Investigations, evidence & reporting
Work alerts through to explained, evidenced outcomes.
ChainGuard structures the investigation workflow from a triggered alert through to a case, a timeline of what was known and when, and an evidence package that supports the eventual outcome.
Case lifecycle
Seven steps from a signal to a defensible outcome.
The reasoning behind an outcome should not depend on institutional memory. Each step below writes what it knew into the case.
Alert raised
A rule, a threshold or an analyst observation opens the question. The trigger itself is recorded.
Case opened
The alert becomes a working container that holds the customer, the addresses, the transfers and everything found since.
Entities resolved
Addresses and clusters are attributed to the counterparties behind them, on Bitcoin as on account-based networks.
Timeline assembled
What was known, and when it was known, reconstructed chronologically across the case.
Evidence package composed
Policy version, triggered rules, source facts, inferred intelligence, missing data and approvals, content-hashed together.
MLRO sign-off
The case routes to the money laundering reporting officer with the full evidence trail attached.
Dossier prepared
A suspicious transaction or activity report is assembled from the same case data used throughout, without re-keying.
Capabilities
Grouped by what the analyst is actually doing.
Working the case
- Alerts
- Cases
- Entities
- Timeline
Building the record
- Evidence packages
- Explanations
- Legal hold
Reporting out
- Regulatory dossiers
- MLRO workflow
- Report preparation
- Reporting exports
External regulatory filing remains a controlled, human-authorized action.
ChainGuard assembles the dossier and preserves the record. It does not submit on your behalf, and it does not represent a prepared dossier as a filed one.
Bring investigations and evidence into one auditable workflow.
Map ChainGuard to your institution’s transaction, policy and evidence workflows.