Cable (Cable, Jack. *Ransomwhere: A Crowdsourced Ransomware Payment Dataset*, Zenodo, [doi:10.5281/zenodo.13999026](https://doi.org/10.5281/zenodo.13999026)), used under [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/); addresses appear 90 days after submission. Tornado Cash itself was removed from the OFAC SDN list in March 2025, so its association lists are exposure intelligence, never sanctions hits.

<Warning>
  `tornado_cash_recipients` is a deliberately weak signal and ships disabled: since 2022, "dusting" attacks have sprayed small Tornado Cash withdrawals at prominent addresses that never opted in, so receiving a withdrawal is not evidence of intent. Depositor and relayer hits (`tornado_cash`) reflect active use of the mixer — though a depositor recorded via a smart-contract wallet or bundler identifies the contract, not necessarily the person behind it.
</Warning>

The API is served at `https://api.compliapi.com/api/v1` and is also available as an [MCP server](/mcp) for AI agents.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.