[
  {
    "id": 102,
    "slug": "bitrefill",
    "domain": "bitrefill.com",
    "name": "Bitrefill",
    "type": "Gift Cards",
    "cat": "gift",
    "kyc": "light",
    "kycLevel": 1,
    "fees": {
      "transaction": 2
    },
    "limits": {
      "daily": 10000
    },
    "features": [
      "AU Visa Digital",
      "170+ Countries",
      "Lightning",
      "eSIMs",
      "Instant"
    ],
    "networks": [],
    "badge": "POPULAR",
    "url": "https://www.bitrefill.com/",
    "geo": [
      "GLOBAL",
      "US",
      "UK",
      "EU",
      "AU",
      "IN",
      "CA",
      "SG",
      "ZA",
      "NG",
      "KE",
      "BR",
      "AR",
      "MX"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": true,
    "countries": [
      "US",
      "UK",
      "EU",
      "AU",
      "IN",
      "CA",
      "SG",
      "ZA",
      "NG",
      "KE",
      "BR",
      "AR",
      "MX"
    ],
    "categories": [
      "Gift Cards",
      "Agent Money"
    ],
    "description": "Sells gift cards, mobile top-ups, eSIMs and bill payments for crypto, with Airfill Prepaid AB named in its terms.",
    "cardSummary": "Gift cards, top-ups and eSIMs bought with crypto.",
    "jurisdiction": "SE",
    "auditedBy": null,
    "founderIntel": null,
    "vcIntel": null,
    "tagline": "A custodial or semi-custodial financial service.",
    "kycNote": "Terms state suspicious transactions may require KYC to continue using gift-card/top-up services; verified accounts are required for some bill/card products and processors may collect identity data.",
    "affiliate": "",
    "updatedAt": "2026-08-25",
    "fee": "2%",
    "stateActorFlag": null,
    "privacyWarning": "Bitrefill monitors platform use for compliance and can collect account, email, purchase, payment, IP and verification data. Public reporting says a March 2026 breach exposed about 18,500 purchase records, including email, crypto-payment-address and IP metadata; about 1,000 records also included customer names.",
    "followTheMoney": "  Bitrefill AB - Stockholm, Sweden (SE)\n  ──────────────────────────────────────\n  CEO: Sergej Kotliar · Founded: 2014\n  Funding: $2M seed (2019)\n  Investors: Fulgur, Draper, Boost VC\n  Revenue: ~2% markup on gift cards\n  ├─ Swedish jurisdiction (GDPR)\n  ├─ Fulgur: Kaspersky-background co-founder\n  └─ Account required: collects purchase data",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "https://help.bitrefill.com/hc/en-us/articles/36440135758738-How-Strong-Customer-Authentication-SCA-requirements-apply-to-the-Bitrefill-Card",
    "jurisdictionConfidence": "verified",
    "agentMoney": {
      "compatible": true,
      "controlSurfaces": [
        "api",
        "mcp",
        "dashboard",
        "manual"
      ],
      "protocols": [
        "mcp",
        "merchant-api",
        "gift-card"
      ],
      "authorizationModel": [
        "api-key",
        "account-permission",
        "human-approval",
        "merchant-lock"
      ],
      "settlementRail": [
        "crypto",
        "lightning",
        "gift-card"
      ],
      "autonomyLevel": 2,
      "custodyModel": "merchant-credit",
      "spendLimits": false,
      "merchantLock": true,
      "categoryLock": false,
      "pauseClose": false,
      "transactionWebhooks": false,
      "fundingSource": "crypto-funded",
      "identitySurface": "light-kyc",
      "dataPath": [
        "AI agent",
        "Bitrefill API/MCP or account",
        "crypto or Lightning payment",
        "Bitrefill order record",
        "gift card or top-up issuer",
        "merchant redemption"
      ],
      "notes": "Useful for automated gift-card, eSIM, top-up, and bill-payment purchases through API/MCP surfaces, but not anonymous: account, order, payment, issuer, and redemption metadata can remain linkable.",
      "protocolPrivacyNotes": "Treat the API/MCP account as an identity-bearing control plane. Crypto funding can reduce bank-card exposure, but order history, redemption records, account metadata, and merchant behavior still form a durable trail.",
      "mandateLoggingRisk": "high",
      "revocationQuality": "partial",
      "sourceLinks": [
        {
          "label": "Bitrefill homepage",
          "href": "https://www.bitrefill.com/",
          "scope": "provider"
        },
        {
          "label": "Bitrefill API",
          "href": "https://www.bitrefill.com/api/",
          "scope": "controls"
        }
      ]
    },
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://www.bitrefill.com/terms/?hl=en",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "AIRFILL PREPAID AB",
        "citation": "https://www.bitrefill.com/terms/?hl=en"
      },
      "registrationNumber": {
        "value": "559001-6035",
        "citation": "https://www.bitrefill.com/terms/?hl=en"
      },
      "incorporationJurisdiction": {
        "value": "Sweden",
        "citation": "https://www.bitrefill.com/terms/?hl=en"
      },
      "registeredAddress": {
        "value": "Mailbox 2333, 111 75 Stockholm, Sweden",
        "citation": "https://www.bitrefill.com/privacy/?hl=en"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://help.bitrefill.com/hc/en-us/articles/36440135758738-How-Strong-Customer-Authentication-SCA-requirements-apply-to-the-Bitrefill-Card",
            "https://help.bitrefill.com/hc/en-us",
            "https://www.bitrefill.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://help.bitrefill.com/hc/en-us/articles/36440135758738-How-Strong-Customer-Authentication-SCA-requirements-apply-to-the-Bitrefill-Card",
            "https://help.bitrefill.com/hc/en-us",
            "https://www.bitrefill.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://help.bitrefill.com/hc/en-us/articles/36440135758738-How-Strong-Customer-Authentication-SCA-requirements-apply-to-the-Bitrefill-Card",
            "https://help.bitrefill.com/hc/en-us",
            "https://www.bitrefill.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 103,
    "slug": "coinsbee",
    "domain": "coinsbee.com",
    "name": "Coinsbee",
    "type": "Gift Cards",
    "cat": "gift",
    "kyc": "light",
    "kycLevel": 2,
    "fees": {
      "transaction": 1.5
    },
    "limits": {
      "daily": 10000
    },
    "features": [
      "5,000+ brands",
      "200+ cryptocurrencies",
      "185+ countries",
      "Instant delivery"
    ],
    "networks": [],
    "badge": "GLOBAL",
    "url": "https://www.coinsbee.com/",
    "geo": [
      "GLOBAL",
      "US",
      "UK",
      "EU",
      "AU",
      "IN",
      "CA",
      "ZA",
      "NG",
      "KE",
      "MX",
      "BR",
      "AR"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "countries": [
      "US",
      "UK",
      "EU",
      "AU",
      "IN",
      "CA",
      "ZA",
      "NG",
      "KE",
      "MX",
      "BR",
      "AR"
    ],
    "categories": [
      "Gift Cards"
    ],
    "description": "Gift-card and mobile top-up marketplace with 5,000+ brands in 185+ countries; verification is required past applicable limits.",
    "cardSummary": "5,000+ gift-card brands and top-ups in 185+ countries.",
    "jurisdiction": "DE",
    "auditedBy": null,
    "twitter": "https://x.com/coinsbee",
    "telegram": "https://t.me/coinsbee",
    "founderIntel": "Tobias Sorn (CEO) and Marius H. (co-founder, last name unconfirmed publicly) - German nationals, Stuttgart-based. Sorn background: IT specialist at Stas GmbH, .NET developer at mobisys GmbH, software developer at Axians (VINCI Energies group - French multinational, no intel connections). Coinsbee GmbH, HRB 767979, Stuttgart, Germany. 6 employees (Germany + Ukraine). No state-actor ties.",
    "vcIntel": "No external investors - appears self-funded/bootstrapped. German GmbH, EU/GDPR jurisdiction.",
    "tagline": "A custodial or semi-custodial financial service.",
    "kycNote": "Official KYC/AML page says verification is via Sumsub; unverified limits are max €1,000 per order and €10,000 total, and some products are only available to verified accounts.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-08-25",
    "fee": "1.5%",
    "stateActorFlag": null,
    "privacyWarning": "Coinsbee GmbH is German/EU-regulated; account/order data, crypto payment metadata and Sumsub KYC data can be collected when limits or product rules trigger verification.",
    "followTheMoney": "  Coinsbee GmbH - Stuttgart, Germany (DE)\n  ──────────────────────────────────────\n  CEO: Tobias Sorn · Bootstrapped\n  Revenue: 1.5% markup on gift cards\n  Funding: Self-funded, no VC\n  ├─ German GmbH (HRB 767979)\n  ├─ EU/GDPR jurisdiction\n  └─ No state-actor connections found",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "https://www.coinsbee.com/",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://www.coinsbee.com/en/imprint/",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Coinsbee GmbH",
        "citation": "https://www.coinsbee.com/en/imprint/"
      },
      "registrationNumber": {
        "value": "HRB 767979",
        "citation": "https://www.coinsbee.com/en/imprint/"
      },
      "registryUrl": {
        "value": "https://www.coinsbee.com/en/imprint/",
        "citation": "https://www.coinsbee.com/en/imprint/"
      },
      "incorporationJurisdiction": {
        "value": "Germany",
        "citation": "https://www.coinsbee.com/en/about-us/"
      },
      "incorporationDate": {
        "value": "January 2019",
        "citation": "https://www.coinsbee.com/en/about-us/"
      },
      "registeredAddress": {
        "value": "Lautenschlagerstr. 16, 70173 Stuttgart",
        "citation": "https://www.coinsbee.com/en/imprint/"
      },
      "officers": {
        "value": [
          "Tobias Sorn"
        ],
        "citation": "https://www.coinsbee.com/en/imprint/"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.coinsbee.com/",
            "https://www.coinsbee.com/en/terms-and-privacy"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.coinsbee.com/",
            "https://www.coinsbee.com/en/terms-and-privacy"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.coinsbee.com/",
            "https://www.coinsbee.com/en/terms-and-privacy"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 214,
    "slug": "coingate-gift-cards",
    "domain": "coingate.com",
    "name": "CoinGate Gift Cards",
    "type": "Gift Cards",
    "cat": "gift",
    "kyc": "light",
    "kycLevel": 2,
    "fees": {
      "transaction": null
    },
    "limits": {},
    "features": [
      "3000+ Brands",
      "70+ Coins",
      "No account",
      "Instant"
    ],
    "networks": [],
    "badge": "NO KYC",
    "url": "https://coingate.com/gift-cards",
    "geo": [
      "GLOBAL",
      "EU",
      "UK"
    ],
    "status": "ok",
    "checkedAt": "2026-08-27",
    "countries": [
      "EU",
      "UK",
      "US"
    ],
    "categories": [
      "Gift Cards"
    ],
    "description": "Worldwide e-gift card marketplace taking crypto or card, run by Lithuanian UAB Decentralized under EU MiCA.",
    "cardSummary": "Worldwide e-gift cards, crypto or card checkout.",
    "jurisdiction": "LT",
    "auditedBy": null,
    "twitter": "https://x.com/coingate_cards",
    "telegram": "https://t.me/coingate_gift_cards",
    "founderIntel": null,
    "vcIntel": null,
    "tagline": "A custodial or semi-custodial financial service.",
    "kycNote": "CoinGate support/legal snippets and official pages describe KYC/AML requirements for personal/business accounts; gift-card checkout is not a no-KYC guarantee.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-06-22",
    "fee": null,
    "stateActorFlag": null,
    "privacyWarning": "Rewards Distributed collects order, payment and recipient data plus IP address, user agent, device fingerprint and browsing metrics; gift-card purchase records are retained for 10 years after the business relationship ends and may be shared with payment processors, gift-card providers, AML/identification providers and authorities.",
    "followTheMoney": "  CoinGate UAB - Vilnius, Lithuania (LT)\n  ──────────────────────────────────────\n  CEO: Dmitrijus Borisenka · Bootstrapped\n  Revenue: 2.5% markup on gift cards\n  Funding: Self-funded, no significant VC\n  ├─ Lithuanian company, EU/GDPR\n  ├─ 50+ employees, Vilnius HQ\n  └─ No account required for gift cards",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_6_2026-06-22",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://coingate.com/policy/privacy-policy",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "UAB \"Decentralized\"",
        "citation": "https://coingate.com/policy/privacy-policy"
      },
      "registrationNumber": {
        "value": "303423510",
        "citation": "https://coingate.com/policy/privacy-policy"
      },
      "registryUrl": {
        "value": "https://okredo.com/en-lt/company/uab-decentralized-303423510",
        "citation": "https://okredo.com/en-lt/company/uab-decentralized-303423510"
      },
      "incorporationJurisdiction": {
        "value": "Lithuania",
        "citation": "https://coingate.com/policy/privacy-policy"
      },
      "incorporationDate": {
        "value": "14/10/2014",
        "citation": "https://okredo.com/en-lt/company/uab-decentralized-303423510"
      },
      "registeredAddress": {
        "value": "A. Goštauto g. 8-331, LT-01108 Vilnius, Lithuania",
        "citation": "https://coingate.com/policy/contractual-terms-and-conditions-for-using-the-coingate-system"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [
          "UAB \"Virtualios Valiutos\""
        ],
        "citation": "https://coingate.com/about-us"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "extensive",
      "controlModel": "hosted-account",
      "sourceModel": "closed"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "extensive",
          "sourceUrls": [
            "https://coingate.com/gift-cards/terms-and-conditions"
          ],
          "reviewedAt": "2026-08-27",
          "note": "identity documents when requested plus order, payment, wallet and transaction data"
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://coingate.com/gift-cards/terms-and-conditions"
          ],
          "reviewedAt": "2026-08-27",
          "note": "commissioned-purchasing-agent"
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://coingate.com/gift-cards"
          ],
          "reviewedAt": "2026-08-27",
          "note": "closed-service"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "Security.txt contact exists but linked policy returns 410; no current gift-card audit report."
      }
    },
    "limit": null
  },
  {
    "id": 215,
    "slug": "cryptorefills",
    "domain": "cryptorefills.com",
    "name": "CryptoRefills",
    "type": "Gift Cards",
    "cat": "gift",
    "kyc": "light",
    "kycLevel": 1,
    "fees": null,
    "limits": {
      "daily": null
    },
    "features": [
      "Flights & Hotels",
      "eSIMs",
      "Mobile Top-Ups",
      "6,600+ products",
      "100+ cryptocurrencies",
      "AI-agent purchasing (MCP/x402)",
      "eSIM data-balance tracking"
    ],
    "networks": [],
    "badge": "TRAVEL",
    "url": "https://www.cryptorefills.com/",
    "geo": [
      "GLOBAL",
      "US",
      "EU",
      "UK",
      "AU",
      "IN",
      "ZA",
      "NG",
      "KE",
      "BR",
      "AR",
      "MX"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "countries": [
      "US",
      "EU",
      "UK",
      "AU",
      "IN",
      "ZA",
      "NG",
      "KE",
      "BR",
      "AR",
      "MX"
    ],
    "categories": [
      "Gift Cards"
    ],
    "description": "Gift cards, eSIMs, mobile top-ups, flights and stays across 6,600+ products in 180+ countries, payable with 100+ cryptocurrencies; risk and travel cases can trigger identity data.",
    "cardSummary": "Gift cards, top-ups and travel bought with crypto.",
    "jurisdiction": "NL",
    "auditedBy": null,
    "twitter": "https://x.com/cryptorefills",
    "telegram": "https://t.me/cryptorefillsofficial",
    "founderIntel": "Massimiliano Silenzi (CEO), Simonluca Landi (CTO), Mats Veenman - Italian/Dutch founders. Amsterdam-based (Big Dream Ventures B.V., registration 63338149, Weteringschans 165C). 30 years combined digital payments experience. No state-actor ties. Netherlands jurisdiction (EU, GDPR).",
    "vcIntel": "Seed round Oct 2022 - investor names not publicly disclosed. Netherlands B.V., EU/GDPR jurisdiction. Monitor for investor disclosure.",
    "kycNote": "Homepage advertises no KYC for standard purchases. Terms allow Tier 3/full KYC with photo ID and live image for suspicious/risk patterns; accounts use legal name/email, travel requires passenger/identity data, and open-loop payment processors apply separate terms.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-08-25",
    "fee": "No fixed platform fee published; final total is shown at checkout and blockchain network fees vary",
    "stateActorFlag": null,
    "privacyWarning": "No-KYC marketing is limit/risk-dependent; privacy policy covers passenger/guest data for travel bookings plus fraud, legal and traffic-data processing.",
    "followTheMoney": "  Big Dream Ventures B.V. - Amsterdam (NL)\n  ──────────────────────────────────────\n  CEO: Massimiliano Silenzi\n  Revenue: ~1% markup, seed undisclosed\n  Funding: Seed round Oct 2022 (undisclosed)\n  ├─ Dutch B.V., EU/GDPR jurisdiction\n  ├─ Flights, eSIMs, mobile top-ups\n  └─ No KYC - Italian/Dutch founders",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "primary_source_rereview_2026-08-25",
    "jurisdictionConfidence": "inferred",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://www.cryptorefills.com/en/terms-of-service",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Big Dream Ventures B.V.",
        "citation": "https://www.cryptorefills.com/en/terms-of-service"
      },
      "registrationNumber": {
        "value": "63338149",
        "citation": "https://www.cryptorefills.com/en/terms-of-service"
      },
      "registryUrl": {
        "value": "https://www.kvk.nl/",
        "citation": "https://www.cryptorefills.com/en/terms-of-service"
      },
      "incorporationJurisdiction": {
        "value": "The Netherlands",
        "citation": "https://www.cryptorefills.com/en/terms-of-service"
      },
      "registeredAddress": {
        "value": "Keizersgracht 482, 1017 EG Amsterdam, The Netherlands",
        "citation": "https://play.google.com/store/apps/details?id=com.cryptorefills"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.cryptorefills.com/",
            "https://www.cryptorefills.com/en/terms-of-service",
            "https://www.cryptorefills.com/en/help/payments",
            "https://x.com/Cryptorefills/status/2087890693838766345"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.cryptorefills.com/",
            "https://www.cryptorefills.com/en/terms-of-service",
            "https://www.cryptorefills.com/en/help/payments",
            "https://x.com/Cryptorefills/status/2087890693838766345"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.cryptorefills.com/",
            "https://www.cryptorefills.com/en/terms-of-service",
            "https://www.cryptorefills.com/en/help/payments",
            "https://x.com/Cryptorefills/status/2087890693838766345"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 219,
    "slug": "bitpay-gift-cards",
    "domain": "bitpay.com",
    "name": "BitPay Gift Cards",
    "type": "Gift Cards",
    "cat": "gift",
    "kyc": "light",
    "kycLevel": 1,
    "fees": {
      "transaction": null
    },
    "limits": {},
    "features": [
      "Major US Brands",
      "In-app",
      "Bill Pay"
    ],
    "networks": [],
    "badge": "USA",
    "url": "https://www.bitpay.com/gift-cards",
    "geo": [
      "US"
    ],
    "status": "ok",
    "checkedAt": "2026-08-27",
    "countries": [
      "US"
    ],
    "categories": [
      "Gift Cards"
    ],
    "description": "Brand gift cards bought with crypto inside the BitPay app, operated by a US licensed virtual-currency business.",
    "cardSummary": "Brand gift cards bought in the BitPay app.",
    "jurisdiction": "US",
    "auditedBy": null,
    "twitter": "https://x.com/bitpay",
    "privacyWarning": "US/Five Eyes regulated provider with NMLS/NYDFS licensing; BitPay may collect account, device, transaction and identity-verification data depending on service path.",
    "founderIntel": "Stephen Pair (CEO) and Tony Gallippi (Co-founder). Corporate Entity: BitPay Inc., headquartered in Atlanta, Georgia, US. Backing: Highly venture-backed to the tune of over $70M by tier-1 institutional investors including Founders Fund, Index Ventures, Virgin Group, and Aquiline Technology Growth. Fully compliant US MSB.",
    "vcIntel": "BitPay Inc (US). Series B led by Index Ventures, Founders Fund, and Aquiline Capital Partners.",
    "tagline": "A custodial or semi-custodial financial service.",
    "kycNote": "Gift-card page does not surface document KYC, but BitPay legal/privacy pages describe identity verification, fraud prevention and regulated financial-service compliance across BitPay services.",
    "stateActorFlag": "2013 seed investment led by Peter Thiel's Founders Fund. Thiel co-founded Palantir Technologies with CIA In-Q-Tel seed money. Founders Fund has invested in Palantir and Anduril (defense tech). Indirect Palantir/In-Q-Tel-adjacent investor chain, not direct In-Q-Tel investment.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-06-22",
    "fee": null,
    "followTheMoney": "  BitPay Inc - Atlanta, Georgia (US)\n  ──────────────────────────────────────\n  CEO: Stephen Pair · Co-founder: Gallippi\n  Raised: $70M+ from institutional VCs\n  Investors: Founders Fund\n             Index Ventures, Virgin Group\n  ├─ US MSB, FinCEN registered\n  └─ Five Eyes jurisdiction (US)",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_6_2026-06-22",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://www.bitpay.com/legal/terms-of-use",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "BitPay, Inc.",
        "citation": "https://www.bitpay.com/legal/terms-of-use"
      },
      "incorporationJurisdiction": {
        "value": "Delaware, USA",
        "citation": "https://www.bitpay.com/legal/terms-of-use"
      },
      "registeredAddress": {
        "value": "1870 The Exchange SE Ste 220, PMB 91017, Atlanta, GA 30339-2171 USA",
        "citation": "https://www.bitpay.com/legal/terms-of-use"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "hosted-account",
      "sourceModel": "partial"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://www.bitpay.com/legal/terms-of-use"
          ],
          "reviewedAt": "2026-08-27",
          "note": "account, device, transaction, payment and identity-verification data depending on path"
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://www.bitpay.com/legal/terms-of-use"
          ],
          "reviewedAt": "2026-08-27",
          "note": "hybrid-wallet-and-operator-purchase"
        },
        "sourceModel": {
          "value": "partial",
          "sourceUrls": [
            "https://www.bitpay.com/legal/terms-of-use"
          ],
          "reviewedAt": "2026-08-27",
          "note": "partial-open-source-wallet"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "Trust-center material did not establish a current gift-card-specific audit citation/date/scope."
      }
    },
    "limit": null
  },
  {
    "id": 218,
    "slug": "egifter",
    "domain": "egifter.com",
    "name": "eGifter",
    "type": "Gift Cards",
    "cat": "gift",
    "kyc": "light",
    "kycLevel": 2,
    "fees": {
      "transaction": null
    },
    "limits": {},
    "features": [
      "US Focus",
      "Points Program",
      "Instant"
    ],
    "networks": [],
    "badge": "USA",
    "url": "https://www.egifter.com/crypto",
    "geo": [
      "US"
    ],
    "status": "ok",
    "checkedAt": "2026-08-27",
    "countries": [
      "US"
    ],
    "categories": [
      "Gift Cards"
    ],
    "description": "US e-gift marketplace with Visa and brand cards on crypto checkout, subject to account and payment-authenticity checks.",
    "cardSummary": "US e-gift cards with crypto checkout.",
    "jurisdiction": "US",
    "auditedBy": null,
    "privacyWarning": "US/Five Eyes service; privacy policy says eGifter may collect name, postal address, email, phone/cell, IP, date of birth, payment data, order data and fraud-detection data from third parties.",
    "founderIntel": null,
    "vcIntel": null,
    "tagline": "A custodial or semi-custodial financial service.",
    "kycNote": "Terms require an account/email for purchases and say additional measures may be necessary to ensure transaction and payment authenticity; no public no-KYC promise found.",
    "stateActorFlag": "US/Five Eyes jurisdiction (Huntington, NY). Subject to NSLs (National Security Letters with mandatory gag orders), FISA Section 702, and US law enforcement subpoenas. Full PII collection: name, payment card, billing address, phone, email, IP, date of birth, full purchase history.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-06-22",
    "fee": null,
    "followTheMoney": "eGifter Inc - Huntington, New York\nCEO: Tyler Roye\nFounded: 2012\nFunding: about $11M reported\nRevenue: gift-card markup and points program\nData: identity, payment, device, and purchase records",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_6_2026-06-22",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://tsccap.egifter.com/terms",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "GroupGifting.com, Inc.",
        "citation": "https://tsccap.egifter.com/terms"
      },
      "incorporationJurisdiction": {
        "value": "Delaware",
        "citation": "https://tsccap.egifter.com/terms"
      },
      "registeredAddress": {
        "value": "315 Main St., 2nd Fl., Huntington, New York 11743",
        "citation": "https://egifter.pissedconsumer.com/customer-service.html"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "extensive",
      "controlModel": "hosted-account",
      "sourceModel": "closed"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "extensive",
          "sourceUrls": [
            "https://tsccap.egifter.com/terms"
          ],
          "reviewedAt": "2026-08-27",
          "note": "account, identity/contact, order, payment, device/IP and fraud data"
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://tsccap.egifter.com/terms"
          ],
          "reviewedAt": "2026-08-27",
          "note": "operator-gift-card-marketplace"
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://tsccap.egifter.com/terms"
          ],
          "reviewedAt": "2026-08-27",
          "note": "closed-service"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No current independent audit evidence."
      }
    },
    "limit": null
  },
  {
    "id": 217,
    "slug": "coincards",
    "domain": "coincards.com",
    "name": "CoinCards",
    "type": "Gift Cards",
    "cat": "gift",
    "kyc": "light",
    "kycLevel": 2,
    "fees": {
      "transaction": null
    },
    "limits": {},
    "features": [
      "CA/EU/UK Brands",
      "Instant e-codes"
    ],
    "networks": [],
    "badge": "REGIONAL",
    "url": "https://coincards.com/",
    "geo": [
      "CA",
      "US",
      "UK",
      "EU",
      "AU"
    ],
    "status": "warning",
    "checkedAt": "2026-08-27",
    "countries": [
      "CA",
      "EU",
      "UK"
    ],
    "categories": [
      "Gift Cards"
    ],
    "description": "Canadian gift cards and top-ups from Stuff Technologies Inc., paid in Bitcoin, Lightning, Monero or Litecoin.",
    "cardSummary": "Canadian gift cards and top-ups for crypto.",
    "jurisdiction": "CA",
    "auditedBy": null,
    "twitter": "https://x.com/coincards",
    "telegram": "https://t.me/coincardsofficial",
    "privacyWarning": "Canada/Five Eyes operator; can collect account, transaction, contact and formal identification data under legal/risk requirements.",
    "founderIntel": null,
    "vcIntel": null,
    "kycNote": "Privacy policy says CoinCards may require additional information to verify identity/address and lists formal ID records including passports, driver licences and national identity cards.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-06-22",
    "fee": null,
    "stateActorFlag": null,
    "followTheMoney": "  CoinCards - Vancouver, Canada (CA)\n  ──────────────────────────────────────\n  CEO: Mike Olthoff · Bootstrapped\n  Revenue: ~2% markup on gift codes\n  Funding: 100% self-funded\n  ├─ Five Eyes (Canada) jurisdiction\n  ├─ No VC, fully independent\n  └─ BTC + XMR accepted, no KYC",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_6_2026-06-22",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://coincards.com/terms-conditions/",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Stuff Technologies Inc.",
        "citation": "https://coincards.com/terms-conditions/"
      },
      "incorporationJurisdiction": {
        "value": "Canada",
        "citation": "https://coincards.com/terms-conditions/"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "extensive",
      "controlModel": "hosted-account",
      "sourceModel": "closed"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "extensive",
          "sourceUrls": [
            "https://coincards.com/terms-conditions/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "account/order/payment, identity/EDD and fraud-prevention data"
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://coincards.com/terms-conditions/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "operator-gift-card-merchant"
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://coincards.com/security-incident-august-04-2025/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "closed-service"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No current independent audit evidence."
      }
    },
    "limit": null
  },
  {
    "id": 208,
    "slug": "rewarble",
    "domain": "rewarble.com",
    "name": "Rewarble",
    "type": "Visa Gift Codes",
    "cat": "gift",
    "kyc": "light",
    "kycLevel": 2,
    "fees": {
      "transaction": 10
    },
    "limits": {
      "daily": 5000
    },
    "features": [
      "Virtual Visa",
      "3-D Secure options",
      "Instant"
    ],
    "networks": [],
    "badge": "FALLBACK",
    "url": "https://rewarble.com/",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-23",
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Visa Gift Codes"
    ],
    "description": "Digital payout platform issuing Visa and Mastercard codes, e-wallet top-ups, bank transfers and virtual prepaid cards.",
    "cardSummary": "Prepaid Visa and Mastercard payout codes.",
    "jurisdiction": "NL",
    "auditedBy": [],
    "twitter": "https://x.com/rewarbleglobal",
    "founderIntel": "Corporate/operator transparency remains limited in accessible official sources.",
    "vcIntel": "No public VC or funding source confirmed in this pass.",
    "tagline": "A custodial or semi-custodial financial service.",
    "kycNote": "No public direct KYC policy could be extracted due Vercel blocking; card/bank/e-wallet payout rails can trigger provider verification or high-risk blocks.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-06-22",
    "fee": "10%",
    "stateActorFlag": null,
    "privacyWarning": "Direct site is bot-protected from the VPS and financial payout rails create issuer/provider KYC, block and counterparty risk.",
    "followTheMoney": "  Rewarble - Unknown / Offshore (??)\n  ──────────────────────────────────────\n  Founders: completely anonymous\n  Revenue: 10% markup on virtual Visa\n  Funding: no disclosed investors\n  ├─ No corporate structure identified\n  ├─ Zero transparency - high risk\n  └─ Unvetted: no reviews or filings",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_4_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "limited",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://rewarble.com/policies/terms-and-conditions",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Centiward B.V.",
        "citation": "https://rewarble.com/policies/terms-and-conditions"
      },
      "registrationNumber": {
        "value": "96903163",
        "citation": "https://rewarble.com/about-us"
      },
      "registryUrl": {
        "value": "https://www.northdata.com/Centiward+B.V.,+Eindhoven/KVK+96903163",
        "citation": "https://www.northdata.com/Centiward+B.V.,+Eindhoven/KVK+96903163"
      },
      "incorporationJurisdiction": {
        "value": "Netherlands",
        "citation": "https://rewarble.com/policies/terms-and-conditions"
      },
      "registeredAddress": {
        "value": "Essenstraat 1, 5616 LG Eindhoven, Netherlands",
        "citation": "https://rewarble.com/about-us"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "hosted-account",
      "sourceModel": "closed"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://docs.rewarble.com/client/overview",
            "https://rewarble.com/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "The documented client/API/account model necessarily exposes account, redemption, order and payment metadata, but live policies were blocked."
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://docs.rewarble.com/client/overview",
            "https://rewarble.com/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Rewarble operates hosted voucher/redemption and API accounts."
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://docs.rewarble.com/client/overview"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No official service-core source or reproducible build was located."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced; no audit points are granted."
      }
    }
  },
  {
    "id": 213,
    "slug": "moon",
    "domain": "paywithmoon.com",
    "name": "Moon (Pay with Moon)",
    "type": "Virtual Visa Codes",
    "cat": "gift",
    "kyc": "light",
    "kycLevel": 2,
    "fees": {
      "transaction": 1
    },
    "limits": {
      "daily": 1000
    },
    "features": [
      "BTC/USDC",
      "US online merchants",
      "Instant"
    ],
    "networks": [
      "visa"
    ],
    "badge": "ONLINE",
    "url": "https://paywithmoon.com/",
    "geo": [
      "US"
    ],
    "status": "ok",
    "checkedAt": "2026-06-24",
    "countries": [
      "US"
    ],
    "categories": [
      "Virtual Visa Codes"
    ],
    "description": "Moon LLC crypto-funded virtual Visa cards issued by partner financial institutions, plus merchant gift-card spend.",
    "cardSummary": "Crypto-funded virtual Visa cards.",
    "jurisdiction": "US",
    "auditedBy": [],
    "privacyWarning": "Moon collects account, device, use, support and transaction data; card products rely on issuers/partners. Terms are governed by Próspera, Honduras, while the operator is named only as Moon LLC and product geography/eligibility is issuer-specific.",
    "founderIntel": null,
    "vcIntel": null,
    "tagline": "A custodial or semi-custodial financial service.",
    "kycNote": "Public legal pages did not expose explicit KYC text, but Moon requires an account, may refuse/cancel accounts, and Visa card issuance is through partner financial institutions with product/geography restrictions.",
    "stateActorFlag": null,
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-06-22",
    "fee": "1%",
    "followTheMoney": "  Moon Technologies Inc - New York (US)\n  ──────────────────────────────────────\n  CEO: Ken Kruger · Founded: 2018\n  Raised: $2.2M (Fenbushi, Flight Ventures)\n  Revenue: 1% virtual card fee\n  ├─ Fenbushi: Wanxiang/China-adjacent VC\n  ├─ Five Eyes (US) jurisdiction\n  └─ Single-use Visa via Lightning",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_6_2026-06-22",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "unresolved",
        "citation": "unknown",
        "note": "Pass 1 researched this service but established no registry facts."
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "custodial",
      "sourceModel": "closed"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://paywithmoon.com/faqs",
            "https://paywithmoon.com/legal/terms-and-conditions-en"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Moon account, email, card/order and transaction/support records establish moderate operator exposure; a current standalone privacy page was not captured to support extensive."
        },
        "controlModel": {
          "value": "custodial",
          "sourceUrls": [
            "https://paywithmoon.com/faqs",
            "https://paywithmoon.com/legal/terms-and-conditions-en"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Moon and issuer partners control account access and prepaid card issuance/spend authorization."
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://paywithmoon.com/legal/terms-and-conditions-en"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No official critical-core source or reproducible-build evidence is disclosed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced in the reopened first-party source family."
      }
    }
  },
  {
    "id": 206,
    "slug": "pintopay",
    "domain": "pintopay.me",
    "name": "Pintopay",
    "type": "Virtual/Physical Card",
    "cat": "card",
    "kyc": "full",
    "kycLevel": 4,
    "fees": {
      "transaction": 3
    },
    "limits": {
      "daily": 5000
    },
    "features": [
      "Apple/Google Pay",
      "ATM on physical",
      "USDT top-ups"
    ],
    "networks": [
      "visa",
      "mastercard",
      "applepay",
      "googlepay",
      "3ds",
      "atm"
    ],
    "badge": "GLOBAL",
    "url": "https://pintopay.me/",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-23",
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Virtual/Physical Card"
    ],
    "description": "Crypto card and top-up product. Its official homepage advertises AML/KYC controls and 3D Secure.",
    "cardSummary": "Crypto card and top-up product with AML checks.",
    "jurisdiction": "HK",
    "auditedBy": [],
    "founderIntel": "Mikhail Kovshov (CEO) - Russian national, Dubai/Bali/Hong Kong-based fintech entrepreneur. Vladislav Poliakov (Head of Marketing). Delaware LLC (16192 Coastal Highway, Lewes, DE) with UAE operations. Telegram Mini App cryptobank. No formal regulatory licensing found. \"Digital nomads turned fintech\" founding narrative is opaque.",
    "vcIntel": "No VC investors identified. Appears self-funded or early-stage. Delaware incorporation is common anonymizing shell structure.",
    "tagline": "A custodial or semi-custodial financial service.",
    "kycNote": "Account/card/wallet services may require full identity verification including name, date of birth, residence, national ID or passport data, contact details, financial profile and source of funds; transaction fees are shown before acceptance.",
    "stateActorFlag": "Russian-operated: CEO Mikhail Kovshov is a Russian national based between Dubai, Bali, and Hong Kong. Delaware shell + UAE operational base. No direct FSB/GRU connections found but Russian-operated fintech with minimal transparency warrants heightened scrutiny.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-06-22",
    "fee": null,
    "privacyWarning": "UANT Ltd collects identity/KYC, contact, transaction, device/IP, financial profile and source-of-funds data and shares data with card, payment, AML/KYC and infrastructure providers as needed.",
    "followTheMoney": "  Pintopay - Delaware LLC / UAE Ops (US)\n  ──────────────────────────────────────\n  CEO: Mikhail Kovshov (Russian national)\n  Revenue: 3% card fee + fx spread\n  Funding: self-funded (no VC disclosed)\n  ├─ Delaware shell + UAE operations\n  ├─ Russian operator, minimal transparency\n  └─ No regulatory licenses confirmed",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_2_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://www.scribd.com/document/904246795/Pintopay-Introducer-Fee-Agreement",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "UANT Limited",
        "citation": "https://www.scribd.com/document/904246795/Pintopay-Introducer-Fee-Agreement"
      },
      "registrationNumber": {
        "value": "77341227",
        "citation": "https://www.ltddir.com/companies/uant-limited/"
      },
      "registryUrl": {
        "value": "https://www.cr.gov.hk/",
        "citation": "https://www.cr.gov.hk/"
      },
      "incorporationJurisdiction": {
        "value": "Hong Kong",
        "citation": "https://www.ltddir.com/companies/uant-limited/"
      },
      "incorporationDate": {
        "value": "18-NOV-2024",
        "citation": "https://www.ltddir.com/companies/uant-limited/"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "extensive",
      "controlModel": "custodial",
      "sourceModel": "closed"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "extensive",
          "sourceUrls": [
            "https://pintopay.me/privacy-policy.pdf"
          ],
          "reviewedAt": "2026-08-27",
          "note": "The privacy policy covers government identity documents, source-of-funds, financial profile, transactions, device/IP and processor data: this is extensive exposure."
        },
        "controlModel": {
          "value": "custodial",
          "sourceUrls": [
            "https://pintopay.me/",
            "https://pintopay.me/terms-and-conditions.pdf"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Pintopay accounts/cards/wallets and issuer controls are custodial."
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://pintopay.me/terms-and-conditions.pdf"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No official critical-core source or reproducible deployment was disclosed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced; no audit points are granted."
      }
    }
  },
  {
    "id": 223,
    "slug": "kemycard",
    "domain": "kemycard.com",
    "name": "KemyCard",
    "type": "Virtual/Physical Card",
    "cat": "card",
    "kyc": "full",
    "kycLevel": 4,
    "fees": {
      "transaction": 5
    },
    "limits": {
      "daily": 10000
    },
    "features": [
      "Virtual cards",
      "Physical Mastercard",
      "Multi-currency accounts",
      "Crypto top-up",
      "Apple Pay",
      "Google Pay",
      "Full eKYC",
      "AML monitoring"
    ],
    "networks": [
      "visa",
      "mastercard",
      "applepay",
      "googlepay",
      "3ds"
    ],
    "badge": "POWER",
    "url": "https://kemycard.com/en/home",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-27",
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Virtual/Physical Card"
    ],
    "description": "Crypto-funded virtual and physical cards whose terms require full eKYC via Sumsub or Veriff plus AML monitoring.",
    "cardSummary": "Crypto-funded cards with full eKYC.",
    "jurisdiction": "US",
    "auditedBy": [],
    "telegram": "https://t.me/kemycard",
    "twitter": "https://x.com/kemycard",
    "founderIntel": "Founders completely anonymous. No named team members, no LinkedIn profiles, no About page found. Kemite Group LLC / Kemygroup LLC, Delaware (reg #20250007719), 111b S Governors Ave STE 23648, Dover DE 19904. HN post from apparent founders gives no names. Cannot assess nationality or state-actor connections. Major transparency gap for a financial product.",
    "vcIntel": "No investors identified. Bootstrapped/anonymous. Delaware LLC opacity structure. No regulatory licenses or MSB registrations found.",
    "tagline": "A custodial or semi-custodial financial service.",
    "kycNote": "Full KYC required for the main card/account flow; official pages cite automated ID and biometric verification plus AML monitoring.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-08-27",
    "fee": "5%",
    "stateActorFlag": null,
    "privacyWarning": "US MSB/Five Eyes jurisdiction. Requires account registration, personal-data processing, full eKYC, biometric/ID verification, and AML transaction monitoring.",
    "followTheMoney": "  Kemite Group LLC - Dover, Delaware (US)\n  ──────────────────────────────────────\n  Founders: completely anonymous\n  Revenue: 5% fee on card loads\n  Funding: no investors identified\n  ├─ Delaware shell (reg #20250007719)\n  ├─ No team names or profiles found\n  └─ No MSB registration confirmed",
    "lastReviewed": "2026-08-27",
    "kycLastChecked": "2026-08-27",
    "reviewSource": "Primary-source review 2026-08-27",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://kemycard.com/en/privacy",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Kemite Group, LLC",
        "citation": "https://kemycard.com/en/privacy"
      },
      "registrationNumber": {
        "value": "20250007719",
        "citation": "https://kemycard.com/en/privacy"
      },
      "incorporationJurisdiction": {
        "value": "Delaware, United States",
        "citation": "https://kemycard.com/en/privacy"
      },
      "registeredAddress": {
        "value": "111b South Governors Ave, STE 23648, Dover, DE, 19904, USA",
        "citation": "https://kemycard.com/en/privacy"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "extensive",
      "controlModel": "custodial",
      "sourceModel": "closed"
    },
    "changedAt": "2026-08-27",
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "extensive",
          "sourceUrls": [
            "https://kemycard.com/en/privacy",
            "https://kemycard.com/en/terms"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Account, identity/compliance, transaction, card, device/network and support data create extensive operator exposure."
        },
        "controlModel": {
          "value": "custodial",
          "sourceUrls": [
            "https://kemycard.com/en",
            "https://kemycard.com/en/terms"
          ],
          "reviewedAt": "2026-08-27",
          "note": "The provider/issuance chain controls accounts, cards and on/off-ramp access."
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://kemycard.com/en/terms"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No official critical-core source repository or reproducible-build evidence is disclosed; terms restrict service technology use."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced in the reopened first-party source family."
      }
    }
  },
  {
    "id": 207,
    "slug": "hodlhodl",
    "domain": "hodlhodl.com",
    "name": "Hodl Hodl",
    "type": "P2P / Escrow",
    "cat": "p2p",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0.6
    },
    "limits": {
      "daily": "No Limit"
    },
    "features": [
      "Multisig escrow",
      "100+ fiat rails",
      "BTC/LTC"
    ],
    "networks": [],
    "badge": "P2P",
    "url": "https://hodlhodl.com/",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-27",
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "P2P / Escrow"
    ],
    "description": "Non-custodial P2P Bitcoin exchange using multisig escrow, with an official no-KYC and no-custody claim.",
    "cardSummary": "Non-custodial P2P bitcoin trades via multisig.",
    "jurisdiction": "??",
    "auditedBy": [],
    "telegram": "https://t.me/hodlhodl",
    "twitter": "https://x.com/hodlhodl",
    "founderIntel": null,
    "vcIntel": null,
    "tagline": "A custodial or semi-custodial financial service.",
    "kycNote": "Official FAQ says anonymous global P2P trades without KYC/AML; legacy voluntary verified status remains visible for older users but new voluntary verification has been removed.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-08-27",
    "fee": "0.6%",
    "stateActorFlag": null,
    "privacyWarning": "Accounts use username, email and password. Identity/KYC/AML information may be collected for disputes or compliance; AML-related personal data may be retained for five years. Counterparty payment methods add separate exposure.",
    "followTheMoney": "  HODLEX LTD - Riga, Latvia (EU)\n  ──────────────────────────────────────\n  CEO: Max Keidun · Founded: ~2016\n  Series B (2021): Kingsway, Ten31, XBTO\n  Revenue: 0.6% escrow fee\n  ├─ VC-backed P2P exchange (unusual)\n  ├─ Malta-registered for operations\n  └─ EU/GDPR - no mandatory KYC logs",
    "lastReviewed": "2026-08-27",
    "kycLastChecked": "2026-08-27",
    "reviewSource": "Primary-source review 2026-08-27",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://hodlhodl.com/terms_of_service",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Hodlex Ltd",
        "citation": "https://hodlhodl.com/terms_of_service"
      },
      "registrationNumber": {
        "value": "89220",
        "citation": "https://hodlhodl.com/terms_of_service"
      },
      "incorporationJurisdiction": {
        "value": "Marshall Islands",
        "citation": "https://hodlhodl.com/terms_of_service"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "noncustodial-hosted",
      "sourceModel": "closed"
    },
    "changedAt": "2026-08-27",
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://accounts.hodlhodl.com/privacy-policy",
            "https://accounts.hodlhodl.com/terms-of-service"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Account email, account/trade records, counterparty/payment data and technical logs create moderate operator exposure even without routine KYC."
        },
        "controlModel": {
          "value": "noncustodial-hosted",
          "sourceUrls": [
            "https://hodlhodl.com/pages/faq"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Trades settle wallet-to-wallet through multisig escrow; the platform does not custody fiat or Bitcoin but hosts coordination and dispute controls."
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://accounts.hodlhodl.com/terms-of-service"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No official score-critical platform repository or reproducible-build evidence was found."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced in the reopened first-party source family."
      }
    }
  },
  {
    "id": 209,
    "slug": "bisq",
    "domain": "bisq.network",
    "name": "Bisq",
    "type": "P2P / Desktop",
    "cat": "p2p",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0.3
    },
    "limits": {
      "daily": "No Limit"
    },
    "features": [
      "Tor",
      "Non-custodial",
      "Bank/Cash/SEPA"
    ],
    "networks": [],
    "badge": "PRIVATE",
    "url": "https://bisq.network/",
    "geo": [
      "GLOBAL"
    ],
    "status": "warning",
    "checkedAt": "2026-08-27",
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "P2P / Desktop"
    ],
    "description": "Decentralized open-source desktop P2P Bitcoin exchange over Tor, with no registration stated as required.",
    "cardSummary": "Desktop P2P bitcoin exchange over Tor.",
    "jurisdiction": "??",
    "auditedBy": null,
    "twitter": "https://x.com/bisq_network",
    "telegram": "https://t.me/bisq_p2p",
    "founderIntel": "Manfred Karrer - Austrian developer. Founded Bisq (originally Bitsquare) in 2014. No intelligence contractor background. Left day-to-day operations ~2020, replaced by community DAO governance. Chris Beams was early key contributor. Fully decentralized - no CEO, no company, no employees in the traditional sense.",
    "followTheMoney": "Bisq DAO\n────────────────────────\nOwners: traders and contributors\nLeadership: no CEO or central team\nRevenue: trading fees\ndistributed through BSQ",
    "publicClaims": {
      "followTheMoney": {
        "value": "Bisq DAO\n────────────────────────\nOwners: traders and contributors\nLeadership: no CEO or central team\nRevenue: trading fees\ndistributed through BSQ",
        "reviewedAt": "2026-07-15",
        "sources": [
          {
            "label": "Bisq - The DAO",
            "href": "https://bisq.network/dao/",
            "type": "official"
          }
        ]
      }
    },
    "vcIntel": "Zero VC. No external funding of any kind. No legal entity. Funded entirely by trading fees distributed through DAO. No OFAC designation. No hack incidents. Governance via BSQ (DAO token). One of the oldest continuously-operating P2P exchanges.",
    "tagline": "The original decentralized P2P Bitcoin exchange. No company, no server, no KYC.",
    "kycNote": "No account, email or identity KYC in the Bisq protocol; individual fiat payment methods can expose data to counterparties/banks.",
    "bestFor": [
      "Maximum decentralization",
      "BTC/fiat P2P",
      "Privacy-maximalist"
    ],
    "fee": "~0.4%",
    "affiliate": "",
    "trending": false,
    "privacyWarning": "Bisq suffered a May 1, 2026 trade-protocol exploit causing 11.59104 BTC in user losses. Victims were reimbursed, but XMR auto-confirmation remained disabled pending audit in June, and August releases v1.10.6 and v2.1.12 were mandatory security updates. Fiat methods may reveal payment metadata to counterparties/providers; do not keep long-term savings in the integrated hot wallet.",
    "updatedAt": "2026-06-22",
    "stateActorFlag": null,
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_4_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "danger",
    "corporate": {
      "entityType": {
        "value": "unresolved",
        "citation": "unknown",
        "note": "Pass 1 researched this service but established no registry facts."
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "limited",
      "controlModel": "decentralized",
      "sourceModel": "open"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "limited",
          "sourceUrls": [
            "https://bisq.network/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "local client data plus counterparty/payment-rail exposure; no central operator account database"
        },
        "controlModel": {
          "value": "decentralized",
          "sourceUrls": [
            "https://bisq.network/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "decentralized-dao-client"
        },
        "sourceModel": {
          "value": "open",
          "sourceUrls": [
            "https://github.com/bisq-network/bisq/releases/tag/v1.10.7"
          ],
          "reviewedAt": "2026-08-27",
          "note": "open-source"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "Bisq 2 v2.1.12 says vulnerabilities were identified during a recent security audit, but no complete audit citation/scope report was found."
      }
    }
  },
  {
    "id": 210,
    "slug": "robosats",
    "domain": "robosats.org",
    "name": "RoboSats",
    "type": "P2P / Lightning",
    "cat": "p2p",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0.2
    },
    "limits": {
      "daily": "No Limit"
    },
    "features": [
      "Tor",
      "LN escrow",
      "Quick trades"
    ],
    "networks": [],
    "badge": "TOR",
    "url": "https://robosats.org/",
    "geo": [
      "GLOBAL"
    ],
    "status": "warning",
    "checkedAt": "2026-06-22",
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "P2P / Lightning"
    ],
    "description": "Open-source P2P Bitcoin exchange using Lightning hold invoices, robot avatars and Tor-first access.",
    "cardSummary": "Tor-first P2P bitcoin swaps over Lightning.",
    "jurisdiction": "??",
    "auditedBy": [],
    "founderIntel": "Pseudonymous/open-source RoboSats project; official GitHub is RoboSats/robosats.",
    "vcIntel": "No VC found. Open-source project funded by contributors/donations/fees.",
    "tagline": "Tor-native P2P Lightning exchange with zero account requirement.",
    "kycNote": "No account/KYC model found in official repository; robot identities are generated per use and Lightning hold invoices handle bonds/escrow.",
    "bestFor": [
      "BTC/fiat P2P trading",
      "High privacy users",
      "Tor-only workflows"
    ],
    "fee": "0.2%",
    "affiliate": "",
    "trending": false,
    "twitter": "https://x.com/RoboSats",
    "privacyWarning": "Tor-only access reduces network exposure but does not remove coordinator trust. In versions through 0.8.6, a coordinator can run JavaScript through raw-HTML notices and password-protected public orders can be read without authentication, including payment method, amount, maker nick and F2F latitude/longitude. Wait for or verify upgrade to 0.8.7+.",
    "updatedAt": "2026-06-22",
    "stateActorFlag": null,
    "followTheMoney": "  RoboSats - Decentralised (Lightning)\n  ──────────────────────────────────────\n  Founder: Reckless_Satoshi (pseudonymous)\n  Funding: 0.2% trading fees + donations\n  Revenue: zero VC, no corporate entity\n  ├─ Tor-only, federated architecture\n  ├─ Robot identities: no persistent ID\n  └─ Open-source AGPL, GitHub public",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_4_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "unresolved",
        "citation": "unknown",
        "note": "Pass 1 researched this service but established no registry facts."
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "federated",
      "sourceModel": "open"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://learn.robosats.com/",
            "https://github.com/RoboSats/robosats/security/advisories/GHSA-r6f6-x59j-8q69"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Coordinators process order, robot, payment-method, dispute and escrow metadata; current advisories show private-order and root-token exposure, which is moderate rather than limited."
        },
        "controlModel": {
          "value": "federated",
          "sourceUrls": [
            "https://learn.robosats.com/",
            "https://github.com/RoboSats/robosats"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Users choose among independently operated coordinators in a federation; no single hosted account controls the full network."
        },
        "sourceModel": {
          "value": "open",
          "sourceUrls": [
            "https://github.com/RoboSats/robosats",
            "https://github.com/RoboSats/robosats/security"
          ],
          "reviewedAt": "2026-08-27",
          "note": "The full web/coordinator project is published under AGPL with official build/release history."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced; no audit points are granted."
      }
    }
  },
  {
    "id": 211,
    "slug": "localcoinswap",
    "domain": "localcoinswap.com",
    "name": "LocalCoinSwap",
    "type": "P2P / Escrow",
    "cat": "p2p",
    "kyc": "light",
    "kycLevel": 1,
    "fees": {
      "transaction": 0.25
    },
    "limits": {
      "daily": "No Limit"
    },
    "features": [
      "Multi-crypto",
      "Escrow",
      "Global"
    ],
    "networks": [],
    "badge": "FLEX",
    "url": "https://localcoinswap.com/",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-27",
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "P2P / Escrow"
    ],
    "description": "P2P crypto marketplace with escrow and hundreds of payment methods, whose terms reserve discretionary KYC checks.",
    "cardSummary": "P2P crypto marketplace with escrow.",
    "jurisdiction": "??",
    "auditedBy": [],
    "telegram": "https://t.me/localcoinswap",
    "twitter": "https://x.com/localcoinswap_",
    "privacyWarning": "Registration requires account information; the privacy policy lists email, usage data, geographic position, username, picture, city, phone number, cookies and system logs/IP addresses. Disputes can require payment records, government ID, proof of address, photos, audio or video. The terms permit disclosure and account restrictions and exclude multiple jurisdictions.",
    "founderIntel": null,
    "vcIntel": null,
    "tagline": "A custodial or semi-custodial financial service.",
    "kycNote": "Terms say LocalCoinSwap may require KYC/AML documentation at its sole discretion and may require payment records or KYC information for dispute resolution.",
    "stateActorFlag": null,
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-08-27",
    "fee": "0.25%",
    "followTheMoney": "  LocalCoinSwap - Hong Kong (HK/PRC)\n  ──────────────────────────────────────\n  Founders: Worsley brothers (AU)\n  Funding: LCS token ICO (2018)\n  Revenue: 0.25% escrow fee\n  ├─ HK NSL: PRC data demands apply\n  ├─ ICO-funded: token value unclear\n  └─ Dispute resolution = user ID risk",
    "lastReviewed": "2026-08-27",
    "kycLastChecked": "2026-08-27",
    "reviewSource": "Primary-source review 2026-08-27",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://localcoinswap.com/privacy",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "TechHouse Limited",
        "citation": "https://localcoinswap.com/privacy"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "noncustodial-hosted",
      "sourceModel": "partial"
    },
    "changedAt": "2026-08-27",
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://localcoinswap.com/privacy"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Email, username/profile, usage/geolocation, payment/trade/dispute and optional phone data create moderate operator exposure."
        },
        "controlModel": {
          "value": "noncustodial-hosted",
          "sourceUrls": [
            "https://localcoinswap.com/terms-of-service"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Terms describe non-custodial technical infrastructure and escrow, with users retaining asset ownership/control outside protocol locks."
        },
        "sourceModel": {
          "value": "partial",
          "sourceUrls": [
            "https://github.com/LocalCoinSwap/LocalCoinSwap",
            "https://localcoinswap.com/terms-of-service"
          ],
          "reviewedAt": "2026-08-27",
          "note": "The official repository covers protocol/open-source work, not demonstrably every hosted platform component."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced in the reopened first-party source family."
      }
    }
  },
  {
    "id": 227,
    "slug": "peachbitcoin",
    "domain": "peachbitcoin.com",
    "name": "Peach Bitcoin",
    "type": "P2P / Mobile",
    "cat": "p2p",
    "kyc": "light",
    "kycLevel": 1,
    "fees": {
      "transaction": 2
    },
    "limits": {
      "daily": null,
      "monthly": "Anonymous payment methods, gift cards, cash meetups, and USDT: 1,000 CHF equivalent"
    },
    "features": [
      "Mobile app",
      "Web app",
      "2-of-2 multisignature Bitcoin escrow",
      "P2P fiat payment methods"
    ],
    "networks": [],
    "badge": "APP",
    "url": "https://peachbitcoin.com/",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-22",
    "countries": [],
    "categories": [
      "P2P / Mobile"
    ],
    "description": "Swiss non-custodial P2P Bitcoin marketplace with no-registration standard trading, optional KYC for verified high-volume sellers, and material jurisdiction restrictions.",
    "cardSummary": "Swiss P2P bitcoin marketplace with optional verification.",
    "jurisdiction": "CH",
    "auditedBy": [],
    "twitter": "https://x.com/peachbitcoin",
    "telegram": "https://t.me/peachtopeach",
    "founderIntel": "Stéphanie (CEO/founder, known publicly as \"proofofsteph\") - French entrepreneur, Switzerland-based. Real surname not publicly disclosed. Co-founders operate under pseudonyms (@czino, @bitcoinlabrador). Incorporated as Peach SARL, Neuchâtel, Switzerland. Fully open-source client code. No state-actor ties found.",
    "vcIntel": "Seed round 2022: Ten31 (bitcoin-native VC, Tennessee) + small group of unnamed angels. No problematic VCs.",
    "tagline": "A custodial or semi-custodial financial service.",
    "kycNote": "Standard trading is promoted as no-registration/no-KYC where local law permits, but sellers may complete KYC to remove registration-free limits and increase selling capacity; Peach stores their identification documents and interview recording.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-06-22",
    "fee": "2% of escrow output plus applicable Bitcoin network fees",
    "stateActorFlag": null,
    "privacyWarning": "P2P payment metadata can reach counterparties and banks. Peach retains encrypted order-book, payment, chat, device-hash, and dispute data, and optional high-volume-seller KYC records. The service is unavailable in the US, China, and sanctioned regions and is not actively offered or marketed in the EU/EEA.",
    "followTheMoney": "  Peach SARL - Neuchâtel, Switzerland (CH)\n  ──────────────────────────────────────\n  CEO: proofofsteph (French, real name pvt)\n  Seed: Ten31 VC (Bitcoin-native, TN)\n  Revenue: 1% escrow fee, self-custodial\n  ├─ Swiss jurisdiction (strong privacy)\n  ├─ Ten31: bitcoin-only VC, no red flags\n  └─ Open-source client code",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_6_2026-06-22",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://peachbitcoin.com/privacy-policy/",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Peach Sàrl",
        "citation": "https://peachbitcoin.com/privacy-policy/"
      },
      "registrationNumber": {
        "value": "CHE-158.025.408",
        "citation": "https://peachbitcoin.com/privacy-policy/"
      },
      "registryUrl": {
        "value": "https://www.zefix.admin.ch/",
        "citation": "https://peachbitcoin.com/privacy-policy/"
      },
      "incorporationJurisdiction": {
        "value": "Switzerland",
        "citation": "https://peachbitcoin.com/privacy-policy/"
      },
      "registeredAddress": {
        "value": "c/o Nohä Fiduciaire SA, Rue Saint-Honoré 2, 2000 Neuchâtel, SWITZERLAND",
        "citation": "https://peachbitcoin.com/privacy-policy/"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "local-self-custody",
      "sourceModel": "partial"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://peachbitcoin.com/privacy-policy/",
            "https://peachbitcoin.com/terms-and-conditions/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Order, payment, chat, dispute, device-hash and optional seller-KYC records create moderate operator exposure despite no-registration standard trading."
        },
        "controlModel": {
          "value": "local-self-custody",
          "sourceUrls": [
            "https://peachbitcoin.com/",
            "https://peachbitcoin.com/terms-and-conditions/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Users retain keys and trades use 2-of-2 multisignature escrow; Peach coordinates the market without unilateral custody."
        },
        "sourceModel": {
          "value": "partial",
          "sourceUrls": [
            "https://github.com/Peach2Peach/peach-app",
            "https://github.com/Peach2Peach"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Official client/web/supporting repositories are visible, but current evidence does not establish that the complete coordinator/market critical core is inspectable and reproducible."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced; no audit points are granted."
      }
    }
  },
  {
    "id": 228,
    "slug": "bitcoin-depot",
    "domain": "bitcoindepot.com",
    "name": "Bitcoin Depot",
    "type": "Bitcoin ATM",
    "cat": "p2p",
    "kyc": "full",
    "kycLevel": 4,
    "fees": {
      "transaction": 15
    },
    "limits": {
      "daily": 900
    },
    "features": [
      "US/CA",
      "Buy & Sell",
      "Cash"
    ],
    "networks": [
      "atm"
    ],
    "badge": "ATM",
    "url": "https://www.bitcoindepot.com/",
    "geo": [
      "US",
      "CA"
    ],
    "status": "down",
    "checkedAt": "2026-08-07",
    "countries": [
      "US",
      "CA"
    ],
    "categories": [
      "Bitcoin ATM"
    ],
    "description": "Bitcoin ATM network taken offline in May 2026 when its operator filed for Chapter 11.",
    "cardSummary": "Bitcoin ATM operator wound down May 2026; network offline.",
    "jurisdiction": "US",
    "auditedBy": null,
    "twitter": "https://x.com/bitcoin_depot",
    "privacyWarning": "US/Five Eyes MSB, FinCEN/FINTRAC registered, that collected phone, email, wallet/transaction, ID, biometric and SSN-related data. Now in Chapter 11 wind-down: customer records are an asset in a court-supervised sale, and a claims agent holds the process.",
    "founderIntel": null,
    "vcIntel": null,
    "tagline": "A custodial or semi-custodial financial service.",
    "kycNote": "Required photo ID on every kiosk transaction from a phased rollout beginning 24 February 2026, up from ID on larger purchases only. The network went offline on 18 May 2026 with the Chapter 11 filing, so no current verification surface exists to check.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-08-07",
    "fee": "15%",
    "stateActorFlag": "US-corp. Bitcoin ATM operator. Registered with FinCEN. Full KYC on large transactions.",
    "followTheMoney": "  Bitcoin Depot Inc - Atlanta, Georgia (US)\n  ──────────────────────────────────────\n  CEO: Scott Buchanan · NASDAQ: BTM\n  Investors: Vanguard, Two Sigma, Invesco\n  Revenue: ~15% ATM fee spread\n  ├─ NASDAQ public company (SPAC 2023)\n  ├─ FinCEN registered MSB\n  └─ Five Eyes (US) - full KYC exposure",
    "lastReviewed": "2026-08-07",
    "kycLastChecked": "2026-08-07",
    "reviewSource": "official_site_batch_6_2026-06-22",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "danger",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://www.sec.gov/Archives/edgar/data/1901799/0001193125-26-227832/d130621d8k.htm",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Bitcoin Depot Inc.",
        "citation": "https://www.sec.gov/Archives/edgar/data/1901799/0001193125-26-227832/d130621d8k.htm"
      },
      "registrationNumber": {
        "value": "87-3219029 (I.R.S. Employer Identification No.); CIK 0001901799",
        "citation": "https://www.sec.gov/Archives/edgar/data/1901799/0001193125-26-227832/d130621d8k.htm"
      },
      "registryUrl": {
        "value": "https://www.sec.gov/cgi-bin/browse-edgar?CIK=0001901799",
        "citation": "https://www.sec.gov/cgi-bin/browse-edgar?CIK=0001901799"
      },
      "incorporationJurisdiction": {
        "value": "Delaware",
        "citation": "https://www.sec.gov/Archives/edgar/data/1901799/0001193125-26-227832/d130621d8k.htm"
      },
      "incorporationDate": {
        "value": "June 30, 2023 (name change via Second Amended and Restated Certificate of Incorporation following SPAC merger; predecessor Lux Vending, LLC incorporated June 7, 2016 in Georgia)",
        "citation": "https://ir.bitcoindepot.com/sec-filings/all-sec-filings/content/0001193125-26-113938/btm-20251231.htm"
      },
      "registeredAddress": {
        "value": "8601 Dunwoody Place, Sandy Springs, GA 30350",
        "citation": "https://ir.bitcoindepot.com/sec-filings/all-sec-filings/content/0001193125-26-227832/0001193125-26-227832.pdf"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [
          "GSR II Meteora Acquisition Corp. (SPAC predecessor)",
          "Lux Vending, LLC (Georgia LLC, merged 2023)"
        ],
        "citation": "https://ir.bitcoindepot.com/sec-filings/all-sec-filings/content/0001193125-26-113938/btm-20251231.htm"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.bitcoindepot.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.bitcoindepot.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.bitcoindepot.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 229,
    "slug": "coinflip",
    "domain": "coinflip.tech",
    "name": "CoinFlip",
    "type": "Bitcoin ATM",
    "cat": "p2p",
    "kyc": "light",
    "kycLevel": 2,
    "fees": {
      "transaction": null
    },
    "limits": {},
    "features": [
      "US",
      "Buy & Sell",
      "Cash"
    ],
    "networks": [
      "atm"
    ],
    "badge": "ATM",
    "url": "https://coinflip.tech/",
    "geo": [
      "US",
      "CA"
    ],
    "status": "ok",
    "checkedAt": "2026-08-27",
    "countries": [
      "US"
    ],
    "categories": [
      "Bitcoin ATM"
    ],
    "description": "CoinFlip/Olliv crypto ATM and wallet service, with US ATM locations and a separate EU page operating under MiCA.",
    "cardSummary": "Crypto ATM and wallet service.",
    "jurisdiction": "US",
    "auditedBy": null,
    "twitter": "https://x.com/coinflipatms",
    "privacyWarning": "Five Eyes/regulated ATM risk retained; official geolocated page also shows Olliv Italia S.r.l. MiCA authorization, so jurisdiction/routing should be rechecked from a US network before stronger claims.",
    "founderIntel": null,
    "vcIntel": null,
    "tagline": "A custodial or semi-custodial financial service.",
    "kycNote": "Existing phone/ID verification risk retained; the source pass confirmed the live CoinFlip site but it redirected to an Italy page, so US-specific KYC thresholds were not upgraded from official text.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-06-22",
    "fee": null,
    "stateActorFlag": "US-corp. Bitcoin ATM. FinCEN registered. KYC required above thresholds.",
    "followTheMoney": "  CoinFlip Inc - Chicago, Illinois (US)\n  ──────────────────────────────────────\n  CEO: Benjamin Weiss · Founded: 2015\n  Seed: $7.84M (Shoreline, JetBlue VC)\n  Revenue: ~15% ATM fee spread\n  ├─ JetBlue VC: aviation tech, no intel\n  ├─ FinCEN registered, US MSB\n  └─ 2,500+ US ATMs, cash accepted",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_6_2026-06-22",
    "jurisdictionConfidence": "inferred",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://coinflip.tech/terms/terms-of-service",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "GPD Holdings LLC",
        "citation": "https://coinflip.tech/terms/terms-of-service"
      },
      "incorporationJurisdiction": {
        "value": "Delaware",
        "citation": "https://calixsolutions.io/wp-content/uploads/2020/01/CoinFlip-ATM-Placement-Agreement.pdf"
      },
      "registeredAddress": {
        "value": "433 W. Van Buren St., Suite 1050N, Chicago, IL, 60607",
        "citation": "https://apps.sos.wv.gov/business/corporations/organization.aspx?org=497016"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "extensive",
      "controlModel": "noncustodial-hosted",
      "sourceModel": "closed"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "extensive",
          "sourceUrls": [
            "https://coinflip.tech/about-us"
          ],
          "reviewedAt": "2026-08-27",
          "note": "identity, contact, device, location, transaction, marketing and partner data"
        },
        "controlModel": {
          "value": "noncustodial-hosted",
          "sourceUrls": [
            "https://coinflip.tech/about-us"
          ],
          "reviewedAt": "2026-08-27",
          "note": "regulated-operator-plus-self-custodial-wallet"
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://coinflip.tech/about-us"
          ],
          "reviewedAt": "2026-08-27",
          "note": "closed-service-with-separate-wallet"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No current product-specific independent audit citation/date/scope found."
      }
    },
    "limit": null
  },
  {
    "id": 231,
    "slug": "localcoin-au",
    "domain": "localcoinatm.com",
    "name": "Localcoin (AU)",
    "type": "Bitcoin ATM",
    "cat": "p2p",
    "kyc": "full",
    "kycLevel": 4,
    "fees": {
      "transaction": null
    },
    "limits": {
      "daily": 20000
    },
    "features": [
      "Australia",
      "BTC/ETH/USDT/USDC"
    ],
    "networks": [
      "atm"
    ],
    "badge": "AU",
    "url": "https://localcoinatm.com/en-au/",
    "geo": [
      "AU"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "countries": [
      "AU"
    ],
    "categories": [
      "Bitcoin ATM"
    ],
    "description": "Australian crypto ATM service for cash trades, requiring government-issued ID verification before transactions.",
    "cardSummary": "Australian crypto ATMs, ID required.",
    "jurisdiction": "AU",
    "auditedBy": null,
    "twitter": "https://x.com/localcoinatm",
    "privacyWarning": "Australia/Five Eyes ATM operator; identity, selfie, phone, wallet, cash transaction and support data are exposed to compliance workflows.",
    "founderIntel": "Tristan Fong and Jay Pandher (Founders). Corporate Entity: Localcoin. Headquartered in Toronto, Canada, but operating ATM fleets inside Australia. Backing: Privately held, bootstrapped retail crypto operation expanding across Five Eyes jurisdictions.",
    "vcIntel": "Australian ATM operator. Five Eyes jurisdiction. Compliant with AUSTRAC (Australian financial intelligence).",
    "tagline": "A custodial or semi-custodial financial service.",
    "kycNote": "Official Australia support snippets and KYC page state all users must verify identity before transactions, including government-issued photo ID and selfie/mobile verification.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-08-25",
    "fee": "Variable exchange fee included in the displayed rate; exact percentage is not published",
    "stateActorFlag": "Australian operator. Five Eyes jurisdiction. Subject to AML/CTF Act.",
    "followTheMoney": "  Localcoin - Toronto, Canada (CA)\n  ──────────────────────────────────────\n  Founders: Tristan Fong, Jay Pandher\n  Revenue: ~12% ATM fee spread (AU)\n  Funding: bootstrapped retail operation\n  ├─ AU ops under AUSTRAC oversight\n  ├─ Five Eyes: CA + AU jurisdiction\n  └─ Phone verification required",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "primary_source_rereview_2026-08-25",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://localcoinatm.com/en-au/terms-service"
      },
      "legalEntity": {
        "value": "Damasca Pty Ltd o/a Localcoin",
        "citation": "https://localcoinatm.com/en-au/terms-service"
      },
      "incorporationJurisdiction": {
        "value": "Australia",
        "citation": "https://localcoinatm.com/en-au/terms-service"
      },
      "source": "primary source re-review 2026-08-25",
      "reviewedAt": "2026-08-25"
    },
    "limit": "$5 AUD minimum; $5,000 per transaction; $20,000 daily",
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://localcoinatm.com/en-au/faq/",
            "https://localcoinatm.com/en-au/terms-service",
            "https://localcoinatm.com/en-au/privacy-policy/",
            "https://localcoinatm.com/en-au/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://localcoinatm.com/en-au/faq/",
            "https://localcoinatm.com/en-au/terms-service",
            "https://localcoinatm.com/en-au/privacy-policy/",
            "https://localcoinatm.com/en-au/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://localcoinatm.com/en-au/faq/",
            "https://localcoinatm.com/en-au/terms-service",
            "https://localcoinatm.com/en-au/privacy-policy/",
            "https://localcoinatm.com/en-au/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 240,
    "slug": "lnp2pbot",
    "domain": "lnp2pbot.com",
    "name": "@lnp2pBot",
    "type": "Telegram P2P (Lightning)",
    "cat": "p2p",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0.5
    },
    "limits": {
      "daily": "No Limit"
    },
    "features": [
      "TG escrow",
      "LN only",
      "Global"
    ],
    "networks": [],
    "badge": "TG",
    "url": "https://lnp2pbot.com/",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-24",
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Telegram P2P (Lightning)"
    ],
    "description": "Open-source Telegram P2P Bitcoin marketplace over Lightning hold invoices, with no registration or KYC stated.",
    "cardSummary": "Telegram P2P bitcoin trades over Lightning.",
    "jurisdiction": "??",
    "auditedBy": null,
    "founderIntel": null,
    "vcIntel": null,
    "tagline": "A custodial or semi-custodial financial service.",
    "kycNote": "No KYC, no registration, no identity verification per official site; Telegram account metadata still applies.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-06-22",
    "fee": "0.5%",
    "stateActorFlag": null,
    "privacyWarning": "Telegram-based access leaks Telegram account/network metadata; fiat settlement happens peer-to-peer outside the bot.",
    "followTheMoney": "  @lnp2pBot - Venezuela / Global\n  ──────────────────────────────────────\n  Founder: Francisco Calderón (@negrunch)\n  Funding: Human Rights Foundation grant\n  Revenue: 0.5% Lightning escrow fee\n  ├─ HRF: US-based pro-freedom NGO\n  ├─ Open-source, no custodial risk\n  └─ Widely used LATAM no-KYC BTC",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_4_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "unresolved",
        "citation": "unknown",
        "note": "Pass 1 researched this service but established no registry facts."
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://lnp2pbot.com/",
            "https://github.com/lnp2pBot/doc-site/blob/main/english/src/fees-and-commissions.md",
            "https://github.com/lnp2pBot"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://lnp2pbot.com/",
            "https://github.com/lnp2pBot/doc-site/blob/main/english/src/fees-and-commissions.md",
            "https://github.com/lnp2pBot"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://lnp2pbot.com/",
            "https://github.com/lnp2pBot/doc-site/blob/main/english/src/fees-and-commissions.md",
            "https://github.com/lnp2pBot"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 241,
    "slug": "bitcoinvoucherbot",
    "domain": "bitcoinvoucher.bot",
    "name": "BitcoinVoucherBot",
    "type": "Telegram Vouchers",
    "cat": "gift",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 5
    },
    "limits": {
      "daily": 500
    },
    "features": [
      "No-KYC",
      "No email",
      "No documents",
      "LN escrow",
      "Tor-friendly"
    ],
    "networks": [],
    "badge": "TG",
    "url": "https://bitcoinvoucher.bot/",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-22",
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "P2P / Lightning"
    ],
    "description": "Non-custodial P2P Bitcoin marketplace where pseudonymous avatars trade through automated Lightning escrow.",
    "cardSummary": "Non-custodial P2P bitcoin over Lightning.",
    "jurisdiction": "??",
    "auditedBy": null,
    "founderIntel": null,
    "vcIntel": null,
    "tagline": "A custodial or semi-custodial financial service.",
    "kycNote": "No email, phone or ID; avatar creation uses a small Lightning anti-spam invoice and password.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-06-22",
    "fee": "5%",
    "stateActorFlag": null,
    "privacyWarning": "Fiat settlement happens directly between users via bank transfer, Revolut, Wise, vouchers, cash or other methods, which can expose counterparty/payment metadata.",
    "followTheMoney": "  BitcoinVoucherBot - Italy / Global\n  ──────────────────────────────────────\n  Founder: Massimo Musumeci (Massmux, IT)\n  Funding: solo operator, self-funded\n  Revenue: 5% fee on voucher sales\n  ├─ Italian physicist, 25yr crypto bg\n  ├─ On-chain + Lightning + Liquid\n  └─ No accounts, no KYC required",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_4_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "unresolved",
        "citation": "unknown",
        "note": "Pass 1 researched this service but established no registry facts."
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://bitcoinvoucher.bot/",
            "https://bitcoinvoucher.bot/#escrow",
            "https://bitcoinvoucher.bot/#features",
            "https://bitcoinvoucher.bot/manual.html",
            "https://p2p.bitcoinvoucher.bot/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://bitcoinvoucher.bot/",
            "https://bitcoinvoucher.bot/#escrow",
            "https://bitcoinvoucher.bot/#features",
            "https://bitcoinvoucher.bot/manual.html",
            "https://p2p.bitcoinvoucher.bot/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://bitcoinvoucher.bot/",
            "https://bitcoinvoucher.bot/#escrow",
            "https://bitcoinvoucher.bot/#features",
            "https://bitcoinvoucher.bot/manual.html",
            "https://p2p.bitcoinvoucher.bot/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 220,
    "slug": "uquid",
    "domain": "uquid.com",
    "name": "UQUID Shop",
    "type": "Gift Cards & Top-ups",
    "cat": "gift",
    "kyc": "light",
    "kycLevel": 2,
    "fees": {
      "transaction": 2
    },
    "limits": {
      "daily": 3000
    },
    "features": [
      "Top-ups",
      "eSIMs",
      "Bills"
    ],
    "networks": [],
    "badge": "GLOBAL",
    "url": "https://uquid.com/",
    "geo": [
      "GLOBAL",
      "EU",
      "UK",
      "IN",
      "NG",
      "KE",
      "ZA",
      "BR",
      "MX",
      "AR",
      "AU"
    ],
    "status": "ok",
    "checkedAt": "2026-08-26",
    "countries": [
      "IN",
      "NG",
      "KE",
      "ZA",
      "BR",
      "MX",
      "AR",
      "US",
      "EU",
      "UK",
      "AU"
    ],
    "categories": [
      "Gift Cards & Top-ups"
    ],
    "description": "Crypto shopping, gift-card, top-up and prepaid-card platform where card limits can require identity documents.",
    "cardSummary": "Crypto shopping, gift cards and prepaid cards.",
    "jurisdiction": "CZ",
    "auditedBy": null,
    "twitter": "https://x.com/uquidcard",
    "telegram": "https://t.me/uquidcoinofficial",
    "founderIntel": null,
    "vcIntel": null,
    "kycNote": "Top-up/shop paths may be account-light, but Uquid card FAQ references upgrade thresholds, identity verification and uploaded documents for higher card use.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-06-22",
    "fee": "2%",
    "stateActorFlag": null,
    "privacyWarning": "Card and bank-like features can require identity documents and issuer/provider verification; not suitable as a zero-KYC card route.",
    "followTheMoney": "  Cocsi LTD / UQUID - Tallinn, Estonia\n  ──────────────────────────────────────\n  CEO: Tran Hung (Vietnamese, UK-educated)\n  Funding: bootstrapped, no VC\n  Revenue: ~2% markup on gift/top-ups\n  ├─ Estonia registered, EU/GDPR\n  ├─ Founder also ran OMGFIN exchange\n  └─ No KYC for standard purchases",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_4_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/08504004",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "COCSI LTD",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/08504004"
      },
      "registrationNumber": {
        "value": "08504004",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/08504004"
      },
      "registryUrl": {
        "value": "https://find-and-update.company-information.service.gov.uk/company/08504004",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/08504004"
      },
      "incorporationJurisdiction": {
        "value": "United Kingdom",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/08504004"
      },
      "incorporationDate": {
        "value": "25 April 2013",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/08504004"
      },
      "registeredAddress": {
        "value": "Office 14, Steeple House, Percy Street, Coventry, England, CV1 3BY",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/08504004"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-26",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://uquid.com/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "terms/privacy material unavailable"
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://uquid.com/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "accessible product pages do not establish card issuer custody/control"
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://uquid.com/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "no reviewed official source establishes a source model"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "no-score-points-no-cap-exception"
      }
    }
  },
  {
    "id": 243,
    "slug": "bando",
    "domain": "bando.cool",
    "name": "Bando",
    "type": "Top-ups & Vouchers",
    "cat": "gift",
    "kyc": "full",
    "kycLevel": 4,
    "fees": {
      "transaction": null
    },
    "limits": {
      "daily": null
    },
    "features": [
      "Mexican CETES",
      "Digital-dollar treasury",
      "MXN conversion",
      "KYB/KYC onboarding",
      "China payouts (coming soon)"
    ],
    "networks": [],
    "badge": "TOP-UP",
    "url": "https://bando.cool/",
    "geo": [
      "GLOBAL",
      "IN",
      "NG",
      "KE",
      "ZA",
      "BR",
      "MX",
      "AR"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "countries": [
      "MX"
    ],
    "categories": [
      "Treasury",
      "Stablecoin Payments"
    ],
    "description": "Business treasury platform for Mexican CETES and digital dollars, with MXN conversion and required KYB/KYC onboarding; China payouts are marked coming soon.",
    "cardSummary": "Business treasury for CETES and digital dollars.",
    "jurisdiction": "MX",
    "auditedBy": null,
    "twitter": "https://x.com/bandocool",
    "founderIntel": "Bando.cool is operated by ETERNAL TECH HIRO S.A. DE C.V.; financial-service compliance is provided by Etherfuse Liquid Mx, S.A.P.I. de C.V. and Etherfuse Mx, S.A. de C.V.",
    "vcIntel": "Earlier public funding/team notes are superseded for listing purposes by current official terms; current service is compliance-heavy treasury infrastructure.",
    "kycNote": "Official terms require Know Your Customer and Know Your Business policies for platform use and related financial services.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-08-25",
    "fee": "Product-specific; disclosed during onboarding or in the applicable service terms.",
    "stateActorFlag": null,
    "privacyWarning": "No longer fits a no-KYC spend/top-up listing. Financial services are compliance-managed by Etherfuse entities; Bando operates as technology provider ETERNAL TECH HIRO S.A. DE C.V.",
    "followTheMoney": "  Bando - Mexico City, Mexico (MX)\n  ──────────────────────────────────────\n  Founders: Abraham, Luis, Eduardo (Bitso)\n  Raised: $200K (Outlier Ventures + 99)\n  Revenue: ~2% markup on LATAM top-ups\n  ├─ Outlier Ventures: UK Web3 (clean)\n  ├─ Non-Five Eyes: MX jurisdiction\n  └─ LATAM focus: airtime + gaming",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "https://bando.cool/",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://bando.cool/privacy",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "ETERNAL TECH HIRO S.A. DE C.V.",
        "citation": "https://bando.cool/privacy"
      },
      "incorporationJurisdiction": {
        "value": "Mexico",
        "citation": "https://bando.cool/privacy"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://bando.cool/",
            "https://bando.cool/terms"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://bando.cool/",
            "https://bando.cool/terms"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://bando.cool/",
            "https://bando.cool/terms"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 31,
    "slug": "payylink",
    "domain": "payy.network",
    "name": "Payy",
    "type": "Virtual/Physical Visa",
    "cat": "card",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "limits": {
      "daily": null
    },
    "features": [
      "EVM compatible",
      "Stablecoin native",
      "Native ZK proofs",
      "Privacy layer",
      "Zero-fee private ERC-20 transfers",
      "Existing-wallet RPC compatibility"
    ],
    "networks": [
      "EVM",
      "ERC-20"
    ],
    "badge": "AU",
    "url": "https://payy.network/",
    "geo": [
      "AU"
    ],
    "status": "ok",
    "checkedAt": "2026-06-24",
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Stablecoin Card",
      "Private Payments"
    ],
    "description": "Privacy-first EVM-compatible stablecoin chain with native zero-knowledge support and zero-fee private ERC-20 transfers.",
    "cardSummary": "EVM stablecoin chain with native ZK privacy.",
    "jurisdiction": "??",
    "auditedBy": [],
    "twitter": "https://x.com/payy_link",
    "founderIntel": "Payy by Zeplo, Inc.; privacy policy lists Zeplo, Inc. and contact page previously identified a New York address.",
    "vcIntel": "Public site lists FirstMark, 6th Man Ventures, Protocol Labs, Circle, DBA, Orange DAO, Upfront Ventures, Visa and others; news section says $6M seed led by FirstMark.",
    "tagline": "A custodial or semi-custodial financial service.",
    "kycNote": "The current public chain/docs expose no identity onboarding for protocol use. Ramps, wallets and applications may impose their own account or KYC requirements.",
    "privacyWarning": "Protocol-level privacy does not make ramps, wallets or applications private by default. Public terms/privacy pages exposed only client shells, so operator identity, data handling and the relationship to the retired KYC wallet/card product remain unresolved.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-06-22",
    "fee": "Zero fee for private ERC-20 transfers; other operations and integrations may require gas or provider fees",
    "stateActorFlag": null,
    "followTheMoney": "  PayyLink - Unknown (AU-based service)\n  ──────────────────────────────────────\n  Founders: completely anonymous\n  Revenue: card fees (undisclosed)\n  Funding: no investors identified\n  ├─ Zero web footprint beyond domain\n  ├─ No regulatory filings found\n  └─ High-risk: no corporate structure",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_4_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "limited",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "unresolved",
        "citation": "unknown",
        "note": "Pass 1 researched this service but established no registry facts."
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://docs.payy.network/",
            "https://payy.network/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Current protocol documentation describes private transfers but the live privacy/terms routes are client shells, so operator telemetry, retention and account boundaries cannot be established."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://docs.payy.network/",
            "https://docs.payy.network/privacy/native-zk"
          ],
          "reviewedAt": "2026-08-27",
          "note": "The docs establish an EVM-compatible chain and privacy components but do not establish who controls sequencing, upgrades or emergency authority."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://docs.payy.network/",
            "https://payy.network/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No official score-critical implementation repository, license or reproducible deployment evidence was located."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced; no audit points are granted."
      }
    }
  },
  {
    "id": 301,
    "slug": "sideshift",
    "domain": "sideshift.ai",
    "name": "SideShift.ai",
    "type": "Swap",
    "cat": "swap",
    "kyc": "light",
    "kycLevel": 2,
    "fees": null,
    "fee": "Variable and included in the quoted transaction rate; network/deployer fees may vary",
    "limits": {
      "daily": null
    },
    "features": [
      "Direct-to-wallet",
      "300+ coins",
      "Fixed and variable rates",
      "Wallet-connected interface",
      "Automated transaction risk screening"
    ],
    "networks": [],
    "badge": "SWAP",
    "url": "https://sideshift.ai/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Swap"
    ],
    "description": "Direct-to-wallet swaps across 300+ coins with fixed/variable rates; automated risk controls may freeze or refuse a transaction and request compliance information.",
    "cardSummary": "Instant non-custodial swaps, 600+ pairs.",
    "jurisdiction": "KN",
    "auditedBy": null,
    "twitter": "https://x.com/sideshiftai",
    "telegram": "https://t.me/joinsideshiftai",
    "founderIntel": null,
    "vcIntel": null,
    "kycNote": "No traditional exchange account is required for a basic shift, but SideShift uses automated risk screening, may freeze/refuse transactions, and may request verification or compliance data.",
    "updatedAt": "2026-08-25",
    "stateActorFlag": null,
    "privacyWarning": "SideShift collects IP/device/usage, wallet addresses, transaction metadata and PostHog analytics. Automated risk screening may freeze/refuse a shift and compliance information may be requested or disclosed to authorities. Terms exclude US, Cuba, Iran, North Korea, Saint Kitts and Nevis, and Syria.",
    "followTheMoney": "  Paradigm Ltd - Saint Kitts & Nevis\n  ──────────────────────────────────────\n  CEO: Andreas Brekken (Norwegian)\n  Seed: $787K (investors undisclosed)\n  Revenue: ~1% swap spread\n  ├─ SKN registered, no OFAC action\n  ├─ Norwegian founder, non-custodial\n  └─ No accounts, 600+ coin pairs",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "primary_source_rereview_2026-08-25",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://sideshift.ai/legal",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Paradigm Ltd",
        "citation": "https://sideshift.ai/legal"
      },
      "incorporationJurisdiction": {
        "value": "St. Kitts and Nevis",
        "citation": "https://sideshift.ai/legal"
      },
      "registeredAddress": {
        "value": "858 Zenway Blvd, Frigate Bay, P.O. Box 2086, 0000, Basseterre, St. Kitts & Nevis (c/o IIC Management Company Ltd)",
        "citation": "https://play.google.com/store/apps/details?id=ai.sideshift.app"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://sideshift.ai/",
            "https://sideshift.ai/legal",
            "https://sideshift.ai/privacy"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://sideshift.ai/",
            "https://sideshift.ai/legal",
            "https://sideshift.ai/privacy"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://sideshift.ai/",
            "https://sideshift.ai/legal",
            "https://sideshift.ai/privacy"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 302,
    "slug": "fixedfloat",
    "domain": "ff.io",
    "name": "FixedFloat",
    "type": "Swap",
    "cat": "swap",
    "kyc": "light",
    "kycLevel": 3,
    "fees": {
      "transaction": 0.5
    },
    "fee": "0.5–1%",
    "limits": {
      "daily": null
    },
    "features": [
      "Fixed rate",
      "Variable rate",
      "No account",
      "Instant",
      "Refund address"
    ],
    "networks": [],
    "badge": "SWAP",
    "url": "https://ff.io/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Swap"
    ],
    "description": "Fixed and floating rate crypto swaps with no account required, supporting Lightning Network and major assets.",
    "cardSummary": "Fixed and floating swaps, no account needed.",
    "jurisdiction": "GE",
    "auditedBy": null,
    "twitter": "https://x.com/fixedfloat",
    "telegram": "https://t.me/fixedfloat",
    "founderIntel": "Fully anonymous team. No founder names disclosed. Post-hack communications included team member named \"Evgenii\" - Russian first name. ~12% of web traffic from Russia (2nd after US at 26%). Legal entity: registered in London, UK per Tracxn (not Seychelles as previously stated). Cooperated with law enforcement and blockchain forensics companies after 2024 hack by own admission.",
    "vcIntel": "Registered in London, UK. Anonymous operators. Zero public VC. SECURITY INCIDENTS: Hacked twice in 2024 - .1M (Feb 16) and .8M additional (March 31) by same attacker group exploiting third-party Time4VPS hosting. Coordinated with law enforcement per their public blog. Russian-speaking team likely; majority of non-US traffic from Russia.",
    "kycNote": "No account is required for an ordinary exchange, but current AML rules permit order suspension and requests for source-of-funds details or identity verification when risk controls trigger.",
    "privacyWarning": "Two thefts were reported in 2024: $26.1M on February 16 and $2.8M on April 1. The service attributed the incidents to infrastructure vulnerabilities involving third-party providers. The operating team is not named.",
    "updatedAt": "2026-08-25",
    "stateActorFlag": null,
    "followTheMoney": "Registered location: London, UK\nTeam: not publicly named\nFunding: no venture funding recorded\nRevenue: 0.5% to 1% swap fee\nIncidents: two thefts in 2024, $28.9M reported total",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "https://ff.io/terms-of-service",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://ff.io/en/terms-of-service",
        "note": "Registry-sourced corporate record established in pass 1 via incorporationJurisdiction."
      },
      "incorporationJurisdiction": {
        "value": "Georgia",
        "citation": "https://ff.io/en/terms-of-service"
      },
      "registeredAddress": {
        "value": "88 Avtomshenebeli Street, Kutaisi 4600, Georgia",
        "citation": "https://ff.io/en/terms-of-service"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "current official Terms reviewed 2026-08-25; prior Georgian registry evidence retained",
      "reviewedAt": "2026-08-25",
      "legalEntity": {
        "value": "FFGX Group LLC",
        "citation": "https://ff.io/terms-of-service"
      }
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://ff.io/terms-of-service",
            "https://ff.io/blog/news/weekly-2026-08-22",
            "https://ff.io/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://ff.io/terms-of-service",
            "https://ff.io/blog/news/weekly-2026-08-22",
            "https://ff.io/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://ff.io/terms-of-service",
            "https://ff.io/blog/news/weekly-2026-08-22",
            "https://ff.io/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 304,
    "slug": "stealthex",
    "domain": "stealthex.io",
    "name": "StealthEX",
    "type": "Swap",
    "cat": "swap",
    "kyc": "light",
    "kycLevel": 1,
    "fees": {
      "transaction": 0.4
    },
    "fee": "0.4%",
    "limits": {
      "daily": null
    },
    "features": [
      "1000+ pairs",
      "No account",
      "Non-custodial",
      "Instant",
      "No registration"
    ],
    "networks": [],
    "badge": "SWAP",
    "url": "https://stealthex.io/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-26",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Swap"
    ],
    "description": "Instant swap front-end with no registration step, though its terms reserve KYC checks through third parties.",
    "cardSummary": "Instant swaps, compliance checks reserved.",
    "jurisdiction": "CR",
    "auditedBy": null,
    "founderIntel": null,
    "vcIntel": null,
    "kycNote": "No-registration swap UX, but official terms say third-party compliance procedures may include KYC; do not treat as zero-KYC.",
    "updatedAt": "2026-06-22",
    "stateActorFlag": null,
    "privacyWarning": "Risk-based KYC can be requested directly by StealthEx, and third-party fiat providers conduct their own compliance checks. The privacy policy also covers IP/device, transaction, blockchain-analytics, profile, and identity-verification data.",
    "followTheMoney": "  Offshore (Cayman/SVG/Marshall Islands)\n  ──────────────────────────────────────\n  CEO: Maria Carola (Lithuanian-educated)\n  Funding: bootstrapped, no public VC\n  Revenue: 0.4% swap fee\n  ├─ Multiple offshore registrations\n  ├─ Founded 2018, 1000+ coin pairs\n  └─ No OFAC action, caution advised",
    "lastReviewed": "2026-08-26",
    "kycLastChecked": "2026-08-26",
    "reviewSource": "Primary-source review 2026-08-26",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://stealthex.io/kyc-aml/",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "StealthEx Ltd",
        "citation": "https://stealthex.io/kyc-aml/"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "noncustodial-hosted",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-26",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://stealthex.io/privacy-policy/",
            "https://stealthex.io/kyc-aml/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "official privacy and KYC policies describe personal-data and identity-verification processing"
        },
        "controlModel": {
          "value": "noncustodial-hosted",
          "sourceUrls": [
            "https://stealthex.io/terms/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "official terms expressly say no custody is retained during transaction processing"
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://stealthex.io/privacy-policy/",
            "https://stealthex.io/kyc-aml/",
            "https://stealthex.io/terms/",
            "https://stealthex.io/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "ownership language does not establish whether the deployed source is public or closed"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "no-score-points-no-cap-exception"
      }
    }
  },
  {
    "id": 305,
    "slug": "mullvad-vpn",
    "domain": "mullvad.net",
    "name": "Mullvad VPN",
    "type": "VPN",
    "cat": "vpn",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 5
    },
    "fee": "€5/mo",
    "limits": {
      "daily": null
    },
    "features": [
      "No email required",
      "Account number only",
      "Cash accepted",
      "XMR accepted",
      "BTC accepted",
      "No logs",
      "Audited",
      "No Cloudflare",
      "Open source client",
      "WireGuard + OpenVPN"
    ],
    "networks": [],
    "badge": "VPN",
    "url": "https://mullvad.net/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-24",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "VPN"
    ],
    "description": "Swedish VPN using numbered accounts, whose policy states no activity logging and accepts cash, BTC and XMR.",
    "cardSummary": "Numbered-account VPN with no activity logs.",
    "jurisdiction": "SE",
    "auditedBy": [
      "Cure53"
    ],
    "twitter": "https://x.com/mullvadnet",
    "founderIntel": null,
    "vcIntel": null,
    "kycNote": "No identity KYC for account creation; account-number model. Payment method can still create metadata depending on payment rail.",
    "updatedAt": "2026-06-22",
    "stateActorFlag": null,
    "privacyWarning": null,
    "followTheMoney": "Mullvad VPN AB\n────────────────────────\nParent: Amagicom AB\nOwners: Fredrik Strömberg\nand Daniel Berntsson\nOwnership: founders hold 100%",
    "publicClaims": {
      "followTheMoney": {
        "value": "Mullvad VPN AB\n────────────────────────\nParent: Amagicom AB\nOwners: Fredrik Strömberg\nand Daniel Berntsson\nOwnership: founders hold 100%",
        "reviewedAt": "2026-07-15",
        "sources": [
          {
            "label": "Mullvad - About",
            "href": "https://mullvad.net/en/about",
            "type": "official"
          }
        ]
      }
    },
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_2_2026-06-22",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://mullvad.net/en/help/terms-service",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Mullvad VPN AB",
        "citation": "https://mullvad.net/en/help/terms-service"
      },
      "registrationNumber": {
        "value": "559238-4001",
        "citation": "https://mullvad.net/en/help/terms-service"
      },
      "registryUrl": {
        "value": "https://bolagsverket.se/",
        "citation": "https://mullvad.net/en/help/terms-service"
      },
      "incorporationJurisdiction": {
        "value": "Sweden",
        "citation": "https://mullvad.net/en/help/terms-service"
      },
      "incorporationDate": {
        "value": "2020-01-24",
        "citation": "https://lei.bloomberg.com/leis/view/636700KMQ59YDJ6AW887"
      },
      "registeredAddress": {
        "value": "PO Box 53049, 40014 Gothenburg, Sweden",
        "citation": "https://mullvad.net/en/help/terms-service"
      },
      "parentEntity": {
        "value": "Amagicom AB",
        "citation": "https://mullvad.net/en/help/terms-service"
      },
      "ultimateOwner": {
        "value": "Fredrik Strömberg and Daniel Berntsson",
        "citation": "https://mullvad.net/en/about"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://mullvad.net/en/pricing",
            "https://mullvad.net/en/help/no-logging-data-policy",
            "https://mullvad.net/en/help/terms-service",
            "https://mullvad.net/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://mullvad.net/en/pricing",
            "https://mullvad.net/en/help/no-logging-data-policy",
            "https://mullvad.net/en/help/terms-service",
            "https://mullvad.net/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://mullvad.net/en/pricing",
            "https://mullvad.net/en/help/no-logging-data-policy",
            "https://mullvad.net/en/help/terms-service",
            "https://mullvad.net/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 306,
    "slug": "trocador",
    "domain": "trocador.app",
    "name": "Trocador",
    "type": "Swap",
    "cat": "swap",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "limits": {
      "daily": null
    },
    "features": [
      "Rate aggregator",
      "XMR pairs",
      "No account",
      "Tor-accessible",
      "Privacy-first"
    ],
    "networks": [],
    "badge": "SWAP",
    "url": "https://trocador.app/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-26",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Swap"
    ],
    "description": "Crypto swap rate aggregator covering XMR, plus prepaid cards, gift cards, DeFi bridges and AnonPay surfaces.",
    "cardSummary": "Swap aggregator with private routing options.",
    "jurisdiction": null,
    "auditedBy": null,
    "telegram": "https://t.me/trocadorsupportbot",
    "founderIntel": "Created by CryptoMorpheus_ - pseudonymous Monero community developer who also built Moneroj.net (Monero metrics/statistics site). Identity intentionally anonymous, consistent with Monero community values. No corporate structure disclosed. No legal entity found in any public registry. Community-trusted operator with positive track record.",
    "vcIntel": "No legal entity, no corporate registration found. Intentionally anonymous operator. Non-custodial aggregator model - earns referral commissions from partner exchanges without handling funds. Zero state-actor connections found. No OFAC designation. Receives commissions from partner exchanges, disclosed on-site.",
    "kycNote": "Swap surface is no-account style, but users should still expect partner-exchange risk controls and possible KYC/AML checks depending on route, amount, and provider.",
    "changedAt": "2026-03-12",
    "updatedAt": "2026-06-22",
    "fee": "Free",
    "stateActorFlag": null,
    "privacyWarning": "Trocador deletes ordinary trade details after 14 days or on request, but may retain IP address, User-Agent, Accept-Language and exchange-required data for longer; partner exchanges keep their own data and may require KYC. Terms prohibit US and EEA citizens/residents plus UN/OFAC-sanctioned jurisdictions.",
    "followTheMoney": "  Trocador.app - Unknown jurisdiction\n  ──────────────────────────────────────\n  Founders: pseudonymous\n  Funding: bootstrapped, no VC\n  Revenue: 0.5–1.5% swap spread\n  ├─ No KYC, no accounts\n  ├─ Aggregates 20+ exchange APIs\n  └─ No corporate parent disclosed",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_browser_verified_batch_2_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://trocador.app/en/anonpaydocumentation",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Reta Development Assets LLC",
        "citation": "https://trocador.app/en/anonpaydocumentation"
      },
      "incorporationJurisdiction": {
        "value": "Saint Kitts and Nevis",
        "citation": "https://trocador.app/en/anonpaydocumentation"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-26",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://trocador.app/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "current privacy policy unavailable"
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://trocador.app/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "current terms unavailable"
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://trocador.app/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "no reviewed official source establishes a source model"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "no-score-points-no-cap-exception"
      }
    }
  },
  {
    "id": 307,
    "slug": "nicevps",
    "domain": "nicevps.net",
    "name": "NiceVPS",
    "type": "Hosting",
    "cat": "hosting",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "limits": {
      "daily": null
    },
    "features": [
      "XMR-native",
      "No account email",
      "VPS",
      "Domains",
      "Anonymous"
    ],
    "networks": [],
    "badge": "HOSTING",
    "url": "https://nicevps.net/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-23",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Hosting"
    ],
    "description": "VPS, hosting, domains, SMTP relay and VPN whose homepage states no personal details or KYC, paid in BTC or XMR.",
    "cardSummary": "VPS, hosting and VPN paid in crypto.",
    "jurisdiction": "DM",
    "auditedBy": [],
    "founderIntel": "Anonymous operator. Corporate entity not publicly disclosed. Accepts cryptocurrency. Threat-intelligence reports have linked activity to addresses on shared NiceVPS infrastructure; this does not identify unrelated customers or establish operator involvement.",
    "vcIntel": "Independent hosting provider. Accepts XMR. No public VC. Opaque ownership.",
    "kycNote": "Official homepage states it will never request personal details / no KYC; accepts cryptocurrencies including Bitcoin, Monero, Dash, and Zcash.",
    "stateActorFlag": null,
    "privacyWarning": "Threat-intelligence reports have linked third-party activity to addresses on NiceVPS infrastructure. This records shared-hosting abuse, not a direct incident against NiceVPS users. No user-loss or service-compromise incident is recorded. Current terms (last updated 2017) say signup collects email, username and password and uses session/remember-me cookies; the dedicated privacy route exposes no substantive policy. No public status or security advisory source was located.",
    "updatedAt": "2026-06-22",
    "fee": "Free",
    "followTheMoney": "NiceVPS - operator not disclosed\nFunding: not recorded\nRevenue: hosting and domain fees\nAbuse reports: infrastructure linked to Cosmic Lynx and TeamTNT activity",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_2_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "limited",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://bgp.tools/as/49447",
        "note": "NiceVPS is operated as a commercial hosting service by Nice IT Services Group Inc., confirmed by the ASN AS49447 website field linking to nicevps.net, matching Dominica jurisdiction in the site's ToS, and RIPE organisation records."
      },
      "legalEntity": {
        "value": "Nice IT Services Group Inc.",
        "citation": "https://rest.db.ripe.net/search.json?query-string=ORG-NISG8-RIPE"
      },
      "registrationNumber": {
        "value": "2017/IBC00113",
        "citation": "https://rest.db.ripe.net/search.json?query-string=ORG-NISG8-RIPE"
      },
      "registryUrl": {
        "value": "https://cipo.gov.dm/",
        "citation": "https://cipo.gov.dm/"
      },
      "incorporationJurisdiction": {
        "value": "Dominica",
        "citation": "https://rest.db.ripe.net/search.json?query-string=ORG-NISG8-RIPE"
      },
      "registeredAddress": {
        "value": "28 Cork Street, 00152 Roseau, DOMINICA",
        "citation": "https://rest.db.ripe.net/search.json?query-string=ORG-NISG8-RIPE"
      },
      "officers": {
        "value": [
          "Kimon S."
        ],
        "citation": "https://rest.db.ripe.net/search.json?query-string=KS10518-RIPE"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "hosted-account",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://nicevps.net/index/tos"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Terms state email, username and password collection plus hosted-service/security context, supporting moderate rather than none/limited exposure."
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://nicevps.net/index/tos"
          ],
          "reviewedAt": "2026-08-27",
          "note": "NiceVPS provisions and controls hosted services through customer accounts."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://nicevps.net/index/tos",
            "https://nicevps.net/index/privacy-policy"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No current official source/license statement was found and the dedicated privacy route returned 404; critical-core source status is unknown, not safely closed/open."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced in the reopened first-party source family."
      }
    }
  },
  {
    "id": 308,
    "slug": "zashi-wallet",
    "noOperatorData": true,
    "domain": "zodl.com",
    "name": "Zodl (formerly Zashi)",
    "type": "Wallet",
    "cat": "wallet",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "0.0001 ZEC/tx",
    "limits": {
      "daily": null
    },
    "features": [
      "Shielded ZEC",
      "Zcash Shielded Assets",
      "Self-custody",
      "Open source",
      "CrossPay",
      "Private swaps via NEAR Intents",
      "Keystone hardware-wallet support",
      "Flexa merchant spend",
      "iOS + Android",
      "Zcash Open Development Lab"
    ],
    "networks": [],
    "badge": "ZEC",
    "url": "https://zodl.com/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": true,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Wallet"
    ],
    "description": "Self-custodial Zcash wallet with shielded payments, CrossPay, private swaps through NEAR Intents, Keystone hardware-wallet support, and Flexa merchant checkout.",
    "cardSummary": "Shielded Zcash wallet with swaps and hardware support.",
    "jurisdiction": "US",
    "auditedBy": null,
    "privacyWarning": "Wallet keys and activity stay local to Zodl, but CrossPay, NEAR Intents swap routing, transparent-address interactions, app stores, crash reporting, and Flexa merchant checkout can expose metadata to third parties. Third-party routes may impose their own screening, availability, and fee rules.",
    "founderIntel": "Built by Electric Coin Company (ECC), creator of Zcash. CEO: Josh Swihart (US). CTO: Kris Nuttycombe (US). Board/Advisors: Zaki Manian - CRITICAL: Manian knowingly withheld FBI information about North Korean developers (Lazarus Group-linked) who had contributed to the Cosmos blockchain codebase. US DOJ investigated. Separately, entire ECC engineering team resigned January 2026 amid internal governance disputes. Zashi development continuity uncertain post-Jan 2026.",
    "vcIntel": "Built by Electric Coin Company (ECC). ECC originally funded by Pantera Capital, Naval Ravikant, DCG via Zcash Founders Reward. US-incorporated (Colorado). Silicon Valley ecosystem.",
    "kycNote": "No identity KYC found for wallet use. Flexa merchant spend / CrossPay involve third-party rails and should be treated separately from base wallet custody.",
    "stateActorFlag": "ECC Bootstrap board advisor Zaki Manian withheld FBI intelligence about DPRK (Lazarus Group) developers in Cosmos codebase. Full ECC dev team resigned January 2026.",
    "updatedAt": "2026-08-25",
    "followTheMoney": "  Electric Coin Company - Denver, CO (US)\n  ──────────────────────────────────────\n  CEO: Josh Swihart · Founded: 2016\n  Backers: Pantera, Naval Ravikant, DCG\n  Revenue: Zcash Founders Reward (20%)\n  ├─ Advisor withheld FBI DPRK intel\n  ├─ Entire dev team resigned Jan 2026\n  └─ Five Eyes (US) - FISA exposure",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "https://zodl.com/",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://zodl.com/privacy-policy/",
        "note": "Terms of Service explicitly identify Zcash Open Development Lab (“ZODL,” “the company”) as the provider/developer of the Zodl wallet; confirmed as Znewco, Inc. d/b/a ZODL in SEC filings and app store developer info."
      },
      "governanceModel": {
        "value": "company-sponsored",
        "citation": "https://zodl.com/about/"
      },
      "repositoryUrl": {
        "value": "https://github.com/zodl-inc",
        "citation": "https://github.com/zodl-inc"
      },
      "legalEntity": {
        "value": "Znewco, Inc. (d/b/a Zcash Open Development Lab / ZODL)",
        "citation": "https://www.sec.gov/Archives/edgar/data/1509745/000110465926060662/cyph-20260331x10q.htm"
      },
      "incorporationJurisdiction": {
        "value": "Texas, United States",
        "citation": "https://uspto.report/company/Znewco-Inc"
      },
      "registeredAddress": {
        "value": "3723 Greenville Ave Ste 41367, Dallas, TX 75206-5311, United States",
        "citation": "https://play.google.com/store/apps/details?id=co.electriccoin.zcash&hl=en_US"
      },
      "officers": {
        "value": [
          {
            "name": "Josh Swihart",
            "role": "Founder and CEO"
          }
        ],
        "citation": "https://www.linkedin.com/in/swihart"
      },
      "priorEntities": {
        "value": [
          "The Zerocoin Electric Coin Company, LLC (Electric Coin Company / ECC) -- Prior developer/publisher of the Zashi wallet (now Zodl); entire team left ECC in January 2026 to form Znewco/ZODL"
        ],
        "citation": "https://zodl.com/about/"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://zodl.com/",
            "https://zodl.com/privacy-policy"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://zodl.com/",
            "https://zodl.com/privacy-policy"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://zodl.com/",
            "https://zodl.com/privacy-policy"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 309,
    "slug": "ywallet",
    "domain": "ywallet.app",
    "name": "YWallet",
    "type": "Wallet",
    "cat": "wallet",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "0.0001 ZEC/tx",
    "limits": {
      "daily": null
    },
    "features": [
      "Shielded",
      "Unified Addresses",
      "ZEC + Ycash",
      "Encrypted memo",
      "Self-custody",
      "Desktop + Mobile",
      "Open source",
      "Fast sync"
    ],
    "networks": [],
    "badge": "ZEC",
    "url": "https://ywallet.app/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "warning",
    "checkedAt": "2026-08-26",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Wallet"
    ],
    "description": "Advanced Zcash wallet for iOS, Android and desktop with full shielded support, fast sync and encrypted memos.",
    "cardSummary": "Shielded Zcash wallet for mobile and desktop.",
    "jurisdiction": null,
    "auditedBy": null,
    "founderIntel": "Pseudonymous developer known as 'Hanh'. Corporate Entity: None. Backing: Development is entirely funded through decentralized grants awarded by the Zcash Community Grants (ZCG) program. Represents independent, open-source community infrastructure.",
    "vcIntel": "Independent dev (Hanh Huynh). Donation funded. Zero VC. Pure community project.",
    "kycNote": "Self-custodial Zcash/Ycash wallet; no service account or identity KYC required to use the wallet.",
    "updatedAt": "2026-06-22",
    "stateActorFlag": null,
    "privacyWarning": "YWallet is deprecated and no longer supports Zcash after Ironwood; Ycash remains supported, with future work limited to security fixes and protocol updates. Zcash users are directed by the maintainer to ZKool.",
    "followTheMoney": "  YWallet - Open-source / Community\n  ──────────────────────────────────────\n  Dev: Hanh Huynh (pseudonymous)\n  Funding: Zcash Community Grants (ZCG)\n  Revenue: none (free, zero VC)\n  ├─ ZCG: community-voted XMR/ZEC grants\n  ├─ No corporate entity, no investors\n  └─ Self-custody ZEC, fast sync",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_3_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "project-no-legal-entity",
        "citation": "https://github.com/hhanh00/zwallet",
        "note": "Open-source self-custody wallet solely developed and MIT-copyrighted by individual Hanh Huynh Huu (hhanh00); Google Play lists him personally (Hong Kong) while Ycash Foundation is only the iOS App Store publisher/grantor and the project remains independent."
      },
      "governanceModel": {
        "value": "individual",
        "citation": "https://github.com/hhanh00/zwallet/blob/main/LICENSE.md"
      },
      "repositoryUrl": {
        "value": "https://github.com/hhanh00/zwallet",
        "citation": "https://github.com/hhanh00/zwallet"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "none",
      "controlModel": "local-self-custody",
      "sourceModel": "open"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-26",
      "inputs": {
        "operatorDataExposure": {
          "value": "none",
          "sourceUrls": [
            "https://raw.githubusercontent.com/hhanh00/zwallet/main/README.md"
          ],
          "reviewedAt": "2026-08-26",
          "note": "official README states no data upload and user-configurable server selection"
        },
        "controlModel": {
          "value": "local-self-custody",
          "sourceUrls": [
            "https://raw.githubusercontent.com/hhanh00/zwallet/main/README.md"
          ],
          "reviewedAt": "2026-08-26",
          "note": "official README describes seed/secret-key recoverability and local wallet signing features"
        },
        "sourceModel": {
          "value": "open",
          "sourceUrls": [
            "https://github.com/hhanh00/zwallet"
          ],
          "reviewedAt": "2026-08-26",
          "note": "official public source repository"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "no-score-points-no-cap-exception"
      }
    }
  },
  {
    "id": 310,
    "slug": "cake-wallet",
    "noOperatorData": true,
    "domain": "cakewallet.com",
    "name": "Cake Wallet",
    "type": "Wallet",
    "cat": "wallet",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "limits": {
      "daily": null
    },
    "features": [
      "XMR + ZEC + BTC + LTC",
      "Self-custody",
      "Built-in swap",
      "Open source",
      "iOS + Android",
      "No account",
      "Exchange via Trocador"
    ],
    "networks": [],
    "badge": "XMR/ZEC",
    "url": "https://cakewallet.com/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "warning",
    "checkedAt": "2026-06-24",
    "trending": true,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Wallet"
    ],
    "description": "Multi-coin privacy wallet - XMR, ZEC, BTC, LTC. Self-custody, built-in no-KYC swap, open source. iOS and Android. (Zero KYC)",
    "cardSummary": "Multi-coin wallet with built-in swaps.",
    "jurisdiction": "US",
    "auditedBy": null,
    "privacyWarning": "Cake Labs nodes may transiently receive IP address, wallet sync height, and submitted transactions/channels but state they do not retain them. Optional third-party buy/sell and swap services have separate privacy/KYC practices and may request personal information.",
    "founderIntel": "Vikrant Sharma (CEO). Location: United States. Background: Former Director at Lipstick.com, various mobile dev roles. Open-source iOS/Android wallet for XMR, BTC, LTC, ZEC. No KYC. Non-custodial. Active GitHub: github.com/cake-tech. US domicile noted but wallet is non-custodial - no user funds held. Community-trusted.",
    "vcIntel": "Cake Technologies LLC (US). Bootstrapped by Vik Sharma. No VC rounds. Self-funded via in-app exchange fees. US jurisdiction but independent.",
    "kycNote": "Advertises No-KYC, but strictly adhere to OPSEC rules. Access via Tor, pay with XMR.",
    "updatedAt": "2026-03-13",
    "fee": "Free",
    "stateActorFlag": null,
    "followTheMoney": "Cake Wallet\n────────────────────────\nFounder and CEO: Vikrant Sharma\nCake Wallet founded: 2018\nCake Labs founded: 2017\nSoftware: open source",
    "publicClaims": {
      "followTheMoney": {
        "value": "Cake Wallet\n────────────────────────\nFounder and CEO: Vikrant Sharma\nCake Wallet founded: 2018\nCake Labs founded: 2017\nSoftware: open source",
        "reviewedAt": "2026-07-15",
        "sources": [
          {
            "label": "Cake Wallet - About",
            "href": "https://cakewallet.com/about/",
            "type": "official"
          }
        ]
      }
    },
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_1_2026-06-22",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://cakewallet.com/terms/",
        "note": "Official Terms of Use state the apps are provided by Cake Labs LLC, a limited liability company formed under the laws of Nevis; security page and copyright also name Cake Labs LLC as developer."
      },
      "governanceModel": {
        "value": "company-sponsored",
        "citation": "https://cakelabs.com/"
      },
      "repositoryUrl": {
        "value": "https://github.com/cake-tech/cake_wallet",
        "citation": "https://github.com/cake-tech/cake_wallet"
      },
      "legalEntity": {
        "value": "Cake Labs LLC",
        "citation": "https://cakewallet.com/terms/"
      },
      "incorporationJurisdiction": {
        "value": "Nevis (Saint Kitts and Nevis)",
        "citation": "https://cakewallet.com/terms/"
      },
      "officers": {
        "value": [
          {
            "name": "Vikrant Sharma",
            "role": "CEO / Founder"
          },
          {
            "name": "Seth For Privacy",
            "role": "COO"
          }
        ],
        "citation": "https://cakewallet.com/about/"
      },
      "priorEntities": {
        "value": [
          "Cake Technologies, LLC (later renamed BLOCKBUY LLC) -- Florida LLC originally FOTOLOCKR, LLC (2015), renamed Cake Technologies, LLC (2018), renamed BLOCKBUY LLC (2022), voluntary dissolution 2024-07-12; managers included Vikrant Sharma and Sunali Sharma; Apple App Store still lists Cake Technologies, LLC as developer name",
          "Cake Labs LLC (Florida) -- Separate Florida LLC filed 2026-07-14, active; principal address 1416 Haven Dr, Orlando, FL 32803; authorized member Adam R Dewolfe - not the Nevis operating entity named in Terms"
        ],
        "citation": "https://search.sunbiz.org/Inquiry/CorporationSearch/SearchResultDetail?inquirytype=EntityName&directionType=Initial&searchNameOrder=CAKETECHNOLOGIES%20L150000241281&aggregateId=flal-l15000024128-fe067468-d0a1-4996-8c43-2a6e0a2d919b&searchTerm=CAKE%20TECHNOLOGIES&listNameOrder=CAKETECHNOLOGIES%20L150000241281"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://cakewallet.com/",
            "https://cakewallet.com/terms/",
            "https://cakewallet.com/privacy/",
            "https://cakewallet.com/security/",
            "https://github.com/cake-tech/cake_wallet/releases/tag/v6.4.1",
            "https://status.cakewallet.com/api/status-page/cake/badge",
            "https://status.cakewallet.com/api/status-page/cake"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://cakewallet.com/",
            "https://cakewallet.com/terms/",
            "https://cakewallet.com/privacy/",
            "https://cakewallet.com/security/",
            "https://github.com/cake-tech/cake_wallet/releases/tag/v6.4.1",
            "https://status.cakewallet.com/api/status-page/cake/badge",
            "https://status.cakewallet.com/api/status-page/cake"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://cakewallet.com/",
            "https://cakewallet.com/terms/",
            "https://cakewallet.com/privacy/",
            "https://cakewallet.com/security/",
            "https://github.com/cake-tech/cake_wallet/releases/tag/v6.4.1",
            "https://status.cakewallet.com/api/status-page/cake/badge",
            "https://status.cakewallet.com/api/status-page/cake"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 311,
    "slug": "nighthawk-wallet",
    "noOperatorData": true,
    "domain": "nighthawkwallet.com",
    "name": "Nighthawk Wallet",
    "type": "Wallet",
    "cat": "wallet",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "0.0001 ZEC/tx",
    "limits": {
      "daily": null
    },
    "features": [
      "Shielded ZEC",
      "Unified Addresses",
      "Self-custody",
      "Open source",
      "Android + iOS",
      "Community-built"
    ],
    "networks": [],
    "badge": "ZEC",
    "url": "https://nighthawkwallet.com/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "warning",
    "checkedAt": "2026-08-27",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Wallet"
    ],
    "description": "Open-source Zcash mobile wallet with shielded support and Unified Addresses. Community-built, no KYC, self-custodial. (Zero KYC)",
    "cardSummary": "Open-source shielded Zcash mobile wallet.",
    "jurisdiction": "US",
    "auditedBy": [],
    "twitter": "https://x.com/nighthawkwallet",
    "privacyWarning": "Current privacy policy says App Store/Play Store error reporting can collect IP address, device name, OS version, app configuration, usage time/date and statistics. The official site now markets a DarkFi testnet wallet as coming soon while the linked Android repository's latest release is the November 2024 Zcash v2.2.16 build.",
    "founderIntel": "Nighthawk Apps team. Zcash-focused mobile wallet. Non-custodial. Open source. US-based team. No known state actor or intelligence ties. Active maintenance. Zcash Community Grants funded.",
    "vcIntel": "Nighthawk Apps Inc (US). Small team, Zcash ecosystem grant funded. No major VC.",
    "kycNote": "Advertises No-KYC, but strictly adhere to OPSEC rules. Access via Tor, pay with XMR.",
    "updatedAt": "2026-08-27",
    "stateActorFlag": null,
    "followTheMoney": "  Nighthawk Apps Inc - USA (CO)\n  ──────────────────────────────────────\n  Founders: small team, US-based\n  Funding: Zcash Community Grants (ZCG)\n  Revenue: none (free, grant-funded)\n  ├─ ZCG community grants, no VC\n  ├─ Five Eyes (US) - FISA exposure\n  └─ Self-custody ZEC, open-source",
    "lastReviewed": "2026-08-27",
    "kycLastChecked": "2026-08-27",
    "reviewSource": "Primary-source review 2026-08-27",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "project-no-legal-entity",
        "citation": "https://nighthawkwallet.com/privacypolicy/",
        "note": "Open-source self-custody wallet published by the 'Nighthawk Apps' brand/GitHub org with no registered company, foundation, or legal-entity name, number, or jurisdiction cited in Terms, Privacy Policy, App Store seller info, or official registries."
      },
      "governanceModel": {
        "value": "individual",
        "citation": "https://z.cash/zcon3-speaker-highlight-aditya-bharadwaj/"
      },
      "repositoryUrl": {
        "value": "https://github.com/nighthawk-apps/nighthawk-android-wallet",
        "citation": "https://github.com/nighthawk-apps/nighthawk-android-wallet"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "limited",
      "controlModel": "local-self-custody",
      "sourceModel": "open"
    },
    "changedAt": "2026-08-27",
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "limited",
          "sourceUrls": [
            "https://nighthawkwallet.com/privacypolicy/",
            "https://api.github.com/repos/nighthawk-apps/nighthawk-android-wallet/releases/latest"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No operator account/custody exists, but app-store services and error Log Data can include IP/device/network metadata; operator exposure is limited, not none."
        },
        "controlModel": {
          "value": "local-self-custody",
          "sourceUrls": [
            "https://api.github.com/repos/nighthawk-apps/nighthawk-android-wallet/releases/latest"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Release notes explicitly state non-custodial operation and sole user responsibility for funds/seeds."
        },
        "sourceModel": {
          "value": "open",
          "sourceUrls": [
            "https://github.com/nighthawk-apps/nighthawk-android-wallet",
            "https://api.github.com/repos/nighthawk-apps/nighthawk-android-wallet/releases/latest"
          ],
          "reviewedAt": "2026-08-27",
          "note": "The official wallet repository and current release metadata are public; reproducible-build evidence was not established."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced in the reopened first-party source family."
      }
    }
  },
  {
    "id": 312,
    "slug": "godex",
    "domain": "godex.io",
    "name": "Godex.io",
    "type": "Swap",
    "cat": "swap",
    "kyc": "light",
    "kycLevel": 1,
    "fees": {
      "transaction": 0.5
    },
    "fee": "0.5%",
    "limits": {
      "daily": null
    },
    "features": [
      "No email",
      "No registration",
      "Non-custodial",
      "XMR supported",
      "ZEC supported",
      "No limit",
      "Tor-friendly",
      "935 cryptocurrencies",
      "24/7 support"
    ],
    "networks": [],
    "badge": "SWAP",
    "url": "https://godex.io/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Swap"
    ],
    "description": "No-registration crypto swaps across 935 cryptocurrencies including XMR and ZEC; AML policy can trigger verification and regional exclusions.",
    "cardSummary": "No-registration swaps across 935 cryptocurrencies.",
    "jurisdiction": "SC",
    "auditedBy": null,
    "twitter": "https://x.com/godex_io",
    "founderIntel": "Fully anonymous team. No founders named or identified. Legal entity: Godex Foundation Limited, incorporated under Hong Kong Companies Ordinance (Chapter 622), Registrar Number 77557945. Listed London address (45 Wellington Road) is a mail drop / registered agent. Also described in some sources as Seychelles-registered - possible dual-entity structure. No state-actor connections verifiable.",
    "vcIntel": "Legal entity: Godex Foundation Limited (Hong Kong, Reg# 77557945). London address is a mail drop. Anonymous founders - identity unverifiable. Zero public VC. Founded 2017–2018. No OFAC designation or AML enforcement found.",
    "kycNote": "Routine flow advertises no registration/no KYC; AML/KYC policy can require government ID under risk controls.",
    "updatedAt": "2026-08-25",
    "stateActorFlag": null,
    "privacyWarning": "Godex publishes an AML/KYC policy with customer verification language despite no-KYC marketing; US and sanctioned jurisdictions are prohibited.",
    "followTheMoney": "  Godex Foundation Ltd - Hong Kong (HK)\n  ──────────────────────────────────────\n  Founders: anonymous, unverified\n  Funding: bootstrapped (no public VC)\n  Revenue: ~0.5% swap fee\n  ├─ HK reg# 77557945, London mail drop\n  ├─ Post-NSL HK: PRC data demands\n  └─ No OFAC action - rated #1 no-KYC",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "https://godex.io/",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://godex.io/aml-policy",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Nrnb Ltd.",
        "citation": "https://godex.io/aml-policy"
      },
      "registrationNumber": {
        "value": "224730",
        "citation": "https://www.gazette.sc/sites/default/files/2025-10/Gazette%20No%2068%20-%206th%20October%202025.pdf"
      },
      "registryUrl": {
        "value": "https://www.gazette.sc",
        "citation": "https://www.gazette.sc/sites/default/files/2025-10/Gazette%20No%2068%20-%206th%20October%202025.pdf"
      },
      "incorporationJurisdiction": {
        "value": "Republic of Seychelles",
        "citation": "https://godex.io/aml-policy"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://godex.io/",
            "https://godex.io/robots.txt"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://godex.io/",
            "https://godex.io/robots.txt"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://godex.io/",
            "https://godex.io/robots.txt"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 313,
    "slug": "changehero",
    "domain": "changehero.io",
    "name": "ChangeHero",
    "type": "Swap",
    "cat": "swap",
    "kyc": "light",
    "kycLevel": 1,
    "fees": {
      "transaction": 0.5
    },
    "fee": "Up to 0.5% Best Rate / up to 0.7% Fixed Rate",
    "limits": {
      "daily": null
    },
    "features": [
      "No account",
      "ZEC supported",
      "XMR supported",
      "Instant",
      "Fixed + floating rate",
      "350+ swap assets",
      "150+ fiat-purchase assets"
    ],
    "networks": [],
    "badge": "SWAP",
    "url": "https://changehero.io/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Swap"
    ],
    "description": "No-account crypto swap and fiat on-ramp advertising no KYC to 700 EUR, with terms reserving AML document requests.",
    "cardSummary": "No-account swaps and fiat on-ramp.",
    "jurisdiction": "CR",
    "auditedBy": null,
    "telegram": "https://t.me/changehero",
    "twitter": "https://x.com/changehero_io",
    "founderIntel": "Igor Zelenovski (CEO). Rotterdam, Netherlands-based. Background: economics, entrepreneurship, international politics. Ukrainian/Russian/Eastern European surname. Company registered as Herofintechs LIMITADA (Costa Rica) but SEC filings list Hong Kong. Russian and Pakistan presence in team per company profiles. \".ru\" language support on site.",
    "vcIntel": "Dual registration: Herofintechs LIMITADA (Costa Rica) + Hong Kong per SEC/Exodus filings. Post-NSL 2020 Hong Kong = PRC data demands apply. Company also maintains Russian and Pakistan offices per staffing data. No external VC. CEO Igor Zelenovski Twitter: @Igor_Zelenovski.",
    "kycNote": "No account for basic swaps; fiat/card flows and flagged transactions can require email, one-time verification, or AML/KYC documents.",
    "updatedAt": "2026-08-25",
    "stateActorFlag": null,
    "privacyWarning": "Canadian MSB/Five Eyes exposure via MoneyMaple Tech Ltd.; terms allow AML/KYC procedures and identity-document requests.",
    "followTheMoney": "  Herofintechs LIMITADA - Costa Rica/HK\n  ──────────────────────────────────────\n  CEO: Igor Zelenovski (Rotterdam, NL)\n  Funding: bootstrapped, no public VC\n  Revenue: ~0.5% swap fee\n  ├─ HK registration: PRC NSL exposure\n  ├─ Also Russian + Pakistan operations\n  └─170+ coins, ZEC/XMR supported",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "https://changehero.io/",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://changehero.io/press-kit",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "HEROFINTECHS LIMITADA",
        "citation": "https://changehero.io/press-kit"
      },
      "registrationNumber": {
        "value": "4062001322968",
        "citation": "https://changehero.io/press-kit"
      },
      "incorporationJurisdiction": {
        "value": "Costa Rica",
        "citation": "https://changehero.io/press-kit"
      },
      "registeredAddress": {
        "value": "Los Yoses, Cale 39. Avenidas, 8 & 9, San José, San Pedro, 11501, Costa Rica",
        "citation": "https://changehero.io/press-kit"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "limit": "Crypto swaps: no hard maximum; fiat purchases: €25 minimum",
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://changehero.io/",
            "https://changehero.io/legal/privacy-policy"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://changehero.io/",
            "https://changehero.io/legal/privacy-policy"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://changehero.io/",
            "https://changehero.io/legal/privacy-policy"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 315,
    "slug": "flexa",
    "domain": "flexa.co",
    "name": "Flexa",
    "type": "Merchants",
    "cat": "merchant",
    "kyc": "light",
    "kycLevel": 2,
    "fees": {
      "transaction": 0
    },
    "fee": "No end-user transaction fee; merchant/provider pricing is not publicly stated",
    "limits": {
      "daily": null
    },
    "features": [
      "ZEC at major retailers",
      "XMR supported",
      "BTC supported",
      "Works via Zashi",
      "Chipotle",
      "GameStop",
      "Sheetz",
      "Instant settlement",
      "Money-movement platform in 37 SEPA countries/territories"
    ],
    "networks": [],
    "badge": "MERCHANTS",
    "url": "https://flexa.co/",
    "affiliate": "",
    "geo": [
      "US",
      "EU"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": true,
    "countries": [
      "US",
      "EU"
    ],
    "categories": [
      "Merchants"
    ],
    "description": "Licensed crypto payment and money-movement network for merchants and wallets, tying each account to a verifiable identity and operating in the US and 37 SEPA countries/territories.",
    "cardSummary": "Licensed crypto payment network for merchants.",
    "jurisdiction": "US",
    "auditedBy": null,
    "twitter": "https://x.com/flexahq",
    "privacyWarning": "US/Five Eyes payment network; privacy policy says Flexa may collect name, email and identity-verification information directly or through third parties.",
    "founderIntel": null,
    "vcIntel": null,
    "kycNote": "Official terms authorize identity inquiries and say Flexa may close, suspend or limit access if required identity information cannot be obtained.",
    "updatedAt": "2026-08-25",
    "stateActorFlag": null,
    "followTheMoney": "  Flexa Network - New York, USA (US)\n  ──────────────────────────────────────\n  CEO: Tyler Spalding · Founded: 2017\n  Investors: Pantera, CoinFund, Nima Cap\n  Revenue: ~1% merchant processing fee\n  ├─ Pantera: institutional crypto VC\n  ├─ Five Eyes (US) - FISA exposure\n  └─ Spend ZEC/XMR at US retailers",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "https://flexa.co/legal/licenses",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://flexa.co/legal/privacy",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Flexa Inc.",
        "citation": "https://flexa.co/legal/privacy"
      },
      "registrationNumber": {
        "value": "31000325761492",
        "citation": "https://flexa.co/legal/licenses"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://flexa.co/legal/licenses",
            "https://x.com/FlexaHQ/status/2039055571790557413",
            "https://x.com/FlexaHQ/status/2067612295287484716",
            "https://x.com/FlexaHQ/status/2074880812018016287",
            "https://flexa.co/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://flexa.co/legal/licenses",
            "https://x.com/FlexaHQ/status/2039055571790557413",
            "https://x.com/FlexaHQ/status/2067612295287484716",
            "https://x.com/FlexaHQ/status/2074880812018016287",
            "https://flexa.co/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://flexa.co/legal/licenses",
            "https://x.com/FlexaHQ/status/2039055571790557413",
            "https://x.com/FlexaHQ/status/2067612295287484716",
            "https://x.com/FlexaHQ/status/2074880812018016287",
            "https://flexa.co/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 316,
    "slug": "haveno-dex",
    "domain": "haveno.exchange",
    "name": "Haveno",
    "type": "P2P",
    "cat": "p2p",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0.15
    },
    "fee": "0.15% maker / 0.75% taker",
    "limits": {
      "daily": null
    },
    "features": [
      "XMR settlement",
      "Fiat-to-XMR",
      "Crypto-to-XMR",
      "Tor-only",
      "Non-custodial",
      "Open source",
      "Security deposit",
      "Decentralized",
      "Bisq fork"
    ],
    "networks": [],
    "badge": "DEX",
    "url": "https://haveno.exchange/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "warning",
    "checkedAt": "2026-08-27",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "P2P"
    ],
    "description": "Decentralized Tor-only P2P exchange settling in Monero, using a non-custodial security deposit model.",
    "cardSummary": "Tor-only P2P exchange settled in Monero.",
    "jurisdiction": null,
    "auditedBy": [],
    "twitter": "https://x.com/havenodex",
    "telegram": "https://t.me/havenodex",
    "founderIntel": "ErCiccione (pseudonymous, Monero community contributor with 1,200+ contributions to Monero codebase since ~2018, appears Italian based on pseudonym) and Woodser (pseudonymous lead developer, appears US-based from GitHub timezone patterns). No real identities publicly confirmed. No company structure - volunteer core team. Bisq fork.",
    "vcIntel": "No VCs. Community-funded via Monero CCS (Community Crowdfunding System) - individual XMR donations only. No institutional sponsors or corporate backers.",
    "kycNote": "Advertises No-KYC, but strictly adhere to OPSEC rules. Access via Tor, pay with XMR.",
    "changedAt": "2026-08-27",
    "updatedAt": "2026-08-27",
    "stateActorFlag": null,
    "privacyWarning": "The Haveno core team publishes software but does not operate or endorse a live mainnet network. Mainnet installers, fees, operators, privacy terms and dispute agents are network-specific; fiat payment methods may expose identity and payment-account data to a counterparty.",
    "followTheMoney": "  Haveno - Decentralised (Monero chain)\n  ──────────────────────────────────────\n  Fork of Bisq · Open-source (AGPL)\n  Funding: Monero community + donations\n  Revenue: 0% (protocol fee going to DAO)\n  ├─ No company, no CEO, no VC\n  ├─ Non-custodial P2P trades\n  └─ Tor-native: no IP exposed",
    "lastReviewed": "2026-08-27",
    "kycLastChecked": "2026-08-27",
    "reviewSource": "Primary-source review 2026-08-27",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "unresolved",
        "citation": "unknown",
        "note": "Pass 1 researched this service but established no registry facts."
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "none",
      "controlModel": "decentralized",
      "sourceModel": "open"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "none",
          "sourceUrls": [
            "https://haveno.exchange/faq/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "The project does not operate a mainnet network instance and requires no central account/KYC; network peers and arbitrators are not a single operator."
        },
        "controlModel": {
          "value": "decentralized",
          "sourceUrls": [
            "https://haveno.exchange/faq/",
            "https://github.com/haveno-dex/haveno"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Haveno is a peer-to-peer decentralized protocol whose independent networks and users hold control."
        },
        "sourceModel": {
          "value": "open",
          "sourceUrls": [
            "https://haveno.exchange/faq/",
            "https://github.com/haveno-dex/haveno"
          ],
          "reviewedAt": "2026-08-27",
          "note": "The official project describes the platform as open source and links the implementation repository; reproducible builds were not established."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced in the reopened first-party source family."
      }
    }
  },
  {
    "id": 317,
    "slug": "retoswap",
    "domain": "retoswap.com",
    "name": "RetoSwap",
    "type": "P2P",
    "cat": "p2p",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0.1
    },
    "fee": "0.1% maker / 0.8% crypto taker / 2% fiat taker",
    "limits": {
      "daily": null
    },
    "features": [
      "Haveno-based",
      "XMR settlement",
      "Tor + I2P",
      "Non-custodial",
      "Open source",
      "No registration"
    ],
    "networks": [
      "XMR",
      "USDT",
      "ETH",
      "TRON",
      "BTC",
      "LTC",
      "BCH"
    ],
    "badge": "DEX",
    "url": "https://retoswap.com/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "warning",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "P2P"
    ],
    "description": "Haveno-based P2P exchange whose FAQ states it has no means to verify identities, settling in Monero.",
    "cardSummary": "Haveno-based P2P exchange with Monero settlement.",
    "jurisdiction": null,
    "auditedBy": null,
    "twitter": "https://x.com/wilderko",
    "founderIntel": "Pseudonymous / Independent. Corporate Entity: Obscured/Non-existent. A hyper-niche privacy swapping protocol operating without VC backing or traditional corporate constraints.",
    "vcIntel": "Fork of Bisq (formerly known as Haveno-reto). Community maintained. Zero corporate structure, zero VC. Decentralized P2P exchange.",
    "kycNote": "Official FAQ says RetoSwap itself is open-source software without ability to verify user identities; trades are P2P with XMR settlement.",
    "updatedAt": "2026-08-25",
    "stateActorFlag": null,
    "privacyWarning": "RetoSwap is anonymous/pseudonymous open-source P2P software with no verified legal entity. A June 2026 Haveno trade-protocol exploit caused a trading halt; service resumed on v1.8.0 and recovery was coordinated with affected users. P2P counterparty, arbitration, software, and live-liquidity risk remain.",
    "followTheMoney": "  RetoSwap - Decentralised (Haveno fork)\n  ──────────────────────────────────────\n  Founders: pseudonymous, community-run\n  Funding: zero VC, Bisq/Haveno fork\n  Revenue: 0.15% maker / 0.75% taker\n  ├─ Tor + I2P: network-level privacy\n  ├─ XMR settlement, no accounts\n  └─ Open-source AGPL, no entity",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "https://retoswap.com/",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "unresolved",
        "citation": "unknown",
        "note": "Pass 1 researched this service but established no registry facts."
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://retoswap.com/",
            "https://x.com/RetoSwap/status/2066960238545162410",
            "https://x.com/RetoSwap/status/2069472096644653110",
            "https://x.com/RetoSwap/status/2069472807646367875"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://retoswap.com/",
            "https://x.com/RetoSwap/status/2066960238545162410",
            "https://x.com/RetoSwap/status/2069472096644653110",
            "https://x.com/RetoSwap/status/2069472807646367875"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://retoswap.com/",
            "https://x.com/RetoSwap/status/2066960238545162410",
            "https://x.com/RetoSwap/status/2069472096644653110",
            "https://x.com/RetoSwap/status/2069472807646367875"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 318,
    "slug": "wasabi-wallet",
    "domain": "wasabiwallet.io",
    "name": "Wasabi Wallet",
    "type": "Wallet",
    "cat": "wallet",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "limits": {
      "daily": null
    },
    "features": [
      "Bitcoin CoinJoin",
      "Tor built-in",
      "Self-custody",
      "Open source",
      "Desktop",
      "Non-custodial",
      "UTXO management",
      "Third-party coordinators",
      "Silent Payments"
    ],
    "networks": [],
    "badge": "BTC",
    "url": "https://wasabiwallet.io/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-26",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Wallet"
    ],
    "description": "Self-custodial Bitcoin desktop wallet with Tor, Silent Payments and optional third-party coordinated CoinJoin.",
    "cardSummary": "Bitcoin desktop wallet with Tor and CoinJoin.",
    "jurisdiction": null,
    "auditedBy": null,
    "twitter": "https://x.com/wasabiwallet",
    "telegram": "https://t.me/wasabiwallet",
    "founderIntel": "Founded by Adam Ficsor (nopara73), pseudonymous Hungarian developer. DISAMBIGUATION: Adam Ficsor the Wasabi founder is NOT the same individual as the Hungarian Government official of the same name (former Deputy Minister for Intelligence Services). Operating entity: zkSNACKs Ltd, Gibraltar. CoinJoin coordinator shut down June 20, 2024 after US OFAC designation pressure on CoinJoin services. Privacy-focused development continues but flagship privacy feature is defunct.",
    "vcIntel": "zkSNACKs Ltd (Gibraltar). Bootstrapped. Founded by Adam Ficsor (nopara73). No VC. Shut down coinjoin coordinator June 2024 under regulatory pressure despite having no investors to pressure them.",
    "kycNote": "No account or identity KYC to use the wallet. CoinJoin now depends on user-selected third-party coordinators, so coordinator policy/liquidity varies.",
    "stateActorFlag": "OFAC/US Treasury pressure: CoinJoin coordinator shut down June 2024. US sanctions enforcement effectively killed the primary privacy feature. No intelligence actor tie to founders found - OFAC pressure is regulatory, not personnel-based.",
    "privacyWarning": "The default zkSNACKs coordinator ended service in 2024; current Wasabi CoinJoin use requires a third-party coordination provider. Wallet remains self-custodial, but coordinator availability and policy are no longer controlled by the original service.",
    "updatedAt": "2026-06-22",
    "fee": "Free",
    "followTheMoney": "  zkSNACKs Ltd - Gibraltar (GI)\n  ──────────────────────────────────────\n  Founder: Adam Ficsor (nopara73, HU)\n  Funding: bootstrapped, no VC\n  Revenue: CoinJoin coordinator fee\n  ├─ OFAC pressure → CoinJoin shutdown\n  ├─ Gibraltar: EU-adjacent jurisdiction\n  └─ Wallet works; mixing disabled",
    "lastReviewed": "2026-08-26",
    "kycLastChecked": "2026-08-26",
    "reviewSource": "Primary-source review 2026-08-26",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "project-no-legal-entity",
        "citation": "https://docs.wasabiwallet.io/FAQ/FAQ-Installation.html",
        "note": "Official docs describe zkSNACKs as 'the company originally behind Wasabi'; GitHub maintainers state the project continues after zkSNACKs' shutdown with access revoked from company contributors, and the wallet is presented solely as libre open-source software with third-party coordinators."
      },
      "governanceModel": {
        "value": "maintainer-group",
        "citation": "https://github.com/orgs/WalletWasabi/discussions/13249"
      },
      "repositoryUrl": {
        "value": "https://github.com/WalletWasabi/WalletWasabi",
        "citation": "https://github.com/WalletWasabi/WalletWasabi"
      },
      "priorEntities": {
        "value": [
          "zkSNACKs Ltd / Zksnacks Limited -- Gibraltar company that originally developed and operated the default coordinator for Wasabi Wallet; coordinator shut down 2024-06-01 and company discontinued related operations; company number reported as 117429, incorporated 2018-05-25"
        ],
        "citation": "https://docs.wasabiwallet.io/FAQ/FAQ-Introduction.html"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "limited",
      "controlModel": "local-self-custody",
      "sourceModel": "open-reproducible"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-26",
      "inputs": {
        "operatorDataExposure": {
          "value": "limited",
          "sourceUrls": [
            "https://docs.wasabiwallet.io/FAQ/FAQ-Installation.html"
          ],
          "reviewedAt": "2026-08-26",
          "note": "local wallet is non-custodial, but optional coordinator and node use can expose IP/transaction linkage"
        },
        "controlModel": {
          "value": "local-self-custody",
          "sourceUrls": [
            "https://docs.wasabiwallet.io/FAQ/FAQ-Introduction.html"
          ],
          "reviewedAt": "2026-08-26",
          "note": "official documentation says users control the Bitcoin address and sign on their computer"
        },
        "sourceModel": {
          "value": "open-reproducible",
          "sourceUrls": [
            "https://docs.wasabiwallet.io/FAQ/FAQ-Introduction.html",
            "https://github.com/WalletWasabi/WalletWasabi/releases"
          ],
          "reviewedAt": "2026-08-26",
          "note": "official documentation/release materials say code is MIT open source and builds are reproducible"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "no-score-points-no-cap-exception"
      }
    }
  },
  {
    "id": 319,
    "slug": "sparrow-wallet",
    "domain": "sparrowwallet.com",
    "name": "Sparrow Wallet",
    "type": "Wallet",
    "cat": "wallet",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "limits": {
      "daily": null
    },
    "features": [
      "Bitcoin only",
      "Full node support",
      "CoinJoin (Whirlpool)",
      "PSBT signing",
      "Hardware wallet",
      "Open source",
      "Desktop",
      "UTXO control"
    ],
    "networks": [],
    "badge": "BTC",
    "url": "https://sparrowwallet.com/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-23",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Wallet"
    ],
    "description": "Bitcoin desktop wallet for power users. CoinJoin, full node, hardware wallet support, complete UTXO control. (Zero KYC)",
    "cardSummary": "Bitcoin desktop wallet with full UTXO control.",
    "jurisdiction": null,
    "auditedBy": null,
    "twitter": "https://x.com/sparrowwallet",
    "telegram": "https://t.me/sparrowwallet",
    "founderIntel": "Independent/Bootstrapped or Pseudonymous operator. No known institutional or intelligence ties.",
    "vcIntel": "Bootstrapped. Craig Raw (solo dev). Zero VC. Donation funded. Pure Bitcoin sovereignty tool.",
    "kycNote": "Advertises No-KYC, but strictly adhere to OPSEC rules. Access via Tor, pay with XMR.",
    "updatedAt": "2026-03-13",
    "fee": "Free",
    "stateActorFlag": null,
    "privacyWarning": "The published privacy policy is explicitly scoped to a mobile App on the Apple App Store, not the desktop wallet described in this record.",
    "followTheMoney": "Sparrow Wallet\n────────────────────────\nBuilt by: Craig Raw\nModel: open source and free to use\nFunding: user donations",
    "publicClaims": {
      "followTheMoney": {
        "value": "Sparrow Wallet\n────────────────────────\nBuilt by: Craig Raw\nModel: open source and free to use\nFunding: user donations",
        "reviewedAt": "2026-07-15",
        "sources": [
          {
            "label": "Sparrow Wallet - About",
            "href": "https://sparrowwallet.com/about/",
            "type": "official"
          }
        ]
      }
    },
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_2_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "project-no-legal-entity",
        "citation": "https://bitcoinmagazine.com/news/craig-raw-apple-might-kill-it-by-june-30",
        "note": "Multiple sources including Bitcoin Magazine describe it as built and maintained by solo developer Craig Raw in South Africa with no company behind him; privacy policy lists only 'Developer: Craig Raw' and site calls it an open-source project."
      },
      "governanceModel": {
        "value": "individual",
        "citation": "https://sparrowwallet.com/privacy/"
      },
      "repositoryUrl": {
        "value": "https://github.com/sparrowwallet/sparrow",
        "citation": "https://github.com/sparrowwallet/sparrow"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://sparrowwallet.com/",
            "https://sparrowwallet.com/features/",
            "https://sparrowwallet.com/about/",
            "https://sparrowwallet.com/privacy/",
            "https://raw.githubusercontent.com/sparrowwallet/sparrow/master/SECURITY.md",
            "https://github.com/sparrowwallet/sparrow/releases/tag/2.5.3",
            "https://github.com/sparrowwallet/sparrow/releases/tag/1.9.0",
            "https://github.com/sparrowwallet/sparrow/security/advisories"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://sparrowwallet.com/",
            "https://sparrowwallet.com/features/",
            "https://sparrowwallet.com/about/",
            "https://sparrowwallet.com/privacy/",
            "https://raw.githubusercontent.com/sparrowwallet/sparrow/master/SECURITY.md",
            "https://github.com/sparrowwallet/sparrow/releases/tag/2.5.3",
            "https://github.com/sparrowwallet/sparrow/releases/tag/1.9.0",
            "https://github.com/sparrowwallet/sparrow/security/advisories"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://sparrowwallet.com/",
            "https://sparrowwallet.com/features/",
            "https://sparrowwallet.com/about/",
            "https://sparrowwallet.com/privacy/",
            "https://raw.githubusercontent.com/sparrowwallet/sparrow/master/SECURITY.md",
            "https://github.com/sparrowwallet/sparrow/releases/tag/2.5.3",
            "https://github.com/sparrowwallet/sparrow/releases/tag/1.9.0",
            "https://github.com/sparrowwallet/sparrow/security/advisories"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 320,
    "slug": "njalla",
    "domain": "njal.la",
    "name": "Njalla",
    "type": "Hosting",
    "cat": "hosting",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "limits": {
      "daily": null
    },
    "features": [
      "Domain proxy registration",
      "VPS",
      "XMR accepted",
      "BTC accepted",
      "Privacy-first",
      "No personal info",
      "Tor-accessible"
    ],
    "networks": [],
    "badge": "HOSTING",
    "url": "https://njal.la/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-24",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Hosting"
    ],
    "description": "Domain and VPS provider that holds domains on the customer's behalf, with email or XMPP signup and XMR payments.",
    "cardSummary": "Domains and VPS registered on your behalf.",
    "jurisdiction": "CR",
    "auditedBy": [],
    "founderIntel": "Peter Sunde (Co-founder of The Pirate Bay). Corporate Entity: 1337 LLC, registered in Nevis (Caribbean). Backing: Bootstrapped, independent, explicitly anti-authoritarian domain registrar and VPS provider that legally shields its users by purchasing domains on their behalf.",
    "vcIntel": "Founded by Peter Sunde (Pirate Bay co-founder). Nevis (KN) jurisdiction. Bootstrapped. Zero VC. Deliberately structured as privacy-first domain registrar.",
    "kycNote": "Signup uses email or XMPP; official FAQ lists Bitcoin, Litecoin, Monero, Ethereum, and PayPal payments. No identity KYC claim was found in this pass.",
    "updatedAt": "2026-06-22",
    "fee": "Free",
    "stateActorFlag": null,
    "privacyWarning": "Njalla is normally the registered owner/registrant of customer domains, although its terms say beneficial ownership vests in the customer and transfer can be requested. It stores email/XMPP, password, and voluntarily supplied data, may provide relevant information to authorities, and may suspend, cancel, or keep a domain under listed conditions.",
    "followTheMoney": "Njalla\n────────────────────────\nOperator: njalla.srl\nBase: Costa Rica\nModel: Njalla registers customer domains",
    "publicClaims": {
      "followTheMoney": {
        "value": "Njalla\n────────────────────────\nOperator: njalla.srl\nBase: Costa Rica\nModel: Njalla registers customer domains",
        "reviewedAt": "2026-07-15",
        "sources": [
          {
            "label": "Njalla - About",
            "href": "https://njal.la/about/",
            "type": "official"
          }
        ]
      }
    },
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_2_2026-06-22",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://njal.la/tos/",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Njalla SRL",
        "citation": "https://njal.la/tos/"
      },
      "incorporationJurisdiction": {
        "value": "Costa Rica",
        "citation": "https://njal.la/about/"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "custodial",
      "sourceModel": "closed"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://njal.la/tos/",
            "https://njal.la/faq/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Email/XMPP account, payment/service records and legal/abuse handling create moderate operator exposure."
        },
        "controlModel": {
          "value": "custodial",
          "sourceUrls": [
            "https://njal.la/tos/",
            "https://njal.la/faq/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "For the defining domain service Njalla is registrant and can keep, suspend or cancel registrations; that is custodial operator control, not federated control."
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://njal.la/tos/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No official critical-core source repository or reproducible-build evidence is disclosed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced in the reopened first-party source family."
      }
    }
  },
  {
    "id": 321,
    "slug": "lnvpn",
    "domain": "nadanada.me",
    "name": "LNVPN",
    "type": "VPN",
    "cat": "vpn",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Pay-per-minute via Lightning",
    "limits": {
      "daily": null
    },
    "features": [
      "Lightning-native",
      "No account",
      "No logs",
      "No email",
      "Pay-per-minute",
      "eSIMs",
      "Disposable numbers",
      "WireGuard"
    ],
    "networks": [],
    "badge": "VPN",
    "url": "https://nadanada.me/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "warning",
    "checkedAt": "2026-08-27",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "VPN"
    ],
    "description": "VPN, disposable SMS numbers and eSIMs with no account or email stated as required, paid in BTC, XMR or ZEC.",
    "cardSummary": "VPN, disposable SMS numbers and eSIMs.",
    "jurisdiction": null,
    "auditedBy": [],
    "twitter": "https://x.com/ln_vpn",
    "telegram": "https://t.me/+x_j8zikjnqhiodiy",
    "founderIntel": "Pseudonymous Lightning network developer base. Corporate Entity: Independent. Backing: Bootstrapped, privacy-first VPN reseller bridging the Lightning Network to Mullvad and other VPN configs without requiring user accounts.",
    "vcIntel": "Lightning-native VPN. Bootstrapped/donation funded. Anonymous operator. Zero VC.",
    "kycNote": "Official homepage states no account, no email, no KYC, no identity checks; Bitcoin, Monero, and Zcash accepted.",
    "updatedAt": "2026-08-27",
    "stateActorFlag": null,
    "privacyWarning": "The website stores a truncated IP prefix for 7 days. VPN endpoints retain public key, PSK and bandwidth use, with source IP held in memory until 5 minutes of inactivity; eSIM service metadata and rental SMS are retained for service duration. Stripe/MixPay and telecom partners process additional data. The public site does not identify a legal operator or jurisdiction.",
    "followTheMoney": "  LNVPN - Pseudonymous / Global\n  ──────────────────────────────────────\n  Operator: anonymous Lightning dev\n  Funding: bootstrapped, no VC\n  Revenue: Lightning micropayments\n  ├─ Resells Mullvad VPN access via LN\n  ├─ Pay-per-minute, no account\n  └─ Unvetted: anonymous operator",
    "lastReviewed": "2026-08-27",
    "kycLastChecked": "2026-08-27",
    "reviewSource": "Primary-source review 2026-08-27",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://nadanada.me/terms",
        "note": "Commercial hosted VPN/eSIM/phone-number service sold for payment under the nadanada/LNVPN brand; Terms and Privacy never name a legal operator and no registry record was found."
      },
      "governanceModel": {
        "value": "individual",
        "citation": "https://github.com/LightRider5/lnvpn"
      },
      "repositoryUrl": {
        "value": "https://github.com/LightRider5/lnvpn",
        "citation": "https://github.com/LightRider5/lnvpn"
      },
      "priorEntities": {
        "value": [
          "LNVPN (lnvpn.net)"
        ],
        "citation": "https://nadanada.me/blog/lnvpn-is-now-nadanada"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "limited",
      "controlModel": "hosted-account",
      "sourceModel": "partial"
    },
    "changedAt": "2026-08-27",
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "limited",
          "sourceUrls": [
            "https://nadanada.me/privacy",
            "https://nadanada.me/blog/lnvpn-is-now-nadanada"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No account/email/KYC is required for the VPN purchase flow, but connection provisioning, public keys, transaction and short-lived web/security data create limited exposure."
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://nadanada.me/terms"
          ],
          "reviewedAt": "2026-08-27",
          "note": "The provider operates WireGuard endpoints and grants service access through purchase tokens/configuration rather than user custody."
        },
        "sourceModel": {
          "value": "partial",
          "sourceUrls": [
            "https://github.com/LightRider5/lnvpn",
            "https://nadanada.me/blog/lnvpn-is-now-nadanada"
          ],
          "reviewedAt": "2026-08-27",
          "note": "The legacy LNVPN implementation is public, but the expanded nadanada production stack and all score-critical services are not shown as fully open."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced in the reopened first-party source family."
      }
    }
  },
  {
    "id": 322,
    "slug": "ivpn",
    "domain": "ivpn.net",
    "name": "IVPN",
    "type": "VPN",
    "cat": "vpn",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 6
    },
    "fee": "$6/mo",
    "limits": {
      "daily": null
    },
    "features": [
      "No email required",
      "Account ID only",
      "XMR accepted",
      "BTC accepted",
      "No logs",
      "Audited",
      "Open source client",
      "Multi-hop",
      "WireGuard + OpenVPN"
    ],
    "networks": [],
    "badge": "VPN",
    "url": "https://www.ivpn.net/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-24",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "VPN"
    ],
    "description": "Anonymous VPN - account ID only, no email, accepts XMR/BTC. No logs, independently audited, multi-hop. Open source. (Zero KYC)",
    "cardSummary": "Audited VPN using account IDs, no email.",
    "jurisdiction": "GI",
    "auditedBy": [],
    "twitter": "https://x.com/ivpnnet",
    "founderIntel": "Nick Pestell - UK-based security professional. Background: Royal Bank of Scotland, Network Rail, ABN AMRO Bank. No intelligence contractor background. In 2024, IVPN acquired Safing GmbH (Austria) - makers of Portmaster open-source firewall and SPN network. Safing founders Raphael and Daniel joined IVPN team post-acquisition.",
    "vcIntel": "No external investors. Sole-owner bootstrapped by Nick Pestell. IVPN Limited (formerly Privatus Limited) - Gibraltar, British Overseas Territory. Only responds to Gibraltar law enforcement - explicitly refuses non-Gibraltar government requests. 12 law enforcement requests received in 2024, zero data provided (no logs). Open source apps, independently audited. 2024: Acquired Safing GmbH (Austria) and their Portmaster/SPN products.",
    "kycNote": "Advertises No-KYC, but strictly adhere to OPSEC rules. Access via Tor, pay with XMR.",
    "updatedAt": "2026-06-22",
    "stateActorFlag": null,
    "privacyWarning": "On 7 August 2026, an exploited critical BTCPay Server vulnerability exposed IVPN’s Lightning-node credentials and 0.6168 BTC in operating funds was stolen. IVPN says no customer data or funds and no VPN infrastructure were affected; Lightning payments were restored on 10 August after patching, credential rotation and a rebuild.",
    "followTheMoney": "IVPN Limited\n────────────────────────\nFounder and CEO: Nicholas Pestell\nOwnership: Nicholas Pestell, 100%\nTeam: 10 people across 7 countries",
    "publicClaims": {
      "followTheMoney": {
        "value": "IVPN Limited\n────────────────────────\nFounder and CEO: Nicholas Pestell\nOwnership: Nicholas Pestell, 100%\nTeam: 10 people across 7 countries",
        "reviewedAt": "2026-07-15",
        "sources": [
          {
            "label": "IVPN - Team",
            "href": "https://www.ivpn.net/en/team/",
            "type": "official"
          }
        ]
      }
    },
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_1_2026-06-22",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://www.ivpn.net/en/tos/",
        "note": "Official Terms of Service state the service is operated by IVPN Limited; confirmed on legal-process, trust, privacy, and company name-change pages as a Gibraltar limited company."
      },
      "legalEntity": {
        "value": "IVPN Limited",
        "citation": "https://www.ivpn.net/en/tos/"
      },
      "registrationNumber": {
        "value": "112432",
        "citation": "https://www.datocapital.com.gi/companies/Ivpn-Ltd.html"
      },
      "registryUrl": {
        "value": "https://www.companieshouse.gi/",
        "citation": "https://www.companieshouse.gi/"
      },
      "incorporationJurisdiction": {
        "value": "Gibraltar",
        "citation": "https://www.ivpn.net/blog/change-company-name-privatus-ivpn-limited/"
      },
      "registeredAddress": {
        "value": "5 Secretary's lane, GX11 1AA, Gibraltar",
        "citation": "https://www.ivpn.net/en/legal-process-guidelines/"
      },
      "parentEntity": {
        "value": "none",
        "citation": "https://www.ivpn.net/trust/"
      },
      "ultimateOwner": {
        "value": "Nicholas Pestell",
        "citation": "https://www.ivpn.net/en/team/"
      },
      "officers": {
        "value": [
          "Nicholas Pestell (Founder, CEO, 100% owner)"
        ],
        "citation": "https://www.ivpn.net/en/team/"
      },
      "priorEntities": {
        "value": [
          "Privatus Limited (former legal name of the same Gibraltar company; renamed to IVPN Limited in August 2023)"
        ],
        "citation": "https://www.ivpn.net/blog/change-company-name-privatus-ivpn-limited/"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "hosted-account",
      "sourceModel": "partial"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://www.ivpn.net/en/privacy/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Account IDs avoid identity intake, but payment/accounting records and temporary authentication/session processing create moderate operator exposure."
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://www.ivpn.net/en/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "IVPN operates gateways and an account-based hosted VPN service."
        },
        "sourceModel": {
          "value": "partial",
          "sourceUrls": [
            "https://github.com/ivpn/desktop-app",
            "https://www.ivpn.net/en/blog/tags/audit/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Official clients are inspectable; current evidence does not establish that every score-critical server/control-plane component is open."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "Remove current audit credit until a dated, scoped report or conclusion covering the score-critical service is normalized; a scheduled audit and historic program are insufficient for this field-level pass."
      }
    }
  },
  {
    "id": 323,
    "slug": "proton-vpn",
    "domain": "protonvpn.com",
    "name": "Proton VPN",
    "type": "VPN",
    "cat": "vpn",
    "kyc": "none",
    "kycLevel": 1,
    "fees": {
      "transaction": 0
    },
    "fee": "Free tier available",
    "limits": {
      "daily": null
    },
    "features": [
      "Free tier",
      "XMR accepted",
      "BTC accepted",
      "No logs",
      "Audited",
      "Open source",
      "Tor servers",
      "Secure Core"
    ],
    "networks": [],
    "badge": "VPN",
    "url": "https://protonvpn.com/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-27",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "VPN"
    ],
    "description": "Open-source Swiss VPN with an audited no-logs policy, though account and payment metadata risk remains.",
    "cardSummary": "Swiss VPN with an audited no-logs policy.",
    "jurisdiction": "CH",
    "auditedBy": [
      "Securitum"
    ],
    "telegram": "https://t.me/proton_privacy",
    "founderIntel": null,
    "vcIntel": null,
    "kycNote": "No identity KYC for VPN account, but account/payment metadata can exist. Official no-logs page states Proton VPN does not log browsing, IP, session length, or location.",
    "updatedAt": "2026-08-27",
    "stateActorFlag": "Swiss-based. Proton AG complied with a 2021 court order logging climate activist IP. Has since added no-log mode and appeals process. Swiss jurisdiction, GDPR compliant.",
    "privacyWarning": "The 2021 IP-logging case concerned Proton Mail, not Proton VPN. Proton states that Swiss law treats email and VPN differently and cannot compel Proton VPN to log user data. Account, payment and abuse/security metadata can still be processed, and crypto payment does not make an account anonymous by itself.",
    "followTheMoney": "  Proton AG - Geneva, Switzerland (CH)\n  ──────────────────────────────────────\n  Founded: CERN researchers, 2014\n  Funding: EU Horizon 2020 grants\n           + Charles River Ventures\n  ├─ Swiss non-profit foundation model\n  ├─ Proton Mail + VPN + Drive bundle\n  └─ Swiss law: strong privacy baseline",
    "lastReviewed": "2026-08-27",
    "kycLastChecked": "2026-08-27",
    "reviewSource": "Primary-source review 2026-08-27",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://proton.me/legal/terms",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Proton AG",
        "citation": "https://proton.me/legal/terms"
      },
      "registrationNumber": {
        "value": "CHE-354.686.492 (UID); CH-660.1.995.014-1 (commercial register)",
        "citation": "https://app2.ge.ch/ecohrcinternet/extract?lang=en&companyOfsUid=CHE-354.686.492"
      },
      "registryUrl": {
        "value": "https://app2.ge.ch/ecohrcinternet/extract?lang=en&companyOfsUid=CHE-354.686.492",
        "citation": "https://app2.ge.ch/ecohrcinternet/extract?lang=en&companyOfsUid=CHE-354.686.492"
      },
      "incorporationJurisdiction": {
        "value": "Switzerland (Canton of Geneva)",
        "citation": "https://proton.me/legal/terms"
      },
      "incorporationDate": {
        "value": "18.07.2014",
        "citation": "https://www.moneyhouse.ch/en/company/proton-ag-4537282131"
      },
      "registeredAddress": {
        "value": "Route de la Galaise 32, 1228 Plan-les-Ouates, Geneva, Switzerland",
        "citation": "https://proton.me/legal/terms"
      },
      "ultimateOwner": {
        "value": "Proton Foundation (primary shareholder)",
        "citation": "https://proton.me/legal/terms"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [
          "Proton Technologies AG"
        ],
        "citation": "https://en.wikipedia.org/wiki/Proton_AG"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "hosted-account",
      "sourceModel": "partial"
    },
    "changedAt": "2026-08-27",
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://protonvpn.com/privacy-policy",
            "https://proton.me/blog/climate-activist-arrest"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Proton accounts, payment, abuse/security and support metadata remain hosted even though VPN traffic and user-identifiable connection logs are excluded by policy and audit."
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://protonvpn.com/",
            "https://protonvpn.com/privacy-policy"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Proton operates the account, VPN gateways and service control plane."
        },
        "sourceModel": {
          "value": "partial",
          "sourceUrls": [
            "https://github.com/ProtonVPN",
            "https://protonvpn.com/blog/no-logs-audit/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "All official apps are open, but server/control-plane implementation is not established as fully inspectable; the source model is partial."
        }
      },
      "audit": {
        "scoreEligible": true,
        "auditor": "Securitum",
        "completedAt": "2026-08-27",
        "scope": "Retain only Securitum: the dated 2026 no-logs review explicitly covers server configurations, VPN infrastructure, operating procedures and user-identifiable logging. Remove historic SEC Consult credit from the current score field because no current scoped SEC Consult report was normalized.",
        "sourceUrls": [
          "https://protonvpn.com/blog/no-logs-audit/",
          "https://drive.proton.me/urls/DZVEJZFYHM#FPSKdUEykprb",
          "https://protonvpn.com/security",
          "https://protonvpn.com/blog/open-source/"
        ]
      }
    }
  },
  {
    "id": 324,
    "slug": "incognet",
    "domain": "incognet.io",
    "name": "IncogNET",
    "type": "Hosting",
    "cat": "hosting",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "limits": {
      "daily": null
    },
    "features": [
      "XMR accepted",
      "BTC accepted",
      "Anonymous",
      "VPS",
      "Dedicated servers",
      "No logs",
      "US-based",
      "DMCA-ignored"
    ],
    "networks": [],
    "badge": "HOSTING",
    "url": "https://incognet.io/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "warning",
    "checkedAt": "2026-06-24",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Hosting"
    ],
    "description": "Anonymous VPS and dedicated server hosting. Accepts XMR and BTC, no personal info required. No logs. (Zero KYC)",
    "cardSummary": "VPS and dedicated servers paid in XMR or BTC.",
    "jurisdiction": "US",
    "auditedBy": [],
    "twitter": "https://x.com/incognetllc",
    "telegram": "https://t.me/incognet_io",
    "privacyWarning": "Wyoming/United States jurisdiction applies. IncogNET may log IP addresses for new orders and sign-ups, standard webserver access logs, transaction records, and security-related records; it uses third-party operational software, deletes accounts periodically rather than immediately, and may disclose information when legally required.",
    "founderIntel": "Independent free-speech and privacy hosting provider. Corporate Entity: Operates out of the US but utilizes offshore routing and server locations (Netherlands, Finland). Bootstrapped entirely without venture capital.",
    "vcIntel": "US-registered LLC. Bootstrapped. No VC. Five Eyes jurisdiction is a risk despite privacy focus.",
    "kycNote": "Advertises No-KYC, but strictly adhere to OPSEC rules. Access via Tor, pay with XMR.",
    "updatedAt": "2026-03-13",
    "fee": "Free",
    "stateActorFlag": null,
    "followTheMoney": "  IncogNET LLC - United States (US)\n  ──────────────────────────────────────\n  Founders: independent, US-based\n  Funding: bootstrapped, no VC\n  Revenue: VPS/server subscription fees\n  ├─ Five Eyes (US) - NSL/FISA risk\n  ├─ Servers in NL + FI (offshore)\n  └─ XMR/BTC, DMCA-resistant",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_1_2026-06-22",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://incognet.io/privacy",
        "note": "Privacy policy states IncogNET LLC is a business organized in the United States and registered in Wyoming; about page and knowledgebase confirm it is an operating LLC providing hosting services."
      },
      "legalEntity": {
        "value": "IncogNET LLC",
        "citation": "https://incognet.io/about"
      },
      "registrationNumber": {
        "value": "2021-000998592",
        "citation": "https://wyobiz.wyo.gov/Business/FilingDetails.aspx?eFNum=229163159131103035162114075077079168168187129050"
      },
      "registryUrl": {
        "value": "https://wyobiz.wyo.gov/Business/FilingDetails.aspx?eFNum=229163159131103035162114075077079168168187129050",
        "citation": "https://wyobiz.wyo.gov/Business/FilingDetails.aspx?eFNum=229163159131103035162114075077079168168187129050"
      },
      "incorporationJurisdiction": {
        "value": "Wyoming, United States",
        "citation": "https://incognet.io/privacy"
      },
      "incorporationDate": {
        "value": "2021-04-21",
        "citation": "https://incognet.io/about"
      },
      "registeredAddress": {
        "value": "1309 Coffeen Avenue, STE 1200, Sheridan, WY 82801",
        "citation": "https://incognet.io/about"
      },
      "parentEntity": {
        "value": "Internet Speech & Privacy LLC",
        "citation": "https://theispco.com/"
      },
      "officers": {
        "value": [
          {
            "name": "Curtis",
            "role": "Founder"
          }
        ],
        "citation": "https://incognet.io/about"
      },
      "priorEntities": {
        "value": [
          "Incog.Host (prior operating name since November 2020)"
        ],
        "citation": "https://incognet.io/about"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "hosted-account",
      "sourceModel": "closed"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://incognet.io/privacy-policy",
            "https://incognet.io/kvm-vps"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Email/account identifiers, payments, support, service records and infrastructure/security logs create moderate exposure."
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://incognet.io/kvm-vps"
          ],
          "reviewedAt": "2026-08-27",
          "note": "IncogNET provisions and operates KVM/VirtFusion hosted infrastructure under customer accounts."
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://incognet.io/legalstuff"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No official score-critical hosting implementation source or reproducible-build evidence was located."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced in the reopened first-party source family."
      }
    }
  },
  {
    "id": 326,
    "slug": "flokinet",
    "domain": "flokinet.is",
    "name": "FlokiNET",
    "type": "Hosting",
    "cat": "hosting",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "From €7.99/mo",
    "limits": {
      "daily": null
    },
    "features": [
      "Iceland jurisdiction",
      "Romania jurisdiction",
      "Finland jurisdiction",
      "XMR accepted",
      "ZEC accepted",
      "BTC accepted",
      "Outside 14-Eyes",
      "Strong data protection",
      "Free speech",
      "No data retention mandate",
      "DMCA-resistant"
    ],
    "networks": [],
    "badge": "OFFSHORE",
    "url": "https://flokinet.is/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-24",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Hosting"
    ],
    "description": "Offshore VPS and dedicated servers in Iceland, Romania and Finland, accepting XMR, ZEC and BTC.",
    "cardSummary": "Offshore VPS in Iceland, Romania and Finland.",
    "jurisdiction": "IS",
    "auditedBy": [],
    "twitter": "https://x.com/flokinetehf",
    "founderIntel": "Founded by Kolja Weber. Operations split between Iceland (FlokiNET ehf) and Romania. Iceland entity registered at Kringlunni 4-12, Reykjavik. Kolja Weber is a German privacy advocate with no known intelligence connections. Strong anti-censorship, anti-surveillance editorial stance. Clients include journalists, activists, whistleblower platforms. Accepts XMR. GDPR applicable (Iceland/Romania EU-adjacent). No known state actor tie.",
    "vcIntel": "Icelandic hosting. Bootstrapped. Known for hosting WikiLeaks. Zero VC. Strong anti-surveillance track record.",
    "kycNote": "Advertises No-KYC, but strictly adhere to OPSEC rules. Access via Tor, pay with XMR.",
    "updatedAt": "2026-03-13",
    "stateActorFlag": null,
    "privacyWarning": "The privacy policy says FlokiNET logs IP address and visit metadata, may collect full name, billing and contact data for customer accounts, may retain network access logs for any period at its discretion, and may retain personal information indefinitely in specified cases.",
    "followTheMoney": "FlokiNET\n────────────────────────\nFounded: Iceland, 2012\nOperations: Iceland, Romania, Finland,\nand the Netherlands\nRevenue model: prepaid hosting services",
    "publicClaims": {
      "followTheMoney": {
        "value": "FlokiNET\n────────────────────────\nFounded: Iceland, 2012\nOperations: Iceland, Romania, Finland,\nand the Netherlands\nRevenue model: prepaid hosting services",
        "reviewedAt": "2026-07-15",
        "sources": [
          {
            "label": "FlokiNET - About",
            "href": "https://flokinet.is/about/",
            "type": "official"
          },
          {
            "label": "FlokiNET - Hosting and payment model",
            "href": "https://flokinet.is/",
            "type": "official"
          }
        ]
      }
    },
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_1_2026-06-22",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://www.skatturinn.is/fyrirtaekjaskra/leit/kennitala/4308120920",
        "note": "Official Icelandic Register of Enterprises lists FlokiNET ehf. as an active private limited company (einkahlutafélag); site TOS/AUP and contact pages name FlokiNET ehf as the operating entity."
      },
      "legalEntity": {
        "value": "FlokiNET ehf.",
        "citation": "https://www.skatturinn.is/fyrirtaekjaskra/leit/kennitala/4308120920"
      },
      "registrationNumber": {
        "value": "4308120920",
        "citation": "https://www.skatturinn.is/fyrirtaekjaskra/leit/kennitala/4308120920"
      },
      "registryUrl": {
        "value": "https://www.skatturinn.is/fyrirtaekjaskra/leit/kennitala/4308120920",
        "citation": "https://www.skatturinn.is/fyrirtaekjaskra/leit/kennitala/4308120920"
      },
      "incorporationJurisdiction": {
        "value": "Iceland",
        "citation": "https://www.skatturinn.is/fyrirtaekjaskra/leit/kennitala/4308120920"
      },
      "incorporationDate": {
        "value": "2012-08-01",
        "citation": "https://www.skatturinn.is/fyrirtaekjaskra/leit/kennitala/4308120920"
      },
      "registeredAddress": {
        "value": "Skólavörðustíg 12, 101 Reykjavík, Iceland",
        "citation": "https://www.skatturinn.is/fyrirtaekjaskra/leit/kennitala/4308120920"
      },
      "ultimateOwner": {
        "value": "Kolja Finn Weber (100% direct ownership)",
        "citation": "https://www.skatturinn.is/fyrirtaekjaskra/leit/kennitala/4308120920"
      },
      "officers": {
        "value": [
          "Kolja Finn Weber (stjórnarmaður / board member)"
        ],
        "citation": "https://www.skatturinn.is/fyrirtaekjaskra/leit/kennitala/4308120920"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "hosted-account",
      "sourceModel": "closed"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://flokinet.is/privacy-policy/",
            "https://flokinet.is/vps/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "The hosted account, billing/contact records, service telemetry and infrastructure traffic context give the operator moderate exposure despite privacy-preserving payment options."
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://flokinet.is/vps/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "FlokiNET provisions and controls hosted VPS/server infrastructure through customer accounts."
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://flokinet.is/about/",
            "https://flokinet.is/terms-of-service/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No official score-critical hosting implementation repository or reproducible-build claim was located; the legal/source scope could not be fully reopened."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced in the reopened first-party source family."
      }
    }
  },
  {
    "id": 327,
    "slug": "1984-hosting",
    "domain": "1984.hosting",
    "name": "1984 Hosting",
    "type": "Hosting",
    "cat": "hosting",
    "kyc": "light",
    "kycLevel": 1,
    "fees": {
      "transaction": 0
    },
    "fee": "From €3.99/mo",
    "limits": {
      "daily": null
    },
    "features": [
      "Iceland jurisdiction",
      "Named after Orwell",
      "XMR accepted",
      "BTC accepted",
      "Strong privacy stance",
      "Free speech host",
      "Domains",
      "VPS",
      "Shared hosting",
      "No data retention mandate"
    ],
    "networks": [],
    "badge": "OFFSHORE",
    "url": "https://1984.hosting/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "warning",
    "checkedAt": "2026-08-27",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Hosting"
    ],
    "description": "Iceland-based provider of domains, VPS and shared hosting under Icelandic data protection, taking XMR and BTC.",
    "cardSummary": "Iceland hosting, domains, VPS and shared plans.",
    "jurisdiction": "IS",
    "auditedBy": null,
    "founderIntel": "Independent/Bootstrapped or Pseudonymous operator. No known institutional or intelligence ties.",
    "vcIntel": "1984 ehf (Iceland). Named after Orwell. Bootstrapped. Zero VC. Icelandic jurisdiction = strong privacy laws outside Five Eyes.",
    "kycNote": "An account can involve contact, support, payment, and fraud-prevention data; no identity-document requirement was established.",
    "updatedAt": "2026-03-13",
    "stateActorFlag": null,
    "privacyWarning": "1984 logs IP address, visit timing and device/browser information. Its privacy policy says bookkeeping details are kept for seven years, network access logs may be kept for any duration at its discretion, and some account data may be retained indefinitely for investigations, fraud prevention or post-termination blocking.",
    "followTheMoney": "  1984 ehf - Reykjavik, Iceland (IS)\n  ──────────────────────────────────────\n  Founders: Icelandic team (anonymous)\n  Funding: bootstrapped, no VC\n  Revenue: hosting/domain subscriptions\n  ├─ Iceland: outside Five Eyes\n  ├─ Strong free-speech + privacy laws\n  └─ XMR/BTC, domains + VPS",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_1_2026-06-22",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://www.skatturinn.is/fyrirtaekjaskra/leit/kennitala/5003062110",
        "note": "Official Icelandic company registry lists 1984 ehf. as an active einkahlutafélag (private limited company) operating the hosting service, corroborated by the company's own contact, ToS and privacy pages naming 1984 ehf."
      },
      "legalEntity": {
        "value": "1984 ehf.",
        "citation": "https://www.skatturinn.is/fyrirtaekjaskra/leit/kennitala/5003062110"
      },
      "registrationNumber": {
        "value": "5003062110",
        "citation": "https://www.skatturinn.is/fyrirtaekjaskra/leit/kennitala/5003062110"
      },
      "registryUrl": {
        "value": "https://www.skatturinn.is/fyrirtaekjaskra/leit/kennitala/5003062110",
        "citation": "https://www.skatturinn.is/fyrirtaekjaskra/leit/kennitala/5003062110"
      },
      "incorporationJurisdiction": {
        "value": "Iceland",
        "citation": "https://www.skatturinn.is/fyrirtaekjaskra/leit/kennitala/5003062110"
      },
      "incorporationDate": {
        "value": "2006-02-23",
        "citation": "https://www.skatturinn.is/fyrirtaekjaskra/leit/kennitala/5003062110"
      },
      "registeredAddress": {
        "value": "Breiðagerði 37, 108 Reykjavík (lögheimili); Pósthólf 126, 121 Reykjavík (postal)",
        "citation": "https://www.skatturinn.is/fyrirtaekjaskra/leit/kennitala/5003062110"
      },
      "ultimateOwner": {
        "value": "Sigurður Þorfinnur Einarsson (42.5% direct); Mörður Áslaugarson (42.5% direct)",
        "citation": "https://www.skatturinn.is/fyrirtaekjaskra/leit/kennitala/5003062110"
      },
      "officers": {
        "value": [
          "Daði Áslaugarson (stjórnarformaður / chairman)"
        ],
        "citation": "https://www.skatturinn.is/fyrirtaekjaskra/leit/kennitala/5003062110"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "hosted-account",
      "sourceModel": "closed"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://1984.hosting/GDPR/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "subscriber contact, account, support, payment and fraud-prevention data"
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://1984.hosting/GDPR/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "operator-hosted"
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://1984.hosting/GDPR/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "closed-service"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "ISO/IEC 27001:2022 certificate IS 834168 covers design, development and service management; certification is not a product security audit."
      }
    }
  },
  {
    "id": 329,
    "slug": "silentlink",
    "domain": "silent.link",
    "name": "Silent.link",
    "type": "Comms",
    "cat": "comms",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": null
    },
    "fee": "Pay-as-you-go",
    "limits": {
      "daily": null
    },
    "features": [
      "Anonymous eSIM",
      "160+ countries",
      "No email",
      "No KYC",
      "XMR accepted",
      "BTC + Lightning",
      "No sign-up",
      "US/UK phone number options",
      "Data eSIM",
      "QR code activation"
    ],
    "networks": [],
    "badge": "eSIM",
    "url": "https://silent.link/",
    "affiliate": "",
    "geo": [],
    "status": "ok",
    "checkedAt": "2026-06-24",
    "trending": true,
    "countries": [],
    "categories": [
      "Comms"
    ],
    "description": "Global eSIM and data service covering 160+ countries, paid with Bitcoin, Lightning, Monero or USDT.",
    "cardSummary": "Global eSIM and data across 160+ countries.",
    "jurisdiction": null,
    "auditedBy": [],
    "twitter": "https://x.com/silentlink1",
    "founderIntel": "The reviewed official pages do not name a legal entity, founders, or jurisdiction; they present a commercial eSIM service and publish a support contact.",
    "vcIntel": null,
    "kycNote": "No KYC required per official homepage; no email/sign-up flow for eSIM purchase retained from existing source data.",
    "updatedAt": "2026-06-22",
    "stateActorFlag": null,
    "privacyWarning": "Anonymous telecom reseller with no clearly disclosed corporate entity; eSIM/network operators still see network metadata.",
    "followTheMoney": "Silent Link\nModel: commercial pay-as-you-go eSIM service\nPayments: Bitcoin, Lightning, Monero, USDT, or other crypto\nLegal operator and jurisdiction: not disclosed on reviewed operator pages",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_4_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "limited",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "unresolved",
        "citation": "unknown",
        "note": "The official site presents a paid eSIM service but does not disclose a legal entity, registration, address, officers, or jurisdiction on the reviewed pages."
      },
      "source": "No controlling corporate document found on reviewed operator routes on 2026-08-25"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "noncustodial-hosted",
      "sourceModel": "closed"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://silent.link/",
            "https://silent.link/faq"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No account/email/KYC is claimed, but order, eSIM, payment, support and unavoidable carrier/network metadata create moderate operator exposure."
        },
        "controlModel": {
          "value": "noncustodial-hosted",
          "sourceUrls": [
            "https://silent.link/",
            "https://silent.link/faq"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Silent Link is a hosted prepaid provisioning service without a persistent customer account or custody of user assets after delivery."
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://silent.link/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No source repository or reproducible critical-core evidence is published."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced; no audit points are granted."
      }
    }
  },
  {
    "id": 330,
    "slug": "jmp-chat",
    "domain": "jmp.chat",
    "name": "JMP.chat",
    "type": "Comms",
    "cat": "comms",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "$2.99/mo",
    "limits": {
      "daily": null
    },
    "features": [
      "XMPP-based",
      "Real US phone number",
      "SMS + calls",
      "BTC + Lightning",
      "Open source",
      "No identity required",
      "Jabber/XMPP"
    ],
    "networks": [],
    "badge": "COMMS",
    "url": "https://jmp.chat/",
    "affiliate": "",
    "geo": [
      "US",
      "CA"
    ],
    "status": "ok",
    "checkedAt": "2026-08-27",
    "trending": false,
    "countries": [
      "US",
      "CA"
    ],
    "categories": [
      "Comms"
    ],
    "description": "Canadian and US phone numbers for SMS, MMS and calls over XMPP, operating under Canadian and BC jurisdiction.",
    "cardSummary": "Phone numbers for SMS and calls over XMPP.",
    "jurisdiction": "CA",
    "auditedBy": [],
    "privacyWarning": "XMPP account data and telecom metadata are processed. Voicemail/MMS are deleted after 30 days; other message content may leave cache after 7 days; call records, DID number and destination metadata may persist for billing and troubleshooting.",
    "founderIntel": "Denver Gingerich. Corporate Entity: Soprani.ca project. Backing: Open-source collective building XMPP gateways to SMS/MMS. Entirely community-funded, anti-surveillance communications project with no VC oversight.",
    "vcIntel": "JMP.chat (US). Small open-source team. Donation funded. XMPP-based. Five Eyes jurisdiction but minimal data collection.",
    "kycNote": "No identity KYC surfaced in official FAQ/privacy pages; users need service signup/payment and phone-number provisioning rather than document verification.",
    "updatedAt": "2026-08-27",
    "stateActorFlag": null,
    "followTheMoney": "JMP\n────────────────────────\nProduct of: MBOA Technology\nCo-operative Inc\nSoftware: free and open source\nRevenue: monthly subscriptions",
    "publicClaims": {
      "followTheMoney": {
        "value": "JMP\n────────────────────────\nProduct of: MBOA Technology\nCo-operative Inc\nSoftware: free and open source\nRevenue: monthly subscriptions",
        "reviewedAt": "2026-07-15",
        "sources": [
          {
            "label": "JMP - Credits and source code",
            "href": "https://jmp.chat/credits",
            "type": "official"
          },
          {
            "label": "JMP - Service and pricing",
            "href": "https://jmp.chat/",
            "type": "official"
          }
        ]
      }
    },
    "lastReviewed": "2026-08-27",
    "kycLastChecked": "2026-08-27",
    "reviewSource": "Primary-source review 2026-08-27",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://jmp.chat/credits",
        "note": "Official JMP credits page states JMP is a product of MBOA TECHNOLOGY CO-OPERATIVE INC; the co-op's own blog states it was incorporated to house JMP as a worker co-operative commercial operator."
      },
      "repositoryUrl": {
        "value": "https://soprani.ca/",
        "citation": "https://soprani.ca/"
      },
      "legalEntity": {
        "value": "MBOA TECHNOLOGY CO-OPERATIVE INC",
        "citation": "https://jmp.chat/credits"
      },
      "incorporationJurisdiction": {
        "value": "Canada",
        "citation": "https://jmp.chat/privacy"
      },
      "registeredAddress": {
        "value": "50 Ottawa St S Suite 200, Kitchener, ON N2G 3S7, Canada",
        "citation": "https://play.google.com/store/apps/details?id=chat.jmp.simmanager&hl=en_US"
      },
      "ultimateOwner": {
        "value": "worker-members of the co-operative (employee/member-owned)",
        "citation": "https://blog.jmp.chat/b/december-newsletter-2022"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "federated",
      "sourceModel": "open"
    },
    "changedAt": "2026-08-27",
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://jmp.chat/privacy"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Phone service necessarily processes numbers, call/SMS routing metadata and short-lived content/media while account credit and abuse records persist."
        },
        "controlModel": {
          "value": "federated",
          "sourceUrls": [
            "https://jmp.chat/faq"
          ],
          "reviewedAt": "2026-08-27",
          "note": "JMP bridges carrier telephony to user-selected/self-hosted federated XMPP identities."
        },
        "sourceModel": {
          "value": "open",
          "sourceUrls": [
            "https://jmp.chat/credits"
          ],
          "reviewedAt": "2026-08-27",
          "note": "The official credits page identifies corresponding source for service components; no reproducible-build claim was found."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced in the reopened first-party source family."
      }
    }
  },
  {
    "id": 331,
    "slug": "grapheneos",
    "noOperatorData": true,
    "domain": "grapheneos.org",
    "name": "GrapheneOS",
    "type": "Privacy Tools",
    "cat": "privacy",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Free",
    "limits": {
      "daily": null
    },
    "features": [
      "Hardened Android fork",
      "Google-free option",
      "Sandboxed Google Play",
      "Verified boot",
      "Open source",
      "Pixel devices",
      "No account required",
      "Auto-updates",
      "Advanced permission controls",
      "Duress PIN/password"
    ],
    "networks": [],
    "badge": "OS",
    "url": "https://grapheneos.org/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-09",
    "trending": true,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Privacy Tools"
    ],
    "description": "Open-source Android-compatible mobile OS for Pixel devices, with no account required to install or use it.",
    "cardSummary": "Hardened Android OS for Pixel devices.",
    "jurisdiction": "CA",
    "auditedBy": null,
    "twitter": "https://x.com/grapheneos",
    "founderIntel": "Daniel Micay (founder) - stepped down as lead developer May 2023 due to escalating harassment including swatting attacks. Still listed as a director of GrapheneOS Foundation in Canadian registry as of December 2025. Current team: multiple full-time/part-time developers. No intelligence community connections found. Confirmed no OTF funding per independent fact-check (factually.co).",
    "vcIntel": "Donation-only: GitHub Sponsors, Bitcoin, Monero, bank transfers to GrapheneOS Foundation (Canadian non-profit, est. March 2023). Hosting: ReliableSite, Tempest, OBH (Canada). No government grants, no VC, no OTF. Cleanest funding structure of any privacy OS.",
    "kycNote": "No user account or identity KYC required for OS use; donation routes through GitHub Sponsors, crypto, PayPal, Wise or bank transfer may identify donors by rail.",
    "changedAt": "2026-08-09",
    "updatedAt": "2026-08-09",
    "stateActorFlag": null,
    "privacyWarning": null,
    "followTheMoney": "  GrapheneOS Project - Non-profit (CA)\n  ──────────────────────────────────────\n  Lead: Daniel Micay + contributors\n  Funding: donations + Invisible Things\n  Revenue: none (free OS)\n  ├─ No company, no VC, no tracking\n  ├─ Removes all Google monetisation\n  └─ Pixel hardware required",
    "lastReviewed": "2026-08-09",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "https://grapheneos.org/features#duress",
    "jurisdictionConfidence": "inferred",
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://ised-isde.canada.ca/cc/lgcy/fdrlCrpDtls.html?p=0&corpId=14857577&crpNm=grapheneos",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "GrapheneOS Foundation",
        "citation": "https://ised-isde.canada.ca/cc/lgcy/fdrlCrpDtls.html?p=0&corpId=14857577&crpNm=grapheneos"
      },
      "registrationNumber": {
        "value": "1485757-7",
        "citation": "https://ised-isde.canada.ca/cc/lgcy/fdrlCrpDtls.html?p=0&corpId=14857577&crpNm=grapheneos"
      },
      "registryUrl": {
        "value": "https://ised-isde.canada.ca/cc/lgcy/fdrlCrpDtls.html?p=0&corpId=14857577&crpNm=grapheneos",
        "citation": "https://ised-isde.canada.ca/cc/lgcy/fdrlCrpDtls.html?p=0&corpId=14857577&crpNm=grapheneos"
      },
      "incorporationJurisdiction": {
        "value": "Canada (federal)",
        "citation": "https://ised-isde.canada.ca/cc/lgcy/fdrlCrpDtls.html?p=0&corpId=14857577&crpNm=grapheneos"
      },
      "incorporationDate": {
        "value": "2023-03-17",
        "citation": "https://ised-isde.canada.ca/cc/lgcy/fdrlCrpDtls.html?p=0&corpId=14857577&crpNm=grapheneos"
      },
      "registeredAddress": {
        "value": "198 Bain Avenue, Toronto ON M4K 1G1, Canada",
        "citation": "https://ised-isde.canada.ca/cc/lgcy/fdrlCrpDtls.html?p=0&corpId=14857577&crpNm=grapheneos"
      },
      "officers": {
        "value": [
          "Khalykbek Yelshibekov",
          "Daniel Micay",
          "Dmytro Mukhomor"
        ],
        "citation": "https://ised-isde.canada.ca/cc/lgcy/fdrlCrpDtls.html?p=0&corpId=14857577&crpNm=grapheneos"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://grapheneos.org/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://grapheneos.org/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://grapheneos.org/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 332,
    "slug": "calyx-institute",
    "domain": "calyxinstitute.org",
    "name": "Calyx Institute",
    "type": "Privacy Tools",
    "cat": "privacy",
    "kyc": "light",
    "kycLevel": 1,
    "fees": {
      "transaction": 0
    },
    "fee": "Free (membership optional)",
    "limits": {
      "daily": null
    },
    "features": [
      "CalyxOS",
      "Android fork",
      "microG included",
      "Pixel + Motorola",
      "Open source",
      "VPN included",
      "No Google account"
    ],
    "networks": [],
    "badge": "OS",
    "url": "https://calyxinstitute.org/",
    "affiliate": "",
    "geo": [
      "US",
      "CA",
      "PR"
    ],
    "status": "ok",
    "checkedAt": "2026-08-27",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Privacy Tools"
    ],
    "description": "US nonprofit digital-rights organization offering privacy tools, memberships, hotspots and CalyxOS phones.",
    "cardSummary": "US nonprofit privacy tools and hotspots.",
    "jurisdiction": "US",
    "auditedBy": null,
    "twitter": "https://x.com/calyxinstitute",
    "privacyWarning": "Mobile-internet membership requires contact/account data and uses T-Mobile/Mobile Citizen infrastructure. New CalyxOS phone memberships are temporarily paused; current memberships and phones are unaffected.",
    "founderIntel": null,
    "vcIntel": null,
    "kycNote": "No identity KYC to use Calyx tools, but memberships/hardware require user-provided contact/shipping and payment data; privacy policy says cash or Bitcoin payments retain only provided information plus membership ID.",
    "updatedAt": "2026-06-22",
    "stateActorFlag": "Calyx Institute received OTF (Open Technology Fund = US State Dept / USAGM) funding for CalyxOS development.",
    "followTheMoney": "  Calyx Institute - New York, USA (US)\n  ──────────────────────────────────────\n  Co-founder: Nicholas Merrill (anti-NSL)\n  Funders: Jack Dorsey $1M, Ford Found.\n           NLnet, DuckDuckGo, OTF (US)\n  ├─ OTF = US State Dept USAGM funding\n  ├─ Five Eyes (US) jurisdiction\n  └─ Strong anti-surveillance posture",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_6_2026-06-22",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "foundation",
        "citation": "https://calyxinstitute.org/about",
        "note": "Official site and IRS filings describe it as a 501(c)(3) nonprofit/public charity (New York domestic not-for-profit corporation) founded 2010."
      },
      "governanceModel": {
        "value": "foundation",
        "citation": "https://projects.propublica.org/nonprofits/organizations/272800937"
      },
      "repositoryUrl": {
        "value": "https://gitlab.com/CalyxOS",
        "citation": "https://gitlab.com/CalyxOS"
      },
      "legalEntity": {
        "value": "The Calyx Institute (CALYX INSTITUTE)",
        "citation": "https://calyxinstitute.org/files/2022CalyxForm990-Public.pdf"
      },
      "registrationNumber": {
        "value": "EIN 27-2800937; NY DOS ID 3951504",
        "citation": "https://projects.propublica.org/nonprofits/organizations/272800937"
      },
      "registryUrl": {
        "value": "https://apps.dos.ny.gov/publicInquiry/",
        "citation": "https://en.wikipedia.org/wiki/Calyx_Institute"
      },
      "incorporationJurisdiction": {
        "value": "New York, United States",
        "citation": "https://calyxinstitute.org/files/2022CalyxForm990-Public.pdf"
      },
      "incorporationDate": {
        "value": "2010-05-19",
        "citation": "https://en.wikipedia.org/wiki/Calyx_Institute"
      },
      "registeredAddress": {
        "value": "254 36th St Ste C660, Brooklyn, NY 11232, USA",
        "citation": "https://calyxinstitute.org/files/2022CalyxForm990-Public.pdf"
      },
      "parentEntity": {
        "value": "none",
        "citation": "https://www.causeiq.com/organizations/calyxinstitute,272800937/"
      },
      "ultimateOwner": {
        "value": "none (501(c)(3) public charity)",
        "citation": "https://projects.propublica.org/nonprofits/organizations/272800937"
      },
      "officers": {
        "value": [
          "Nicholas Merrill (President)",
          "Ellen McDermott (Interim Executive Director)",
          "Eric Bortel (Engineering Director)",
          "Benjamin Knauss (Finance Director)",
          "Ashi Krishnan (Director)",
          "Liz O'Sullivan (Director)",
          "Carey Shenkman (Director)",
          "Kobi Snitz (Director)"
        ],
        "citation": "https://projects.propublica.org/nonprofits/organizations/272800937"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "hosted-account",
      "sourceModel": "partial"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://calyx.org/legal/privacy-policy"
          ],
          "reviewedAt": "2026-08-27",
          "note": "membership identity/contact, membership ID, possible IP logs and service-provider data"
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://calyx.org/legal/privacy-policy"
          ],
          "reviewedAt": "2026-08-27",
          "note": "mixed-membership-service-and-open-source-os"
        },
        "sourceModel": {
          "value": "partial",
          "sourceUrls": [
            "https://calyxos.org/news/2026/07/01/calyxos-official-release-is-back/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "open-source-os-plus-operator-service"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No current organization/service-wide independent audit citation/date/scope established."
      }
    }
  },
  {
    "id": 333,
    "slug": "mysudo",
    "domain": "mysudo.com",
    "name": "MySudo",
    "type": "Comms",
    "cat": "comms",
    "kyc": "light",
    "kycLevel": 2,
    "fees": {
      "transaction": 0
    },
    "fee": "Free tier / $0.99-$14.99/mo",
    "limits": {
      "daily": null
    },
    "features": [
      "Multiple phone numbers",
      "Separate identities (Sudos)",
      "Email aliases",
      "Private browser",
      "Calls + SMS",
      "iOS + Android",
      "Option-level identity verification"
    ],
    "networks": [],
    "badge": "COMMS",
    "url": "https://mysudo.com/",
    "affiliate": "",
    "geo": [
      "US",
      "CA",
      "UK",
      "AU"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "US",
      "CA",
      "UK",
      "AU"
    ],
    "categories": [
      "Comms"
    ],
    "description": "MySudo/Anonyome app suite for private phone numbers, email aliases, messaging, VPN and optional virtual-card/identity services.",
    "cardSummary": "App suite for private numbers and aliases.",
    "jurisdiction": "US",
    "auditedBy": null,
    "twitter": "https://x.com/anonyomelabs",
    "privacyWarning": "Anonyome Labs Inc. is US/Five Eyes; some phone-number and virtual-card features require identity verification, and existing founder surveillance-tech warning remains material.",
    "founderIntel": "Greg Clark (Co-founder): CEO of Blue Coat Systems (2011-2016) when Citizen Lab documented their DPI gear deployed in Syria to surveil/censor dissidents; Iran; Sudan. Clark then became CEO of Symantec (.65B acquisition of Blue Coat). Now Co-Founder & Managing Partner at Crosspoint Capital Partners (PE firm investing in cybersecurity). Steve Shillingford (Co-founder/CEO): CEO of Solera Networks - built surveillance software for corporations and government agencies by his own description. Said he got \"uncomfortable\" with inward-facing surveillance and pivoted to privacy. Both met the definition of surveillance-industry veterans who then built a privacy app marketed to exactly the users they previously helped target.",
    "vcIntel": "Anonyome Labs Inc. Utah, USA - Five Eyes jurisdiction. Series B .4M (2017). Investors: Greg Clark (co-founder, Crosspoint Capital), John Mumford, Todd Davis (LifeLock founder - ironic: identity theft protection company), Ken Eldred (Ariba co-founder), Hanna Ventures (Utah-based). No public VC firm transparency. All investors from US enterprise/security orbit.",
    "kycNote": "Terms/privacy say telephony services from some countries and virtual-card services may require legal identity information, government ID, address, date of birth and/or a non-MySudo phone number.",
    "stateActorFlag": "Founder connections to Blue Coat Systems and Solera Networks, both documented surveillance tech vendors. Utah, USA - Five Eyes jurisdiction.",
    "updatedAt": "2026-08-25",
    "followTheMoney": "Anonyome Labs Inc - Utah, United States\nCEO: Steve Shillingford\nCo-founder: Greg Clark, former Blue Coat CEO\nFunding: $19.4M Series B reported\nRelevant history: Blue Coat products were documented in censorship and surveillance deployments",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "https://anonyome.com/terms-of-service",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://anonyome.com/terms-of-service/",
        "note": "Official Terms of Service name Anonyome Labs, Inc. as the operator of mysudo.com and related applications/services; Apple App Store and Google Play list Anonyome Labs, Inc. as the developer/seller."
      },
      "legalEntity": {
        "value": "Anonyome Labs, Inc.",
        "citation": "https://anonyome.com/terms-of-service/"
      },
      "registryUrl": {
        "value": "https://icis.corp.delaware.gov/Ecorp/EntitySearch/NameSearch.aspx",
        "citation": "https://ttabvue.uspto.gov/ttabvue/ttabvue-87521673-EXT-1.pdf"
      },
      "incorporationJurisdiction": {
        "value": "Delaware, United States",
        "citation": "https://ttabvue.uspto.gov/ttabvue/ttabvue-87521673-EXT-1.pdf"
      },
      "registeredAddress": {
        "value": "32 West 200 South #315, Salt Lake City, UT 84101",
        "citation": "https://anonyome.com/terms-of-service/"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://anonyome.com/terms-of-service/",
            "https://anonyome.com/terms-of-service",
            "https://anonyome.com/individuals/mysudo-plans/",
            "https://mysudo.com/mysudo-plans",
            "https://mysudo.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://anonyome.com/terms-of-service/",
            "https://anonyome.com/terms-of-service",
            "https://anonyome.com/individuals/mysudo-plans/",
            "https://mysudo.com/mysudo-plans",
            "https://mysudo.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://anonyome.com/terms-of-service/",
            "https://anonyome.com/terms-of-service",
            "https://anonyome.com/individuals/mysudo-plans/",
            "https://mysudo.com/mysudo-plans",
            "https://mysudo.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 401,
    "slug": "proton-mail",
    "domain": "proton.me",
    "name": "Proton Mail",
    "type": "Email",
    "cat": "email",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Free / from $3.99/mo",
    "limits": {
      "daily": null
    },
    "features": [
      "End-to-end encrypted",
      "Zero-access encryption",
      "Anonymous signup",
      "Swiss jurisdiction",
      "Open source",
      "Tor onion site",
      "BTC payment accepted",
      "Automatic inbox categories"
    ],
    "networks": [],
    "badge": "POPULAR",
    "url": "https://proton.me/mail",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": true,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Email"
    ],
    "description": "Swiss end-to-end encrypted email with free accounts, zero-access encryption and no phone signup by default.",
    "cardSummary": "Swiss end-to-end encrypted email.",
    "jurisdiction": "CH",
    "auditedBy": [
      "Securitum"
    ],
    "telegram": "https://t.me/proton_privacy",
    "founderIntel": "Same team as Proton VPN - Andy Yen, Jason Stockman, Wei Sun, Dingchao Lu (CERN physicists). SimpleLogin acquisition (2022): Son Nguyen Kim - Vietnamese-French, École Polytechnique MSc, IMO gold medalist. Prior: ML at Criteo (French ad-tech). SimpleLogin had zero investors pre-acquisition. Post-acquisition: Son Nguyen Kim joined Proton. Board includes Tim Berners-Lee and Carissa Véliz (Oxford, anti-surveillance).",
    "vcIntel": "Identical to Proton VPN. CRV transferred to FONGIT 2021. Proton Foundation primary shareholder 2024. SimpleLogin: bootstrapped with zero investors pre-acquisition.",
    "kycNote": "Official mail page says no phone number is required for signup, but Proton may request extra verification in rare anti-abuse situations via captcha, email or SMS.",
    "updatedAt": "2026-08-25",
    "stateActorFlag": "Proton AG (Swiss) complied with a 2021 court order and logged climate activist IP. Has since improved policies. Swiss law, GDPR.",
    "privacyWarning": "Swiss provider with strong privacy posture but court-order history; privacy policy says IPs/emails/phone numbers supplied for verification can be saved temporarily for anti-spam/abuse controls.",
    "followTheMoney": "Proton AG\n────────────────────────\nPrimary shareholder: Proton Foundation\nFoundation: Swiss non-profit\nRevenue allocation: 1%\nwhen financial conditions allow",
    "publicClaims": {
      "followTheMoney": {
        "value": "Proton AG\n────────────────────────\nPrimary shareholder: Proton Foundation\nFoundation: Swiss non-profit\nRevenue allocation: 1%\nwhen financial conditions allow",
        "reviewedAt": "2026-07-15",
        "sources": [
          {
            "label": "Proton Foundation - Governance",
            "href": "https://proton.me/foundation",
            "type": "official"
          }
        ]
      }
    },
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "https://proton.me/mail",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://proton.me/legal/terms",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Proton AG",
        "citation": "https://proton.me/legal/terms"
      },
      "registrationNumber": {
        "value": "CHE-354.686.492",
        "citation": "https://www.zefix.ch/ZefixREST/api/v1/firm/search.json (Swiss Central Business Names Index, official federal registry API, agent-verified by direct query 2026-08-08: ehraid=1189263, legalSeat=Plan-les-Ouates, status=EXISTIEREND)"
      },
      "registryUrl": {
        "value": "https://www.zefix.ch/en/search/entity/list?name=Proton%20AG",
        "citation": "https://www.zefix.ch/ZefixREST/api/v1/firm/search.json (agent-verified 2026-08-08)"
      },
      "incorporationJurisdiction": {
        "value": "Switzerland",
        "citation": "https://proton.me/legal/terms"
      },
      "incorporationDate": {
        "value": "18.07.2014",
        "citation": "https://www.moneyhouse.ch/en/company/proton-ag-4537282131"
      },
      "registeredAddress": {
        "value": "Route de la Galaise 32, 1228 Plan-les-Ouates, Geneva, Switzerland",
        "citation": "https://proton.me/legal/terms"
      },
      "parentEntity": {
        "value": "Proton Foundation",
        "citation": "https://proton.me/legal/terms"
      },
      "ultimateOwner": {
        "value": "Proton Foundation",
        "citation": "https://proton.me/legal/terms"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [
          "Proton Technologies AG"
        ],
        "citation": "https://www.northdata.com/Proton%20AG,%20Plan-les-Ouates/CHE-354.686.492"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://proton.me/mail",
            "https://x.com/ProtonMail/status/2090462386947862992"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://proton.me/mail",
            "https://x.com/ProtonMail/status/2090462386947862992"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://proton.me/mail",
            "https://x.com/ProtonMail/status/2090462386947862992"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 402,
    "slug": "tuta",
    "domain": "tuta.com",
    "name": "Tuta",
    "type": "Email",
    "cat": "email",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Free / from €3/mo",
    "limits": {
      "daily": null
    },
    "features": [
      "End-to-end encrypted",
      "Encrypted subject lines",
      "Anonymous signup",
      "German jurisdiction",
      "Open source",
      "Calendar included",
      "No ad tracking"
    ],
    "networks": [],
    "badge": "PRIVATE",
    "url": "https://tuta.com",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-24",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Email"
    ],
    "description": "German encrypted email, calendar and contacts from Tutao GmbH with end-to-end/post-quantum encryption and open-source clients.",
    "cardSummary": "German encrypted email, calendar and contacts.",
    "jurisdiction": "DE",
    "auditedBy": [
      "Cure53"
    ],
    "founderIntel": "Matthias Pfau (CEO) and Arne Möhle - German software engineers, met at FHDW Hannover. Pfau background: FinanzIT developer 2003-2007, Zühlke Engineering 2007-2011. Commercial software career, zero intelligence background. 100% founder-owned, no external investors. Only external funding: €1.5M German government KMU-innovativ research grant. Honeypot allegation (2023, RCMP officer Cameron Ortis criminal trial) was rebutted with zero evidence - multiple outlets confirmed Tuta denial. 2020 German court order for single-account monitoring (extortion case) was publicly disclosed - lawful intercept compliance, not a backdoor.",
    "vcIntel": "No investors. Fully bootstrapped. Only external funding: €1.5M German government KMU-innovativ R&D grant for post-quantum encrypted cloud storage. Tutao GmbH, Hannover, Germany.",
    "kycNote": "No identity KYC surfaced for normal email use; terms/privacy say business customers need full name/address and paid variants may collect domicile, optional invoice name/address or VAT data.",
    "updatedAt": "2026-06-22",
    "stateActorFlag": null,
    "privacyWarning": "German/EU jurisdiction with data-minimization posture; paid/business billing metadata may still exist.",
    "followTheMoney": "Tutao GmbH - Hanover, Germany\n────────────────────────\nRepresented by: Arne Möhle,\nHanna Bozakov, and Matthias Pfau\nRegistration: Hanover HRB 208014",
    "publicClaims": {
      "followTheMoney": {
        "value": "Tutao GmbH - Hanover, Germany\n────────────────────────\nRepresented by: Arne Möhle,\nHanna Bozakov, and Matthias Pfau\nRegistration: Hanover HRB 208014",
        "reviewedAt": "2026-07-15",
        "sources": [
          {
            "label": "Tuta - Legal notice",
            "href": "https://tuta.com/imprint",
            "type": "official"
          }
        ]
      }
    },
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_6_2026-06-22",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://tuta.com/imprint",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Tutao GmbH",
        "citation": "https://tuta.com/imprint"
      },
      "registrationNumber": {
        "value": "HRB 208014",
        "citation": "https://tuta.com/imprint"
      },
      "registryUrl": {
        "value": "https://www.northdata.com/Tutao+GmbH,+Hannover/HRB+208014",
        "citation": "https://www.northdata.com/Tutao+GmbH,+Hannover/HRB+208014"
      },
      "incorporationJurisdiction": {
        "value": "Germany",
        "citation": "https://tuta.com/imprint"
      },
      "registeredAddress": {
        "value": "Deisterstr. 17a, 30449 Hanover, Germany",
        "citation": "https://tuta.com/imprint"
      },
      "officers": {
        "value": [
          "Arne Möhle",
          "Hanna Bozakov",
          "Matthias Pfau"
        ],
        "citation": "https://tuta.com/imprint"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://tuta.com/pricing",
            "https://tuta.com/privacy-policy",
            "https://github.com/tutao/tutanota/releases",
            "https://tuta.com"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://tuta.com/pricing",
            "https://tuta.com/privacy-policy",
            "https://github.com/tutao/tutanota/releases",
            "https://tuta.com"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://tuta.com/pricing",
            "https://tuta.com/privacy-policy",
            "https://github.com/tutao/tutanota/releases",
            "https://tuta.com"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 403,
    "slug": "posteo",
    "domain": "posteo.de",
    "name": "Posteo",
    "type": "Email",
    "cat": "email",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "€1/mo",
    "limits": {
      "daily": null
    },
    "features": [
      "Anonymous signup",
      "Cash payment by mail",
      "German jurisdiction",
      "End-to-end encrypted",
      "No IP logging",
      "Sustainable infrastructure",
      "No tracking",
      "4 GB included storage"
    ],
    "networks": [],
    "badge": "ANONYMOUS",
    "url": "https://posteo.de",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Email"
    ],
    "description": "German privacy email from Posteo e.K. with 4GB included at €1/month, anonymous signup/payment options, no ads and no linking of payment data to accounts.",
    "cardSummary": "German email with anonymous payment options.",
    "jurisdiction": "DE",
    "auditedBy": null,
    "founderIntel": "Patrik Löhr and Sabrina Löhr - German married couple, Berlin. Met through Greenpeace volunteer work. She: PR background. He: system/email administration background. Founded Posteo e.K., Berlin-Kreuzberg, 2009. 100% self-financed by subscriptions. Publishes annual transparency reports since 2014. No Intel connections. Note: \"Pamela Joerns\" as founder elsewhere is incorrect - Löhr couple are the founders.",
    "vcIntel": "No investors. Fully bootstrapped via customer subscriptions. Banking with GLS Bank (German ethical/cooperative bank). No state or commercial bank involvement. Cleanest possible funding structure for an email provider.",
    "kycNote": "Official homepage says Posteo does not collect personal data, does not link payment data to accounts, and supports anonymized payment.",
    "updatedAt": "2026-08-25",
    "stateActorFlag": null,
    "privacyWarning": "German/EU jurisdiction; service is privacy-forward, but lawful orders can still compel whatever account/payment data exists.",
    "followTheMoney": "Posteo - Berlin, Germany\n────────────────────────\nFounders: Patrik and Sabrina Löhr\nFounded: 2009\nDebt and loans: €0\nAdvertising income: €0",
    "publicClaims": {
      "followTheMoney": {
        "value": "Posteo - Berlin, Germany\n────────────────────────\nFounders: Patrik and Sabrina Löhr\nFounded: 2009\nDebt and loans: €0\nAdvertising income: €0",
        "reviewedAt": "2026-07-15",
        "sources": [
          {
            "label": "Posteo - About",
            "href": "https://posteo.de/en/site/about_posteo",
            "type": "official"
          }
        ]
      }
    },
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "primary_source_rereview_2026-08-25",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://posteo.de/en/site/legal_notice",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Posteo e.K.",
        "citation": "https://posteo.de/en/site/legal_notice"
      },
      "registrationNumber": {
        "value": "HRA 47592 B",
        "citation": "https://posteo.de/en/site/legal_notice"
      },
      "registryUrl": {
        "value": "https://www.handelsregister.de/",
        "citation": "https://posteo.de/en/site/legal_notice"
      },
      "incorporationJurisdiction": {
        "value": "Germany",
        "citation": "https://posteo.de/en/site/legal_notice"
      },
      "registeredAddress": {
        "value": "Methfesselstr. 38, 10965 Berlin, Germany",
        "citation": "https://posteo.de/en/site/legal_notice"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://posteo.de/en",
            "https://posteo.de/en/site/2026/02/new-posteo-doubles-storage-space-to-4-gb",
            "https://posteo.de/en/site/privacy_policy",
            "https://posteo.de"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://posteo.de/en",
            "https://posteo.de/en/site/2026/02/new-posteo-doubles-storage-space-to-4-gb",
            "https://posteo.de/en/site/privacy_policy",
            "https://posteo.de"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://posteo.de/en",
            "https://posteo.de/en/site/2026/02/new-posteo-doubles-storage-space-to-4-gb",
            "https://posteo.de/en/site/privacy_policy",
            "https://posteo.de"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 404,
    "slug": "mailbox-org",
    "domain": "mailbox.org",
    "name": "Mailbox.org",
    "type": "Email",
    "cat": "email",
    "kyc": "light",
    "kycLevel": 1,
    "fees": {
      "transaction": 0
    },
    "fee": "From €1/mo",
    "limits": {
      "daily": null
    },
    "features": [
      "OpenPGP encryption",
      "Alias addresses",
      "German jurisdiction",
      "Pseudonymous signup",
      "Cash payment",
      "Calendar + contacts",
      "No ads"
    ],
    "networks": [],
    "badge": "SECURE",
    "url": "https://mailbox.org",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-24",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Email"
    ],
    "description": "German email and workspace suite allowing pseudonymous signup, paid by bank, card, PayPal or cash by post.",
    "cardSummary": "German secure email and workspace with OpenPGP.",
    "jurisdiction": "DE",
    "auditedBy": null,
    "founderIntel": "Independent/Bootstrapped or Pseudonymous operator. No known institutional or intelligence ties.",
    "vcIntel": "Heinlein Hosting GmbH (Germany). Bootstrapped. Zero VC. Berlin-based. Independent. German jurisdiction.",
    "kycNote": "Registration asks for first and last name, but mailbox.org says it does not verify them and pseudonyms are allowed. Paid accounts create billing/payment metadata; anonymous cash payment routes exist, but cryptocurrency is not accepted.",
    "updatedAt": "2026-06-22",
    "stateActorFlag": null,
    "privacyWarning": "Hosted German email/workspace account with billing/support metadata. Real-name billing data may be needed for invoices or employer reimbursement.",
    "followTheMoney": "  Heinlein Hosting GmbH - Berlin (DE)\n  ──────────────────────────────────────\n  Operator: Peer Heinlein (German)\n  Funding: bootstrapped, subscription\n  Revenue: from €1/mo subscriptions\n  ├─ DE/GDPR: strong legal protection\n  ├─ Independent, Berlin-based\n  └─ OpenPGP, calendar + contacts",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_7_2026-06-22",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://mailbox.org/en/legal-information/",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Heinlein Hosting GmbH",
        "citation": "https://mailbox.org/en/legal-information/"
      },
      "registrationNumber": {
        "value": "HRB 220010 B",
        "citation": "https://mailbox.org/en/legal-information/"
      },
      "registryUrl": {
        "value": "https://www.handelsregister.de/",
        "citation": "https://mailbox.org/en/legal-information/"
      },
      "incorporationJurisdiction": {
        "value": "Germany",
        "citation": "https://mailbox.org/en/legal-information/"
      },
      "registeredAddress": {
        "value": "Schwedter Straße 8/9A, 10119 Berlin, Germany",
        "citation": "https://mailbox.org/en/legal-information/"
      },
      "officers": {
        "value": [
          "Peer Heinlein"
        ],
        "citation": "https://mailbox.org/en/legal-information/"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://mailbox.org/de/",
            "https://mailbox.org"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://mailbox.org/de/",
            "https://mailbox.org"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://mailbox.org/de/",
            "https://mailbox.org"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 405,
    "slug": "simplelogin",
    "domain": "simplelogin.io",
    "name": "SimpleLogin",
    "type": "Email",
    "cat": "email",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Free / $36/yr premium for new subscribers",
    "limits": {
      "daily": null
    },
    "features": [
      "Email aliasing",
      "Anonymous forwarding",
      "No document KYC",
      "Open source",
      "Self-hostable",
      "Proton-integrated",
      "BTC payment"
    ],
    "networks": [],
    "badge": "ALIASES",
    "url": "https://simplelogin.io",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-27",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Email"
    ],
    "description": "Open-source email alias service from Proton AG, forwarding and replying without exposing the real mailbox.",
    "cardSummary": "Email aliases that forward to a real mailbox.",
    "jurisdiction": "CH",
    "auditedBy": [],
    "twitter": "https://x.com/mxschumacher",
    "founderIntel": null,
    "vcIntel": null,
    "kycNote": "No document identity verification found for the alias service. Account, destination mailbox, alias and payment metadata still exist, and the service is now contracted through Proton AG in Switzerland.",
    "updatedAt": "2026-08-27",
    "stateActorFlag": null,
    "privacyWarning": "Owned by Proton AG under Swiss terms; destination mailbox, aliases and abuse/payment metadata can still be account-linked even though aliases hide the real address from third parties.",
    "followTheMoney": "SimpleLogin SAS - Paris, France\n────────────────────────\nJoined Proton: April 2022\nOperations: independent service\nAdditional resources: Proton",
    "publicClaims": {
      "followTheMoney": {
        "value": "SimpleLogin SAS - Paris, France\n────────────────────────\nJoined Proton: April 2022\nOperations: independent service\nAdditional resources: Proton",
        "reviewedAt": "2026-07-15",
        "sources": [
          {
            "label": "SimpleLogin - Joins the Proton family",
            "href": "https://simplelogin.io/blog/simplelogin-join-proton/",
            "type": "official"
          }
        ]
      }
    },
    "lastReviewed": "2026-08-27",
    "kycLastChecked": "2026-08-27",
    "reviewSource": "Primary-source review 2026-08-27",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://simplelogin.io/privacy/",
        "note": "Official Privacy Policy and Terms state SimpleLogin is a service offered by Proton AG, a Swiss registered corporation."
      },
      "governanceModel": {
        "value": "company-sponsored",
        "citation": "https://simplelogin.io/"
      },
      "repositoryUrl": {
        "value": "https://github.com/simple-login/",
        "citation": "https://github.com/simple-login/"
      },
      "legalEntity": {
        "value": "Proton AG",
        "citation": "https://simplelogin.io/privacy/"
      },
      "registrationNumber": {
        "value": "CHE-354.686.492",
        "citation": "https://simplelogin.io/privacy/"
      },
      "registryUrl": {
        "value": "https://www.uid.admin.ch/Detail.aspx?lang=en&uid_id=CHE354686492",
        "citation": "https://www.uid.admin.ch/Detail.aspx?lang=en&uid_id=CHE354686492"
      },
      "incorporationJurisdiction": {
        "value": "Switzerland",
        "citation": "https://simplelogin.io/privacy/"
      },
      "incorporationDate": {
        "value": "2014-07-18",
        "citation": "https://www.moneyhouse.ch/en/company/proton-ag-4537282131"
      },
      "registeredAddress": {
        "value": "Route de la Galaise 32, 1228 Plan-les-Ouates, Switzerland",
        "citation": "https://simplelogin.io/terms/"
      },
      "parentEntity": {
        "value": "Proton Foundation (primary shareholder)",
        "citation": "https://proton.me/about"
      },
      "ultimateOwner": {
        "value": "Proton Foundation",
        "citation": "https://proton.me/foundation"
      },
      "officers": {
        "value": [
          "Andy Yen",
          "Antonio Gambardella",
          "Alisé Gabrielle Elsa Elise de Tonnac de Villeneuve",
          "Rosemary Leith"
        ],
        "citation": "https://www.moneyhouse.ch/en/company/proton-ag-4537282131"
      },
      "priorEntities": {
        "value": [
          "SimpleLogin SAS -- Prior French operating entity; legal domicile moved to Proton AG (Switzerland) effective 2024-01-01"
        ],
        "citation": "https://simplelogin.io/blog/simplelogin-switzerland/"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "hosted-account",
      "sourceModel": "open"
    },
    "changedAt": "2026-08-27",
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://simplelogin.io/privacy/",
            "https://simplelogin.io/terms/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Account email plus forwarding metadata, payment/support and mail-operation records create moderate hosted exposure."
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://simplelogin.io/",
            "https://simplelogin.io/security/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "The public SimpleLogin service is account-based and Proton-operated, although users can self-host the same stack."
        },
        "sourceModel": {
          "value": "open",
          "sourceUrls": [
            "https://github.com/simple-login/app",
            "https://github.com/simple-login/app/blob/master/README.md"
          ],
          "reviewedAt": "2026-08-27",
          "note": "The official repository includes backend/web code and self-hosting instructions for the critical service."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced; no audit points are granted."
      }
    }
  },
  {
    "id": 406,
    "slug": "internxt",
    "domain": "internxt.com",
    "name": "Internxt",
    "type": "Cloud Storage",
    "cat": "cloud",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Free 1GB; paid annual/lifetime/business pricing is plan-specific",
    "limits": {
      "daily": null
    },
    "features": [
      "Zero-knowledge encryption",
      "Post-quantum encryption",
      "No identity or email verification",
      "1 GB free tier",
      "Crypto payments",
      "Open source",
      "Drive + Send suite",
      "Spanish jurisdiction"
    ],
    "networks": [],
    "badge": "ZERO-KNOWLEDGE",
    "url": "https://internxt.com",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": true,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Cloud Storage"
    ],
    "description": "Spanish zero-knowledge encrypted cloud storage and file transfer, taking crypto for lifetime plans.",
    "cardSummary": "Spanish zero-knowledge encrypted cloud storage.",
    "jurisdiction": "ES",
    "auditedBy": null,
    "twitter": "https://x.com/internxt",
    "founderIntel": "Fran Villalba Segarra (CEO/founder) - Spanish national, Valencia. BA International Business, Rotterdam School of Management (Erasmus University). Forbes 30 Under 30. Young privacy entrepreneur, clean background. No intel connections.",
    "vcIntel": "Telefónica/Wayra (CONCERN: state-aligned telecom investor), Prosegur (CONCERN: security contractor), Notion Capital, Juan Roig (Mercadona founder), Andorra Telecom, Angels Capital, TheVentureCity, Crowdcube, Spanish CDTI €1.4M grant, EU funds. Total raised: ~€8.46M. Zero-knowledge encryption technology is solid and has won Spanish DPA awards.",
    "kycNote": "No document KYC found. Accounts and contact/payment data still exist; crypto checkout is source-verified only for lifetime plans, while annual plans use other payment methods.",
    "stateActorFlag": null,
    "updatedAt": "2026-08-25",
    "privacyWarning": "Spanish/EU provider with account, payment and support metadata. Existing investor/state-aligned telecom and security-contractor cautions remain relevant despite zero-knowledge storage claims.",
    "followTheMoney": "  Internxt SLU - Valencia, Spain (ES)\n  ──────────────────────────────────────\n  CEO: Fran Villalba Segarra (Spanish)\n  Raised: ~€8.46M total\n  Investors: Telefónica/Wayra, Prosegur\n  ├─ Telefónica: Spanish state telecom\n  ├─ Prosegur: gov security contractor\n  └─ Tech is solid; investors are risky",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "https://internxt.com/pricing",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://internxt.com/legal",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Internxt Universal Technologies, S.L.",
        "citation": "https://internxt.com/legal"
      },
      "registrationNumber": {
        "value": "B98936354",
        "citation": "https://internxt.com/legal"
      },
      "registryUrl": {
        "value": "https://www.einforma.com/informacion-empresa/internxt-universal-technologies",
        "citation": "https://www.einforma.com/informacion-empresa/internxt-universal-technologies"
      },
      "incorporationJurisdiction": {
        "value": "Spain",
        "citation": "https://internxt.com/legal"
      },
      "incorporationDate": {
        "value": "2017-08-24",
        "citation": "https://www.einforma.com/informacion-empresa/internxt-universal-technologies"
      },
      "registeredAddress": {
        "value": "C/ La Travesia s/n, Edificio Angels, 46024, Valencia, España",
        "citation": "https://internxt.com/legal"
      },
      "officers": {
        "value": [
          {
            "name": "Francisco Leopoldo Villalba Segarra",
            "role": "Adm. Unico"
          }
        ],
        "citation": "https://www.boe.es/borme/dias/2025/11/17/pdfs/BORME-A-2025-219-46.pdf"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://internxt.com/pricing",
            "https://internxt.com/legal",
            "https://internxt.com"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://internxt.com/pricing",
            "https://internxt.com/legal",
            "https://internxt.com"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://internxt.com/pricing",
            "https://internxt.com/legal",
            "https://internxt.com"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 407,
    "slug": "filen",
    "domain": "filen.io",
    "name": "Filen",
    "type": "Cloud Storage",
    "cat": "cloud",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Free 10GB / from €0.99/mo",
    "limits": {
      "daily": null
    },
    "features": [
      "End-to-end encrypted",
      "Zero-knowledge",
      "German jurisdiction",
      "Open source",
      "Major cards + PayPal",
      "Desktop + mobile apps",
      "GDPR compliant"
    ],
    "networks": [],
    "badge": "E2EE",
    "url": "https://filen.io",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-24",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Cloud Storage"
    ],
    "description": "German zero-knowledge cloud storage with end-to-end encrypted files, chats and collaboration tools.",
    "cardSummary": "German zero-knowledge encrypted cloud storage.",
    "jurisdiction": "DE",
    "auditedBy": null,
    "twitter": "https://x.com/filen_io",
    "founderIntel": null,
    "vcIntel": null,
    "kycNote": "No document KYC found. Paid accounts use conventional payment rails such as major cards and PayPal; free and lifetime accounts have inactivity rules tied to account login.",
    "updatedAt": "2026-06-22",
    "stateActorFlag": null,
    "privacyWarning": "German hosted cloud account with payment, support and account-activity metadata. No current official crypto-payment route was source-verified in this pass.",
    "followTheMoney": "Filen\n────────────────────────\nOperator: Filen Cloud Dienste UG\nBase: Recklinghausen, Germany\nRepresentative: Jan Lenczyk\nRegistration: HRB 8896",
    "publicClaims": {
      "followTheMoney": {
        "value": "Filen\n────────────────────────\nOperator: Filen Cloud Dienste UG\nBase: Recklinghausen, Germany\nRepresentative: Jan Lenczyk\nRegistration: HRB 8896",
        "reviewedAt": "2026-07-15",
        "sources": [
          {
            "label": "Filen - Imprint",
            "href": "https://filen.io/imprint",
            "type": "official"
          }
        ]
      }
    },
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_7_2026-06-22",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://filen.io/imprint",
        "note": "Official Imprint and Terms name the operating entity as Filen Cloud Dienste UG (haftungsbeschränkt), a German limited-liability company registered under HRB 8896."
      },
      "repositoryUrl": {
        "value": "https://github.com/FilenCloudDienste",
        "citation": "https://github.com/FilenCloudDienste"
      },
      "legalEntity": {
        "value": "Filen Cloud Dienste UG (haftungsbeschränkt)",
        "citation": "https://filen.io/imprint"
      },
      "registrationNumber": {
        "value": "HRB 8896",
        "citation": "https://filen.io/imprint"
      },
      "registryUrl": {
        "value": "https://www.northdata.com/Filen%20Cloud%20Dienste%20UG,%20Recklinghausen/HRB%208896",
        "citation": "https://www.northdata.com/Filen%20Cloud%20Dienste%20UG,%20Recklinghausen/HRB%208896"
      },
      "incorporationJurisdiction": {
        "value": "Germany (Amtsgericht Recklinghausen)",
        "citation": "https://filen.io/imprint"
      },
      "incorporationDate": {
        "value": "2021-06-29",
        "citation": "https://www.northdata.de/?id=6613973733"
      },
      "registeredAddress": {
        "value": "Breite Straße 27, 45657 Recklinghausen, Germany",
        "citation": "https://filen.io/imprint"
      },
      "officers": {
        "value": [
          {
            "name": "Jan Lenczyk",
            "role": "Geschäftsführer (Managing Director)"
          }
        ],
        "citation": "https://filen.io/imprint"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://filen.io/pricing",
            "https://filen.io/privacy",
            "https://github.com/FilenCloudDienste",
            "https://filen.io"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://filen.io/pricing",
            "https://filen.io/privacy",
            "https://github.com/FilenCloudDienste",
            "https://filen.io"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://filen.io/pricing",
            "https://filen.io/privacy",
            "https://github.com/FilenCloudDienste",
            "https://filen.io"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 408,
    "slug": "proton-drive",
    "domain": "proton.me",
    "name": "Proton Drive",
    "type": "Cloud Storage",
    "cat": "cloud",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Free plan includes 5 GB; paid plans are available.",
    "limits": {
      "daily": null
    },
    "features": [
      "End-to-end encrypted",
      "Zero-access encryption",
      "Password-protected sharing",
      "Private Docs and Sheets",
      "Automatic photo backup",
      "Anonymous account option",
      "Swiss jurisdiction",
      "BTC payment",
      "Integrated Proton suite",
      "Open source"
    ],
    "networks": [],
    "badge": "SWISS",
    "url": "https://proton.me/drive",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Cloud Storage"
    ],
    "description": "Swiss end-to-end encrypted cloud storage encrypting file contents, filenames and folder names before upload.",
    "cardSummary": "Swiss end-to-end encrypted cloud storage.",
    "jurisdiction": "CH",
    "auditedBy": [
      "Securitum"
    ],
    "telegram": "https://t.me/proton_privacy",
    "founderIntel": "Andy Yen (CEO). Corporate Entity: Proton AG, based in Geneva, Switzerland. Backing: The parent company is majority-owned by the non-profit Proton Foundation. Minority equity is held by employees and American venture capital firm Charles River Ventures (CRV).",
    "vcIntel": "Part of Proton AG ecosystem. Same funding as Proton Mail: Fidelity (US), CRV (US). Swiss jurisdiction but US institutional money.",
    "kycNote": "No Drive-specific identity KYC found. Use requires a Proton account, so account, abuse-prevention and billing metadata from the wider Proton service still apply.",
    "updatedAt": "2026-08-25",
    "stateActorFlag": "Proton AG (Swiss). Same compliance history as Proton Mail - court-ordered IP logging in 2021.",
    "privacyWarning": "Same Proton AG compliance surface as Proton Mail. Drive encrypts file contents and names client-side, but account, billing, sharing and legal-request metadata remain outside file encryption.",
    "followTheMoney": "  Proton AG - Geneva, Switzerland (CH)\n  ──────────────────────────────────────\n  Part of Proton One bundle\n  Investors: CRV (US), Fidelity (US)\n  Revenue: Proton One subscription\n  ├─ Same entity as Proton Mail\n  ├─ 2021 court-order logging history\n  └─ Client-side E2E encryption",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "https://proton.me/drive",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://proton.me/legal/terms",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Proton AG",
        "citation": "https://proton.me/legal/terms"
      },
      "registrationNumber": {
        "value": "CHE-354.686.492",
        "citation": "https://proton.me/legal/dpa"
      },
      "registryUrl": {
        "value": "https://www.zefix.ch/",
        "citation": "https://www.moneyhouse.ch/en/company/proton-ag-4537282131"
      },
      "incorporationJurisdiction": {
        "value": "Switzerland",
        "citation": "https://proton.me/legal/terms"
      },
      "incorporationDate": {
        "value": "18 July 2014",
        "citation": "https://www.moneyhouse.ch/en/company/proton-ag-4537282131"
      },
      "registeredAddress": {
        "value": "Route de la Galaise 32, 1228 Plan-les-Ouates, Geneva, Switzerland",
        "citation": "https://proton.me/legal/terms"
      },
      "ultimateOwner": {
        "value": "Proton Foundation",
        "citation": "https://proton.me/about"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [
          "Proton Technologies AG"
        ],
        "citation": "https://www.northdata.com/Proton%20AG,%20Plan-les-Ouates/CHE-354.686.492"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://proton.me/drive",
            "https://proton.me/drive/security"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://proton.me/drive",
            "https://proton.me/drive/security"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://proton.me/drive",
            "https://proton.me/drive/security"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 409,
    "slug": "mullvad-dns",
    "domain": "mullvad.net",
    "name": "Mullvad DNS",
    "type": "DNS",
    "cat": "dns",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Free",
    "limits": {
      "daily": null
    },
    "features": [
      "DNS over HTTPS",
      "DNS over TLS",
      "No logging",
      "Ad blocking",
      "Tracker blocking",
      "Malware blocking",
      "Swedish jurisdiction"
    ],
    "networks": [],
    "badge": "NO-LOG",
    "url": "https://mullvad.net/en/help/dns-over-https-and-dns-over-tls/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-24",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "DNS"
    ],
    "description": "Free public encrypted DNS with DoH and DoT endpoints plus optional ad, tracker and malware blocking.",
    "cardSummary": "Free encrypted DNS with optional blocking.",
    "jurisdiction": "SE",
    "auditedBy": [
      "Cure53"
    ],
    "twitter": "https://x.com/mullvadnet",
    "founderIntel": "Daniel Berntsson, Fredrik Strömberg. Corporate Entity: Mullvad VPN AB / Amagicom AB, based in Gothenburg, Sweden. Backing: **100% Founder-Owned**. The founders explicitly ban outside venture capital or IPOs via corporate directive to protect user data from shareholder profit motives.",
    "vcIntel": "Part of Mullvad VPN (Amagicom AB). 100% bootstrapped. Zero VC. Same gold-standard independence as Mullvad VPN.",
    "kycNote": "No account, payment or identity verification required for public Mullvad DNS endpoints.",
    "updatedAt": "2026-06-22",
    "stateActorFlag": null,
    "privacyWarning": "Encrypted DNS protects queries in transit but does not make the resolver blind to live requests. Mullvad states it logs no DNS requests or IP addresses. Anycast routing can send queries to a distant server, causing slowness or timeouts, and DNS blocking cannot block all ads or trackers.",
    "followTheMoney": "  Mullvad VPN AB (Amagicom) - Sweden\n  ──────────────────────────────────────\n  Owners: Fredrik Strömberg + Berntsson\n  Funding: 100% bootstrapped, zero VC\n  Revenue: Mullvad VPN subscriptions\n  ├─ Free DNS add-on to VPN\n  ├─ SE jurisdiction, Cure53 audited\n  └─ DoH/DoT, no logs, ad-blocking",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_7_2026-06-22",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://mullvad.net/en/help/privacy-policy",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Mullvad VPN AB",
        "citation": "https://mullvad.net/en/help/privacy-policy"
      },
      "registrationNumber": {
        "value": "559238-4001",
        "citation": "https://mullvad.net/en/help/privacy-policy"
      },
      "incorporationJurisdiction": {
        "value": "Sweden",
        "citation": "https://mullvad.net/en/help/privacy-policy"
      },
      "registeredAddress": {
        "value": "Box 53049, 400 14 Gothenburg, Sweden",
        "citation": "https://mullvad.net/en/help/privacy-policy"
      },
      "parentEntity": {
        "value": "Amagicom AB",
        "citation": "https://mullvad.net/en/help/faq"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://mullvad.net/en/help/dns-over-https-and-dns-over-tls",
            "https://mullvad.net/en/help/no-logging-data-policy",
            "https://mullvad.net/en/help/privacy-policy",
            "https://mullvad.net/en/help/faq",
            "https://mullvad.net/en/help/how-report-bug-or-vulnerability",
            "https://github.com/mullvad/encrypted-dns-profiles",
            "https://github.com/mullvad/dns-blocklists/commit/e47bce2ed1db7ae59b5fd36e840d196f625d86ab",
            "https://mullvad.net/en/help/dns-over-https-and-dns-over-tls/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://mullvad.net/en/help/dns-over-https-and-dns-over-tls",
            "https://mullvad.net/en/help/no-logging-data-policy",
            "https://mullvad.net/en/help/privacy-policy",
            "https://mullvad.net/en/help/faq",
            "https://mullvad.net/en/help/how-report-bug-or-vulnerability",
            "https://github.com/mullvad/encrypted-dns-profiles",
            "https://github.com/mullvad/dns-blocklists/commit/e47bce2ed1db7ae59b5fd36e840d196f625d86ab",
            "https://mullvad.net/en/help/dns-over-https-and-dns-over-tls/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://mullvad.net/en/help/dns-over-https-and-dns-over-tls",
            "https://mullvad.net/en/help/no-logging-data-policy",
            "https://mullvad.net/en/help/privacy-policy",
            "https://mullvad.net/en/help/faq",
            "https://mullvad.net/en/help/how-report-bug-or-vulnerability",
            "https://github.com/mullvad/encrypted-dns-profiles",
            "https://github.com/mullvad/dns-blocklists/commit/e47bce2ed1db7ae59b5fd36e840d196f625d86ab",
            "https://mullvad.net/en/help/dns-over-https-and-dns-over-tls/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 410,
    "slug": "quad9",
    "domain": "quad9.net",
    "name": "Quad9",
    "type": "DNS",
    "cat": "dns",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Free",
    "limits": {
      "daily": null
    },
    "features": [
      "DNS over HTTPS",
      "DNS over TLS",
      "Malware blocking",
      "No IP logging",
      "Swiss nonprofit",
      "DNSSEC validation",
      "No account required"
    ],
    "networks": [],
    "badge": "NONPROFIT",
    "url": "https://quad9.net",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "DNS"
    ],
    "description": "Free recursive DNS from a Swiss foundation with malware blocking, DNSSEC and DoH, DoT and DoQ options.",
    "cardSummary": "Swiss public DNS with malware blocking.",
    "jurisdiction": "CH",
    "auditedBy": null,
    "founderIntel": "Bill Woodcock IV (President/Chair): Secretary General of PCH, invented anycast routing 1989, pure Internet infrastructure career, no intelligence background. Philip Reitinger (GCA board/co-founder): deep US government cyber career (DHS, DoD, DOJ) - now GCA CEO. John Todd (GM): PCH technical operations, no flags. Swiss foundation structure provides legal buffer.",
    "vcIntel": "Non-profit foundation - no VC investors. Funded by PCH (Packet Clearing House), Global Cyber Alliance (GCA), and IBM partnership. IBM donated the 9.9.9.9 IP address and provides X-Force threat intelligence. Swiss-incorporated foundation (Zürich) but US government-adjacent governance via GCA.",
    "kycNote": "No account or identity verification. Quad9 transparency materials state there is no user database and no account-to-query correlation.",
    "privacyWarning": "Resolver operator still sits in the DNS path. Threat blocking depends on vetted third-party intelligence providers, and the existing IBM/GCA governance caveat remains relevant for adversarial threat models.",
    "stateActorFlag": "GCA co-founder and Quad9 board member Philip Reitinger is a career US government cybersecurity insider: former DHS Deputy Undersecretary (National Cyber Security Center director 2009), first Executive Director DoD Cyber Crime Center, DOJ Computer Crime section prosecutor, Microsoft Chief Trustworthy Infrastructure Strategist, Sony CISO. IBM (threat intelligence provider) is a major US national security contractor - IBM X-Force data determines Quad9 domain blocking decisions.",
    "updatedAt": "2026-06-22",
    "followTheMoney": "  Quad9 Foundation - Zürich, Switzerland\n  ──────────────────────────────────────\n  Board: PCH + Global Cyber Alliance\n  Funder: IBM (donated 9.9.9.9 IP)\n  Revenue: donations + IBM partnership\n  ├─ GCA co-founder: ex-DHS cybersec\n  ├─ IBM X-Force controls blocklist\n  └─ Swiss nonprofit, no query logs",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "primary_source_rereview_2026-08-25",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://quad9.net/privacy/policy/",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Quad9 Foundation (Quad9 Stiftung / Swiss foundation Quad9)",
        "citation": "https://quad9.net/privacy/policy/"
      },
      "registrationNumber": {
        "value": "CHE-435.091.407",
        "citation": "https://zh.chregister.ch/cr-portal/auszug/auszug.xhtml?uid=CHE-435.091.407"
      },
      "registryUrl": {
        "value": "https://zh.chregister.ch/cr-portal/auszug/auszug.xhtml?uid=CHE-435.091.407",
        "citation": "https://quad9.net/privacy/policy/"
      },
      "incorporationJurisdiction": {
        "value": "Switzerland (Canton of Zurich)",
        "citation": "https://zh.chregister.ch/cr-portal/auszug/auszug.xhtml?uid=CHE-435.091.407"
      },
      "registeredAddress": {
        "value": "c/o SWITCH, Werdstrasse 2, 8004 Zürich, Switzerland",
        "citation": "https://quad9.net/privacy/policy/"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://uptime.quad9.net/",
            "https://uptime.quad9.net/incidents",
            "https://quad9.net/privacy/policy/",
            "https://quad9.net/about/transparency-report/",
            "https://quad9.net"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://uptime.quad9.net/",
            "https://uptime.quad9.net/incidents",
            "https://quad9.net/privacy/policy/",
            "https://quad9.net/about/transparency-report/",
            "https://quad9.net"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://uptime.quad9.net/",
            "https://uptime.quad9.net/incidents",
            "https://quad9.net/privacy/policy/",
            "https://quad9.net/about/transparency-report/",
            "https://quad9.net"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 411,
    "slug": "nextdns",
    "domain": "nextdns.io",
    "name": "NextDNS",
    "type": "DNS",
    "cat": "dns",
    "kyc": "light",
    "kycLevel": 1,
    "fees": {
      "transaction": 0
    },
    "fee": "Free 300k queries/mo / $1.99/mo",
    "limits": {
      "daily": null
    },
    "features": [
      "Fully configurable",
      "DNS over HTTPS",
      "DNS over TLS",
      "QUIC support",
      "Ad + tracker blocking",
      "Per-device profiles",
      "Crypto payment"
    ],
    "networks": [],
    "badge": "CONFIGURABLE",
    "url": "https://nextdns.io",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-27",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "DNS"
    ],
    "description": "Configurable DNS firewall with blocklists, per-device profiles and logging retention that can be disabled.",
    "cardSummary": "Configurable private DNS firewall.",
    "jurisdiction": "US",
    "auditedBy": [],
    "twitter": "https://x.com/nextdns",
    "privacyWarning": "US-incorporated DNS resolver. Logs and analytics are configurable from no-logs to long retention; disable logging for privacy-sensitive use.",
    "founderIntel": null,
    "vcIntel": null,
    "kycNote": "No document KYC found. No signup is required to try the resolver, but paid/custom profiles create account, payment and optional DNS-log metadata controlled by the user.",
    "updatedAt": "2026-08-27",
    "stateActorFlag": "US-incorporated (Five Eyes). Logs policies depend on configuration. Cloud DNS has privacy tradeoffs vs. self-hosted.",
    "followTheMoney": "  NextDNS Inc - Delaware, USA (US)\n  ──────────────────────────────────────\n  Founders: Cointepas + Poitrey (French)\n  Funding: bootstrapped, profitable\n  Revenue: $1.99/mo unlimited tier\n  ├─ US-incorporated: NSL/FISA exposure\n  ├─ French founders, 3-person team\n  └─ Configurable per-device blocklists",
    "lastReviewed": "2026-08-27",
    "kycLastChecked": "2026-08-27",
    "reviewSource": "Primary-source review 2026-08-27",
    "jurisdictionConfidence": "inferred",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://nextdns.io/privacy",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "NextDNS Inc.",
        "citation": "https://nextdns.io/privacy"
      },
      "incorporationJurisdiction": {
        "value": "Delaware, United States",
        "citation": "https://help.nextdns.io/t/y4hmv0n/who-is-behind-nextdns"
      },
      "incorporationDate": {
        "value": "May 2019",
        "citation": "https://help.nextdns.io/t/y4hmv0n/who-is-behind-nextdns"
      },
      "registeredAddress": {
        "value": "2810 N Church St PMB 73778, Wilmington DE 19802-4447, United States",
        "citation": "https://nextdns.io/privacy (via forum confirmation of address); https://help.nextdns.io/t/83hjpa4/is-nextdns-trustworthy-where-is-your-legal-contact"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "limited",
      "controlModel": "hosted-account",
      "sourceModel": "closed"
    },
    "changedAt": "2026-08-27",
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "limited",
          "sourceUrls": [
            "https://nextdns.io/privacy"
          ],
          "reviewedAt": "2026-08-27",
          "note": "DNS request data is discarded by default and logging is user-controlled; account/configuration/payment and optional logs still create limited exposure."
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://nextdns.io/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "NextDNS operates hosted resolvers and user account/configuration controls."
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://nextdns.io/",
            "https://nextdns.io/privacy"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No official score-critical resolver/control-plane repository or reproducible-build evidence was located."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced in the reopened first-party source family."
      }
    }
  },
  {
    "id": 412,
    "slug": "veilcards",
    "domain": "veil.cards",
    "name": "VeilCards",
    "type": "Virtual Cards",
    "cat": "cards",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "One-time load fee",
    "limits": {
      "daily": null
    },
    "features": [
      "No identity verification",
      "Crypto-funded",
      "Online purchases",
      "Instant issuance",
      "Single-use option",
      "BTC, ETH, stables",
      "No account required"
    ],
    "networks": [],
    "badge": "NO-KYC",
    "url": "https://veil.cards",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "down",
    "checkedAt": "2026-08-26",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Virtual/Physical Card"
    ],
    "description": "Prepaid virtual card service claiming no identity verification, with opaque ownership and issuer details.",
    "cardSummary": "Prepaid virtual cards, operator undisclosed.",
    "jurisdiction": "US",
    "auditedBy": [],
    "founderIntel": "No public-facing team whatsoever. Complete unknown. Zero accountability trail. Hostinger-registered domain, privacy-protected owner.",
    "vcIntel": "No investors disclosed. No funding found. Zero business registration data in public sources.",
    "kycNote": "Official homepage claims anonymous prepaid/virtual cards with no KYC and no identity verification; ownership and issuer details remain opaque.",
    "privacyWarning": "Service and legal/privacy pages are inaccessible. RDAP shows clientHold, auto-renew period and ns1/ns2.dns-expired.com; DNS A and NS queries returned NXDOMAIN. Do not use or advance KYC/fee/corporate claims until an official restoration is verified.",
    "updatedAt": "2026-06-22",
    "stateActorFlag": null,
    "followTheMoney": "VeilCards - jurisdiction unknown\nFounders: not publicly named\nRevenue: card load fees, amount not published\nFunding: no investors identified\nCompany information: not found at review\nDomain age at review: about five months",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_2_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "partial",
    "riskLevel": "danger",
    "corporate": {
      "entityType": {
        "value": "unresolved",
        "citation": "unknown",
        "note": "Pass 1 researched this service but established no registry facts."
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-26",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://veil.cards"
          ],
          "reviewedAt": "2026-08-26",
          "note": "operator source unavailable"
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://veil.cards"
          ],
          "reviewedAt": "2026-08-26",
          "note": "operator source unavailable"
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://veil.cards"
          ],
          "reviewedAt": "2026-08-26",
          "note": "operator source unavailable"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "no-score-points-no-cap-exception"
      }
    }
  },
  {
    "id": 413,
    "slug": "laso-finance",
    "domain": "laso.finance",
    "name": "Laso Finance",
    "type": "Virtual Cards",
    "cat": "cards",
    "kyc": "light",
    "kycLevel": 2,
    "fees": {
      "transaction": 0
    },
    "fee": "Small load fee",
    "limits": {
      "daily": null
    },
    "features": [
      "Stablecoin voucher system",
      "Option-level KYC",
      "USDT, USDC, DAI",
      "Instant virtual card",
      "Online purchases",
      "x402 agent API",
      "Disposable cards"
    ],
    "networks": [],
    "badge": "STABLECOIN",
    "url": "https://laso.finance",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-24",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Virtual/Physical Card",
      "Agent Money"
    ],
    "description": "Stablecoin-funded virtual cards issued through a voucher system, loaded with USDT, USDC or DAI.",
    "cardSummary": "Stablecoin-funded virtual cards via vouchers.",
    "jurisdiction": "US",
    "auditedBy": [],
    "twitter": "https://x.com/lasofinance",
    "telegram": "https://t.me/+psqbakiynkvkm2ux",
    "founderIntel": "Anonymous founders. No named team members anywhere in public records. Founded 2022 (some sources: 2024). Registered agent address in Austin TX. FinCEN registration implies some identity disclosure to US authorities.",
    "vcIntel": "No VC funding. Unfunded anonymous startup. Supports USDC/USDT/DAI across Ethereum/Solana/Stellar/Arbitrum/Base/Polygon.",
    "kycNote": "KYC is option-specific. Laso documents most x402 endpoints as available without verification, Venmo/PayPal payouts as KYC-gated, and bank profiles as requiring in-person owner verification.",
    "stateActorFlag": "US jurisdiction (Five Eyes). Laso Finance LLC, 5900 Balcones Drive Suite 100, Austin TX 78731 (registered-agent address). FinCEN Money Services Business registration #31000249413002 - US Treasury has operator identity even though public does not.",
    "privacyWarning": "Anonymous founders - no public team identified. US-incorporated MSB (Texas). FinCEN-registered means US Treasury has identity of operators. Five Eyes jurisdiction applies. Cannot be independently vetted despite FinCEN compliance signal.",
    "updatedAt": "2026-08-09",
    "followTheMoney": "  Laso Finance LLC - Austin, Texas (US)\n  ──────────────────────────────────────\n  Founders: anonymous (FinCEN has ID)\n  Funding: unfunded, anonymous startup\n  Revenue: small stablecoin load fee\n  ├─ Five Eyes (US) - FinCEN #3100024\n  ├─ Treasury has operator identity\n  └─ Unvetted: use small amounts only",
    "lastReviewed": "2026-08-09",
    "kycLastChecked": "2026-08-09",
    "reviewSource": "laso_agent_docs_option_review_2026-08-09",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "agentMoney": {
      "compatible": true,
      "controlSurfaces": [
        "api",
        "dashboard"
      ],
      "protocols": [
        "x402",
        "virtual-card",
        "gift-card",
        "merchant-api"
      ],
      "authorizationModel": [
        "api-key",
        "wallet-grant",
        "human-approval"
      ],
      "settlementRail": [
        "card",
        "stablecoin",
        "bank",
        "gift-card",
        "internal-ledger"
      ],
      "autonomyLevel": 4,
      "custodyModel": "provider-custody",
      "mandateLoggingRisk": "high",
      "revocationQuality": "partial",
      "spendLimits": true,
      "merchantLock": false,
      "categoryLock": false,
      "pauseClose": true,
      "transactionWebhooks": true,
      "fundingSource": "stablecoin-funded",
      "identitySurface": "light-kyc",
      "dataPath": [
        "AI agent",
        "Laso bearer or wallet authentication",
        "Laso managed wallet or self-custody x402 payment",
        "option-specific issuer or payout rail",
        "merchant or recipient"
      ],
      "notes": "The identity and control posture changes by option: most x402 shopping endpoints are documented without verification, Venmo and PayPal require KYC, and bank payouts require an approved identity-bearing banking profile.",
      "protocolPrivacyNotes": "x402 constrains each quoted route payment but is not an account-wide budget. Provider custody, bearer access, option-specific recipient data, and downstream card or bank records remain separate privacy and safety surfaces.",
      "sourceLinks": [
        {
          "label": "Laso agent API documentation",
          "href": "https://agents.laso.finance/llms.txt",
          "scope": "docs"
        },
        {
          "label": "Laso agent introduction",
          "href": "https://agents.laso.finance/api-reference/introduction",
          "scope": "protocol"
        }
      ]
    },
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://laso.finance/",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Laso Finance LLC",
        "citation": "https://laso.finance/"
      },
      "registrationNumber": {
        "value": "31000328975254",
        "citation": "https://laso.finance/"
      },
      "incorporationJurisdiction": {
        "value": "United States (Texas)",
        "citation": "https://laso.finance/"
      },
      "registeredAddress": {
        "value": "5900 Balcones Drive Suite 100, Austin, TX 78731",
        "citation": "https://laso.finance/"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://laso.finance/about",
            "https://laso.finance"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://laso.finance/about",
            "https://laso.finance"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://laso.finance/about",
            "https://laso.finance"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1001,
    "slug": "hyperliquid",
    "domain": "hyperliquid.xyz",
    "name": "Hyperliquid",
    "type": "DEX (Perpetuals)",
    "cat": "swap",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0.045
    },
    "limits": {
      "daily": "No Limit"
    },
    "features": [
      "No account",
      "Perpetuals",
      "Instant",
      "Spot Trading"
    ],
    "networks": [
      "arbitrum"
    ],
    "badge": "NO ACCOUNT",
    "url": "https://app.hyperliquid.xyz",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": true,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Swap"
    ],
    "description": "Wallet-connected perpetuals and spot trading on Hyperliquid L1; interface terms exclude listed restricted persons, Singapore access is blocked, and MAS lists Hyperliquid on its Investor Alert List.",
    "cardSummary": "Wallet-only perpetuals and spot DEX.",
    "jurisdiction": "US",
    "auditedBy": [],
    "founderIntel": null,
    "vcIntel": null,
    "tagline": "Wallet-only perps/spot trading with strict front-end jurisdiction restrictions.",
    "kycNote": "No identity-document KYC in the normal wallet-connect flow, but this is not a generic privacy/no-KYC swap. Hyperliquid’s official interface is unavailable to US persons, Ontario, sanctioned/restricted territories, and citizens of restricted territories; its terms also prohibit VPN/proxy/location-concealment circumvention.",
    "bestFor": [
      "Non-restricted users who want wallet-only perpetuals or spot trading",
      "Users who understand that front-end access is geofenced and compliance-restricted"
    ],
    "privacyWarning": "Wallet-only/no-account does not mean anonymous: Hyperliquid Corp. collects IP/device/usage and wallet/transaction information, uses analytics/cookies, applies automated risk controls, restricts US persons, Ontario and sanctioned persons, blocks Singapore access, and prohibits VPN/proxy circumvention. MAS added Hyperliquid to its Investor Alert List on 2026-06-26.",
    "stateActorFlag": null,
    "affiliate": "",
    "updatedAt": "2026-08-25",
    "fee": "Base perps: 0.045% taker / 0.015% maker; base spot: 0.070% taker / 0.040% maker; tiers, staking discounts and rebates vary",
    "followTheMoney": "  Hyperliquid Corp / Hyperliquid Strategies Inc\n  ──────────────────────────────────────\n  CEO: Jeff Yan (Harvard, ex-HRT trader)\n  Funding: self-funded, zero VC claimed\n  Revenue: trading fees\n  ├─ Official interface excludes US/Ontario/restricted persons\n  ├─ Terms prohibit VPN/proxy circumvention\n  ├─ Wallet-only flow, no normal identity-document KYC\n  └─ US/company-facing compliance risk",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "primary_source_rereview_2026-08-25",
    "jurisdictionConfidence": "inferred",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://app.hyperliquid.xyz/terms",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Hyperliquid Corp.",
        "citation": "https://app.hyperliquid.xyz/terms"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "twitter": "https://x.com/HyperliquidX",
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://hyperliquid.xyz/",
            "https://hyperliquid.gitbook.io/hyperliquid-docs/trading/fees",
            "https://app.hyperliquid.xyz/terms",
            "https://app.hyperliquid.xyz/privacypolicy",
            "https://www.mas.gov.sg/api/v1/ialsearch?json.nl=map&wt=json&q=Hyperliquid&rows=10&start=0",
            "https://x.com/HyperliquidX/status/2070433243082731757",
            "https://app.hyperliquid.xyz"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://hyperliquid.xyz/",
            "https://hyperliquid.gitbook.io/hyperliquid-docs/trading/fees",
            "https://app.hyperliquid.xyz/terms",
            "https://app.hyperliquid.xyz/privacypolicy",
            "https://www.mas.gov.sg/api/v1/ialsearch?json.nl=map&wt=json&q=Hyperliquid&rows=10&start=0",
            "https://x.com/HyperliquidX/status/2070433243082731757",
            "https://app.hyperliquid.xyz"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://hyperliquid.xyz/",
            "https://hyperliquid.gitbook.io/hyperliquid-docs/trading/fees",
            "https://app.hyperliquid.xyz/terms",
            "https://app.hyperliquid.xyz/privacypolicy",
            "https://www.mas.gov.sg/api/v1/ialsearch?json.nl=map&wt=json&q=Hyperliquid&rows=10&start=0",
            "https://x.com/HyperliquidX/status/2070433243082731757",
            "https://app.hyperliquid.xyz"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1002,
    "slug": "nym-vpn",
    "domain": "nymvpn.com",
    "name": "Nym VPN",
    "type": "VPN",
    "cat": "vpn",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {},
    "limits": {},
    "features": [
      "Decentralized Mixnet",
      "Tor-like routing",
      "Open Source",
      "Zero-Knowledge Proofs"
    ],
    "networks": [],
    "badge": "MIXNET",
    "url": "https://nymvpn.com/",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-03-09",
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "VPN"
    ],
    "description": "Decentralized mixnet VPN. Scrambles traffic across up to 5 hops for metadata surveillance protection. Powered by NYM token.",
    "cardSummary": "Mixnet VPN routing traffic over up to 5 hops.",
    "jurisdiction": "CH",
    "auditedBy": null,
    "twitter": "https://x.com/nymproject",
    "telegram": "https://t.me/nymchan",
    "founderIntel": null,
    "privacyWarning": null,
    "vcIntel": null,
    "kycNote": "Advertises No-KYC, but strictly adhere to OPSEC rules. Access via Tor, pay with XMR.",
    "stateActorFlag": "Multiple Chinese-linked VCs on cap table: Binance Labs (Binance pled guilty US AML violations 2023, documented Chinese ties), Fenbushi Capital (Wanxiang Group/China), HashKey Capital (43.2% owned by Wanxiang Group chairman). Two co-founders (George Danezis + Dave Hrycyszyn) were briefly part of Facebook/Metas Libra/Diem team via Chainspace acquisition 2019.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-03-13",
    "fee": "From $4.49/mo",
    "followTheMoney": null,
    "lastReviewed": "2026-07-05",
    "kycLastChecked": "2026-03-09",
    "reviewSource": "official_url_failed_batch_2_2026-06-22",
    "jurisdictionConfidence": "inferred",
    "evidenceStatus": "partial",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://nym.com/vpn-privacy-statement",
        "note": "Official privacy statement and imprint identify NymVPN as operated by Nym Technologies SA, a registered Swiss limited company (SA/AG)."
      },
      "governanceModel": {
        "value": "company-sponsored",
        "citation": "https://nym.com/trust-center/signals-of-trustworthy-vpns"
      },
      "repositoryUrl": {
        "value": "https://github.com/nymtech/nym-vpn-client",
        "citation": "https://github.com/nymtech/nym-vpn-client"
      },
      "legalEntity": {
        "value": "NYM Technologies SA",
        "citation": "https://nym.com/imprint"
      },
      "registrationNumber": {
        "value": "CHE-367.426.629 (UID); CH-020.3.042.168-7 (CH-ID)",
        "citation": "https://nym.com/imprint"
      },
      "registryUrl": {
        "value": "https://hrc.ne.ch/hrcintapp/externalCompanyReport.action?companyOfrcId13=CH-020-3042168-7",
        "citation": "https://nym.com/trust-center/signals-of-trustworthy-vpns"
      },
      "incorporationJurisdiction": {
        "value": "Switzerland (Canton of Neuchâtel; previously Zürich)",
        "citation": "https://auditorstats.ch/firms/CHE-367.426.629"
      },
      "incorporationDate": {
        "value": "2015-07-02",
        "citation": "https://auditorstats.ch/firms/CHE-367.426.629"
      },
      "registeredAddress": {
        "value": "place Numa-Droz 2, 2000 Neuchâtel, Switzerland",
        "citation": "https://nym.com/imprint"
      },
      "parentEntity": {
        "value": "none",
        "citation": "https://nym.com/trust-center/signals-of-trustworthy-vpns"
      },
      "ultimateOwner": {
        "value": "Privately owned by co-founders Harry Halpin and Alexis Roussel (other co-founders minority stakeholders)",
        "citation": "https://nym.com/trust-center/signals-of-trustworthy-vpns"
      },
      "officers": {
        "value": [
          "Harry Reeves Halpin (Board of directors-President, single signature, since 2020-01-17)",
          "Alexis Thomas Roussel (Board of directors-Member, single signature, since 2020-01-17)"
        ],
        "citation": "https://www.moneyhouse.ch/en/company/nym-technologies-sa-4061718471/management"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://nym.com/",
            "https://nym.com/pricing",
            "https://nym.com/vpn-privacy-statement",
            "https://nymvpn.com/",
            "https://github.com/nymtech/nym-vpn-client",
            "https://nym.com/imprint"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://nym.com/",
            "https://nym.com/pricing",
            "https://nym.com/vpn-privacy-statement",
            "https://nymvpn.com/",
            "https://github.com/nymtech/nym-vpn-client",
            "https://nym.com/imprint"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://nym.com/",
            "https://nym.com/pricing",
            "https://nym.com/vpn-privacy-statement",
            "https://nymvpn.com/",
            "https://github.com/nymtech/nym-vpn-client",
            "https://nym.com/imprint"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1003,
    "slug": "railgun",
    "domain": "railgun.org",
    "name": "RAILGUN",
    "type": "Mixer / Privacy Protocol",
    "cat": "mixer",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {},
    "limits": {},
    "features": [
      "On-Chain Privacy",
      "zk-SNARKs",
      "Private DeFi",
      "Auditable"
    ],
    "networks": [
      "ethereum",
      "arbitrum",
      "polygon",
      "bsc"
    ],
    "badge": "DEFI",
    "url": "https://railgun.org/",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-27",
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Mixer"
    ],
    "description": "On-chain zero-knowledge privacy protocol for Ethereum and EVM chains with Private Proofs of Innocence.",
    "cardSummary": "Zero-knowledge privacy layer for EVM chains.",
    "jurisdiction": null,
    "auditedBy": [],
    "twitter": "https://x.com/RAILGUN_Project",
    "telegram": "https://t.me/railgun_project",
    "founderIntel": null,
    "vcIntel": null,
    "kycNote": "Protocol use has no account/KYC layer, but Private Proofs of Innocence and wallet/app integrations may screen high-risk sources.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-08-27",
    "fee": "0.25% per shield/unshield, plus gas or optional broadcaster premium",
    "stateActorFlag": null,
    "privacyWarning": "Regulatory and sanctions risk remains for mixer/privacy-protocol usage despite Proofs of Innocence; not a consumer cash-out route.",
    "followTheMoney": "  RAILGUN DAO - Decentralised (ETH)\n  ──────────────────────────────────────\n  Contributors: pseudonymous DAO\n  Funding: DAO treasury, community\n  Revenue: none (gas fees to network)\n  ├─ FBI alleged Lazarus Group use 2023\n  ├─ Founder cooperated with FBI\n  └─ No OFAC designation issued",
    "lastReviewed": "2026-08-27",
    "kycLastChecked": "2026-08-27",
    "reviewSource": "Primary-source review 2026-08-27",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "project-no-legal-entity",
        "citation": "https://docs.railgun.org/wiki",
        "note": "Official docs state RAILGUN is ownerless on-chain smart contract code with no owner, used via independent wallets, and governed by a token-holder DAO rather than a company or foundation operator."
      },
      "governanceModel": {
        "value": "dao",
        "citation": "https://docs.railgun.org/wiki/rail-token/protocol-governance"
      },
      "repositoryUrl": {
        "value": "https://github.com/Railgun-Community",
        "citation": "https://github.com/Railgun-Community"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "limited",
      "controlModel": "decentralized",
      "sourceModel": "open"
    },
    "changedAt": "2026-08-27",
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "limited",
          "sourceUrls": [
            "https://docs.railgun.org/wiki",
            "https://docs.railgun.org/wiki/learn/privacy-system/community-relayers"
          ],
          "reviewedAt": "2026-08-27",
          "note": "On-chain commitments are public and optional broadcasters can observe relay metadata, but no central account operator receives identity or plaintext transaction data."
        },
        "controlModel": {
          "value": "decentralized",
          "sourceUrls": [
            "https://docs.railgun.org/wiki/rail-token/protocol-governance",
            "https://docs.railgun.org/wiki"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Protocol upgrades require on-chain governance; ownerless contracts execute on supported chains."
        },
        "sourceModel": {
          "value": "open",
          "sourceUrls": [
            "https://github.com/Railgun-Community",
            "https://docs.railgun.org/wiki/rail-token/protocol-governance"
          ],
          "reviewedAt": "2026-08-27",
          "note": "The official community organization publishes protocol/contracts and governance material; no reproducible-build enhancement is claimed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced; no audit points are granted."
      }
    }
  },
  {
    "id": 1004,
    "slug": "feather-wallet",
    "domain": "featherwallet.org",
    "name": "Feather Wallet",
    "type": "Wallet",
    "cat": "wallet",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {},
    "limits": {},
    "features": [
      "XMR only",
      "Electrum-like",
      "Tor built-in",
      "Tails OS support",
      "Coin control"
    ],
    "networks": [],
    "badge": "XMR",
    "url": "https://featherwallet.org/",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-27",
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Wallet"
    ],
    "description": "A free, open-source Monero wallet for desktop. Connects via Tor by default, heavily optimized for privacy and power users.",
    "cardSummary": "Monero desktop wallet that connects over Tor.",
    "jurisdiction": null,
    "auditedBy": [],
    "twitter": null,
    "telegram": "https://t.me/featherwallet",
    "founderIntel": "Pseudonymous developers 'dsc' and 'tobtoht'. Corporate Entity: None. Backing: Open-source Monero community project funded entirely through CSS (Community Crowdfunding System) donations. No corporate entity.",
    "vcIntel": "Open source, donation funded. Monero ecosystem. Anonymous maintainer (tobtoht). Zero VC.",
    "kycNote": "Advertises No-KYC, but strictly adhere to OPSEC rules. Access via Tor, pay with XMR.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-08-27",
    "fee": "Free",
    "stateActorFlag": null,
    "privacyWarning": "Feather bundles Tor, but by default routes all network traffic over Tor except wallet synchronization. Synchronization contacts a node, while websocket features fetch fiat price, CCS and block-height data and the updater contacts featherwallet.org; users with stronger threat models should configure always-over-Tor or a local node.",
    "followTheMoney": "  Feather Wallet - Open-source (XMR)\n  ──────────────────────────────────────\n  Developers: tobtoht + community\n  Funding: donations + Monero community\n  Revenue: none (free software)\n  ├─ No company, no VC, no investors\n  ├─ GPL open-source, auditable code\n  └─ Built-in Tor: no IP exposed",
    "lastReviewed": "2026-08-27",
    "kycLastChecked": "2026-08-27",
    "reviewSource": "Primary-source review 2026-08-27",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "project-no-legal-entity",
        "citation": "https://docs.featherwallet.org/guides/about",
        "note": "Official docs state Feather Wallet was created by individuals dsc, tobtoht, and contributors as free open-source software funded solely via Monero CCS and donations, with no company or legal entity referenced on the site, GitHub, or license."
      },
      "governanceModel": {
        "value": "maintainer-group",
        "citation": "https://docs.featherwallet.org/guides/about"
      },
      "repositoryUrl": {
        "value": "https://github.com/feather-wallet/feather",
        "citation": "https://github.com/feather-wallet/feather"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "limited",
      "controlModel": "local-self-custody",
      "sourceModel": "open"
    },
    "changedAt": "2026-08-27",
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "limited",
          "sourceUrls": [
            "https://docs.featherwallet.org/guides/network-traffic",
            "https://docs.featherwallet.org/guides/tor-support"
          ],
          "reviewedAt": "2026-08-27",
          "note": "The local wallet does not require an operator account, but remote-node synchronization and optional direct-clearnet traffic expose limited network metadata."
        },
        "controlModel": {
          "value": "local-self-custody",
          "sourceUrls": [
            "https://docs.featherwallet.org/guides/about",
            "https://github.com/feather-wallet/feather"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Seeds and signing remain on the user device; the user controls the wallet and can connect a local node."
        },
        "sourceModel": {
          "value": "open",
          "sourceUrls": [
            "https://docs.featherwallet.org/guides/about",
            "https://github.com/feather-wallet/feather"
          ],
          "reviewedAt": "2026-08-27",
          "note": "The official documentation identifies the BSD-3 repository; no reproducible-build evidence was located."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced in the reopened first-party source family."
      }
    }
  },
  {
    "id": 74,
    "slug": "briar",
    "name": "Briar",
    "domain": "briarproject.org",
    "url": "https://briarproject.org/",
    "kyc": "none",
    "categories": [
      "Messaging",
      "Offline"
    ],
    "countries": [
      "GLOBAL"
    ],
    "jurisdiction": "GB",
    "description": "Free, open-source peer-to-peer messaging over Tor, Wi-Fi and Bluetooth without central messaging servers; the project is in maintenance mode.",
    "cardSummary": "P2P messaging over Tor, Wi-Fi and Bluetooth.",
    "networks": [
      "Tor",
      "Bluetooth",
      "Wi-Fi",
      "FOSS",
      "Android",
      "Desktop"
    ],
    "privacyWarning": "The project entered maintenance mode on 9 July 2026 and limits work to essential security updates and bug fixes. Official pages list grant funding from Small Media, OTF, Internews, NLnet, Prototype Fund and others; no reviewed primary source establishes donor operational control or a backdoor.",
    "ownership": "Briar Project (voluntary-board governance); website copyright Sublime Software Ltd",
    "founderIntel": null,
    "vcIntel": null,
    "kycNote": "No central app account or identity KYC is documented; the account exists only on the user's device. Optional feedback and crash reports can include stored email and device information, and mailing lists are operated by SourceForge.",
    "stateActorFlag": "Official Briar pages list funding from the Open Technology Fund and other public-interest funders. Funding is relevant to donor-sensitive threat models, but the reviewed primary sources do not establish US-government operational control, intelligence ties or a backdoor.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-08-25",
    "changedAt": "2026-08-25",
    "fee": "Free",
    "followTheMoney": "Briar is free and grant-funded. Its official pages list Small Media, the Open Technology Fund, Internews, NLnet, the Prototype Fund and other funders. The project says it is governed by a voluntary board; Sublime Software Ltd holds the website copyright and is an active UK private limited company controlled by Michael Rogers.",
    "kycLevel": 0,
    "status": "warning",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "primary_source_rereview_2026-08-25",
    "jurisdictionConfidence": "verified",
    "checkedAt": "2026-08-25",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://briarproject.org/copyright/",
        "note": "Briar describes voluntary-board project governance; Sublime Software Ltd holds the website copyright and Companies House lists it as an active UK private limited company."
      },
      "governanceModel": {
        "value": "maintainer-group",
        "citation": "https://briarproject.org/about/"
      },
      "repositoryUrl": {
        "value": "https://code.briarproject.org/briar/briar",
        "citation": "https://code.briarproject.org/briar/briar"
      },
      "legalEntity": {
        "value": "SUBLIME SOFTWARE LTD",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/07051922"
      },
      "registrationNumber": {
        "value": "07051922",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/07051922"
      },
      "registryUrl": {
        "value": "https://find-and-update.company-information.service.gov.uk/company/07051922",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/07051922"
      },
      "incorporationJurisdiction": {
        "value": "United Kingdom",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/07051922"
      },
      "incorporationDate": {
        "value": "2009-10-21",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/07051922"
      },
      "registeredAddress": {
        "value": "26 Carlyle Avenue, Brighton, England, BN2 4DR",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/07051922"
      },
      "ultimateOwner": {
        "value": "Michael Rogers (75% or more of shares)",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/07051922/persons-with-significant-control"
      },
      "officers": {
        "value": [
          "Michael Rogers (Director)"
        ],
        "citation": "https://find-and-update.company-information.service.gov.uk/company/07051922/officers"
      },
      "source": "Briar official governance/copyright pages and Companies House, accessed 2026-08-25",
      "reviewedAt": "2026-08-25"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://briarproject.org/",
            "https://briarproject.org/privacy-policy/",
            "https://briarproject.org/news/2026-maintenance-mode/",
            "https://briarproject.org/about/",
            "https://briarproject.org/copyright/",
            "https://find-and-update.company-information.service.gov.uk/company/07051922",
            "https://find-and-update.company-information.service.gov.uk/company/07051922/persons-with-significant-control",
            "https://code.briarproject.org/briar/briar/-/tags/release-1.5.19",
            "https://briarproject.org/download-briar-desktop/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://briarproject.org/",
            "https://briarproject.org/privacy-policy/",
            "https://briarproject.org/news/2026-maintenance-mode/",
            "https://briarproject.org/about/",
            "https://briarproject.org/copyright/",
            "https://find-and-update.company-information.service.gov.uk/company/07051922",
            "https://find-and-update.company-information.service.gov.uk/company/07051922/persons-with-significant-control",
            "https://code.briarproject.org/briar/briar/-/tags/release-1.5.19",
            "https://briarproject.org/download-briar-desktop/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://briarproject.org/",
            "https://briarproject.org/privacy-policy/",
            "https://briarproject.org/news/2026-maintenance-mode/",
            "https://briarproject.org/about/",
            "https://briarproject.org/copyright/",
            "https://find-and-update.company-information.service.gov.uk/company/07051922",
            "https://find-and-update.company-information.service.gov.uk/company/07051922/persons-with-significant-control",
            "https://code.briarproject.org/briar/briar/-/tags/release-1.5.19",
            "https://briarproject.org/download-briar-desktop/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 75,
    "slug": "meshtastic",
    "noOperatorData": true,
    "name": "Meshtastic",
    "domain": "meshtastic.org",
    "url": "https://meshtastic.org",
    "kyc": "none",
    "categories": [
      "Messaging",
      "Offline",
      "Hardware"
    ],
    "countries": [
      "GLOBAL"
    ],
    "jurisdiction": "US",
    "description": "Open-source LoRa mesh networking for off-grid encrypted text without cellular service or internet.",
    "cardSummary": "LoRa mesh texting without cell service.",
    "networks": [
      "Hardware",
      "LoRa",
      "FOSS"
    ],
    "privacyWarning": "LoRa traffic and node/location metadata can be observable. Channel AES-CTR uses a shared PSK without authentication, so anyone with the PSK can read traffic and impersonate a channel member. Direct messages on 2.5+ use x25519/AES-CCM when keys are known, but may fall back to less-secure channel encryption.",
    "ownership": "Community-driven open source",
    "founderIntel": "Global open-source community project. Corporate Entity: None. Backing: A decentralized mesh networking firmware driven entirely by volunteer hardware hackers and hobbyists. Zero corporate monetization or VC.",
    "vcIntel": "Open source hardware/software. Community funded. Zero VC. Decentralized mesh networking.",
    "kycNote": "No account or identity KYC to use the open-source mesh protocol; hardware purchases, donations, app stores or business programs can identify the buyer/user.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-08-27",
    "fee": "Free",
    "stateActorFlag": null,
    "followTheMoney": "  Meshtastic - Open Source / Community\n  ──────────────────────────────────────\n  Operators: global volunteer community\n  Funding: zero VC, donations only\n  Revenue: none (free firmware + app)\n  ├─ LoRa hardware mesh, no internet\n  ├─ No corporate entity, no investors\n  └─ Buy cheap LoRa device, flash it",
    "kycLevel": 0,
    "status": "ok",
    "lastReviewed": "2026-08-27",
    "kycLastChecked": "2026-08-27",
    "reviewSource": "Primary-source review 2026-08-27",
    "jurisdictionConfidence": "unknown",
    "checkedAt": "2026-08-27",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://meshtastic.org/docs/legal/licensing-and-trademark/",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Meshtastic LLC",
        "citation": "https://meshtastic.org/docs/legal/licensing-and-trademark/"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "none",
      "controlModel": "decentralized",
      "sourceModel": "open"
    },
    "auditedBy": [],
    "changedAt": "2026-08-27",
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "none",
          "sourceUrls": [
            "https://meshtastic.org/docs/about/overview/encryption/limitations/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "There is no central service operator or account; devices exchange mesh packets directly. Peer-visible metadata is a protocol risk, not operator collection."
        },
        "controlModel": {
          "value": "decentralized",
          "sourceUrls": [
            "https://meshtastic.org/docs/about/overview/encryption/limitations/",
            "https://github.com/meshtastic/firmware"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Independent radio nodes form an ad-hoc decentralized mesh with no central signing authority."
        },
        "sourceModel": {
          "value": "open",
          "sourceUrls": [
            "https://meshtastic.org/docs/legal/licensing-and-trademark/",
            "https://github.com/meshtastic/firmware"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Official firmware and software components are published under stated open licenses; reproducible-build evidence was not found."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced in the reopened first-party source family."
      }
    }
  },
  {
    "id": 77,
    "slug": "simplex-chat",
    "name": "SimpleX Chat",
    "domain": "simplex.chat",
    "url": "https://simplex.chat",
    "kyc": "none",
    "categories": [
      "Messaging"
    ],
    "countries": [
      "GLOBAL"
    ],
    "jurisdiction": "UK",
    "description": "Decentralized encrypted messenger with no user IDs, connecting through invitation links or QR codes.",
    "cardSummary": "Encrypted messenger with no user IDs.",
    "networks": [
      "FOSS",
      "Mobile",
      "Desktop",
      "Terminal"
    ],
    "privacyWarning": "UK company under Five Eyes jurisdiction; existing investor caveats remain. The core privacy advantage is protocol-level absence of global user identifiers, not immunity from endpoint/support metadata.",
    "ownership": "SimpleX Chat Ltd",
    "founderIntel": null,
    "vcIntel": null,
    "kycNote": "No phone number, username, global account or document KYC required for normal messaging. Contacting support by email exposes ordinary email metadata to mail providers.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-08-27",
    "fee": "Free",
    "stateActorFlag": "UK-based. Village Global (Bezos/Gates/Zuckerberg LPs) investor. UK jurisdiction subject to Investigatory Powers Act.",
    "followTheMoney": "  SimpleX Chat Ltd - UK (GB)\n  ──────────────────────────────────────\n  Founder: Evgeny Poberezkin\n  Funding: Sequoia Scout, community\n  Revenue: donations + future premium\n  ├─ No user IDs of any kind\n  ├─ UK jurisdiction (Five Eyes)\n  └─ Trail of Bits assessments:\n     ├─ Completed: implementation (Nov 2022)\n     ├─ Completed: protocol design (Jul 2024)\n     └─ Scheduled: implementation (Jun 2026); no published result",
    "kycLevel": 0,
    "status": "ok",
    "lastReviewed": "2026-08-27",
    "kycLastChecked": "2026-08-27",
    "reviewSource": "Primary-source review 2026-08-27",
    "jurisdictionConfidence": "verified",
    "checkedAt": "2026-08-27",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://simplex.chat/privacy/",
        "note": "Official privacy policy, about page, app store listings, and UK Companies House all identify SimpleX Chat Ltd as the operating company developing the software and operating preset servers."
      },
      "governanceModel": {
        "value": "company-sponsored",
        "citation": "https://simplex.chat/about/"
      },
      "repositoryUrl": {
        "value": "https://github.com/simplex-chat/simplex-chat",
        "citation": "https://github.com/simplex-chat/simplex-chat"
      },
      "legalEntity": {
        "value": "SIMPLEX CHAT LTD",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/13691484"
      },
      "registrationNumber": {
        "value": "13691484",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/13691484"
      },
      "registryUrl": {
        "value": "https://find-and-update.company-information.service.gov.uk/company/13691484",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/13691484"
      },
      "incorporationJurisdiction": {
        "value": "United Kingdom (England and Wales)",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/13691484"
      },
      "incorporationDate": {
        "value": "2021-10-20",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/13691484"
      },
      "registeredAddress": {
        "value": "20-22 Wenlock Road, London, England, N1 7GU",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/13691484"
      },
      "ultimateOwner": {
        "value": "Evgeny Poberezkin (PSC, ownership of shares 75% or more)",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/13691484/persons-with-significant-control"
      },
      "officers": {
        "value": [
          "Evgeny Poberezkin (Director, appointed 2021-10-20)",
          "Evgeny Poberezkin (Secretary, appointed 2021-10-20)"
        ],
        "citation": "https://find-and-update.company-information.service.gov.uk/company/13691484/officers"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "decentralized",
      "sourceModel": "open"
    },
    "auditedBy": [],
    "changedAt": "2026-08-27",
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://simplex.chat/privacy/",
            "https://simplex.chat/docs/server.html"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Relay operators can observe connection and queued-message metadata even though users have no global IDs and message content is encrypted."
        },
        "controlModel": {
          "value": "decentralized",
          "sourceUrls": [
            "https://simplex.chat/",
            "https://simplex.chat/docs/server.html"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Users choose or self-host SMP/XFTP relays; the network has no mandatory central account or single operator control plane."
        },
        "sourceModel": {
          "value": "open",
          "sourceUrls": [
            "https://github.com/simplex-chat/simplex-chat",
            "https://github.com/simplex-chat/simplex-chat/security"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Client, protocol and server components are published in the official repository; no reproducible-build enhancement is claimed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced; no audit points are granted."
      }
    }
  },
  {
    "id": 1005,
    "slug": "offline-protocol",
    "name": "Offline Protocol",
    "domain": "offlineprotocol.com",
    "url": "https://www.offlineprotocol.com/",
    "kyc": "light",
    "categories": [
      "Messaging",
      "Offline",
      "Payments",
      "Identity"
    ],
    "countries": [
      "GLOBAL"
    ],
    "jurisdiction": "US",
    "description": "Software and network layer for offline device-to-device communication, identity verification, service discovery, file transfer and opt-in telemetry across multiple transports.",
    "cardSummary": "Mesh stack for messaging, identity and payments.",
    "networks": [
      "Bluetooth LE",
      "Wi-Fi Direct",
      "Internet",
      "Reticulum",
      "Nostr"
    ],
    "privacyWarning": "Identity/reputation layer, token incentives and still-maturing SDK/protocol surfaces require trust in the provider and implementation.",
    "ownership": "Offline Protocol",
    "founderIntel": "Offline Protocol Team. Location: Global. Background: Building the Sovereign Stack. Raised $1.1M. Codebase is currently closed-source.",
    "vcIntel": "Open source project. Community/grant funded. Zero VC.",
    "kycNote": "No document-KYC policy found, but identity/reputation and account/data-request surfaces are core to the product; treat as light identity exposure rather than pure anonymous messaging.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-06-22",
    "fee": "AGPL community evaluation; commercial deployment priced by quote",
    "stateActorFlag": null,
    "followTheMoney": "  Offline Protocol - Unknown (Global)\n  ──────────────────────────────────────\n  Founders: unnamed team\n  Raised: $1.1M (March 2025)\n  Investors: undisclosed\n  ├─ Closed-source codebase currently\n  ├─ Binance wallet integration\n  └─ Unvetted: caution advised",
    "kycLevel": 1,
    "status": "ok",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_5_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "checkedAt": "2026-06-23",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://www.offlineprotocol.com/terms",
        "note": "Terms of use and App Store listings identify Offline Protocol, Inc. as a Delaware corporation operating the service; site has company/careers/shop pages."
      },
      "governanceModel": {
        "value": "company-sponsored",
        "citation": "https://www.offlineprotocol.com/company"
      },
      "repositoryUrl": {
        "value": "https://github.com/Offline-Protocol",
        "citation": "https://github.com/Offline-Protocol"
      },
      "legalEntity": {
        "value": "Offline Protocol, Inc.",
        "citation": "https://www.offlineprotocol.com/terms"
      },
      "registrationNumber": {
        "value": "7545189",
        "citation": "https://nyentitysearch.com/companies/ny_7545189_offline-protocol-inc"
      },
      "registryUrl": {
        "value": "https://nyentitysearch.com/companies/ny_7545189_offline-protocol-inc",
        "citation": "https://nyentitysearch.com/companies/ny_7545189_offline-protocol-inc"
      },
      "incorporationJurisdiction": {
        "value": "Delaware, United States",
        "citation": "https://www.offlineprotocol.com/terms"
      },
      "registeredAddress": {
        "value": "131 Continental Dr, Ste 305, Newark, Delaware 19713-4324, United States",
        "citation": "https://apps.apple.com/ee/app/fernweh-offline-messages/id6738829052"
      },
      "officers": {
        "value": [
          {
            "name": "Satvik Sethi",
            "role": "Founder & CEO"
          }
        ],
        "citation": "https://www.linkedin.com/in/satviksethi"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "limited",
      "controlModel": "local-self-custody",
      "sourceModel": "open"
    },
    "auditedBy": [],
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "limited",
          "sourceUrls": [
            "https://www.offlineprotocol.com/privacy",
            "https://www.offlineprotocol.com/docs/legal/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "The SDK is device-local and peer-to-peer, but current policies and the Fernweh app describe opt-in telemetry, support and service data."
        },
        "controlModel": {
          "value": "local-self-custody",
          "sourceUrls": [
            "https://www.offlineprotocol.com/",
            "https://github.com/Offline-Protocol/offline-protocol-sdk"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Identity keys and encrypted coordination data are held on participant devices; transports switch locally rather than through a required custodial account."
        },
        "sourceModel": {
          "value": "open",
          "sourceUrls": [
            "https://github.com/Offline-Protocol/offline-protocol-sdk",
            "https://www.offlineprotocol.com/security"
          ],
          "reviewedAt": "2026-08-27",
          "note": "The critical SDK, threat model, security policy and AGPL-3.0 license are published in the official repository."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced; no audit points are granted."
      }
    }
  },
  {
    "id": 1006,
    "slug": "cashu",
    "name": "Cashu",
    "domain": "cashu.space",
    "url": "https://cashu.space",
    "kyc": "none",
    "categories": [
      "Privacy Tools",
      "Wallet"
    ],
    "countries": [
      "GLOBAL"
    ],
    "jurisdiction": null,
    "description": "Chaumian e-cash protocol on Bitcoin Lightning where each mint is a custodian holding the backing funds.",
    "cardSummary": "Chaumian e-cash on Bitcoin Lightning.",
    "networks": [
      "Bitcoin",
      "Lightning Route",
      "FOSS"
    ],
    "privacyWarning": "Custodial risk: every Cashu mint is a single-sig custodian of your sats. If a mint rugs, is hacked, or disappears, ecash tokens become worthless. Only use trusted mints and keep amounts small. Proof-of-liabilities not yet standardized. Multi-mint splitting helps but adds UX complexity.",
    "ownership": "Open Source Community (Led by Calle)",
    "founderIntel": "Calle (pseudonymous lead developer). Open source community project. No company entity. OpenSats and HRF grant funded. Creator's own README warns 'I am NOT a cryptographer and this has not been reviewed' - unusual but honest disclosure. No state actor connections.",
    "vcIntel": "OpenSats (Bitcoin-only nonprofit, clean) + HRF grants. No VC, no institutional money. Creator explicitly warns this is experimental. The custody risk is architectural, not a VC red flag.",
    "tagline": "Private Lightning e-cash. The mint can't link sender to receiver. BETA - small amounts only.",
    "kycNote": "The Cashu protocol has no account or identity-verification layer. Individual custodial mint operators can set their own access, compliance, and fee policies.",
    "bestFor": [
      "Lightning privacy",
      "Offline Bitcoin payments",
      "Advanced users"
    ],
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-08-25",
    "fee": "Protocol and mint fees vary; Lightning routing and on-chain fees may also apply.",
    "stateActorFlag": null,
    "type": "Privacy Tools",
    "cat": "privacy",
    "kycLevel": 0,
    "fees": {
      "transaction": null
    },
    "limits": {
      "daily": null
    },
    "features": [
      "Chaumian e-cash",
      "Lightning-native",
      "Offline transactions",
      "QR code / Bluetooth transfer",
      "No account required",
      "Open source",
      "Blind signature privacy",
      "Multi-wallet support"
    ],
    "badge": "BETA",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "auditedBy": [],
    "twitter": "https://x.com/CashuBTC",
    "followTheMoney": "  Cashu - Open Source (Bitcoin/Lightning)\n  ──────────────────────────────────────\n  Lead: Calle (pseudonymous dev)\n  Funders: OpenSats + HRF (Bitcoin NGOs)\n  Revenue: none (bearer token protocol)\n  ├─ OpenSats: Bitcoin-only nonprofit\n  ├─ Custodial risk per mint - use small\n  └─ Creator warns: experimental beta",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "https://cashu.space/",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "project-no-legal-entity",
        "citation": "https://cashu.space/",
        "note": "Cashu is described across its official site, docs, GitHub org, and coverage as a free open-source Chaumian ecash protocol for Bitcoin with no operating company; anyone can run mints/wallets, and a separate Swiss nonprofit (OpenCash Association) only funds/supports development without owning it."
      },
      "governanceModel": {
        "value": "maintainer-group",
        "citation": "https://bitcoinmagazine.com/business/ecash-makes-bitcoin-and-fiat-private-with-calle-cashu"
      },
      "repositoryUrl": {
        "value": "https://github.com/cashubtc",
        "citation": "https://github.com/cashubtc"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://cashu.space/",
            "https://github.com/cashubtc/nuts/commits/main.atom",
            "https://cashu.space"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://cashu.space/",
            "https://github.com/cashubtc/nuts/commits/main.atom",
            "https://cashu.space"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://cashu.space/",
            "https://github.com/cashubtc/nuts/commits/main.atom",
            "https://cashu.space"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1007,
    "slug": "bitchat",
    "name": "Bitchat",
    "domain": "bitchat.free",
    "url": "https://bitchat.free",
    "kyc": "none",
    "categories": [
      "Messaging",
      "Offline",
      "Bitcoin"
    ],
    "countries": [
      "GLOBAL"
    ],
    "jurisdiction": "??",
    "description": "Peer-to-peer messaging over Bluetooth mesh and Nostr relays, with device-held identity keys, no account, and optional persistent local history.",
    "cardSummary": "Bluetooth mesh messaging with Nostr relays.",
    "networks": [
      "Bluetooth Mesh",
      "Nostr"
    ],
    "privacyWarning": "The published web privacy policy says delivered messages are not retained and data is not sent to remote servers, but current clients use Nostr relays and Android 2.0.1 persists private conversation history locally. Bluetooth exposes proximity/relay patterns, Nostr relays can observe connection metadata, and a persistent device identifier is derived from the identity key.",
    "ownership": "Jack Dorsey (Open Source)",
    "founderIntel": "Jack Dorsey (Creator). Location: US. Background: Co-founder of Twitter and Block (formerly Square).",
    "vcIntel": "Open source. Community funded. Zero corporate structure.",
    "kycNote": "No account or identity KYC surface found on the official site; distribution through app stores/GitHub can still expose platform metadata.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-08-25",
    "fee": "Free",
    "stateActorFlag": null,
    "followTheMoney": "Jack Dorsey (creator) - United States\nCreator: Jack Dorsey\nLicense: MIT\nFunding: not recorded\nRevenue: not recorded\nTransport: Bluetooth mesh and Nostr",
    "kycLevel": 0,
    "status": "ok",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "primary_source_rereview_2026-08-25",
    "jurisdictionConfidence": "unknown",
    "checkedAt": "2026-08-25",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "features": [
      "Open source",
      "Bluetooth mesh",
      "Nostr transport",
      "No account",
      "No phone number",
      "Private messages",
      "Emergency wipe",
      "Wear OS",
      "Live push-to-talk",
      "Persistent local conversations",
      "Cashu token preview/redemption"
    ],
    "noOperatorData": true,
    "tagline": "Account-free Bluetooth and Nostr messaging.",
    "bestFor": [
      "Nearby offline messaging",
      "Phone-number-free messaging",
      "Open-source mesh testing"
    ],
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://apps.apple.com/us/app/bitchat-mesh/id6748219622",
        "note": "The iOS app is published and sold by 'permissionless tech, llc' as listed on the Apple App Store developer/seller field; a matching Delaware LLC exists and the open-source project is hosted under the permissionlesstech GitHub org."
      },
      "governanceModel": {
        "value": "company-sponsored",
        "citation": "https://apps.apple.com/us/app/bitchat-mesh/id6748219622"
      },
      "repositoryUrl": {
        "value": "https://github.com/permissionlesstech/bitchat",
        "citation": "https://github.com/permissionlesstech/bitchat"
      },
      "legalEntity": {
        "value": "Permissionless Tech LLC",
        "citation": "https://apps.apple.com/us/app/bitchat-mesh/id6748219622"
      },
      "registrationNumber": {
        "value": "10337715",
        "citation": "https://www.bizapedia.com/de/permissionless-tech-llc.html"
      },
      "registryUrl": {
        "value": "https://icis.corp.delaware.gov/ecorp/entitysearch/namesearch.aspx",
        "citation": "https://www.bizapedia.com/de/permissionless-tech-llc.html"
      },
      "incorporationJurisdiction": {
        "value": "Delaware, United States",
        "citation": "https://www.bizapedia.com/de/permissionless-tech-llc.html"
      },
      "incorporationDate": {
        "value": "2025-09-22",
        "citation": "https://www.bizapedia.com/de/permissionless-tech-llc.html"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "twitter": "https://x.com/BitchatMe_",
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://bitchat.free/privacy",
            "https://github.com/permissionlesstech/bitchat/releases/tag/v1.7.1",
            "https://github.com/permissionlesstech/bitchat-android/releases/tag/v2.0.1",
            "https://x.com/BitchatMe_/status/2088540574949237214",
            "https://bitchat.free"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://bitchat.free/privacy",
            "https://github.com/permissionlesstech/bitchat/releases/tag/v1.7.1",
            "https://github.com/permissionlesstech/bitchat-android/releases/tag/v2.0.1",
            "https://x.com/BitchatMe_/status/2088540574949237214",
            "https://bitchat.free"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://bitchat.free/privacy",
            "https://github.com/permissionlesstech/bitchat/releases/tag/v1.7.1",
            "https://github.com/permissionlesstech/bitchat-android/releases/tag/v2.0.1",
            "https://x.com/BitchatMe_/status/2088540574949237214",
            "https://bitchat.free"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1008,
    "slug": "unified-attestation",
    "name": "Unified Attestation",
    "domain": "uattest.net",
    "url": "https://uattest.net/",
    "kyc": "none",
    "categories": [
      "Developer Tools",
      "Privacy OS",
      "Frameworks"
    ],
    "countries": [
      "GLOBAL"
    ],
    "jurisdiction": "DE",
    "description": "Open-source Play Integrity alternative issuing short-lived Android tokens verifiable offline without device IDs.",
    "cardSummary": "Open-source Android integrity tokens.",
    "networks": [
      "FOSS",
      "Android API"
    ],
    "privacyWarning": "Attestation infrastructure can become an app-access gate even when it avoids Google Play Integrity. Privacy depends on relying apps and server deployment, not only the framework.",
    "founderIntel": "Volla Systeme GmbH. Location: Remscheid, Germany. Founded by Dr. Jörg Wurzer, focusing on de-googled smartphone development.",
    "ownership": "Volla Systeme GmbH",
    "vcIntel": "German-registered. Open source framework. No major VC.",
    "kycNote": "No user account, payment rail or identity KYC found; this is an open-source Android attestation framework/API rather than a consumer account service.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-06-22",
    "fee": "Free",
    "stateActorFlag": null,
    "followTheMoney": "  Volla Systeme GmbH - Remscheid (DE)\n  ──────────────────────────────────────\n  Founder: Dr. Jörg Wurzer (German)\n  Funding: bootstrapped, no VC\n  Revenue: de-googled phone hardware\n  ├─ DE/GDPR: German jurisdiction\n  ├─ Free attestation API for FOSS devs\n  └─ Open-source alternative to Play",
    "kycLevel": 0,
    "status": "ok",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_7_2026-06-22",
    "jurisdictionConfidence": "verified",
    "checkedAt": "2026-06-24",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://uattest.net/",
        "note": "Website states Unified Attestation is an initiative by Volla Systeme GmbH and routes Legal/Imprint/Privacy to that company's pages."
      },
      "governanceModel": {
        "value": "company-sponsored",
        "citation": "https://raw.githubusercontent.com/unifiedAttestation/Website/main/index.html"
      },
      "repositoryUrl": {
        "value": "https://github.com/unifiedAttestation",
        "citation": "https://github.com/unifiedAttestation"
      },
      "legalEntity": {
        "value": "Volla Systeme GmbH",
        "citation": "https://volla.online/en/imprint/index.html"
      },
      "registrationNumber": {
        "value": "HRB 28033",
        "citation": "https://volla.online/en/imprint/index.html"
      },
      "registryUrl": {
        "value": "https://www.northdata.com/Volla%20Systeme%20GmbH,%20Remscheid/Amtsgericht%20Wuppertal%20HRB%2028033",
        "citation": "https://www.northdata.com/Volla%20Systeme%20GmbH,%20Remscheid/Amtsgericht%20Wuppertal%20HRB%2028033"
      },
      "incorporationJurisdiction": {
        "value": "Germany (Amtsgericht Wuppertal)",
        "citation": "https://volla.online/en/imprint/index.html"
      },
      "incorporationDate": {
        "value": "2017-01-30",
        "citation": "https://handelsregister.ai/de/organizations/remscheid/entwicklung-und-programmierung-von-anwendungssoftware/volla-systeme-gmbh-638a1bec64852dc76ad72e5509bdfce6"
      },
      "registeredAddress": {
        "value": "Kölner Straße 102, 42897 Remscheid, Germany",
        "citation": "https://volla.online/en/imprint/index.html"
      },
      "parentEntity": {
        "value": "Dr. Wurzer Beteiligungsgesellschaft mbH",
        "citation": "https://handelsregister.ai/de/organizations/remscheid/entwicklung-und-programmierung-von-anwendungssoftware/volla-systeme-gmbh-638a1bec64852dc76ad72e5509bdfce6"
      },
      "officers": {
        "value": [
          {
            "name": "Dr. Jörg Herbert Wurzer",
            "role": "Geschäftsführer"
          }
        ],
        "citation": "https://volla.online/en/imprint/index.html"
      },
      "priorEntities": {
        "value": [
          "Hallo Welt Systeme UG"
        ],
        "citation": "https://www.northdata.com/Volla%20Systeme%20GmbH,%20Remscheid/Amtsgericht%20Wuppertal%20HRB%2028033"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://uattest.net/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://uattest.net/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://uattest.net/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1009,
    "slug": "divestos",
    "noOperatorData": true,
    "domain": "divested.dev",
    "name": "DivestOS",
    "kyc": "none",
    "categories": [
      "Privacy OS"
    ],
    "countries": [
      "GLOBAL"
    ],
    "jurisdiction": "US",
    "description": "Discontinued Android and LineageOS privacy fork whose development ended in December 2024 without further updates.",
    "cardSummary": "Discontinued hardened Android fork.",
    "networks": [
      "FOSS"
    ],
    "founderIntel": "\"Tad\" / SkewedZeppelin / Tavi - anonymous pseudonymous developer, FSF 2022 Award winner for Outstanding New Free Software Contributor. Clean background, no intel connections. Project discontinued December 2024 due to funding exhaustion.",
    "url": "https://divested.dev/pages/software",
    "vcIntel": "No VC, no government grants. Donation-funded one-person project. Terminated December 2024.",
    "kycNote": "No account, payment rail or identity KYC; the project is discontinued software, not an active hosted service.",
    "privacyWarning": "PROJECT DISCONTINUED December 2024 - no current OS/app/security updates. Treat as historical reference only; use maintained Android privacy OS projects for live devices.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-06-22",
    "fee": "Free",
    "stateActorFlag": "Discontinued in December 2024. No current security updates are published.",
    "followTheMoney": "DivestOS - discontinued\nDeveloper: Tad, known as SkewedZeppelin\nFunding: donations\nDevelopment ended: December 2024\nCurrent status: no security updates",
    "kycLevel": 0,
    "status": "down",
    "lastReviewed": "2026-08-27",
    "kycLastChecked": "2026-08-27",
    "reviewSource": "Primary-source review 2026-08-27",
    "jurisdictionConfidence": "inferred",
    "checkedAt": "2026-08-27",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "verified",
    "riskLevel": "danger",
    "corporate": {
      "entityType": {
        "value": "project-no-legal-entity",
        "citation": "https://divested.dev/pages/donate",
        "note": "Site describes Divested Computing Group as an umbrella for full-time passion projects by individual Tavi who operates independently of any organization or company; developer explicitly confirmed no legal entity exists and 'Divested Computing Group' is just a professional name."
      },
      "governanceModel": {
        "value": "individual",
        "citation": "https://divested.dev/pages/donate"
      },
      "repositoryUrl": {
        "value": "https://codeberg.org/divested-mobile",
        "citation": "https://codeberg.org/divested-mobile"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "none",
      "controlModel": "local-self-custody",
      "sourceModel": "open"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "none",
          "sourceUrls": [
            "https://divested.dev/pages/software"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No operator service data path for local archived builds; website logs governed separately."
        },
        "controlModel": {
          "value": "local-self-custody",
          "sourceUrls": [
            "https://divested.dev/pages/software"
          ],
          "reviewedAt": "2026-08-27",
          "note": "local-user-controlled-archived-software"
        },
        "sourceModel": {
          "value": "open",
          "sourceUrls": [
            "https://codeberg.org/divested-mobile"
          ],
          "reviewedAt": "2026-08-27",
          "note": "open-source-archived"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No audit points claimed or needed for historical/discontinued classification."
      }
    }
  },
  {
    "id": 1010,
    "slug": "qubes-os",
    "noOperatorData": true,
    "domain": "qubes-os.org",
    "name": "Qubes OS",
    "kyc": "none",
    "categories": [
      "Privacy OS"
    ],
    "countries": [
      "GLOBAL"
    ],
    "jurisdiction": "US",
    "description": "Operating system using Xen to isolate activities in separate VMs, with 4.3.1 stable and 4.2 end-of-life.",
    "cardSummary": "Desktop OS isolating your work in Xen VMs.",
    "networks": [
      "FOSS"
    ],
    "founderIntel": "Joanna Rutkowska (founder) - Polish computer security researcher, born Warsaw 1981. Founded Invisible Things Lab (Warsaw). Known for \"evil maid attack\" concept (2009) and Blue Pill hypervisor rootkit research. No military or intelligence connections found. Voluntarily resigned from Qubes OS 2018, joined Golem Project (decentralized computing). Current development maintained by distributed volunteer team.",
    "url": "https://qubes-os.org/",
    "vcIntel": "No VC investors. OTF (~$570K documented), NLnet/EU NGI0, Tether/Bitfinex ($100K). Both OTF and NLnet listed on official partners page.",
    "kycNote": "Advertises No-KYC, but strictly adhere to OPSEC rules. Access via Tor, pay with XMR.",
    "stateActorFlag": "US government (indirect): Confirmed OTF/USAGM funding ~$570,000 documented ($160K 2015 + $410K 2016). Same US State Dept/USAGM funding chain as Briar, Tor, Signal. Additional funders: NLnet Foundation (EU NGI0 PET grant, June 2019–Oct 2022). Tether/Bitfinex $100K USDT public grant.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-03-13",
    "fee": "Free",
    "privacyWarning": "Security depends on compartmentalization plus prompt updates and required restarts. QSB-116 states that multiple Xen issues could allow a malicious qube to compromise Qubes OS or leak data; patched Xen packages are identified for Qubes 4.3.",
    "followTheMoney": "  Qubes OS Foundation - USA (US)\n  ──────────────────────────────────────\n  Founder: Joanna Rutkowska (PL, left 2018)\n  Funders: OTF ~$570K, NLnet, Tether $100K\n  Revenue: donations\n  ├─ OTF = US State Dept funding chain\n  ├─ Tether/Bitfinex $100K USDT grant\n  └─ 4.3.1 current; 4.2 EOL as of Jun 2026",
    "kycLevel": 0,
    "status": "ok",
    "lastReviewed": "2026-07-05",
    "kycLastChecked": "2026-03-13",
    "reviewSource": "legacy_seed_unverified",
    "jurisdictionConfidence": "inferred",
    "checkedAt": "2026-06-23",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "partial",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "unresolved",
        "citation": "unknown",
        "note": "Pass 1 researched this service but established no registry facts."
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.qubes-os.org/",
            "https://www.qubes-os.org/downloads/",
            "https://doc.qubes-os.org/en/latest/introduction/intro.html",
            "https://www.qubes-os.org/terms/",
            "https://www.qubes-os.org/team/",
            "https://www.qubes-os.org/partners/",
            "https://raw.githubusercontent.com/QubesOS/qubes-secpack/master/QSBs/qsb-116-2026.txt",
            "https://doc.qubes-os.org/en/latest/user/how-to-guides/how-to-update.html",
            "https://raw.githubusercontent.com/QubesOS/qubes-secpack/master/QSBs/qsb-115-2026.txt",
            "https://qubes-os.org/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.qubes-os.org/",
            "https://www.qubes-os.org/downloads/",
            "https://doc.qubes-os.org/en/latest/introduction/intro.html",
            "https://www.qubes-os.org/terms/",
            "https://www.qubes-os.org/team/",
            "https://www.qubes-os.org/partners/",
            "https://raw.githubusercontent.com/QubesOS/qubes-secpack/master/QSBs/qsb-116-2026.txt",
            "https://doc.qubes-os.org/en/latest/user/how-to-guides/how-to-update.html",
            "https://raw.githubusercontent.com/QubesOS/qubes-secpack/master/QSBs/qsb-115-2026.txt",
            "https://qubes-os.org/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.qubes-os.org/",
            "https://www.qubes-os.org/downloads/",
            "https://doc.qubes-os.org/en/latest/introduction/intro.html",
            "https://www.qubes-os.org/terms/",
            "https://www.qubes-os.org/team/",
            "https://www.qubes-os.org/partners/",
            "https://raw.githubusercontent.com/QubesOS/qubes-secpack/master/QSBs/qsb-116-2026.txt",
            "https://doc.qubes-os.org/en/latest/user/how-to-guides/how-to-update.html",
            "https://raw.githubusercontent.com/QubesOS/qubes-secpack/master/QSBs/qsb-115-2026.txt",
            "https://qubes-os.org/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1011,
    "slug": "system76",
    "domain": "system76.com",
    "name": "System76",
    "kyc": "none",
    "categories": [
      "Hardware"
    ],
    "countries": [
      "US",
      "GLOBAL"
    ],
    "jurisdiction": "US",
    "description": "Linux hardware manufacturer developing System76 Open Firmware for supported models using coreboot and EDK2.",
    "cardSummary": "Linux hardware with coreboot open firmware.",
    "networks": [
      "Hardware"
    ],
    "founderIntel": "Carl Richell (founder/CEO) - self-made entrepreneur, bootstrapped from $1,500. Started in tech consulting for Lucent Technologies (1990s). No military, intelligence, or government connections found. Name references 1776/American Revolution (open source freedom ethos).",
    "url": "https://system76.com/",
    "vcIntel": "Fully bootstrapped - no external VC investors documented. Carl Richell sole founder.",
    "tagline": "Linux laptops and desktops with open firmware on supported models.",
    "kycNote": "No identity-document check is stated for a normal hardware order. System76 collects name, email, phone, shipping and billing addresses and may use partner information for fraud prevention.",
    "stateActorFlag": null,
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-08-25",
    "fee": "Hardware prices vary",
    "privacyWarning": "US hardware seller collecting name, email, phone, shipping and billing addresses. Order/account/shipping/hosting/reporting/marketing partners may receive data; AWS hosts it, and database backups may retain personal information for up to 30 days after deletion.",
    "followTheMoney": "  System76 Inc - Denver, Colorado (US)\n  ──────────────────────────────────────\n  CEO: Carl Richell · Founded: 2005\n  Funding: bootstrapped from $1,500\n  Revenue: Linux laptop/desktop sales\n  ├─ Uses AWS (US gov cloud contractor)\n  ├─ Five Eyes (US) jurisdiction\n  └─ Pop!_OS + Open Firmware on supported models",
    "kycLevel": 2,
    "status": "ok",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "primary_source_rereview_2026-08-25",
    "jurisdictionConfidence": "inferred",
    "checkedAt": "2026-08-25",
    "geo": [
      "GH",
      "ZA",
      "GU",
      "HK",
      "IL",
      "JP",
      "KR",
      "MO",
      "MY",
      "OM",
      "PH",
      "SG",
      "TW",
      "AE",
      "VN",
      "AU",
      "AT",
      "BE",
      "BG",
      "HR",
      "CY",
      "CZ",
      "DK",
      "EE",
      "FI",
      "FR",
      "DE",
      "GR",
      "GG",
      "HU",
      "IS",
      "IE",
      "IT",
      "JE",
      "LV",
      "LT",
      "LU",
      "MT",
      "MC",
      "NL",
      "NO",
      "PL",
      "PT",
      "RO",
      "SK",
      "SI",
      "ES",
      "SE",
      "CH",
      "GB",
      "CA",
      "KY",
      "CR",
      "CW",
      "GL",
      "GT",
      "JM",
      "PA",
      "PR",
      "US",
      "VI",
      "CL",
      "CO",
      "PE",
      "NZ"
    ],
    "evidenceStatus": "partial",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://system76.com/about/",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "System76, Inc.",
        "citation": "https://system76.com/about/"
      },
      "incorporationJurisdiction": {
        "value": "Colorado, United States",
        "citation": "https://system76.com/content/media/pdf/2024%20System76%20Sustainability%20Report.pdf"
      },
      "registeredAddress": {
        "value": "4240 Carson Street, Suite 101, Denver, CO 80239",
        "citation": "https://system76.com/contact/"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://system76.com/about/",
            "https://system76.com/privacy/",
            "https://system76.com/support",
            "https://system76.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://system76.com/about/",
            "https://system76.com/privacy/",
            "https://system76.com/support",
            "https://system76.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://system76.com/about/",
            "https://system76.com/privacy/",
            "https://system76.com/support",
            "https://system76.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1012,
    "slug": "framework",
    "domain": "frame.work",
    "name": "Framework Computer",
    "kyc": "none",
    "categories": [
      "Hardware"
    ],
    "countries": [
      "US",
      "GLOBAL"
    ],
    "jurisdiction": "US",
    "description": "Modular repairable laptops with camera and microphone kill switches, sold without a preinstalled proprietary OS.",
    "cardSummary": "Modular repairable laptops with kill switches.",
    "networks": [
      "Hardware"
    ],
    "founderIntel": null,
    "url": "https://frame.work/",
    "vcIntel": null,
    "tagline": "Repairable laptops with hardware camera and microphone switches and first-party Linux support.",
    "kycNote": "No identity-document check is recorded for a normal hardware order. Standard account, payment, billing and shipping details can still identify the buyer.",
    "stateActorFlag": null,
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-08-06",
    "fee": "Hardware prices vary",
    "privacyWarning": "Framework’s ecommerce policy states that billing identity and payment data are processed and that necessary personal data can be shared with marketing, shipping, payment-processing and customer-support providers. Normal hardware orders do not state document KYC but still identify the buyer.",
    "followTheMoney": "  Framework Computer Inc - San Francisco\n  ──────────────────────────────────────\n  CEO: Nirav Patel (ex-Oculus/Meta 7yr)\n  Series A/A-1: $18M + $17M - Spark led\n  Also: Anorak, Anzu, Cooler Master, Pathbreaker\n  ├─ Patel: 7yr Meta/Facebook history\n  ├─ Five Eyes (US) jurisdiction\n  └─ Modular hardware, Linux-first, repair focus",
    "kycLevel": 2,
    "status": "ok",
    "lastReviewed": "2026-08-06",
    "kycLastChecked": "2026-08-06",
    "reviewSource": "official_product_and_linux_pages_2026-08-06",
    "jurisdictionConfidence": "inferred",
    "checkedAt": "2026-08-06",
    "geo": [
      "US",
      "CA",
      "SG",
      "TW",
      "CH",
      "NZ",
      "UK",
      "AU",
      "AT",
      "BE",
      "BG",
      "HR",
      "CY",
      "CZ",
      "DK",
      "EE",
      "FI",
      "FR",
      "DE",
      "GR",
      "HU",
      "IE",
      "IT",
      "LV",
      "LT",
      "LU",
      "MT",
      "NL",
      "PL",
      "PT",
      "RO",
      "SK",
      "SI",
      "ES",
      "SE",
      "NO"
    ],
    "evidenceStatus": "partial",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://frame.work/terms-of-sale",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Framework Computer Inc.",
        "citation": "https://frame.work/terms-of-sale"
      },
      "incorporationJurisdiction": {
        "value": "Delaware, United States",
        "citation": "https://frame.work/terms-of-sale"
      },
      "registeredAddress": {
        "value": "447 Sutter St, PMB 135, San Francisco, CA, 94108-4618, United States",
        "citation": "https://frame.work/terms-of-sale"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://frame.work/fi/en/terms-of-sale",
            "https://frame.work/fi/en/about",
            "https://www.iubenda.com/privacy-policy/39604375",
            "https://www.iubenda.com/terms-and-conditions/39604375",
            "https://frame.work/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://frame.work/fi/en/terms-of-sale",
            "https://frame.work/fi/en/about",
            "https://www.iubenda.com/privacy-policy/39604375",
            "https://www.iubenda.com/terms-and-conditions/39604375",
            "https://frame.work/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://frame.work/fi/en/terms-of-sale",
            "https://frame.work/fi/en/about",
            "https://www.iubenda.com/privacy-policy/39604375",
            "https://www.iubenda.com/terms-and-conditions/39604375",
            "https://frame.work/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1014,
    "slug": "i2p",
    "domain": "i2p.net",
    "name": "I2P (Invisible Internet Project)",
    "kyc": "none",
    "categories": [
      "Networking"
    ],
    "countries": [
      "GLOBAL"
    ],
    "jurisdiction": "??",
    "description": "Decentralized network routing traffic through layered encryption across volunteer-operated nodes.",
    "cardSummary": "Anonymous network for internal services.",
    "networks": [
      "FOSS",
      "P2P"
    ],
    "founderIntel": "Primary developer \"zzz\" - pseudonymous, active since 2005, 20+ year track record. No intelligence connections identified. Pseudonymity is appropriate and standard for this type of privacy infrastructure project.",
    "url": "https://i2p.net/",
    "vcIntel": "No VC. Funded by: OTF (usability grants), DuckDuckGo ($5K), Internews (USAID recipient), NLnet, StormyCloud. Project policy: does not take direct donations, contributions go to secondary apps or hiring contributors.",
    "kycNote": "No account, payment or identity KYC to download and run the open-source network software.",
    "stateActorFlag": "US government (indirect): OTF/USAGM funded usability and accessibility work. Amount not publicly specified. Same funding chain as Briar, Qubes OS, Tor. Additional: DuckDuckGo ($5K), Internews (USAID-funded), StormyCloud (US nonprofit, 2025 infrastructure support).",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-08-25",
    "fee": "Free",
    "privacyWarning": "I2P is optimized for internal hidden services, not clearnet exit browsing; privacy depends on correct client/app configuration and threat model.",
    "followTheMoney": "  I2P - Decentralised / Global\n  ──────────────────────────────────────\n  Dev: \"zzz\" (pseudonymous, 20yr track)\n  Funders: OTF (US State Dept), DuckDuckGo\n           Internews (USAID), NLnet, STCloud\n  ├─ OTF = US USAGM funding chain\n  ├─ Same funders as Tor, Briar, Qubes\n  └─ No backdoors documented",
    "kycLevel": 0,
    "status": "ok",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "primary_source_rereview_2026-08-25",
    "jurisdictionConfidence": "unknown",
    "checkedAt": "2026-08-25",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "partial",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "project-no-legal-entity",
        "citation": "https://i2p.net/en/blog/2025/11/01/stormycloud-joins-the-i2p-family/",
        "note": "Official site and blog describe I2P as an open-source community-driven volunteer project with no legal entity of its own; StormyCloud is a separate partner 501(c)(3) that processes donations and provides infrastructure but does not operate or own the core project."
      },
      "governanceModel": {
        "value": "maintainer-group",
        "citation": "https://i2p.net/en/contact/"
      },
      "repositoryUrl": {
        "value": "https://github.com/i2p/i2p.i2p",
        "citation": "https://github.com/i2p/i2p.i2p"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "features": [
      "Layered encrypted routing",
      "Volunteer-operated nodes",
      "Internal hidden services",
      "Open source",
      "Post-quantum NTCP2 transport (2.13.0)",
      "DNS-like address book",
      "BitTorrent and messaging applications"
    ],
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://i2p.net/en/",
            "https://i2p.net/en/blog/2026/07/20/i2p-2.13.0-release/",
            "https://i2p.net/en/privacy/",
            "https://api.github.com/repos/i2p/i2p.i2p/releases/latest",
            "https://i2p.net/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://i2p.net/en/",
            "https://i2p.net/en/blog/2026/07/20/i2p-2.13.0-release/",
            "https://i2p.net/en/privacy/",
            "https://api.github.com/repos/i2p/i2p.i2p/releases/latest",
            "https://i2p.net/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://i2p.net/en/",
            "https://i2p.net/en/blog/2026/07/20/i2p-2.13.0-release/",
            "https://i2p.net/en/privacy/",
            "https://api.github.com/repos/i2p/i2p.i2p/releases/latest",
            "https://i2p.net/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1015,
    "slug": "lokinet",
    "noOperatorData": true,
    "domain": "lokinet.org",
    "name": "Lokinet",
    "kyc": "none",
    "categories": [
      "Networking"
    ],
    "countries": [
      "GLOBAL"
    ],
    "jurisdiction": "AU",
    "description": "An onion-routed internet natively supporting all IP-based protocols (TCP, UDP, ICMP). Part of the Oxen privacy ecosystem.",
    "cardSummary": "Onion-routed network for any IP protocol.",
    "networks": [
      "FOSS"
    ],
    "founderIntel": "Simon Harman (CEO): Australian, later moved to Chainflip project. Kee Jefferys (CTO): Australian. Both privacy-advocate backgrounds, no military or intelligence connections found. Session Technology Foundation president: Alex Linton (former journalist, no intelligence background).",
    "url": "https://lokinet.org/",
    "vcIntel": "No VC funding. Blockchain emission-funded: OXEN token staking rewards from service node operators. No government grants or OTF funding found.",
    "kycNote": "Advertises No-KYC, but strictly adhere to OPSEC rules. Access via Tor, pay with XMR.",
    "stateActorFlag": "Australia = Five Eyes jurisdiction. Australian Assistance and Access Act (AA Bill) 2018 enables government to compel backdoors in encryption products with gag orders. OPTF (Oxen Privacy Tech Foundation) operates under Australian law. No confirmed state actor involvement but structural jurisdiction risk is high. OPTF has publicly criticized the AA Bill.",
    "affiliate": "",
    "trending": false,
    "updatedAt": "2026-03-13",
    "fee": "Free",
    "privacyWarning": null,
    "followTheMoney": "  OPTF (Oxen Privacy Tech Found.) - AU\n  ──────────────────────────────────────\n  CEO: Simon Harman (AU, moved to Chainflip)\n  Funding: OXEN token staking rewards\n  Revenue: blockchain emission, no VC\n  ├─ Five Eyes (AU) - AA Bill risk\n  ├─ OPTF has criticised AA Bill publicly\n  └─ Non-custodial, IP-layer onion routing",
    "kycLevel": 0,
    "status": "ok",
    "lastReviewed": "2026-07-05",
    "kycLastChecked": "2026-03-13",
    "reviewSource": "legacy_seed_unverified",
    "jurisdictionConfidence": "inferred",
    "checkedAt": "2026-06-23",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "partial",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "foundation",
        "citation": "https://lokinet.org/faq",
        "note": "Lokinet's official FAQ states it is developed by OPTF, Australia’s first not-for-profit privacy tech organisation; OPTF LTD is an ACNC-registered Australian charity and public company limited by shares."
      },
      "governanceModel": {
        "value": "foundation",
        "citation": "https://lokinet.org/faq"
      },
      "repositoryUrl": {
        "value": "https://github.com/oxen-io/lokinet",
        "citation": "https://github.com/oxen-io/lokinet"
      },
      "legalEntity": {
        "value": "OPTF LTD",
        "citation": "https://abr.business.gov.au/ABN/View/32624664204"
      },
      "registrationNumber": {
        "value": "ACN 624 664 204 (ABN 32 624 664 204)",
        "citation": "https://abr.business.gov.au/ABN/View/32624664204"
      },
      "registryUrl": {
        "value": "https://www.acnc.gov.au/charity/charities/26214f82-a2cd-e811-a962-000d3ad24182/profile",
        "citation": "https://www.acnc.gov.au/charity/charities/26214f82-a2cd-e811-a962-000d3ad24182/profile"
      },
      "incorporationJurisdiction": {
        "value": "Australia",
        "citation": "https://abr.business.gov.au/ABN/View/32624664204"
      },
      "incorporationDate": {
        "value": "2018-02-26",
        "citation": "https://abr.business.gov.au/ABN/View/32624664204"
      },
      "registeredAddress": {
        "value": "Level 1/452 Flinders St, Melbourne VIC 3000, Australia",
        "citation": "https://acncpubfilesprodstorage.blob.core.windows.net/public/26214f82-a2cd-e811-a962-000d3ad24182-0146866e-31aa-4b66-97e6-dfcfec7e1bd6-Financial%20Report-de926f6a-5c13-f011-9989-000d3ad02a0a-OPTF_Ltd_-_2024_Financial_Statements.pdf"
      },
      "officers": {
        "value": [
          "Christopher Scott McCabe (Public Officer, Chair/Director)",
          "Simon Albert Harman (Director)",
          "Jason Gregory Rhinelander (Director)",
          "Alexander Burnett Linton (Director)",
          "Lucinda Lovegrove (Secretary)"
        ],
        "citation": "https://optf.ngo/about-optf"
      },
      "priorEntities": {
        "value": [
          "LAG Foundation Ltd (same ABN, prior name)"
        ],
        "citation": "https://optf.ngo/assets/pdfs/annual-reports/LAG-Foundation-2019-Annual-Report.pdf"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://lokinet.org/",
            "https://lokinet.org/faq",
            "https://github.com/oxen-io/lokinet",
            "https://optf.ngo/about-optf"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://lokinet.org/",
            "https://lokinet.org/faq",
            "https://github.com/oxen-io/lokinet",
            "https://optf.ngo/about-optf"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://lokinet.org/",
            "https://lokinet.org/faq",
            "https://github.com/oxen-io/lokinet",
            "https://optf.ngo/about-optf"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1017,
    "slug": "boltz",
    "domain": "boltz.exchange",
    "name": "Boltz",
    "type": "Swap",
    "cat": "swap",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0.1
    },
    "fee": "~0.1%",
    "limits": {
      "daily": null
    },
    "features": [
      "Non-custodial",
      "No account required",
      "Lightning ↔ On-chain",
      "Liquid swaps",
      "Open source",
      "Submarine swaps",
      "HTLC-based"
    ],
    "networks": [],
    "badge": "SWAP",
    "url": "https://boltz.exchange/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "warning",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Swap"
    ],
    "description": "Non-custodial Bitcoin bridge swapping between Lightning, on-chain and Liquid using submarine swaps.",
    "cardSummary": "Non-custodial swaps across Lightning and Liquid.",
    "jurisdiction": "SV",
    "auditedBy": [],
    "twitter": "https://x.com/Boltzhq",
    "founderIntel": "Kilian (Twitter: @kilrau) and Michael - Argentine founders. Both pseudonymous/semi-public within Bitcoin community. Founded 2019, incorporated 2023. Active on Stacker News, Bitcoin Magazine. No intelligence contractor background. Self-funded from day one.",
    "vcIntel": "Self-funded. No external VC. Bootstrapped from trading fees since 2019. Incorporated 2023. Argentine founders. No OFAC designation. Open source. One of the largest Lightning Network nodes by channel capacity.",
    "privacyWarning": "Boltz announced a service suspension on 12 August 2026 after targeted attacks. All original founders stepped down, and as of 18 August the old crew still controlled the service while ownership handover remained in progress. Hold normal recommendation until the new operator and resumed service are confirmed by provider-owned sources.",
    "tagline": "Non-custodial Bitcoin Layer 2 bridge via submarine swaps.",
    "bestFor": [
      "Lightning ↔ on-chain swaps",
      "Liquid Bitcoin",
      "Non-custodial workflows"
    ],
    "kycNote": "Fully non-custodial. Uses hash time-locked contracts - funds cannot be seized.",
    "updatedAt": "2026-08-25",
    "stateActorFlag": null,
    "followTheMoney": "  Boltz Exchange - Argentina / Global\n  ──────────────────────────────────────\n  Founders: Kilian (@kilrau) + Michael (AR)\n  Funding: bootstrapped from fees (2019)\n  Revenue: ~0.1% swap spread\n  ├─ No VC, no OFAC designation\n  ├─ Open-source, one of top LN nodes\n  └─ Non-custodial HTLC, no custody risk",
    "lastReviewed": "2026-02-24",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "https://x.com/Boltzhq/status/2089675696494834097",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "danger",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://boltz.exchange/terms",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Boltz S.A. de C.V.",
        "citation": "https://boltz.exchange/terms"
      },
      "incorporationJurisdiction": {
        "value": "El Salvador",
        "citation": "https://boltz.exchange/terms"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://x.com/Boltzhq/status/2089675696494834097",
            "https://x.com/Boltzhq/status/2087636521746674168",
            "https://status.boltz.exchange/",
            "https://boltz.exchange/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://x.com/Boltzhq/status/2089675696494834097",
            "https://x.com/Boltzhq/status/2087636521746674168",
            "https://status.boltz.exchange/",
            "https://boltz.exchange/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://x.com/Boltzhq/status/2089675696494834097",
            "https://x.com/Boltzhq/status/2087636521746674168",
            "https://status.boltz.exchange/",
            "https://boltz.exchange/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1018,
    "slug": "airvpn",
    "domain": "airvpn.org",
    "name": "AirVPN",
    "type": "VPN",
    "cat": "vpn",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 7
    },
    "fee": "~€7/mo",
    "limits": {
      "daily": null
    },
    "features": [
      "No logs",
      "No email required",
      "BTC accepted",
      "XMR accepted",
      "OpenVPN",
      "WireGuard",
      "Tor over VPN",
      "Eddie client open source"
    ],
    "networks": [],
    "badge": "VPN",
    "url": "https://airvpn.org/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "VPN"
    ],
    "description": "Italian hacktivist-operated VPN with OpenVPN, WireGuard and an open-source client, accepting BTC and XMR.",
    "cardSummary": "Italian VPN, no email, accepts BTC and XMR.",
    "jurisdiction": "IT",
    "auditedBy": [],
    "twitter": "https://x.com/AirVPN",
    "founderIntel": "Founded 2010 by Italian hacktivists and activists: NEXA Centre (Italian research group), Telecomix, Juliagruppen, Swedish Pirate Party, Italian Pirate Party, Scambioetico (digital rights org), activists from Mexico and USA. Operator: Paolo Brini, Perugia, Italy. No intelligence contractor background. Described team as \"only hires activists, legal experts and people aware of today's privacy issues.\" In 2024, refused compliance with Italy's Piracy Shield mandatory blocking - stopped serving Italian users rather than comply.",
    "vcIntel": "No external investors or VC. Operated by Italian S.r.l. (Perugia, Italy). EU jurisdiction - subject to Italian law and EU data directives, but Italy is not Five Eyes. No OFAC designation. Track record of resisting Italian government overreach (Piracy Shield refusal 2024 is significant pro-privacy signal).",
    "privacyWarning": "Italy is EU jurisdiction - subject to Italian court orders and EU data directives. Less restrictive than Five Eyes but not Mullvad/IVPN tier. Official terms also prohibit use by residents of Italy.",
    "tagline": "Hacktivist-operated Italian VPN with a track record of resisting government pressure.",
    "bestFor": [
      "EU-based users",
      "Anti-censorship",
      "Tor over VPN"
    ],
    "kycNote": "No email required. Accepts BTC and XMR. Open source client.",
    "updatedAt": "2026-08-25",
    "stateActorFlag": null,
    "followTheMoney": "  AirVPN S.r.l. - Perugia, Italy (IT)\n  ──────────────────────────────────────\n  Operator: Paolo Brini (IT hacktivist)\n  Funding: bootstrapped, subscriptions\n  Revenue: ~€7/mo per subscriber\n  ├─ Refused Italy Piracy Shield 2024\n  ├─ EU jurisdiction (IT, not Five Eyes)\n  └─ No VC, no OFAC, no logs",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "primary_source_rereview_2026-08-25",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://airvpn.org/tos/",
        "note": "Terms of Service explicitly state the VPN is operated by the Italian sole proprietorship AirVPN di Paolo Brini with REA number; corroborated by Privacy Notice and Italian registry extracts."
      },
      "governanceModel": {
        "value": "individual",
        "citation": "https://lei.bloomberg.com/leis/view/815600FA7D8FFB2E9654"
      },
      "repositoryUrl": {
        "value": "https://github.com/AirVPN",
        "citation": "https://github.com/AirVPN"
      },
      "legalEntity": {
        "value": "AIRVPN DI PAOLO BRINI (AirVPN di Paolo Brini / Air di Paolo Brini)",
        "citation": "https://airvpn.org/tos/"
      },
      "registrationNumber": {
        "value": "REA PG-279011 (Partita IVA / VAT IT03297800546)",
        "citation": "https://airvpn.org/tos/"
      },
      "registryUrl": {
        "value": "https://www.ufficiocamerale.it/3460/airvpn-di-paolo-brini",
        "citation": "https://www.ufficiocamerale.it/3460/airvpn-di-paolo-brini"
      },
      "incorporationJurisdiction": {
        "value": "Italy (Camera di Commercio Perugia / PG)",
        "citation": "https://www.ufficiocamerale.it/3460/airvpn-di-paolo-brini"
      },
      "incorporationDate": {
        "value": "2012-11-19",
        "citation": "https://www.ufficiocamerale.it/3460/airvpn-di-paolo-brini"
      },
      "registeredAddress": {
        "value": "Via del Sagittario 4, 06131 Perugia (PG), Italy",
        "citation": "https://airvpn.org/tos/"
      },
      "parentEntity": {
        "value": "none",
        "citation": "https://lei.bloomberg.com/leis/view/815600FA7D8FFB2E9654"
      },
      "ultimateOwner": {
        "value": "Paolo Brini",
        "citation": "https://airvpn.org/privacy/"
      },
      "officers": {
        "value": [
          {
            "name": "Paolo Brini",
            "role": "Titolare (sole proprietor)"
          }
        ],
        "citation": "https://lei.bloomberg.com/leis/view/815600FA7D8FFB2E9654"
      },
      "priorEntities": {
        "value": [
          "Iridium -- Prior operator of the AirVPN service until transfer in November 2012"
        ],
        "citation": "https://airvpn.org/aboutus/"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://airvpn.org/tos/",
            "https://airvpn.org/buy/",
            "https://airvpn.org/privacy/",
            "https://airvpn.org/status/",
            "https://x.com/airvpn/status/2090804473681580168",
            "https://airvpn.org/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://airvpn.org/tos/",
            "https://airvpn.org/buy/",
            "https://airvpn.org/privacy/",
            "https://airvpn.org/status/",
            "https://x.com/airvpn/status/2090804473681580168",
            "https://airvpn.org/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://airvpn.org/tos/",
            "https://airvpn.org/buy/",
            "https://airvpn.org/privacy/",
            "https://airvpn.org/status/",
            "https://x.com/airvpn/status/2090804473681580168",
            "https://airvpn.org/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1020,
    "slug": "btcpay-server",
    "domain": "btcpayserver.org",
    "name": "BTCPay Server",
    "type": "Payments",
    "cat": "payments",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Free",
    "limits": {
      "daily": null
    },
    "features": [
      "Self-hosted",
      "Open source",
      "Lightning",
      "No fees",
      "No KYC",
      "Non-custodial",
      "Merchant payments",
      "WooCommerce plugin",
      "Shopify plugin"
    ],
    "networks": [],
    "badge": "OPEN SOURCE",
    "url": "https://btcpayserver.org/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-27",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Merchants",
      "Privacy Tools",
      "Agent Money"
    ],
    "description": "Self-hosted open-source Bitcoin and Lightning payment processor that is non-custodial and charges no fees.",
    "cardSummary": "Self-hosted Bitcoin and Lightning payments.",
    "jurisdiction": "JP",
    "auditedBy": [],
    "twitter": "https://x.com/BtcpayServer",
    "founderIntel": null,
    "vcIntel": null,
    "privacyWarning": "Self-hosted and non-custodial, but all versions before 2.4.2 exposed LND admin macaroon credentials; attackers exploited the flaw and stole funds. LND operators must update to current BTCPay Server/LND, rotate or regenerate credentials, and review node activity.",
    "stateActorFlag": null,
    "tagline": "Self-hosted Bitcoin payments. No middleman, no fees, no KYC.",
    "bestFor": [
      "Merchants accepting BTC",
      "Self-sovereign payments",
      "No-fee transactions"
    ],
    "kycNote": "No KYC of any kind. You run the server. You control the keys.",
    "updatedAt": "2026-03-13",
    "followTheMoney": "  BTCPay Server Foundation - Japan (JP)\n  ──────────────────────────────────────\n  Founder: Nicolas Dorier (FR, based JP)\n  Grants: Spiral, HRF, Tether ($200K)\n           DG Lab, ACINQ\n  ├─ Self-hosted: grants = zero data view\n  ├─ JP jurisdiction, non-profit entity\n  └─ Open-source, no VC, no custody",
    "lastReviewed": "2026-07-05",
    "kycLastChecked": "2026-03-13",
    "reviewSource": "legacy_seed_unverified",
    "jurisdictionConfidence": "inferred",
    "agentMoney": {
      "compatible": true,
      "controlSurfaces": [
        "api",
        "dashboard",
        "manual"
      ],
      "protocols": [
        "merchant-api",
        "manual"
      ],
      "authorizationModel": [
        "human-approval",
        "policy-engine",
        "wallet-grant"
      ],
      "settlementRail": [
        "crypto",
        "lightning"
      ],
      "autonomyLevel": 1,
      "custodyModel": "self-custody",
      "spendLimits": false,
      "merchantLock": true,
      "categoryLock": false,
      "pauseClose": true,
      "transactionWebhooks": true,
      "fundingSource": "self-hosted",
      "identitySurface": "none",
      "dataPath": [
        "AI agent",
        "approval wallet or operator",
        "BTCPay Greenfield API invoice",
        "self-hosted BTCPay server",
        "Bitcoin or Lightning network",
        "merchant order record"
      ],
      "notes": "Useful as a self-hosted invoice and merchant-payment rail for agent workflows. It avoids platform custody and KYC, but wallet funding, network history, server logs, and merchant order records still need separate controls.",
      "protocolPrivacyNotes": "The safer pattern is agent-drafts, operator-or-policy-signs. Do not put seed material or broad wallet keys in the same runtime that browses, prompts, or receives untrusted task input.",
      "mandateLoggingRisk": "medium",
      "revocationQuality": "strong",
      "sourceLinks": [
        {
          "label": "BTCPay Server homepage",
          "href": "https://btcpayserver.org/",
          "scope": "provider"
        },
        {
          "label": "BTCPay Greenfield API",
          "href": "https://docs.btcpayserver.org/API/Greenfield/v1/",
          "scope": "controls"
        },
        {
          "label": "BTCPay wallet docs",
          "href": "https://docs.btcpayserver.org/Wallet/",
          "scope": "custody"
        }
      ]
    },
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "unresolved",
        "citation": "unknown",
        "note": "Pass 1 researched this service but established no registry facts."
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "none",
      "controlModel": "local-self-custody",
      "sourceModel": "open-reproducible"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "none",
          "sourceUrls": [
            "https://btcpayserver.org/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "deployment administrator controls store, invoice, network and user data"
        },
        "controlModel": {
          "value": "local-self-custody",
          "sourceUrls": [
            "https://btcpayserver.org/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "self-hosted-operator-controlled"
        },
        "sourceModel": {
          "value": "open-reproducible",
          "sourceUrls": [
            "https://github.com/btcpayserver/btcpayserver/releases/tag/v2.4.3"
          ],
          "reviewedAt": "2026-08-27",
          "note": "open-source-self-hosted"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "Security policy exists, but no current complete independent audit report with date/scope was established."
      }
    }
  },
  {
    "id": 1021,
    "slug": "joinmarket",
    "domain": "github.com",
    "name": "JoinMarket",
    "type": "Privacy Tools",
    "cat": "privacy",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0.1
    },
    "fee": "~0.1% (market rate)",
    "limits": {
      "daily": null
    },
    "features": [
      "Decentralized CoinJoin",
      "No coordinator",
      "Earn fees as maker",
      "Bitcoin privacy",
      "Tor-native",
      "Open source",
      "Self-custodial",
      "JoinMarket-Qt GUI"
    ],
    "networks": [],
    "badge": "ADVANCED",
    "url": "https://github.com/JoinMarket-Org/joinmarket-clientserver",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "warning",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Privacy Tools",
      "Bitcoin"
    ],
    "description": "Bitcoin CoinJoin implementation whose clientserver repository was archived read-only as of April 2026.",
    "cardSummary": "Bitcoin CoinJoin with a maker-taker market.",
    "jurisdiction": "??",
    "auditedBy": [],
    "twitter": null,
    "founderIntel": "Originally created by Chris Belcher (pseudonymous), a prominent Bitcoin privacy researcher who also invented Electrum Personal Server and co-authored confidential transactions research. Now community-maintained. No company, no legal entity, no Intel contractor connections. Belcher is one of the most respected Bitcoin privacy researchers.",
    "vcIntel": "No VC. No investors. No company. Funded by community donations and HRF grants (Bitcoin development fund). Belcher received HRF grants for Bitcoin privacy research. Entirely community-owned. No OFAC designation - decentralized coordinator model specifically designed to avoid Tornado Cash precedent.",
    "privacyWarning": "Official repository is archived/read-only; advanced Bitcoin Core/Tor setup is required and future maintenance should be verified before use.",
    "stateActorFlag": null,
    "tagline": "Leaderless CoinJoin. No coordinator, no shutdown risk, earn fees as a maker.",
    "bestFor": [
      "Bitcoin CoinJoin",
      "Advanced privacy",
      "Earning fees from liquidity"
    ],
    "kycNote": "No account, registration or identity KYC; users run local/self-custodial Bitcoin software and coordinate CoinJoins through the protocol.",
    "updatedAt": "2026-06-22",
    "followTheMoney": "  JoinMarket - Decentralised / Community\n  ──────────────────────────────────────\n  Creator: Chris Belcher (pseudonymous)\n  Funders: HRF Bitcoin dev grants\n  Revenue: none (0.1% goes to makers)\n  ├─ No company, no legal entity\n  ├─ Decentralised: no OFAC shutdown risk\n  └─ Open-source, community-maintained",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "primary_source_rereview_2026-08-25",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "project-no-legal-entity",
        "citation": "https://github.com/JoinMarket-Org/joinmarket-clientserver",
        "note": "Open-source decentralized CoinJoin software under the JoinMarket-Org GitHub organization with no company, foundation, or legal entity referenced in the repo, docs, wiki, or related materials; explicitly described as non-entity software coordinating peers."
      },
      "governanceModel": {
        "value": "maintainer-group",
        "citation": "https://docs.mynodebtc.com/coinjoin/joinmarket.html"
      },
      "repositoryUrl": {
        "value": "https://github.com/JoinMarket-Org/joinmarket-clientserver",
        "citation": "https://github.com/JoinMarket-Org/joinmarket-clientserver"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://github.com/JoinMarket-Org/joinmarket-clientserver",
            "https://github.com/JoinMarket-Org/joinmarket-clientserver/releases/tag/v0.9.12"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://github.com/JoinMarket-Org/joinmarket-clientserver",
            "https://github.com/JoinMarket-Org/joinmarket-clientserver/releases/tag/v0.9.12"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://github.com/JoinMarket-Org/joinmarket-clientserver",
            "https://github.com/JoinMarket-Org/joinmarket-clientserver/releases/tag/v0.9.12"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1022,
    "slug": "session",
    "domain": "getsession.org",
    "name": "Session",
    "type": "Comms",
    "cat": "comms",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Free",
    "limits": {
      "daily": null
    },
    "features": [
      "No phone number",
      "No email required",
      "E2E encrypted",
      "Decentralized network",
      "No metadata collection",
      "Open source",
      "iOS + Android + Desktop",
      "Onion routing"
    ],
    "networks": [],
    "badge": "NO ACCOUNT",
    "url": "https://getsession.org/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-24",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Comms",
      "Privacy Tools"
    ],
    "description": "Decentralized encrypted messenger needing no phone number or email, stewarded by a Swiss foundation.",
    "cardSummary": "Encrypted messenger without phone or email.",
    "jurisdiction": "CH",
    "auditedBy": [
      "Quarkslab"
    ],
    "twitter": "https://x.com/session_app",
    "founderIntel": null,
    "vcIntel": null,
    "privacyWarning": "The app requires an initial connection to an STF-organised seed node, which can see but says it does not record the connecting IP; Apple/Google may collect OS telemetry. The only cited independent code audit is from 2021, while 2026 development resumed with a reduced three-developer team funded mainly by donations.",
    "stateActorFlag": null,
    "tagline": "No phone number. No email. Just an ID. Decentralized encrypted messenger.",
    "bestFor": [
      "Anonymous messaging",
      "No-account comms",
      "Decentralized privacy"
    ],
    "kycNote": "No phone number, no email. Session ID only. Decentralized message storage.",
    "updatedAt": "2026-03-13",
    "followTheMoney": "  Session Tech. Foundation - Zürich, CH\n  ──────────────────────────────────────\n  President: Alex Linton (AU journalist)\n  Funding: donations + ecosystem support\n  Revenue: no ads; runway depends on grants/donations\n  ├─ Moved AU→CH 2024 (police contact)\n  ├─ Quarkslab audit: findings resolved\n  └─ Jun 2026: limited development resumes after donations",
    "lastReviewed": "2026-07-05",
    "kycLastChecked": "2026-03-13",
    "reviewSource": "legacy_seed_unverified",
    "jurisdictionConfidence": "inferred",
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://getsession.org/terms-of-service",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Session Technology Foundation (Session Technology Stiftung)",
        "citation": "https://getsession.org/terms-of-service"
      },
      "incorporationJurisdiction": {
        "value": "Switzerland (Zug)",
        "citation": "https://getsession.org/terms-of-service"
      },
      "registeredAddress": {
        "value": "Bahnhofstrasse 7, 6300 Zug, Switzerland",
        "citation": "https://play.google.com/store/apps/details?id=network.loki.messenger"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [
          "Oxen Privacy Tech Foundation (Australia)"
        ],
        "citation": "https://en.wikipedia.org/wiki/Session_(software)"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://getsession.org/",
            "https://getsession.org/privacy-policy",
            "https://getsession.org/terms-of-service",
            "https://getsession.org/blog/introducing-the-session-technology-foundation",
            "https://getsession.org/blog/the-future-of-session",
            "https://getsession.org/blog/session-development-update-pro-beta-protocol-v2",
            "https://getsession.org/blog/session-code-audit",
            "https://github.com/session-foundation/session-desktop/releases/tag/v1.18.1",
            "https://getsession.org/blog/rotating-keys-for-session-repos"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://getsession.org/",
            "https://getsession.org/privacy-policy",
            "https://getsession.org/terms-of-service",
            "https://getsession.org/blog/introducing-the-session-technology-foundation",
            "https://getsession.org/blog/the-future-of-session",
            "https://getsession.org/blog/session-development-update-pro-beta-protocol-v2",
            "https://getsession.org/blog/session-code-audit",
            "https://github.com/session-foundation/session-desktop/releases/tag/v1.18.1",
            "https://getsession.org/blog/rotating-keys-for-session-repos"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://getsession.org/",
            "https://getsession.org/privacy-policy",
            "https://getsession.org/terms-of-service",
            "https://getsession.org/blog/introducing-the-session-technology-foundation",
            "https://getsession.org/blog/the-future-of-session",
            "https://getsession.org/blog/session-development-update-pro-beta-protocol-v2",
            "https://getsession.org/blog/session-code-audit",
            "https://github.com/session-foundation/session-desktop/releases/tag/v1.18.1",
            "https://getsession.org/blog/rotating-keys-for-session-repos"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1023,
    "slug": "librewolf",
    "domain": "librewolf.net",
    "name": "Librewolf",
    "type": "Privacy Tools",
    "cat": "privacy",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Free",
    "limits": {
      "daily": null
    },
    "features": [
      "Firefox fork",
      "No telemetry",
      "uBlock Origin bundled",
      "Strict tracking protection",
      "No Mozilla accounts",
      "Open source",
      "Windows/Mac/Linux",
      "Privacy hardened"
    ],
    "networks": [],
    "badge": "OPEN SOURCE",
    "url": "https://librewolf.net/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-24",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Privacy Tools"
    ],
    "description": "Firefox fork that removes telemetry and data collection while shipping strict privacy and security defaults.",
    "cardSummary": "Firefox fork with telemetry removed.",
    "jurisdiction": "??",
    "auditedBy": [],
    "twitter": "https://x.com/librewolf_fdn",
    "founderIntel": "Community-maintained European project (Dutch/German contributors core team). Pseudonymous contributors. No company, no legal entity. No intelligence contractor connections. Forked from Firefox to remove telemetry, Pocket, and other Mozilla commercial additions.",
    "vcIntel": "No VC. No funding. No company. Volunteer community project. No revenue model. Maintained by privacy-focused developers as a public good. No OFAC designation. No hack incidents.",
    "privacyWarning": "Strict defaults can break sites and increase fingerprint uniqueness if users heavily customize extensions/settings.",
    "stateActorFlag": null,
    "tagline": "Firefox without the surveillance. Pre-hardened, pre-configured, no telemetry.",
    "bestFor": [
      "Privacy-first browsing",
      "Desktop users",
      "Firefox alternative"
    ],
    "kycNote": "No account, phone number or identity KYC needed to download/use the browser.",
    "updatedAt": "2026-06-22",
    "followTheMoney": "  Librewolf - Community / Europe (EU)\n  ──────────────────────────────────────\n  Maintainers: Dutch/German volunteers\n  Funding: none (volunteer public good)\n  Revenue: zero - no ads, no VC\n  ├─ No company, no legal entity\n  ├─ Firefox fork: telemetry stripped\n  └─ EU contributors, pseudonymous team",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_5_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "project-no-legal-entity",
        "citation": "https://librewolf.net/",
        "note": "Official site and FAQ describe LibreWolf as a community-driven open-source Firefox fork with named individual core contributors/maintainers, no company or foundation, and they explicitly refuse donations to avoid administrative overhead."
      },
      "governanceModel": {
        "value": "maintainer-group",
        "citation": "https://librewolf.net/"
      },
      "repositoryUrl": {
        "value": "https://codeberg.org/librewolf",
        "citation": "https://codeberg.org/librewolf"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://librewolf.net/",
            "https://librewolf.net/privacy-policy/",
            "https://librewolf.net/docs/faq/",
            "https://codeberg.org/librewolf/source"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://librewolf.net/",
            "https://librewolf.net/privacy-policy/",
            "https://librewolf.net/docs/faq/",
            "https://codeberg.org/librewolf/source"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://librewolf.net/",
            "https://librewolf.net/privacy-policy/",
            "https://librewolf.net/docs/faq/",
            "https://codeberg.org/librewolf/source"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1024,
    "slug": "searxng",
    "domain": "searxng.org",
    "name": "SearXNG",
    "type": "Privacy Tools",
    "cat": "privacy",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Free",
    "limits": {
      "daily": null
    },
    "features": [
      "Self-hosted",
      "Metasearch engine",
      "No tracking",
      "No logging",
      "Open source",
      "70+ engines",
      "Tor-compatible",
      "No account required"
    ],
    "networks": [],
    "badge": "SELF-HOSTED",
    "url": "https://searxng.org/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-22",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Privacy Tools"
    ],
    "description": "Open-source metasearch engine aggregating up to 276 services, whose docs state users are not tracked or profiled.",
    "cardSummary": "Metasearch across up to 276 services.",
    "jurisdiction": "??",
    "auditedBy": [],
    "twitter": null,
    "founderIntel": "Fork of SearX by a European open-source community (Alexandre Flament and contributors). No company, no legal entity. Fully pseudonymous and community-maintained. No intelligence contractor connections. Originally SearX created by Adam Tauber (Hungarian).",
    "vcIntel": "No VC. No funding. Volunteer-maintained open source project. No revenue model. Anyone can run an instance - no central server to subpoena. The architecture itself is the privacy protection.",
    "privacyWarning": "Privacy depends on the selected instance. Public instances can log or misconfigure requests; self-host or use a trusted operator for sensitive searches.",
    "stateActorFlag": null,
    "tagline": "Self-hosted metasearch. No tracking. 70+ engines. Run your own or use a trusted instance.",
    "bestFor": [
      "Private web search",
      "Self-hosters",
      "Google alternative"
    ],
    "kycNote": "No account or identity KYC for the software; self-hosting avoids relying on a public instance operator.",
    "updatedAt": "2026-06-22",
    "followTheMoney": "SearXNG - community project\nMaintainers: community contributors\nFunding: donations and volunteer work\nRevenue: no advertising model\nHosting: public instances or self-hosted\nOrigin: fork of SearX",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_5_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "unresolved",
        "citation": "unknown",
        "note": "Pass 1 researched this service but established no registry facts."
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://docs.searxng.org/",
            "https://docs.searxng.org/own-instance.html",
            "https://docs.searxng.org/user/about.html",
            "https://raw.githubusercontent.com/searxng/searxng/master/SECURITY.md",
            "https://github.com/searxng/searxng/security/advisories",
            "https://searxng.org/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://docs.searxng.org/",
            "https://docs.searxng.org/own-instance.html",
            "https://docs.searxng.org/user/about.html",
            "https://raw.githubusercontent.com/searxng/searxng/master/SECURITY.md",
            "https://github.com/searxng/searxng/security/advisories",
            "https://searxng.org/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://docs.searxng.org/",
            "https://docs.searxng.org/own-instance.html",
            "https://docs.searxng.org/user/about.html",
            "https://raw.githubusercontent.com/searxng/searxng/master/SECURITY.md",
            "https://github.com/searxng/searxng/security/advisories",
            "https://searxng.org/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1025,
    "slug": "phoenix-wallet",
    "domain": "phoenix.acinq.co",
    "name": "Phoenix Wallet",
    "type": "Wallet",
    "cat": "wallet",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0.4
    },
    "fee": "Lightning send: 0.4% + 4 sat; liquidity: 1% + mining fees; channel creation: 1,000 sat; other on-chain mining fees vary.",
    "limits": {
      "daily": null
    },
    "features": [
      "Self-custodial",
      "No account required",
      "Lightning native",
      "Automated channel management",
      "Taproot on-chain addresses",
      "12-word seed backup",
      "Open source",
      "iOS + Android"
    ],
    "networks": [
      "BTC",
      "Lightning"
    ],
    "badge": "LIGHTNING",
    "url": "https://phoenix.acinq.co/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Wallet"
    ],
    "description": "Self-custodial Lightning wallet by ACINQ that manages channels automatically behind a 12-word seed.",
    "cardSummary": "Self-custodial Lightning wallet by ACINQ.",
    "jurisdiction": "FR",
    "auditedBy": [],
    "twitter": "https://x.com/PhoenixWallet",
    "founderIntel": "ACINQ (Paris, France). Founded by Pierre-Marie Padiou and Fabrice Drouin - French engineers who are core Lightning Network contributors. Built the Eclair Lightning implementation. ACINQ is one of the most technically credible Lightning teams. No intelligence contractor history, no state-actor connections.",
    "vcIntel": "ACINQ raised €8M Series A (2019) from Serena (French VC), Idinvest Partners, business angels. No US VC, no surveillance-adjacent investors. French company. EU jurisdiction (GDPR). Phoenix is non-custodial so ACINQ cannot access user funds.",
    "privacyWarning": "Self-custodial but ACINQ is the Lightning service provider. Phoenix's current FAQ says ACINQ knows the final destination and amount of payments. Channel operations depend on ACINQ availability, although emergency force-close recovery remains available.",
    "stateActorFlag": null,
    "tagline": "Self-custodial Lightning. No account. Your keys, your coins.",
    "bestFor": [
      "Lightning payments",
      "Self-custody",
      "Beginner Lightning"
    ],
    "kycNote": "No account. No email. No phone. 12-word seed only.",
    "updatedAt": "2026-08-25",
    "followTheMoney": "  ACINQ SAS - Paris, France (FR)\n  ──────────────────────────────────────\n  Founders: Pierre-Marie Padiou + Fabrice\n  Series A: €8M (Serena, Idinvest, FR)\n  Revenue: LSP routing fees on Phoenix\n  ├─ Core Lightning Network contributors\n  ├─ EU jurisdiction (GDPR, not Five Eyes)\n  └─ Non-custodial: funds inaccessible",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "https://phoenix.acinq.co/faq/",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://github.com/acinq/phoenix",
        "note": "Phoenix is explicitly developed and published by ACINQ (French SAS), as stated on the canonical GitHub repository, App Store/Google Play listings, and ACINQ website; ACINQ operates the service backend and apps."
      },
      "governanceModel": {
        "value": "company-sponsored",
        "citation": "https://github.com/acinq/phoenix"
      },
      "repositoryUrl": {
        "value": "https://github.com/acinq/phoenix",
        "citation": "https://github.com/acinq/phoenix"
      },
      "legalEntity": {
        "value": "ACINQ (SAS, société par actions simplifiée)",
        "citation": "https://www.pappers.fr/entreprise/acinq-804203792"
      },
      "registrationNumber": {
        "value": "804 203 792 R.C.S. Paris (SIREN 804203792)",
        "citation": "https://www.pappers.fr/entreprise/acinq-804203792"
      },
      "registryUrl": {
        "value": "https://www.pappers.fr/entreprise/acinq-804203792",
        "citation": "https://www.pappers.fr/entreprise/acinq-804203792"
      },
      "incorporationJurisdiction": {
        "value": "France (Paris)",
        "citation": "https://www.pappers.fr/entreprise/acinq-804203792"
      },
      "incorporationDate": {
        "value": "2014-08-25",
        "citation": "https://www.pappers.fr/entreprise/acinq-804203792"
      },
      "registeredAddress": {
        "value": "10 RUE DE PENTHIEVRE, 75008 PARIS, France",
        "citation": "https://www.pappers.fr/entreprise/acinq-804203792"
      },
      "officers": {
        "value": [
          "Pierre-Marie Padiou (Président)",
          "ARIANE CONSULTING (Commissaire aux comptes titulaire)",
          "Nicolas Debock (Autre)",
          "Fabrice Drouin (Autre)",
          "SERENA CAPITAL (Autre)"
        ],
        "citation": "https://www.pappers.fr/entreprise/acinq-804203792"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://phoenix.acinq.co/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://phoenix.acinq.co/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://phoenix.acinq.co/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1026,
    "slug": "zeus-wallet",
    "domain": "zeusln.com",
    "name": "Zeus Wallet",
    "type": "Wallet",
    "cat": "wallet",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Network fees only",
    "limits": {
      "daily": null
    },
    "features": [
      "Connect your own node",
      "Self-hosted",
      "Open source",
      "Tor support",
      "No account required",
      "LND / CLN / Eclair",
      "Lightning + On-chain",
      "ZEUS Pay (embedded node)",
      "Custom Mempool instance",
      "12/24-word LDK seeds",
      "Embedded LND 0.21.2-beta",
      "Cashu CDK 0.17.4",
      "Complete wallet data wipes",
      "NWC expiry and budget hardening",
      "Expired invoice and payment submission guards",
      "BIP353 DNSSEC validation",
      "SHA-256-verified native libraries",
      "Sensitive log scrubbing"
    ],
    "networks": [
      "BTC",
      "Lightning"
    ],
    "badge": "SELF-HOSTED",
    "url": "https://zeusln.com/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-23",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Wallet"
    ],
    "description": "Open-source self-custodial Lightning wallet and node manager. Version 13.2.0 adds custom Mempool endpoints, 12/24-word LDK seeds, and security hardening.",
    "cardSummary": "Lightning wallet and node-management app.",
    "jurisdiction": null,
    "auditedBy": [],
    "twitter": "https://x.com/ZeusLN",
    "founderIntel": "Evan Kaloudis founded ZEUS. Atlas 21, Inc., a Delaware corporation, is the operating company identified by ZEUS's official privacy policy. The wallet is open source under AGPLv3 and is maintained with community contributors.",
    "publicClaims": {
      "founderIntel": {
        "value": "Evan Kaloudis founded ZEUS. Atlas 21, Inc., a Delaware corporation, is the operating company identified by ZEUS's official privacy policy. The wallet is open source under AGPLv3 and is maintained with community contributors.",
        "reviewedAt": "2026-08-23",
        "sources": [
          {
            "label": "ZEUS privacy policy",
            "href": "https://zeusln.com/privacy-policy",
            "type": "official"
          },
          {
            "label": "ZEUS source repository",
            "href": "https://github.com/ZeusLN/zeus",
            "type": "official"
          }
        ]
      }
    },
    "vcIntel": "No VC or institutional funding is recorded in this review. ZEUS is free and open source; the v13.2.0 release post points users to ZEUS Pay+ or donations to support development.",
    "privacyWarning": "Best privacy requires connecting to your own node over Tor. Embedded/LSP or Cashu flows add service/provider metadata that does not exist in a pure own-node setup.",
    "stateActorFlag": null,
    "tagline": "Your node, your rules. Lightning wallet for the self-sovereign bitcoiner.",
    "bestFor": [
      "Node operators",
      "Self-sovereign Lightning",
      "Advanced Bitcoin users"
    ],
    "kycNote": "No KYC for app use; no account required when connecting your own node. Hosted/LSP features can still expose metadata to the selected service path.",
    "updatedAt": "2026-08-23",
    "followTheMoney": "  Atlas 21, Inc. - Delaware, US\n  ──────────────────────────────────────\n  Founder: Evan Kaloudis\n  Product: ZEUS Wallet\n  Support: ZEUS Pay+ and donations\n  ├─ Free and open source under AGPLv3\n  ├─ Self-custodial wallet and node tools\n  └─ Connect own node for max privacy",
    "lastReviewed": "2026-08-23",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_zeus_v13_2_release_2026-08-23",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://zeusln.com/privacy-policy",
        "note": "Official privacy policy, website copyright footer, Google Play/App Store developer listings, ZEUS White ToS, and USPTO trademark all identify Atlas 21 Inc. as the operating entity providing the wallet and services."
      },
      "governanceModel": {
        "value": "company-sponsored",
        "citation": "https://zeusln.com/about"
      },
      "repositoryUrl": {
        "value": "https://github.com/ZeusLN/zeus",
        "citation": "https://github.com/ZeusLN/zeus"
      },
      "legalEntity": {
        "value": "Atlas 21, Inc.",
        "citation": "https://uspto.report/TM/98155390"
      },
      "registryUrl": {
        "value": "https://icis.corp.delaware.gov/Ecorp/EntitySearch/NameSearch.aspx",
        "citation": "https://uspto.report/TM/98155390"
      },
      "incorporationJurisdiction": {
        "value": "Delaware, United States",
        "citation": "https://uspto.report/TM/98155390"
      },
      "registeredAddress": {
        "value": "295 East Swedesford Road, Unit 367, Wayne, PENNSYLVANIA 19087, United States",
        "citation": "https://uspto.report/TM/98155390"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://api.github.com/repos/ZeusLN/zeus/releases/latest",
            "https://zeusln.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://api.github.com/repos/ZeusLN/zeus/releases/latest",
            "https://zeusln.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://api.github.com/repos/ZeusLN/zeus/releases/latest",
            "https://zeusln.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1027,
    "slug": "tails-os",
    "domain": "tails.boum.org",
    "name": "Tails OS",
    "type": "Privacy Tools",
    "cat": "privacy",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Free",
    "limits": {
      "daily": null
    },
    "features": [
      "Amnesic live OS",
      "Tor-only network",
      "USB bootable",
      "Leaves no trace",
      "Encrypted persistent storage",
      "Tor Browser included",
      "KeePassXC included",
      "Open source"
    ],
    "networks": [],
    "badge": "OPEN SOURCE",
    "url": "https://tails.boum.org/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-03-13",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Privacy Tools"
    ],
    "description": "Amnesic live operating system booted from USB that routes traffic through Tor and forgets state at shutdown.",
    "cardSummary": "Amnesic live USB routing traffic over Tor.",
    "jurisdiction": "US",
    "auditedBy": [
      "Radically Open Security"
    ],
    "twitter": "https://x.com/Tails_live",
    "founderIntel": "Developed by an international open-source team. Tails merged into The Tor Project in September 2024 and is now operated within The Tor Project, Inc.",
    "vcIntel": "Tails merged into The Tor Project in September 2024. Tor Project donations now support the combined suite; Tails discloses individual, government-related, foundation/NGO and private-company funding categories.",
    "privacyWarning": "Tails does not make a user invisible: local networks can see Tor use, websites can block Tor, exit traffic can be exposed when unencrypted, and powerful end-to-end correlation or compromised hardware can defeat protections.",
    "stateActorFlag": "Tails discloses government-related funding, including US-government-related entities, within the Tor Project’s combined funding base. Its code remains open source and independently audited.",
    "followTheMoney": "  The Tor Project, Inc. - Massachusetts, US\n  ──────────────────────────────────────\n  Tails merged into Tor Project in 2024\n  Donations support the combined tool suite\n  ├─ Individuals are the largest funding share\n  ├─ Government-related funding is disclosed\n  └─ Open-source nonprofit infrastructure",
    "tagline": "The amnesic operating system. Boot anywhere. Leave no trace.",
    "bestFor": [
      "Journalists",
      "Activists",
      "Sensitive tasks on untrusted hardware"
    ],
    "kycNote": "No account. No signup. Download, verify, boot.",
    "updatedAt": "2026-08-15",
    "lastReviewed": "2026-08-15",
    "kycLastChecked": "2026-08-15",
    "reviewSource": "focused_record_review_2026-08-15",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "partial",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "foundation",
        "citation": "https://tails.net/",
        "note": "Official site states Tails is part of the Tor Project, a global nonprofit; Tor and Tails merged operations in 2024 so Tails is operated by the registered 501(c)(3) The Tor Project, Inc."
      },
      "governanceModel": {
        "value": "foundation",
        "citation": "https://blog.torproject.org/tor-tails-join-forces/"
      },
      "repositoryUrl": {
        "value": "https://gitlab.tails.boum.org/tails/tails",
        "citation": "https://gitlab.tails.boum.org/tails/tails"
      },
      "legalEntity": {
        "value": "The Tor Project, Inc.",
        "citation": "https://support.torproject.org/donation/"
      },
      "registrationNumber": {
        "value": "20-8096820",
        "citation": "https://support.torproject.org/donation/"
      },
      "registryUrl": {
        "value": "https://projects.propublica.org/nonprofits/organizations/208096820",
        "citation": "https://projects.propublica.org/nonprofits/organizations/208096820"
      },
      "incorporationJurisdiction": {
        "value": "Massachusetts, United States",
        "citation": "https://www.torproject.org/static/findoc/2023-2024-TheTorProject-PublicDisclosureForm990.pdf?h=d509d409"
      },
      "incorporationDate": {
        "value": "2006-12-22",
        "citation": "https://en.wikipedia.org/wiki/The_Tor_Project"
      },
      "registeredAddress": {
        "value": "390 West Street, Ste. 3 Box 1064, Mansfield MA 02048 USA",
        "citation": "https://support.torproject.org/donation/"
      },
      "officers": {
        "value": [
          "Isabela Dias Fernandes (Executive Director)",
          "Christian Kaufmann (Chair)",
          "Desigan Chinniah (Vice Chair)",
          "Kendra Albert (Secretary)",
          "Sarah Gran (Treasurer)",
          "Alissa Cooper (Director)",
          "Esra'a Al Shafei (Director)",
          "Julius Mittenzwei (Director)",
          "Maria Xynou (Director)",
          "Roger Dingledine (Co-Founder & Ambassador)",
          "Nick Mathewson (Founder & Network Team Sr Developer)"
        ],
        "citation": "https://projects.propublica.org/nonprofits/organizations/208096820"
      },
      "priorEntities": {
        "value": [
          "Tails (independent open-source project / maintainer collective prior to September 2024 merger into The Tor Project)"
        ],
        "citation": "https://blog.torproject.org/tor-tails-join-forces/"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://tails.net/",
            "https://tails.net/about/index.en.html",
            "https://tails.net/doc/about/warnings/index.en.html",
            "https://tails.net/doc/about/license/index.en.html",
            "https://tails.net/news/version_7.11/",
            "https://tails.net/security/known_security_vulnerabilities_in_7.10.1/",
            "https://tails.net/news/audit_by_ROS_2024/",
            "https://blog.torproject.org/tor-tails-join-forces/",
            "https://support.torproject.org/donation/",
            "https://gitlab.tails.boum.org/api/v4/projects/tails%2Ftails",
            "https://tails.boum.org/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://tails.net/",
            "https://tails.net/about/index.en.html",
            "https://tails.net/doc/about/warnings/index.en.html",
            "https://tails.net/doc/about/license/index.en.html",
            "https://tails.net/news/version_7.11/",
            "https://tails.net/security/known_security_vulnerabilities_in_7.10.1/",
            "https://tails.net/news/audit_by_ROS_2024/",
            "https://blog.torproject.org/tor-tails-join-forces/",
            "https://support.torproject.org/donation/",
            "https://gitlab.tails.boum.org/api/v4/projects/tails%2Ftails",
            "https://tails.boum.org/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://tails.net/",
            "https://tails.net/about/index.en.html",
            "https://tails.net/doc/about/warnings/index.en.html",
            "https://tails.net/doc/about/license/index.en.html",
            "https://tails.net/news/version_7.11/",
            "https://tails.net/security/known_security_vulnerabilities_in_7.10.1/",
            "https://tails.net/news/audit_by_ROS_2024/",
            "https://blog.torproject.org/tor-tails-join-forces/",
            "https://support.torproject.org/donation/",
            "https://gitlab.tails.boum.org/api/v4/projects/tails%2Ftails",
            "https://tails.boum.org/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1028,
    "slug": "whonix",
    "domain": "whonix.org",
    "name": "Whonix",
    "type": "Privacy Tools",
    "cat": "privacy",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Free",
    "limits": {
      "daily": null
    },
    "features": [
      "Two-VM architecture",
      "Tor gateway isolation",
      "IP leak prevention",
      "Persistent anonymous workspace",
      "Qubes OS compatible",
      "Open source",
      "KVM / VirtualBox",
      "Fingerprinting resistance"
    ],
    "networks": [],
    "badge": "ADVANCED",
    "url": "https://www.whonix.org/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-24",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Privacy Tools"
    ],
    "description": "Operating system splitting a Tor gateway and workstation across two VMs to keep the real IP off the workstation.",
    "cardSummary": "Two-VM system splitting Tor gateway and desktop.",
    "jurisdiction": "MH",
    "auditedBy": [],
    "twitter": "https://x.com/Whonix",
    "founderIntel": "Patrick Schleizer, publicly known as adrelanos, is founder and lead developer. ENCRYPTED SUPPORT LLC is the registered operator named in Whonix’s imprint.",
    "vcIntel": "Current monetary sponsors listed by Whonix are FUTO and Power Up Privacy. Open Technology Fund support is recorded as a past 2015 grant, not current funding.",
    "privacyWarning": "Runs as virtual machines - requires a trusted host OS. Combine with Qubes OS for strongest isolation. More complex setup than Tails but offers persistent anonymous workspace.",
    "stateActorFlag": "Whonix records a historical 2015 Open Technology Fund grant. Its current listed monetary sponsors are FUTO and Power Up Privacy.",
    "tagline": "Tor-routed VM workstation. Anonymity even if the OS is compromised.",
    "bestFor": [
      "Advanced OPSEC",
      "Persistent anonymous workspace",
      "High-risk users"
    ],
    "kycNote": "No account. No signup. Free download.",
    "updatedAt": "2026-08-15",
    "followTheMoney": "  Whonix / ENCRYPTED SUPPORT LLC\n  ──────────────────────────────────────\n  Lead: Patrick Schleizer (adrelanos)\n  Current sponsors: FUTO and Power Up Privacy\n  ├─ OTF support was a past 2015 grant\n  ├─ Open-source project funded by sponsorships\n  └─ Operator registered in Marshall Islands",
    "lastReviewed": "2026-08-15",
    "kycLastChecked": "2026-08-15",
    "reviewSource": "focused_record_review_2026-08-15",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "partial",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://www.whonix.org/wiki/Imprint",
        "note": "Official Imprint, Terms of Service, and Privacy Policy name ENCRYPTED SUPPORT LLC as the operator of the website and services."
      },
      "governanceModel": {
        "value": "company-sponsored",
        "citation": "https://www.whonix.org/wiki/Contributors"
      },
      "repositoryUrl": {
        "value": "https://github.com/Whonix",
        "citation": "https://github.com/Whonix"
      },
      "legalEntity": {
        "value": "ENCRYPTED SUPPORT LLC (A Series of OTOCO RMI LLC)",
        "citation": "https://www.whonix.org/wiki/Imprint"
      },
      "registrationNumber": {
        "value": "966308",
        "citation": "https://www.whonix.org/wiki/Imprint"
      },
      "incorporationJurisdiction": {
        "value": "Marshall Islands",
        "citation": "https://www.whonix.org/wiki/Imprint"
      },
      "incorporationDate": {
        "value": "2023-12-04",
        "citation": "https://www.whonix.org/wiki/Imprint"
      },
      "registeredAddress": {
        "value": "Trust Company Complex, Ajeltake Road, Ajeltake Island, Majuro, MH96960, Marshall Islands",
        "citation": "https://www.whonix.org/wiki/Imprint"
      },
      "parentEntity": {
        "value": "OTOCO RMI LLC",
        "citation": "https://www.whonix.org/wiki/Imprint"
      },
      "officers": {
        "value": [
          "Patrick Schleizer (founder and lead developer)"
        ],
        "citation": "https://www.whonix.org/wiki/Patrick_Schleizer"
      },
      "priorEntities": {
        "value": [
          "ENCRYPTED SUPPORT LP (Ontario Limited Partnership No. 280096637, Canada)"
        ],
        "citation": "https://www.encrypted-support.com/"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.whonix.org/",
            "https://www.whonix.org/wiki/Security_Guide"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.whonix.org/",
            "https://www.whonix.org/wiki/Security_Guide"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.whonix.org/",
            "https://www.whonix.org/wiki/Security_Guide"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1029,
    "slug": "azteco",
    "domain": "azte.co",
    "name": "Azteco",
    "type": "Gift Cards",
    "cat": "gift-cards",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 2
    },
    "fee": "~2-5% markup",
    "limits": {
      "daily": 1000
    },
    "features": [
      "Cash purchase option",
      "No account required",
      "190+ countries",
      "Lightning or on-chain",
      "Voucher-based",
      "No KYC up to $1,000",
      "Retail locations",
      "Bitcoin only"
    ],
    "networks": [
      "BTC",
      "Lightning"
    ],
    "badge": "CASH ACCEPTED",
    "url": "https://azte.co/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-24",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Gift Cards",
      "Merchants"
    ],
    "description": "Bitcoin vouchers bought with cash at retail in 190+ countries, redeemed to any Bitcoin or Lightning address.",
    "cardSummary": "Bitcoin vouchers bought with cash in 190+ countries.",
    "jurisdiction": "GB",
    "auditedBy": [],
    "twitter": "https://x.com/Azteco_co",
    "founderIntel": "Akin Fernandez is the London-based founder. Azteco sells Bitcoin vouchers through retail and online channels.",
    "vcIntel": "Jack Dorsey (Block/Square) invested $12M in Azteco in 2023. Block Inc is a US company - but investment in a voucher network does not create data access. No intelligence firm connections. UK jurisdiction (Five Eyes) for the company.",
    "privacyWarning": "The company is based in the UK. Cash retail purchases can avoid an online card trail. Online card purchases expose payment details. Block is an investor.",
    "stateActorFlag": null,
    "tagline": "Bitcoin vouchers. Buy with cash. No account. 190 countries.",
    "bestFor": [
      "Cash Bitcoin on-ramp",
      "Gift Bitcoin to anyone",
      "No-account Bitcoin purchase"
    ],
    "kycNote": "Voucher redemption does not require KYC. A retailer may still collect payment or purchase data.",
    "updatedAt": "2026-03-13",
    "followTheMoney": "  Azteco Ltd - London, UK (GB)\n  ──────────────────────────────────────\n  Founder: Akin Fernandez (Bitcoin edu)\n  Seed: $6M led by Jack Dorsey\n  Revenue: 2–5% voucher markup\n  ├─ UK company, Five Eyes jurisdiction\n  ├─ Block Inc: US payments empire\n  └─ Cash retail purchase = zero exposure",
    "lastReviewed": "2026-07-05",
    "kycLastChecked": "2026-03-13",
    "reviewSource": "legacy_seed_unverified",
    "jurisdictionConfidence": "inferred",
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://azte.co/legal/terms",
        "note": "Official Terms of Service, Privacy Policy and Imprint state the Services are operated by Azteco Holdings USA, Inc.; UK Companies House overseas-company registration FC042098 confirms it as a Delaware private limited company with registration number 4594652."
      },
      "legalEntity": {
        "value": "Azteco Holdings USA, Inc.",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/FC042098"
      },
      "registrationNumber": {
        "value": "4594652",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/FC042098"
      },
      "registryUrl": {
        "value": "https://find-and-update.company-information.service.gov.uk/company/FC042098",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/FC042098"
      },
      "incorporationJurisdiction": {
        "value": "Delaware, United States",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/FC042098"
      },
      "registeredAddress": {
        "value": "1716 12th Street, Santa Monica, CA 90404, USA",
        "citation": "https://azte.co/legal/imprint"
      },
      "officers": {
        "value": [
          "Paul Ferguson (Director)",
          "Alexander Akintokunbo Fernandez (Director)"
        ],
        "citation": "https://find-and-update.company-information.service.gov.uk/company/FC042098/officers"
      },
      "priorEntities": {
        "value": [
          "AZTECO LTD. (UK Companies House 11296915, dissolved 2021-01-19)",
          "AZTECO HOLDINGS LTD. (UK Companies House 12062763, dissolved 2024-01-30)"
        ],
        "citation": "https://find-and-update.company-information.service.gov.uk/officers/SiHPq9mk-cC3IxcxEm4Knup0DqM/appointments"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://azte.co/",
            "https://azte.co/legal/terms",
            "https://azte.co/legal/privacy",
            "https://azte.co/faq"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://azte.co/",
            "https://azte.co/legal/terms",
            "https://azte.co/legal/privacy",
            "https://azte.co/faq"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://azte.co/",
            "https://azte.co/legal/terms",
            "https://azte.co/legal/privacy",
            "https://azte.co/faq"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1030,
    "slug": "coldcard",
    "domain": "coldcard.com",
    "name": "Coldcard",
    "type": "Wallet",
    "cat": "wallet",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "$147-$199 (one-time hardware)",
    "limits": {
      "daily": null
    },
    "features": [
      "Air-gapped signing",
      "Bitcoin-only",
      "Open source firmware",
      "Duress PIN",
      "PSBT via MicroSD",
      "Sparrow compatible",
      "No computer required",
      "Secure element (SE2)"
    ],
    "networks": [
      "BTC"
    ],
    "badge": "HARDWARE",
    "url": "https://coldcard.com/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Wallet",
      "Privacy Tools"
    ],
    "description": "Bitcoin-only air-gapped hardware signer by Coinkite with PSBT signing over MicroSD or QR and duress PIN support.",
    "cardSummary": "Bitcoin-only air-gapped hardware signer.",
    "jurisdiction": "CA",
    "auditedBy": [],
    "twitter": "https://x.com/COLDCARDwallet",
    "founderIntel": "Rodolfo Novak (NVK) and Peter D (Canadian team). Coinkite Inc - Toronto, Canada. No intelligence contractor history. NVK is a well-known Bitcoin privacy advocate and long-time community member. Paranoid-level opsec culture.",
    "vcIntel": "Coinkite is self-funded and bootstrapped. No VC investors. No institutional money. Revenue from hardware sales only. Canadian company - Five Eyes jurisdiction but hardware products create no server-side data exposure. Firmware is open source and auditable.",
    "privacyWarning": "Canada = Five Eyes jurisdiction, but Coldcard is a hardware product - Coinkite holds no user data or keys. Purchase anonymously (use a P.O. box or privacy-preserving shipping). Order with Monero or cash-equivalent if possible. Firmware is open source.",
    "stateActorFlag": null,
    "tagline": "Bitcoin-only. Air-gapped. The hardware signer that trusts nothing.",
    "bestFor": [
      "Cold storage",
      "Air-gapped Bitcoin signing",
      "Maximum self-custody"
    ],
    "kycNote": "No account, no KYC for firmware use. Hardware purchase may expose shipping address.",
    "updatedAt": "2026-08-25",
    "followTheMoney": "  Coinkite Inc - Toronto, Canada (CA)\n  ──────────────────────────────────────\n  Founders: Rodolfo Novak (NVK) + Peter D\n  Funding: bootstrapped, hardware sales\n  Revenue: $147–$199 per unit\n  ├─ Five Eyes (CA) - hardware only\n  ├─ No server data: firmware = open src\n  └─ Order anonymously (XMR/cash/PO box)",
    "lastReviewed": "2026-05-15",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "https://coldcard.com/security/status",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "danger",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://coldcard.com/about",
        "note": "Official Coldcard about page and Coinkite terms state Coldcard is made by Coinkite Inc., a real operating Canadian vendor/shop."
      },
      "governanceModel": {
        "value": "company-sponsored",
        "citation": "https://coldcard.com/about"
      },
      "repositoryUrl": {
        "value": "https://github.com/Coldcard/firmware",
        "citation": "https://github.com/Coldcard/firmware"
      },
      "legalEntity": {
        "value": "Coinkite Inc.",
        "citation": "https://coldcard.com/about"
      },
      "incorporationJurisdiction": {
        "value": "Ontario, Canada",
        "citation": "https://coinkite.com/terms-of-use"
      },
      "registeredAddress": {
        "value": "3219 Yonge St., Unit 376, Toronto, ON M4N 3S1, Canada",
        "citation": "https://coinkite.com/terms-of-use"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://coldcard.com/security/status",
            "https://x.com/COLDCARDwallet/status/2083155034762621425",
            "https://x.com/Coinkite/status/2084630256296624637",
            "https://x.com/COLDCARDwallet/status/2090459345301488071",
            "https://coldcard.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://coldcard.com/security/status",
            "https://x.com/COLDCARDwallet/status/2083155034762621425",
            "https://x.com/Coinkite/status/2084630256296624637",
            "https://x.com/COLDCARDwallet/status/2090459345301488071",
            "https://coldcard.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://coldcard.com/security/status",
            "https://x.com/COLDCARDwallet/status/2083155034762621425",
            "https://x.com/Coinkite/status/2084630256296624637",
            "https://x.com/COLDCARDwallet/status/2090459345301488071",
            "https://coldcard.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1031,
    "slug": "foundation-passport",
    "domain": "foundation.xyz",
    "name": "Foundation Passport Prime",
    "type": "Wallet",
    "cat": "wallet",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Passport Prime listed at €384.95 (locale/tax dependent)",
    "limits": {
      "daily": null
    },
    "features": [
      "Bitcoin wallet",
      "Offline 2FA codes",
      "NFC/USB security keys",
      "50GB encrypted storage",
      "KeyOS microkernel",
      "Sandboxed open-source apps",
      "Encrypted QuantumLink Bluetooth",
      "Envoy companion app",
      "Physical approval"
    ],
    "networks": [
      "BTC"
    ],
    "badge": "HARDWARE",
    "url": "https://foundation.xyz/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Wallet"
    ],
    "description": "Passport Prime is open-source human-authority hardware combining a Bitcoin wallet, offline 2FA codes, NFC/USB security keys, 50GB encrypted storage and sandboxed KeyOS apps.",
    "cardSummary": "Passport Prime for Bitcoin keys, 2FA and encrypted files.",
    "jurisdiction": "US",
    "auditedBy": [
      "Keylabs (Passport Prime hardware audit, 2025)"
    ],
    "twitter": "https://x.com/FOUNDATIONdvcs",
    "founderIntel": "Zach Herbert (CEO), Ken Carpenter - Foundation Devices Inc, Denver Colorado, US. No intelligence contractor history. VC-funded startup focused on Bitcoin-only hardware. No known surveillance connections.",
    "vcIntel": "Foundation raised $7M Series A (2021). Investors: SV Angel (US VC), Lightning Ventures, Ten31 (Bitcoin-only fund), Trammell Venture Partners. SV Angel has broad portfolio (Airbnb, Twitter etc) - no intelligence firm ties. Ten31 is Bitcoin-only focused. US company - Five Eyes for the company entity, but hardware holds no server-side data.",
    "privacyWarning": "Foundation is a US company. Passport keeps keys on the device and publishes its hardware and firmware source. Purchase and shipping records can still identify the buyer.",
    "stateActorFlag": null,
    "tagline": "Open source Bitcoin hardware wallet. QR-only, air-gapped, no USB.",
    "bestFor": [
      "Cold storage",
      "Open source hardware",
      "QR-based signing"
    ],
    "kycNote": "No account needed. No KYC. Hardware purchase may expose shipping address.",
    "updatedAt": "2026-08-25",
    "followTheMoney": "  Foundation Devices Inc - Denver, CO (US)\n  ──────────────────────────────────────\n  CEO: Zach Herbert · Series A: $7M\n  Investors: SV Angel, Ten31, Lightning V.\n  Revenue: $199/unit hardware sales\n  ├─ Five Eyes (US) - hardware only\n  ├─ Open source HW + FW, auditable\n  └─ No server data: QR-only air-gapped",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "primary_source_rereview_2026-08-25",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://foundation.xyz/policies/imprint",
        "note": "Official imprint, terms, copyright notices, and SEC Form D filings identify Foundation Devices, Inc. as the Delaware corporation operating the service and selling the hardware."
      },
      "governanceModel": {
        "value": "company-sponsored",
        "citation": "https://foundation.xyz/policies/terms-of-service"
      },
      "repositoryUrl": {
        "value": "https://github.com/Foundation-Devices",
        "citation": "https://github.com/Foundation-Devices"
      },
      "legalEntity": {
        "value": "Foundation Devices, Inc.",
        "citation": "https://foundation.xyz/policies/imprint"
      },
      "registrationNumber": {
        "value": "0001877524",
        "citation": "https://www.sec.gov/Archives/edgar/data/1877524/000187752421000002/xslFormDX01/primary_doc.xml"
      },
      "registryUrl": {
        "value": "https://www.sec.gov/cgi-bin/browse-edgar?action=getcompany&CIK=0001877524",
        "citation": "https://www.sec.gov/Archives/edgar/data/1877524/000187752421000002/xslFormDX01/primary_doc.xml"
      },
      "incorporationJurisdiction": {
        "value": "Delaware, United States",
        "citation": "https://www.sec.gov/Archives/edgar/data/1877524/000187752421000002/xslFormDX01/primary_doc.xml"
      },
      "incorporationDate": {
        "value": "2020",
        "citation": "https://www.sec.gov/Archives/edgar/data/1877524/000187752421000002/xslFormDX01/primary_doc.xml"
      },
      "registeredAddress": {
        "value": "6 Liberty Square #6018, Boston, MA 02109, United States",
        "citation": "https://foundation.xyz/policies/imprint"
      },
      "officers": {
        "value": [
          "Zachary Herbert (CEO, Director, Cofounder)",
          "Kenneth Carpenter (CTO, Director, Cofounder)",
          "Oleg Mikhalskiy (Director)",
          "Jacob Johnston (Cofounder & VP of Operations)"
        ],
        "citation": "https://www.sec.gov/Archives/edgar/data/1877524/000187752426000002/xslFormDX01/primary_doc.xml"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://foundation.xyz/",
            "https://foundation.xyz/security",
            "https://foundation.xyz/policies/terms-of-service"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://foundation.xyz/",
            "https://foundation.xyz/security",
            "https://foundation.xyz/policies/terms-of-service"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://foundation.xyz/",
            "https://foundation.xyz/security",
            "https://foundation.xyz/policies/terms-of-service"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1032,
    "slug": "seedsigner",
    "domain": "seedsigner.com",
    "name": "SeedSigner",
    "type": "Wallet",
    "cat": "wallet",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "~$50-70 (DIY parts)",
    "limits": {
      "daily": null
    },
    "features": [
      "DIY hardware signer",
      "Stateless (no key storage)",
      "Air-gapped QR signing",
      "Open source",
      "Raspberry Pi Zero",
      "No persistent storage",
      "SeedQR backup format",
      "Bitcoin-only"
    ],
    "networks": [
      "BTC"
    ],
    "badge": "OPEN SOURCE",
    "url": "https://seedsigner.com/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-24",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Wallet",
      "Privacy Tools"
    ],
    "description": "DIY stateless Bitcoin signing device built from Raspberry Pi Zero parts, using air-gapped QR code signing.",
    "cardSummary": "DIY stateless signer built from a Pi Zero.",
    "jurisdiction": null,
    "auditedBy": [],
    "twitter": "https://x.com/SeedSigner",
    "founderIntel": "Anonymous/pseudonymous community project. No company, no legal entity, no commercial interests. Built by Bitcoin community volunteers. No intelligence contractor connections. Source of parts is verifiable commodity hardware.",
    "vcIntel": "No VC. No company. No revenue model. 100% volunteer open source project. HRF (Human Rights Foundation) grant recipient for open source Bitcoin development. No OFAC designation. No third-party manufacturer trust required - you build it from standard Raspberry Pi components.",
    "privacyWarning": null,
    "stateActorFlag": null,
    "tagline": "DIY stateless Bitcoin signer. Build it yourself. Trust nothing. Own everything.",
    "bestFor": [
      "Maximum sovereignty",
      "DIY hardware",
      "Privacy-first cold storage"
    ],
    "kycNote": "No account. No KYC. Build from commodity parts. No manufacturer trust required.",
    "updatedAt": "2026-03-13",
    "followTheMoney": "  SeedSigner - Community / Decentralised\n  ──────────────────────────────────────\n  Team: anonymous volunteer community\n  Funders: HRF Bitcoin dev grants\n  Revenue: none (free firmware)\n  ├─ No company, no manufacturer trust\n  ├─ Raspberry Pi Zero parts (~$50–70)\n  └─ Stateless: powers off, no key store",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_2_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "project-no-legal-entity",
        "citation": "https://github.com/SeedSigner/seedsigner",
        "note": "Official GitHub README states 'Created and maintained by volunteers. There is no corporation. No profit motive.'; website and other sources describe it solely as a volunteer FOSS DIY project with no registered entity."
      },
      "governanceModel": {
        "value": "maintainer-group",
        "citation": "https://bitcoin.design/guide/case-studies/seedsigner/"
      },
      "repositoryUrl": {
        "value": "https://github.com/SeedSigner/seedsigner",
        "citation": "https://github.com/SeedSigner/seedsigner"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://github.com/SeedSigner/seedsigner",
            "https://github.com/SeedSigner/seedsigner/releases",
            "https://seedsigner.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://github.com/SeedSigner/seedsigner",
            "https://github.com/SeedSigner/seedsigner/releases",
            "https://seedsigner.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://github.com/SeedSigner/seedsigner",
            "https://github.com/SeedSigner/seedsigner/releases",
            "https://seedsigner.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1033,
    "slug": "xmrbazaar",
    "domain": "xmrbazaar.com",
    "name": "XMR Bazaar",
    "type": "P2P",
    "cat": "p2p",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Free (no platform fee)",
    "limits": {
      "daily": null
    },
    "features": [
      "P2P Monero trading",
      "No KYC",
      "No fund custody",
      "No IP logging",
      "PGP encrypted comms",
      "Pseudonymous accounts",
      "Email optional",
      "Monero-only"
    ],
    "networks": [
      "XMR"
    ],
    "badge": "MONERO",
    "url": "https://xmrbazaar.com/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-26",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "P2P"
    ],
    "description": "Peer-to-peer Monero marketplace for goods, jobs, rentals and fiat trades with optional client-side escrow.",
    "cardSummary": "Peer-to-peer Monero marketplace.",
    "jurisdiction": null,
    "auditedBy": [],
    "twitter": null,
    "founderIntel": "Unknown/pseudonymous team. No company disclosed. Relatively new service in the Monero ecosystem. No known intelligence contractor connections. Community-vetted but limited independent review.",
    "vcIntel": "No VC. No known investors. Small community project. Limited public information about operators. Unvetted - research independently before large transactions.",
    "privacyWarning": "Direct trades are between users, and XmrBazaar says it cannot refund lost money or products. Optional multisig mediators and bond holders are fellow users rather than platform employees or agents. The terms say the platform cannot guarantee security, remains in beta, and escrow may still have bugs; avoid large trades without careful counterparty and mediator review.",
    "stateActorFlag": null,
    "tagline": "Peer-to-peer Monero. No KYC, no custody, no logging.",
    "bestFor": [
      "P2P Monero trading",
      "XMR-to-fiat",
      "No-custody exchange"
    ],
    "kycNote": "Official terms say no KYC; username and password are required, email is optional for resets/notifications.",
    "updatedAt": "2026-06-22",
    "followTheMoney": "  XMR Bazaar - Pseudonymous / Global\n  ──────────────────────────────────────\n  Operators: unknown/anonymous team\n  Funding: zero VC, no investors known\n  Revenue: no platform fee (unvetted)\n  ├─ No custody: XMR never held\n  ├─ No IP logging, PGP comms\n  └─ Unvetted - use small amounts only",
    "lastReviewed": "2026-08-26",
    "kycLastChecked": "2026-08-26",
    "reviewSource": "Primary-source review 2026-08-26",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "unresolved",
        "citation": "unknown",
        "note": "Pass 1 researched this service but established no registry facts."
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "noncustodial-hosted",
      "sourceModel": "partial"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-26",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://xmrbazaar.com/terms/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "terms enumerate pseudonymous account and marketplace-content records despite no IP logs"
        },
        "controlModel": {
          "value": "noncustodial-hosted",
          "sourceUrls": [
            "https://xmrbazaar.com/about/",
            "https://xmrbazaar.com/terms/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "official about/terms say the hosted marketplace does not hold funds or process transactions"
        },
        "sourceModel": {
          "value": "partial",
          "sourceUrls": [
            "https://raw.githubusercontent.com/xmrbazaar/.github/main/profile/README.md",
            "https://raw.githubusercontent.com/xmrbazaar/.github/main/SECURITY.md"
          ],
          "reviewedAt": "2026-08-26",
          "note": "official repository explicitly limits published source to mobile UX/UI and excludes production website/API/backend"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "no-score-points-no-cap-exception"
      }
    }
  },
  {
    "id": 1034,
    "slug": "addy-io",
    "domain": "addy.io",
    "name": "addy.io",
    "type": "Email",
    "cat": "email",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Free / $1/mo Lite / $4/mo Pro",
    "limits": {
      "daily": null
    },
    "features": [
      "Email aliasing",
      "No KYC",
      "XMR payment accepted",
      "Open source",
      "Self-hostable",
      "Securitum audited",
      "Unlimited aliases (free tier)",
      "Custom domains"
    ],
    "networks": [],
    "badge": "OPEN SOURCE",
    "url": "https://addy.io/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-27",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Email",
      "Privacy Tools"
    ],
    "description": "Open-source email aliasing service supporting self-hosting and crypto subscriptions for yearly plans.",
    "cardSummary": "Email aliasing, self-hostable, crypto accepted.",
    "jurisdiction": "GB",
    "auditedBy": [
      "Securitum"
    ],
    "twitter": "https://x.com/addyio",
    "founderIntel": "Will Browning - solo founder (UK). Open source developer. No company structure or employee list. No intelligence contractor connections. Previously operated as AnonAddy. Well-regarded in the privacy community.",
    "vcIntel": "No VC. No investors. Solo developer project. Revenue from paid subscriptions. XMR accepted for anonymous payment. Open source - can be self-hosted to remove UK jurisdiction concern entirely.",
    "privacyWarning": "Terms are governed by England and Wales. addy.io stores service data on UpCloud servers in the Netherlands, retains Nginx/Postfix logs with IP addresses for 3 days, and can disclose when compelled by law. Open source and self-hostable if UK/legal-process risk is unacceptable.",
    "stateActorFlag": null,
    "tagline": "Unlimited email aliases. No KYC. XMR accepted. Self-hostable.",
    "bestFor": [
      "Email aliasing",
      "Inbox privacy",
      "Stop spam and tracking"
    ],
    "kycNote": "No document KYC found. Registration/subscription can create account, recipient, name and payment metadata; crypto subscriptions are processed by NOWPayments and support BTC, XMR, ETH and other coins.",
    "updatedAt": "2026-06-22",
    "followTheMoney": "addy.io - United Kingdom\nFounder: Will Browning\nFunding: subscriptions\nRevenue: paid plans\nSoftware: open source with a self-hosted option\nAudit: Securitum, 2023",
    "lastReviewed": "2026-08-27",
    "kycLastChecked": "2026-08-27",
    "reviewSource": "Primary-source review 2026-08-27",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://play.google.com/store/apps/details?id=host.stjin.anonaddy&hl=en_US",
        "note": "Google Play and Apple App Store list seller/developer as Who Dares Gains Ltd with matching UK address and contact@help.addy.io; UK trademark ADDY.IO is held by the same company; hosted paid service under England and Wales law."
      },
      "governanceModel": {
        "value": "individual",
        "citation": "https://addy.io/faq/"
      },
      "repositoryUrl": {
        "value": "https://github.com/anonaddy/anonaddy",
        "citation": "https://github.com/anonaddy/anonaddy"
      },
      "legalEntity": {
        "value": "WHO DARES GAINS LTD",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/14499841"
      },
      "registrationNumber": {
        "value": "14499841",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/14499841"
      },
      "registryUrl": {
        "value": "https://find-and-update.company-information.service.gov.uk/company/14499841",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/14499841"
      },
      "incorporationJurisdiction": {
        "value": "United Kingdom (England and Wales)",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/14499841"
      },
      "incorporationDate": {
        "value": "2022-11-22",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/14499841"
      },
      "registeredAddress": {
        "value": "Belmont Suite, Paragon Business Park, Chorley New Road, Horwich, Bolton, England, BL6 6HG",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/14499841"
      },
      "ultimateOwner": {
        "value": "William Harvey Browning (ownership of shares 75% or more; voting rights 75% or more)",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/14499841/persons-with-significant-control"
      },
      "officers": {
        "value": [
          "William Harvey Browning (Director, appointed 2022-11-22)",
          "Chelsea Madeleine Browning (Director, appointed 2025-12-01)",
          "Chelsea Browning (Secretary, appointed 2023-03-24)"
        ],
        "citation": "https://find-and-update.company-information.service.gov.uk/company/14499841/officers"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "hosted-account",
      "sourceModel": "open"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://addy.io/security/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "username, recipient email, aliases, delivery metadata, IP/session and payment metadata"
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://addy.io/security/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "hybrid-hosted-or-self-hosted"
        },
        "sourceModel": {
          "value": "open",
          "sourceUrls": [
            "https://github.com/anonaddy/anonaddy"
          ],
          "reviewedAt": "2026-08-27",
          "note": "open-source-self-hostable"
        }
      },
      "audit": {
        "scoreEligible": true,
        "auditor": "Securitum",
        "completedAt": "2023-09",
        "scope": "addy.io hosted web application",
        "sourceUrls": [
          "https://addy.io/security/"
        ]
      }
    }
  },
  {
    "id": 1035,
    "slug": "monerujo",
    "domain": "monerujo.app",
    "name": "Monerujo",
    "type": "Wallet",
    "cat": "wallet",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Network fees only",
    "limits": {
      "daily": null
    },
    "features": [
      "Monero-only",
      "Android native",
      "Open source",
      "Tor routing via Orbot",
      "Ledger hardware-wallet support",
      "No account required",
      "Sidekick companion-device signing",
      "Exolix integrated swaps",
      "Street Mode",
      "PocketChange",
      "Custom nodes"
    ],
    "networks": [
      "XMR"
    ],
    "badge": "MONERO",
    "url": "https://www.monerujo.app/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Wallet"
    ],
    "description": "Open-source Android Monero wallet with custom nodes/Orbot routing, Ledger and Sidekick support, plus optional Exolix swaps.",
    "cardSummary": "Long-standing Android Monero wallet.",
    "jurisdiction": null,
    "auditedBy": [],
    "twitter": "https://x.com/monerujowallet",
    "founderIntel": "Community project by m2049r (pseudonymous) and contributors. No company entity. Open source under Apache 2.0. Endorsed by the official Monero project. No intelligence contractor connections. Feather Wallet covers Linux/desktop; Monerujo covers Android.",
    "vcIntel": "No VC. No company. Donation-funded open source project. Community maintained. Listed on getmonero.org as a recommended wallet. Monero community grants. No OFAC designation.",
    "privacyWarning": "Wallet keys stay local, but selected Monero daemon nodes can observe network metadata. Optional exchange-rate APIs receive requests, and using integrated Exolix shares the destination address and amount while making the user's IP collectable.",
    "stateActorFlag": null,
    "tagline": "Monero for Android. No account, no KYC, Tor optional.",
    "bestFor": [
      "Android Monero wallet",
      "Mobile XMR transactions",
      "Tor-enabled mobile privacy"
    ],
    "kycNote": "No account. No KYC. Open source Android Monero wallet.",
    "updatedAt": "2026-08-25",
    "followTheMoney": "  Monerujo - Community / Open Source\n  ──────────────────────────────────────\n  Dev: m2049r (pseudonymous) + community\n  Funding: Monero community grants\n  Revenue: none (free, Apache 2.0)\n  ├─ No company, no VC, no entity\n  ├─ getmonero.org endorsed wallet\n  └─ Tor routing via Orbot available",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "primary_source_rereview_2026-08-25",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://play.google.com/store/apps/details?id=com.m2049r.xmrwallet&hl=en_US",
        "note": "Google Play developer listing names Guntherkorp LLC as the app publisher with a Sheridan, WY address; site copyright is Guntherkorp and guntherkorp.org presents Monerujo as its project."
      },
      "governanceModel": {
        "value": "company-sponsored",
        "citation": "https://github.com/m2049r/xmrwallet"
      },
      "repositoryUrl": {
        "value": "https://github.com/m2049r/xmrwallet",
        "citation": "https://github.com/m2049r/xmrwallet"
      },
      "legalEntity": {
        "value": "Guntherkorp LLC",
        "citation": "https://play.google.com/store/apps/details?id=com.m2049r.xmrwallet&hl=en_US"
      },
      "incorporationJurisdiction": {
        "value": "Wyoming, United States",
        "citation": "https://play.google.com/store/apps/details?id=com.m2049r.xmrwallet&hl=en_US"
      },
      "registeredAddress": {
        "value": "30 N Gould St, Sheridan, WY 82801, United States",
        "citation": "https://play.google.com/store/apps/details?id=com.m2049r.xmrwallet&hl=en_US"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.monerujo.app/",
            "https://www.monerujo.app/privacy-policy.html",
            "https://github.com/m2049r/xmrwallet/releases/tag/v4.1.7",
            "https://x.com/monerujowallet/status/2068337780665495592"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.monerujo.app/",
            "https://www.monerujo.app/privacy-policy.html",
            "https://github.com/m2049r/xmrwallet/releases/tag/v4.1.7",
            "https://x.com/monerujowallet/status/2068337780665495592"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.monerujo.app/",
            "https://www.monerujo.app/privacy-policy.html",
            "https://github.com/m2049r/xmrwallet/releases/tag/v4.1.7",
            "https://x.com/monerujowallet/status/2068337780665495592"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1036,
    "slug": "tor-browser",
    "noOperatorData": true,
    "domain": "torproject.org",
    "name": "Tor Browser",
    "type": "Privacy Tools",
    "cat": "privacy",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Free",
    "limits": {
      "daily": null
    },
    "features": [
      "Onion routing",
      "No tracking",
      "Fingerprint resistance",
      "Access .onion sites",
      "Leak-resistant default configuration",
      "Open source",
      "Windows/Mac/Linux/Android",
      "Built-in privacy modes"
    ],
    "networks": [],
    "badge": "OPEN SOURCE",
    "url": "https://www.torproject.org/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Privacy Tools"
    ],
    "description": "Browser from the Tor Project routing traffic over Tor, resisting fingerprinting and enabling .onion access.",
    "cardSummary": "Anonymity browser from the Tor Project.",
    "jurisdiction": "US",
    "auditedBy": [
      "Cure53"
    ],
    "twitter": "https://x.com/torproject",
    "founderIntel": "Tor Project Inc - US 501(c)(3) non-profit, Massachusetts. Founded by Roger Dingledine and Nick Mathewson, both former US Naval Research Laboratory researchers. Tor was originally developed by the US Navy as a tool for intelligence communications - though the project is now independent and open source.",
    "followTheMoney": "  Tor Project Inc - Massachusetts (US)\n  ──────────────────────────────────────\n  501(c)(3) non-profit, founded 2006\n  Funders: US DoS/DoD ~$5M/year\n           DARPA original funding\n           EFF, Mozilla, OTF\n  ├─ US jurisdiction (FISA 702)\n  ├─ Majority funding from US govt\n  └─ Protocol itself is open/audited",
    "vcIntel": "US government historically funded ~35-50% of Tor Project budget via OTF (Open Technology Fund = US State Dept / USAGM), DARPA, and State Dept grants. Also receives private donations (Mozilla, Ford Foundation, EFF). In 2024, the Tor Project merged with Tails. Despite government funding history, Tor's architecture is verifiably open source and audited. Used by CIA.gov as .onion site simultaneously - governments both use and fund it.",
    "privacyWarning": "The Tor Project is a US non-profit with historical US government funding. Logging into personal accounts identifies the account holder even over Tor. Do not install extra plugins or add-ons: Tor warns they may bypass Tor, reveal an IP address, or otherwise compromise privacy.",
    "stateActorFlag": "US non-profit. OTF (US State Dept / USAGM) and historically DARPA funded. Original technology developed by US Naval Research Laboratory. Architecture is open source and verifiably privacy-preserving despite funding origin.",
    "tagline": "Browse anonymously. Hide your IP. Access .onion sites. The original.",
    "bestFor": [
      "Anonymous browsing",
      ".onion access",
      "Censorship circumvention"
    ],
    "kycNote": "No account, payment, phone number, or document KYC is required to download or use Tor Browser.",
    "updatedAt": "2026-08-25",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "https://www.torproject.org/download",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://www.torproject.org/",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "The Tor Project, Inc.",
        "citation": "https://www.torproject.org/"
      },
      "registrationNumber": {
        "value": "20-8096820",
        "citation": "https://www.guidestar.org/profile/20-8096820"
      },
      "registryUrl": {
        "value": "https://corp.sec.state.ma.us/corpweb/CorpSearch/CorpSearch.aspx",
        "citation": "https://corp.sec.state.ma.us/corpweb/CorpSearch/CorpSearch.aspx"
      },
      "incorporationJurisdiction": {
        "value": "Massachusetts, United States",
        "citation": "https://en.wikipedia.org/wiki/The_Tor_Project"
      },
      "incorporationDate": {
        "value": "December 22, 2006",
        "citation": "https://en.wikipedia.org/wiki/The_Tor_Project"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.torproject.org/download/",
            "https://www.torproject.org/download",
            "https://www.torproject.org/about/privacy_policy/",
            "https://www.torproject.org/about/privacy_policy",
            "https://www.torproject.org/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.torproject.org/download/",
            "https://www.torproject.org/download",
            "https://www.torproject.org/about/privacy_policy/",
            "https://www.torproject.org/about/privacy_policy",
            "https://www.torproject.org/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.torproject.org/download/",
            "https://www.torproject.org/download",
            "https://www.torproject.org/about/privacy_policy/",
            "https://www.torproject.org/about/privacy_policy",
            "https://www.torproject.org/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1037,
    "slug": "simpleswap",
    "domain": "simpleswap.io",
    "name": "SimpleSwap",
    "type": "Swap",
    "cat": "swap",
    "kyc": "light",
    "kycLevel": 3,
    "fees": {
      "transaction": null
    },
    "fee": "Quoted through the selected fixed or floating exchange rate; network and provider-route costs may apply.",
    "limits": {
      "daily": null
    },
    "features": [
      "No registration for standard swaps",
      "1,000+ cryptocurrencies",
      "Non-custodial",
      "Fixed + floating rates",
      "Optional Sumsub verification",
      "API available",
      "XMR supported",
      "Mobile app"
    ],
    "networks": [],
    "badge": "1000+ COINS",
    "url": "https://simpleswap.io/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Swap"
    ],
    "description": "No-account instant crypto swaps across 1,000+ coins with fixed and floating rate options, including XMR.",
    "cardSummary": "No-account swaps across 1,000+ coins.",
    "jurisdiction": "PA",
    "auditedBy": [],
    "twitter": "https://x.com/SimpleSwap_io",
    "founderIntel": "Offshore/anonymous team. Company registered in unknown jurisdiction. No individual founders publicly identified. Limited transparency about corporate structure.",
    "vcIntel": "No disclosed VC funding. Revenue from swap spread. Jurisdiction and ownership opaque - standard caution for unverified swap services. FCA warning issued for UK users (2023) - not a direct scam warning but a regulatory flag.",
    "privacyWarning": "UK FCA issued a warning for UK users (2023). Jurisdiction and ownership are not publicly verified. KYC is occasionally triggered on large or algorithmically-flagged transactions. Use for small amounts until service has more independent review.",
    "stateActorFlag": null,
    "tagline": "Instant swaps. 1,000+ coins. No account. No KYC.",
    "bestFor": [
      "Wide coin selection",
      "Quick swaps",
      "XMR to anything"
    ],
    "kycNote": "Standard swaps can be used without registration, but optional account verification uses a government ID and live face scan through Sumsub; AML/compliance checks can also trigger identity review or delays.",
    "updatedAt": "2026-08-25",
    "followTheMoney": "  SimpleSwap - Offshore / Anonymous\n  ──────────────────────────────────────\n  Team: anonymous, jurisdiction opaque\n  Funding: zero VC disclosed\n  Revenue: ~0.5% swap spread\n  ├─ UK FCA warning issued 2023\n  ├─ No individual founders identified\n  └─ Caution: use small amounts only",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "https://simpleswap.io/kyc",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://simpleswap.io/affiliate-terms",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "SimpleSwap Ltd",
        "citation": "https://simpleswap.io/affiliate-terms"
      },
      "incorporationJurisdiction": {
        "value": "Marshall Islands",
        "citation": "https://simpleswap.io/affiliate-terms"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [
          "SIMPLE SWAP LTD (UK company number 11847383, dissolved 27 July 2021)"
        ],
        "citation": "https://find-and-update.company-information.service.gov.uk/company/11847383"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://simpleswap.io/kyc",
            "https://simpleswap.io/sitemap.xml",
            "https://simpleswap.io/sitemap_index_customer_1.xml",
            "https://simpleswap.io/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://simpleswap.io/kyc",
            "https://simpleswap.io/sitemap.xml",
            "https://simpleswap.io/sitemap_index_customer_1.xml",
            "https://simpleswap.io/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://simpleswap.io/kyc",
            "https://simpleswap.io/sitemap.xml",
            "https://simpleswap.io/sitemap_index_customer_1.xml",
            "https://simpleswap.io/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1038,
    "slug": "exolix",
    "domain": "exolix.com",
    "name": "Exolix",
    "type": "Swap",
    "cat": "swap",
    "kyc": "light",
    "kycLevel": 1,
    "fees": {
      "transaction": 0
    },
    "fee": "No separate Exolix fee shown; costs are included in the displayed rate and network overhead",
    "limits": {
      "daily": null
    },
    "features": [
      "No registration",
      "Thousands of tokens",
      "200+ blockchains",
      "Fixed and floating rates",
      "Risk-based AML/KYC",
      "XMR support",
      "API available"
    ],
    "networks": [],
    "badge": "XMR FRIENDLY",
    "url": "https://exolix.com/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Swap"
    ],
    "description": "Cross-chain swap aggregator routing thousands of tokens across 200+ blockchains, with fixed/floating rates and risk-based AML/KYC.",
    "cardSummary": "Cross-chain swap aggregator across 200+ blockchains.",
    "jurisdiction": null,
    "auditedBy": [],
    "twitter": "https://x.com/ExolixCom",
    "founderIntel": "Unknown/pseudonymous team. Company jurisdiction not publicly disclosed. No individual founders identified. Standard caution for offshore swap services with low transparency.",
    "vcIntel": "No disclosed VC. Revenue from swap spread. Integrated into Monerujo Android wallet - which provides some community endorsement by association. Jurisdiction opaque. Limited independent security review.",
    "privacyWarning": "Operator and jurisdiction remain unresolved. Exolix routes swaps through independent providers and applies a risk-based AML/KYC policy that can require checks; its anonymity marketing is not a never-KYC guarantee.",
    "stateActorFlag": null,
    "tagline": "Instant swaps. XMR friendly. Monerujo integrated. No account.",
    "bestFor": [
      "XMR swaps",
      "In-wallet exchanges",
      "Quick conversions"
    ],
    "kycNote": "No account required for standard swaps; AML/KYC policy can trigger identity checks on risk events.",
    "updatedAt": "2026-08-25",
    "followTheMoney": "  Exolix - Offshore / Anonymous\n  ──────────────────────────────────────\n  Team: pseudonymous, jurisdiction opaque\n  Funding: zero VC disclosed\n  Revenue: ~0.5% swap spread\n  ├─ No founders identified publicly\n  ├─ Monerujo integration = community nod\n  └─ Caution: use small amounts only",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "primary_source_rereview_2026-08-25",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "unresolved",
        "citation": "unknown",
        "note": "Pass 1 researched this service but established no registry facts."
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://exolix.com/",
            "https://exolix.com/faq",
            "https://exolix.com/aml-kyc",
            "https://exolix.com/terms"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://exolix.com/",
            "https://exolix.com/faq",
            "https://exolix.com/aml-kyc",
            "https://exolix.com/terms"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://exolix.com/",
            "https://exolix.com/faq",
            "https://exolix.com/aml-kyc",
            "https://exolix.com/terms"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1039,
    "slug": "pikasim",
    "domain": "pikasim.com",
    "name": "PikaSIM",
    "type": "Comms",
    "cat": "comms",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Country plans from $1.50; regional from $4.50; global from $9; unlimited from $6/day; forever plans from $14/GB; SMS from $0.50",
    "limits": {
      "daily": null
    },
    "features": [
      "Anonymous eSIM",
      "190+ countries",
      "BTC/Lightning/XMR payments",
      "No account required",
      "No email",
      "No identity",
      "Self-hosted BTCPay",
      "Cryptocurrency payments",
      "Card payments"
    ],
    "networks": [],
    "badge": "NO ACCOUNT",
    "url": "https://pikasim.com/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-24",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Comms"
    ],
    "description": "Accountless travel eSIM and phone-number service covering 190+ countries, with card or cryptocurrency payments and infrastructure hosted in Finland.",
    "cardSummary": "Travel eSIM with no account or email.",
    "jurisdiction": "US",
    "auditedBy": [],
    "twitter": null,
    "founderIntel": "Unknown/anonymous operators. No company or founders publicly identified. Relatively new entrant to the anonymous eSIM space. Unvetted - requires more community review.",
    "vcIntel": "No disclosed investors or funding. Unknown jurisdiction. New service - limited track record. Self-hosted BTCPay suggests genuine crypto-only model, which is a positive signal.",
    "privacyWarning": "Crypto checkout is the private path; card/Stripe payments require email/payment metadata and eSIM use still exposes carrier/roaming metadata.",
    "stateActorFlag": null,
    "tagline": "Anonymous eSIM. 190+ countries. BTC/XMR. No account, no identity.",
    "bestFor": [
      "Anonymous SIM",
      "Travel data privacy",
      "Silent.link alternative"
    ],
    "kycNote": "Official terms state a strict no-KYC policy: no identity documents, no account registration, no phone number and no required email for crypto purchases.",
    "updatedAt": "2026-06-22",
    "followTheMoney": "  PikaSIM - Anonymous / Unknown\n  ──────────────────────────────────────\n  Operators: unknown, no company listed\n  Funding: zero VC disclosed\n  Revenue: data package fees ($3–15)\n  ├─ BTCPay self-hosted: genuine crypto\n  ├─ New entrant, limited track record\n  └─ Unvetted - compare with Silent.link",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_5_2026-06-22",
    "jurisdictionConfidence": "inferred",
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://play.google.com/store/apps/details?id=com.pikasim.esim&hl=en_US",
        "note": "Google Play and Apple App Store list CodeBru, Inc as the developer/publisher of the PikaSim app; USPTO trademark application serial 99841732 for PIKASIM is filed by CodeBru, Inc (a corporation); site ToS states PikaSim is a digital eSIM service operated in the United States."
      },
      "legalEntity": {
        "value": "CodeBru, Inc",
        "citation": "https://play.google.com/store/apps/details?id=com.pikasim.esim&hl=en_US"
      },
      "registeredAddress": {
        "value": "1100 E 16TH Ave Unit 4, Denver, CO 80218-1566, United States",
        "citation": "https://play.google.com/store/apps/details?id=com.pikasim.esim&hl=en_US"
      },
      "officers": {
        "value": [
          {
            "name": "Zach Caudill",
            "role": "Founder/CEO"
          }
        ],
        "citation": "https://www.codebru.com/our-team"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "noncustodial-hosted",
      "sourceModel": "closed"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://pikasim.com/privacy",
            "https://pikasim.com/tos"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Accountless purchase reduces identity intake, but orders, wallet/top-up records, device/IP logs, processor records and carrier metadata create moderate exposure."
        },
        "controlModel": {
          "value": "noncustodial-hosted",
          "sourceUrls": [
            "https://pikasim.com/",
            "https://pikasim.com/status"
          ],
          "reviewedAt": "2026-08-27",
          "note": "PikaSIM is a hosted provisioning/order service without a required customer account or custody of user assets after fulfillment."
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://pikasim.com/tos"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No official score-critical implementation repository or reproducible build was located."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced; no audit points are granted."
      }
    }
  },
  {
    "id": 1040,
    "slug": "mailfence",
    "domain": "mailfence.com",
    "name": "Mailfence",
    "type": "Email",
    "cat": "email",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Free / €2.50/mo Entry / €7.50/mo Pro",
    "limits": {
      "daily": null
    },
    "features": [
      "End-to-end encrypted",
      "OpenPGP support",
      "No ads",
      "Calendar + docs",
      "Custom domains",
      "Belgian law",
      "BTC accepted",
      "Open source (client)"
    ],
    "networks": [],
    "badge": "E2E ENCRYPTED",
    "url": "https://mailfence.com/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-27",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Email"
    ],
    "description": "Belgian encrypted email and groupware with OpenPGP, calendar, contacts and documents under Belgian and EU law.",
    "cardSummary": "Belgian encrypted email and groupware.",
    "jurisdiction": "BE",
    "auditedBy": [],
    "twitter": "https://x.com/mailfence",
    "founderIntel": null,
    "vcIntel": null,
    "privacyWarning": "Belgian/EU provider, not Five Eyes, but Mailfence can process account, message-index, payment and anti-abuse data and may disclose information when required by Belgian law. Use OpenPGP for content that must stay end-to-end encrypted.",
    "stateActorFlag": null,
    "tagline": "Belgian encrypted email. OpenPGP. No ads. No US jurisdiction.",
    "bestFor": [
      "Encrypted email",
      "OpenPGP users",
      "Non-US jurisdiction"
    ],
    "kycNote": "No document KYC found. Terms require a valid email address and any requested account information; paid accounts can create credit-card or other payment metadata.",
    "updatedAt": "2026-08-27",
    "followTheMoney": "  ContactOffice Group NV - Belgium (BE)\n  ──────────────────────────────────────\n  Founder: Patrick De Schutter (1999, BE)\n  Funding: bootstrapped, private company\n  Revenue: subscriptions from €2.50/mo\n  ├─ EU (Belgium) - not Five Eyes\n  ├─ Donates to EFF, Digital Rights IE\n  └─ No VC, no institutional investors",
    "lastReviewed": "2026-08-27",
    "kycLastChecked": "2026-08-27",
    "reviewSource": "Primary-source review 2026-08-27",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://mailfence.com/en/terms.jsp",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "ContactOffice Group SA",
        "citation": "https://mailfence.com/en/terms.jsp"
      },
      "registrationNumber": {
        "value": "BE 0466.241.584",
        "citation": "https://mailfence.com/en/terms.jsp"
      },
      "incorporationJurisdiction": {
        "value": "Belgium",
        "citation": "https://mailfence.com/en/privacy.jsp"
      },
      "registeredAddress": {
        "value": "Avenue Franklin Roosevelt 47b, B-1050 Brussels, Belgium",
        "citation": "https://mailfence.com/en/terms.jsp"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "extensive",
      "controlModel": "hosted-account",
      "sourceModel": "partial"
    },
    "changedAt": "2026-08-27",
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "extensive",
          "sourceUrls": [
            "https://mailfence.com/en/privacy.jsp"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Hosted email exposes account identifiers plus IP, sender/recipient, subject, message-ID, timestamp and anti-abuse processing; this is extensive score-critical operator data."
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://mailfence.com/en/terms.jsp"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Mailfence operates user mailboxes and account/service infrastructure."
        },
        "sourceModel": {
          "value": "partial",
          "sourceUrls": [
            "https://mailfence.com/en/private-email.jsp",
            "https://mailfence.com/en/terms.jsp"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Client-side/open components do not establish an inspectable hosted mail core; official terms restrict server/site code, so only partial reviewability is supported."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced in the reopened first-party source family."
      }
    }
  },
  {
    "id": 1041,
    "slug": "sporestack",
    "domain": "sporestack.com",
    "name": "SporeStack",
    "type": "Hosting",
    "cat": "hosting",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "From $3/mo",
    "limits": {
      "daily": null
    },
    "features": [
      "XMR/BTC/BCH payments",
      "No email",
      "No KYC",
      "API-driven",
      "No account required",
      "IPv6 native",
      "Linux VPS",
      "Since 2017"
    ],
    "networks": [],
    "badge": "CRYPTO ONLY",
    "url": "https://sporestack.com/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-26",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Hosting"
    ],
    "description": "VPS and bare-metal hosting with token-based account funds and no email required, paid in BTC, BCH or XMR.",
    "cardSummary": "VPS funded by tokens, no email needed.",
    "jurisdiction": "US",
    "auditedBy": [],
    "twitter": null,
    "founderIntel": "Unknown/pseudonymous operator. No company or founders publicly identified. Established 2017 - long track record for anonymous hosting. No known major incidents.",
    "vcIntel": "No VC. No known investors. Revenue from VPS subscriptions paid in crypto. Jurisdiction unknown but transparent Law Enforcement FAQ on site. Established track record since 2017.",
    "privacyWarning": "SporeStack publishes a Law Enforcement FAQ and states they will comply with valid legal requests. This is more transparent than most hosts, but means they are not zero-compliance. Use Tor when administering servers for maximum operational security.",
    "stateActorFlag": null,
    "tagline": "Anonymous VPS since 2017. XMR/BTC. No email. No KYC. API-driven.",
    "bestFor": [
      "Anonymous server hosting",
      "API-driven infra",
      "XMR-paid VPS"
    ],
    "kycNote": "Official homepage states no KYC and no email required; funds are held on a token; accepts Monero, Bitcoin, and Bitcoin Cash.",
    "updatedAt": "2026-06-22",
    "followTheMoney": "  SporeStack - Pseudonymous / Global\n  ──────────────────────────────────────\n  Operator: anonymous (since 2017)\n  Funding: zero VC, crypto subscriptions\n  Revenue: ~$3/mo+ VPS fees (XMR/BTC)\n  ├─ Published Law Enforcement FAQ\n  ├─ Will comply with valid legal orders\n  └─ Use Tor for server admin privacy",
    "lastReviewed": "2026-08-26",
    "kycLastChecked": "2026-08-26",
    "reviewSource": "Primary-source review 2026-08-26",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://whois.arin.net/rest/org/SPORE.html",
        "note": "ARIN org record names SporeStack LLC with comment https://sporestack.com; Texas SOS-derived records (file 0803067941) and PeeringDB confirm the same LLC operates the service; site states it is US-based."
      },
      "legalEntity": {
        "value": "SPORESTACK LLC",
        "citation": "https://corporate.ai/entity/tx/0803067941/sporestack-llc"
      },
      "registrationNumber": {
        "value": "0803067941",
        "citation": "https://corporate.ai/entity/tx/0803067941/sporestack-llc"
      },
      "registryUrl": {
        "value": "https://corporate.ai/entity/tx/0803067941/sporestack-llc",
        "citation": "https://corporate.ai/entity/tx/0803067941/sporestack-llc"
      },
      "incorporationJurisdiction": {
        "value": "Texas, United States",
        "citation": "https://corporate.ai/entity/tx/0803067941/sporestack-llc"
      },
      "incorporationDate": {
        "value": "2018-07-16",
        "citation": "https://corporate.ai/entity/tx/0803067941/sporestack-llc"
      },
      "registeredAddress": {
        "value": "9900 Spectrum Drive, Austin, TX 78717, US",
        "citation": "https://whois.arin.net/rest/org/SPORE.html"
      },
      "officers": {
        "value": [
          "Teran McKinney (sole principal)"
        ],
        "citation": "https://www.bizapedia.com/tx/sporestack-llc.html"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "limited",
      "controlModel": "hosted-account",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-26",
      "inputs": {
        "operatorDataExposure": {
          "value": "limited",
          "sourceUrls": [
            "https://sporestack.com/law-enforcement.html"
          ],
          "reviewedAt": "2026-08-26",
          "note": "token/server association; no website/API IP logs asserted"
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://sporestack.com/law-enforcement.html"
          ],
          "reviewedAt": "2026-08-26",
          "note": "operator-managed upstream account and token-launched servers"
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://sporestack.com/law-enforcement.html",
            "https://sporestack.com/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "no reviewed official source establishes an application source-model classification"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "no-score-points-no-cap-exception"
      }
    }
  },
  {
    "id": 1042,
    "slug": "thorswap",
    "domain": "thorswap.finance",
    "name": "THORSwap",
    "type": "Swap",
    "cat": "swap",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": null
    },
    "fee": "Interface fee is displayed before confirmation; gas and network fees are separate.",
    "limits": {
      "daily": null
    },
    "features": [
      "10,000+ assets across 26+ chains",
      "Native BTC/ETH/LTC swaps",
      "Built-in self-custody wallet",
      "Streaming swaps",
      "No bridges or wrapped assets",
      "No account required",
      "No KYC by protocol",
      "Non-custodial",
      "THORChain protocol"
    ],
    "networks": [
      "BTC",
      "ETH",
      "LTC",
      "BCH",
      "ATOM"
    ],
    "badge": "DECENTRALIZED",
    "url": "https://app.thorswap.finance/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Swap"
    ],
    "description": "Bitcoin-first, non-custodial cross-chain swap interface covering 10,000+ assets across 26+ blockchains with a built-in wallet.",
    "cardSummary": "Cross-chain swaps across 10,000+ assets and 26+ chains.",
    "jurisdiction": null,
    "auditedBy": [],
    "twitter": "https://x.com/THORSwap",
    "founderIntel": null,
    "vcIntel": null,
    "privacyWarning": "THORChain's lending module became insolvent in January 2025 - the SWAP functionality is unaffected but the lending/borrowing module is frozen. Use THORSwap for swaps only. The protocol is genuinely non-custodial for swaps. RUNE token exposure is inherent to the protocol security model.",
    "stateActorFlag": null,
    "tagline": "Decentralized cross-chain swaps. Native BTC. No bridges. No account. No KYC.",
    "bestFor": [
      "Cross-chain swaps",
      "Native BTC trades",
      "No-custodian DEX"
    ],
    "kycNote": "Docs describe THORSwap/Metro as non-custodial and non-KYC DeFi. Wallet-to-wallet swap flow; protocol/frontend risks remain.",
    "updatedAt": "2026-08-25",
    "followTheMoney": "  THORChain Protocol - Decentralised\n  ──────────────────────────────────────\n  Team: anonymous by design (protocol)\n  Funding: RUNE token community treasury\n  Revenue: 0.3% outbound swap fee\n  ├─ No VC, no custodian, no founder ID\n  ├─ Lending module insolvent Jan 2025\n  └─ Core swaps unaffected",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "https://docs.thorswap.finance/",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://docs.thorswap.finance/thorswap/resources/terms-of-service",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Ferdin Incorporated",
        "citation": "https://docs.thorswap.finance/thorswap/resources/terms-of-service"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://docs.thorswap.finance/",
            "https://docs.thorswap.finance/thorswap/resources/terms-of-service",
            "https://x.com/THORSwap/status/2086837929473929563",
            "https://app.thorswap.finance/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://docs.thorswap.finance/",
            "https://docs.thorswap.finance/thorswap/resources/terms-of-service",
            "https://x.com/THORSwap/status/2086837929473929563",
            "https://app.thorswap.finance/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://docs.thorswap.finance/",
            "https://docs.thorswap.finance/thorswap/resources/terms-of-service",
            "https://x.com/THORSwap/status/2086837929473929563",
            "https://app.thorswap.finance/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1043,
    "slug": "azirevpn",
    "domain": "azirevpn.com",
    "name": "AzireVPN",
    "type": "VPN",
    "cat": "vpn",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "monthly": 5
    },
    "fee": "From €5/mo",
    "limits": {
      "daily": null
    },
    "features": [
      "RAM-only servers",
      "Blind Operator 2.0",
      "No personal data required",
      "WireGuard native",
      "Monero accepted",
      "No logs",
      "Multi-hop support",
      "Open source client"
    ],
    "networks": [],
    "badge": "DISKLESS",
    "url": "https://www.azirevpn.com/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-27",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "VPN"
    ],
    "description": "Swedish RAM-only WireGuard VPN with Blind Operator mode and no personal data required at signup.",
    "cardSummary": "Swedish RAM-only VPN with Blind Operator.",
    "jurisdiction": "SE",
    "auditedBy": [],
    "twitter": "https://x.com/AzireVPN",
    "founderIntel": null,
    "vcIntel": null,
    "privacyWarning": "Sweden is a 14 Eyes intelligence-sharing country. AzireVPN uses diskless servers and says its no-logs design was independently audited, but its April 2026 audit disclosure still listed one critical, one medium, and one low finding as in progress. Malwarebytes' privacy policy applies to its websites and products and describes broader website/product data collection.",
    "stateActorFlag": null,
    "tagline": "RAM-only VPN. Blind Operator. Monero accepted. Sweden.",
    "bestFor": [
      "Privacy VPN",
      "WireGuard users",
      "Monero-paying users"
    ],
    "kycNote": "No personal data required. No email, no name. Pay with Monero anonymously.",
    "updatedAt": "2026-03-13",
    "followTheMoney": "  Netbug AB - Sweden (SE, 14 Eyes)\n  ──────────────────────────────────────\n  Founders: Tobias Lövgren + team (SE)\n  Funding: bootstrapped, subscriptions\n  Revenue: from €5/mo per subscriber\n  ├─ 14 Eyes (SE): court orders possible\n  ├─ RAM-only + Blind Operator: no logs\n  └─ WireGuard, XMR accepted, no audit",
    "lastReviewed": "2026-08-27",
    "kycLastChecked": "2026-08-27",
    "reviewSource": "Primary-source review 2026-08-27",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://www.azirevpn.com/about",
        "note": "AzireVPN is operated as a commercial VPN service by Swedish limited company Netbouncer AB and is stated on its official About page to be owned by Malwarebytes following a 2024 acquisition."
      },
      "legalEntity": {
        "value": "Netbouncer AB",
        "citation": "https://play.google.com/store/apps/details?id=com.azirevpn.android&hl=en_US"
      },
      "registrationNumber": {
        "value": "559089-4175",
        "citation": "https://www.allabolag.se/foretag/netbouncer-ab/%C3%A4lvsj%C3%B6/datacenters/2KGO9JZI5YDLG"
      },
      "registryUrl": {
        "value": "https://www.allabolag.se/foretag/netbouncer-ab/%C3%A4lvsj%C3%B6/datacenters/2KGO9JZI5YDLG",
        "citation": "https://www.allabolag.se/foretag/netbouncer-ab/%C3%A4lvsj%C3%B6/datacenters/2KGO9JZI5YDLG"
      },
      "incorporationJurisdiction": {
        "value": "Sweden",
        "citation": "https://www.allabolag.se/foretag/netbouncer-ab/%C3%A4lvsj%C3%B6/datacenters/2KGO9JZI5YDLG"
      },
      "incorporationDate": {
        "value": "2016-12-07",
        "citation": "https://www.allabolag.se/foretag/netbouncer-ab/%C3%A4lvsj%C3%B6/datacenters/2KGO9JZI5YDLG"
      },
      "registeredAddress": {
        "value": "Mässvägen 4, 125 30 Älvsjö, Sweden",
        "citation": "https://www.allabolag.se/foretag/netbouncer-ab/%C3%A4lvsj%C3%B6/datacenters/2KGO9JZI5YDLG"
      },
      "parentEntity": {
        "value": "Malwarebytes",
        "citation": "https://www.azirevpn.com/about"
      },
      "officers": {
        "value": [
          "Tobias Leonard P Windh (styrelseledamot / board member)",
          "Carl William Öling (styrelsesuppleant / deputy board member)"
        ],
        "citation": "https://www.allabolag.se/befattningshavare/netbouncer-ab/%C3%A4lvsj%C3%B6/datacenters/2KGO9JZI5YDLG"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "hosted-account",
      "sourceModel": "partial"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://www.azirevpn.com/privacy"
          ],
          "reviewedAt": "2026-08-27",
          "note": "account credentials and six-month internal payment reference; processor sees payment-path data"
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://www.azirevpn.com/privacy"
          ],
          "reviewedAt": "2026-08-27",
          "note": "operator-hosted-vpn"
        },
        "sourceModel": {
          "value": "partial",
          "sourceUrls": [
            "https://www.azirevpn.com/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "partial-open-source-client"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "Current official audit announcement and report reviewed; scope is the VPN service, not merely the CLI."
      }
    }
  },
  {
    "id": 1044,
    "slug": "phreeli",
    "domain": "phreeli.com",
    "name": "Phreeli",
    "type": "Comms",
    "cat": "comms",
    "kyc": "light",
    "kycLevel": 1,
    "fees": {
      "transaction": 0
    },
    "fee": "prepay",
    "limits": {
      "daily": null
    },
    "features": [
      "eSIM",
      "Anonymous Signup",
      "Tor Delivery",
      "Zero-Knowledge Payments",
      "US Coverage"
    ],
    "networks": [
      "XMR",
      "ZEC"
    ],
    "badge": "NEW",
    "url": "https://www.phreeli.com",
    "affiliate": "",
    "geo": [
      "US"
    ],
    "status": "ok",
    "checkedAt": "2026-08-27",
    "trending": true,
    "countries": [
      "US"
    ],
    "categories": [
      "Comms"
    ],
    "description": "US wireless MVNO whose eSIM purchase avoids name and street address but still requires a residential ZIP code.",
    "cardSummary": "US eSIM MVNO with no name at purchase.",
    "jurisdiction": "US",
    "auditedBy": [],
    "twitter": null,
    "founderIntel": null,
    "vcIntel": null,
    "privacyWarning": "Delaware/US corporation using upstream telecom providers. Privacy policy says username, ZIP and payment are separated from phone usage, but IMEI/eSIM or ICCID can link to issued numbers and upstream providers such as T-Mobile/MVNO Connect can receive required telecom data.",
    "stateActorFlag": null,
    "tagline": "The phone carrier that only needs your ZIP code.",
    "bestFor": [
      "Anonymous US phone service",
      "No-identity cellular",
      "Privacy from carrier data brokers"
    ],
    "kycNote": "No document KYC found for baseline eSIM signup, but Phreeli collects ZIP code and payment information. Physical SIM delivery, e911, Wi-Fi calling, privacy requests, or legal/compliance cases can require additional identity/address information.",
    "updatedAt": "2026-08-27",
    "followTheMoney": "  Phreeli Inc - USA (US), T-Mobile MVNO\n  ──────────────────────────────────────\n  CEO: Nicholas Merrill (anti-NSL, 2004)\n  Investor: $5M anonymous angel (private)\n  Revenue: prepay mobile subscriptions\n  ├─ Five Eyes (US) + T-Mobile towers\n  ├─ T-Mobile logs tower location meta\n  └─ Phreeli stores zero identity data",
    "lastReviewed": "2026-08-27",
    "kycLastChecked": "2026-08-27",
    "reviewSource": "Primary-source review 2026-08-27",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://www.phreeli.com/terms-of-service",
        "note": "Official Terms of Service and Privacy Policy identify the operator as Phreeli Company, a Delaware corporation running a commercial wireless MVNO service."
      },
      "legalEntity": {
        "value": "Phreeli Company",
        "citation": "https://www.phreeli.com/terms-of-service"
      },
      "registrationNumber": {
        "value": "7504761",
        "citation": "https://icc.illinois.gov/docket/P2025-0097/documents/360654/files/631786.pdf"
      },
      "registryUrl": {
        "value": "https://icis.corp.delaware.gov/ecorp/entitysearch/namesearch.aspx",
        "citation": "https://icc.illinois.gov/docket/P2025-0097/documents/360654/files/631786.pdf"
      },
      "incorporationJurisdiction": {
        "value": "Delaware, United States",
        "citation": "https://www.phreeli.com/terms-of-service"
      },
      "incorporationDate": {
        "value": "2019-07-08",
        "citation": "https://icc.illinois.gov/docket/P2025-0097/documents/360654/files/631786.pdf"
      },
      "registeredAddress": {
        "value": "16192 Coastal Highway, Lewes, DE 19958",
        "citation": "https://www.phreeli.com/privacy/policy"
      },
      "officers": {
        "value": [
          {
            "name": "Nicholas Merrill",
            "role": "President, Secretary, Treasurer, Director, Executive Officer"
          },
          {
            "name": "Louis Rossmann",
            "role": "Director"
          },
          {
            "name": "Steven Gelmis",
            "role": "Director"
          },
          {
            "name": "Philip Weiss",
            "role": "Director"
          }
        ],
        "citation": "https://search.sunbiz.org/Inquiry/CorporationSearch/SearchResults?InquiryType=EntityName&InquiryDirectionType=PreviousRecord&SearchTerm=PHRCS%20CORPORATION&SearchNameOrder=PHREEMILZHEADFIRSTENTERTAINMEN%20P200000290810&ListNameOrder=PHRED%20P050001292640&Detail=FL.DOS.Corporations.Shared.Contracts.FilingRecord"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "hosted-account",
      "sourceModel": "closed"
    },
    "changedAt": "2026-08-27",
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://www.phreeli.com/privacy/policy",
            "https://www.phreeli.com/terms-of-service"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Account, purchase, device, support and carrier-required mobile-service data create moderate exposure even though document KYC is not presented at checkout."
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://www.phreeli.com/",
            "https://www.phreeli.com/plans"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Phreeli provisions and manages paid wireless plans through hosted service/account infrastructure."
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://www.phreeli.com/terms-of-service"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No official score-critical service implementation or reproducible build was published."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced; no audit points are granted."
      }
    }
  },
  {
    "id": 1046,
    "slug": "servury",
    "domain": "servury.com",
    "name": "Servury",
    "type": "Hosting",
    "cat": "hosting",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "from $9.99/mo",
    "limits": {
      "daily": null
    },
    "features": [
      "No Account",
      "7 Locations",
      "30s Deploy",
      "Zero Logs",
      "Reseller API",
      "Zero-knowledge encrypted VPS"
    ],
    "networks": [
      "BTC",
      "ETH",
      "LTC",
      "XMR",
      "BSC",
      "TRON"
    ],
    "badge": null,
    "url": "https://servury.com",
    "affiliate": "",
    "geo": [
      "US",
      "CA",
      "UK",
      "EU"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "US",
      "CA",
      "UK",
      "EU"
    ],
    "categories": [
      "Hosting"
    ],
    "description": "VPS, VDS and proxy hosting from Canadian operator Avalanche Systems, with credential-only access, no signup form, and an optional zero-knowledge Blackbox VPS using user-managed disk encryption and SEV-SNP RAM isolation.",
    "cardSummary": "VPS and proxies with no sign-up form.",
    "jurisdiction": "CA",
    "auditedBy": null,
    "twitter": null,
    "founderIntel": "Registered as Avalanche Systems Inc., Montreal, Quebec, Canada. Legal entity identified: publicly listed address at 4388 Rue Saint-Denis Suite 200, Montreal QC H2J 2L1. Founders/operators not publicly named. Company incorporated in Canada - Five Eyes jurisdiction.",
    "vcIntel": "No VC funding information. Small independent operator. Customer testimonials appear organic. Service self-describes as 'privacy-first' with zero-log policy. No state-actor or surveillance-adjacent investors identified.",
    "privacyWarning": "Canada/Five Eyes caveat remains. Privacy policy is source-backed under PIPEDA; terms prohibit illegal use and cryptocurrency mining.",
    "stateActorFlag": null,
    "tagline": "Anonymous VPS and proxies - no email, no KYC, deploy in 30 seconds.",
    "bestFor": [
      "Anonymous VPS hosting",
      "Crypto-paid servers",
      "Privacy-conscious developers"
    ],
    "kycNote": "No identity checks found. Privacy policy says minimum data only, no email/phone/tracking for core service, and Apache access logs piped to /dev/null; card or support paths can add metadata.",
    "updatedAt": "2026-08-25",
    "followTheMoney": "  Avalanche Systems Inc - Montreal, CA\n  ──────────────────────────────────────\n  Founders: unnamed, QC Canada registered\n  Funding: zero VC disclosed\n  Revenue: from $15.58/mo VPS fees\n  ├─ Five Eyes (CA) jurisdiction\n  ├─ No XMR: BTC/ETH/LTC only\n  └─ Unaudited zero-logs claim",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "https://servury.com/",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://servury.com/terms/",
        "note": "Terms of Service and Privacy Policy state Servury is operated by Avalanche Systems Inc. (DBA Servury), a corporation registered in Canada; federal corporation record confirms it."
      },
      "legalEntity": {
        "value": "Avalanche Systems Inc. (DBA Servury)",
        "citation": "https://servury.com/terms/"
      },
      "registrationNumber": {
        "value": "17692978",
        "citation": "https://opengovca.com/corporation/17692978"
      },
      "registryUrl": {
        "value": "https://opengovca.com/corporation/17692978",
        "citation": "https://opengovca.com/corporation/17692978"
      },
      "incorporationJurisdiction": {
        "value": "Canada (federal, CBCA)",
        "citation": "https://opengovca.com/corporation/17692978"
      },
      "incorporationDate": {
        "value": "2026-02-11",
        "citation": "https://opengovca.com/corporation/17692978"
      },
      "registeredAddress": {
        "value": "4388 R. Saint-Denis, Suite 200 #741, Montréal, QC H2J 2L1, Canada",
        "citation": "https://opengovca.com/corporation/17692978"
      },
      "officers": {
        "value": [
          "Matteo Mathieu (Director)"
        ],
        "citation": "https://opengovca.com/corporation/17692978"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://servury.com/",
            "https://servury.com",
            "https://servury.com/privacy",
            "https://x.com/servurycloud/status/2091358930857271394"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://servury.com/",
            "https://servury.com",
            "https://servury.com/privacy",
            "https://x.com/servurycloud/status/2091358930857271394"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://servury.com/",
            "https://servury.com",
            "https://servury.com/privacy",
            "https://x.com/servurycloud/status/2091358930857271394"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1047,
    "slug": "obscuravpn",
    "domain": "obscura.com",
    "name": "Obscura VPN",
    "type": "VPN",
    "cat": "vpn",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "monthly": null
    },
    "fee": "see site",
    "limits": {
      "daily": null
    },
    "features": [
      "2-party relay (Obscura ingress + Mullvad exit)",
      "WireGuard",
      "No email needed",
      "Randomized account number",
      "Monero & Bitcoin LN payments",
      "iOS + macOS + Android"
    ],
    "networks": [
      "XMR",
      "BTC",
      "Lightning"
    ],
    "badge": "NEW",
    "url": "https://obscura.com/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-27",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "VPN"
    ],
    "description": "Two-party relay VPN pairing an Obscura ingress with an independent Mullvad exit and randomized account numbers.",
    "cardSummary": "Two-party relay VPN with a Mullvad exit.",
    "jurisdiction": "US",
    "auditedBy": [],
    "twitter": null,
    "founderIntel": null,
    "vcIntel": null,
    "privacyWarning": "US-incorporated operator caveat retained. The two-party relay design reduces single-party correlation, but ingress account/payment metadata and app-platform metadata still matter.",
    "stateActorFlag": null,
    "tagline": "2-party relay VPN - neither Obscura nor Mullvad alone can see who you are and what you do.",
    "bestFor": [
      "Maximum-trust VPN architecture",
      "Monero-paid VPN",
      "Privacy from ISP and government"
    ],
    "kycNote": "No identity KYC; log in with randomized account number. Card is optional, and BTC Lightning / Monero are supported for lower-payment-metadata use.",
    "updatedAt": "2026-08-27",
    "followTheMoney": "  Sovereign Engineering Inc - USA (US)\n  ──────────────────────────────────────\n  Founder: Carl Dong (ex-Bitcoin Core)\n  Funding: bootstrapped, zero VC\n  Revenue: VPN subscriptions (XMR/LN)\n  ├─ Five Eyes (US) - FISA/NSL risk\n  ├─ 2-party relay: no single correlator\n  └─ Cure53 audit Dec 2025: zero criticals",
    "lastReviewed": "2026-08-27",
    "kycLastChecked": "2026-08-27",
    "reviewSource": "Primary-source review 2026-08-27",
    "jurisdictionConfidence": "inferred",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://obscura.com/legal/",
        "note": "Official Privacy Policy and Terms of Service identify Sovereign Engineering Inc. d/b/a Obscura as the operating legal entity providing the hosted VPN service."
      },
      "repositoryUrl": {
        "value": "https://github.com/Sovereign-Engineering/obscuravpn-client",
        "citation": "https://github.com/Sovereign-Engineering/obscuravpn-client"
      },
      "legalEntity": {
        "value": "Sovereign Engineering Inc. d/b/a Obscura",
        "citation": "https://obscura.com/legal/"
      },
      "registeredAddress": {
        "value": "150 Nassau St, New York, NY 10038-1529, United States",
        "citation": "https://play.google.com/store/apps/details?id=net.obscura.vpnclientapp&hl=en"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "hosted-account",
      "sourceModel": "partial"
    },
    "changedAt": "2026-08-27",
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://obscura.com/legal/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "The legal page identifies hosted account/subscription, payment, support and network-edge processing; the split-hop design limits traffic visibility but does not eliminate operator metadata."
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://obscura.com/",
            "https://obscura.com/legal/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Obscura sells and operates a subscription VPN account and its entry infrastructure, so service control remains hosted."
        },
        "sourceModel": {
          "value": "partial",
          "sourceUrls": [
            "https://github.com/Sovereign-Engineering/obscuravpn-client",
            "https://obscura.com/legal/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "The official repository covers clients/library code; no current evidence establishes inspectable relay/control-plane infrastructure or reproducible deployment."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "Remove Cure53 from score credit: current first-party pages and repository do not expose a dated, scoped report or remediation record for the score-critical service."
      }
    }
  },
  {
    "id": 1048,
    "slug": "orangewebsite",
    "domain": "orangewebsite.com",
    "name": "OrangeWebsite",
    "type": "Hosting",
    "cat": "hosting",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "monthly": null
    },
    "fee": "Shared hosting from €3.40/mo; Cloud VPS from €22.40/mo",
    "limits": {
      "daily": null
    },
    "features": [
      "Iceland datacenter",
      "Freedom of speech hosting",
      "Crypto payments",
      "Monero via CoinPayments",
      "Domain registration",
      "VPS + web hosting"
    ],
    "networks": [
      "BTC",
      "LTC",
      "ETH",
      "BCH",
      "XMR"
    ],
    "badge": null,
    "url": "https://orangewebsite.com",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Hosting"
    ],
    "description": "Iceland-based hosting under IceNetworks Hong Kong Ltd., with content regulated by Icelandic law.",
    "cardSummary": "Iceland free-speech hosting.",
    "jurisdiction": "IS",
    "auditedBy": [],
    "twitter": null,
    "founderIntel": null,
    "vcIntel": null,
    "privacyWarning": "Legal entity changed from the old Belize note to IceNetworks Hong Kong Ltd. under current terms. Icelandic hosting/content law remains relevant, but privacy policy can collect name, address, phone, email, service/payment history, and domain data depending on service/support/payment path.",
    "stateActorFlag": null,
    "tagline": "Freedom of speech hosting in Iceland. Monero accepted. Belize legal entity.",
    "bestFor": [
      "Offshore website hosting",
      "Crypto-paid VPS",
      "DMCA-resistant content"
    ],
    "kycNote": "No identity KYC found for hosting signup; official homepage says anonymous signup is allowed but a valid email is required. Domain registration/support/payment flows can require additional personal or registrar data.",
    "updatedAt": "2026-08-25",
    "followTheMoney": "  IceNetworks Ltd - Belize (BZ) / Iceland\n  ──────────────────────────────────────\n  Founders: anonymous Scandinavian team\n  Funding: bootstrapped since 2006\n  Revenue: VPS/hosting fees (XMR/BTC)\n  ├─ 2016: fraud site documented (RIPE)\n  ├─ Belize entity: limited accountability\n  └─ Iceland servers: strong privacy law",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "primary_source_rereview_2026-08-25",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://www.cr.gov.hk/docs/wrpt/RNC063_2018.01.08-2018.01.14.pdf (HK Companies Registry weekly incorporation report, primary source, agent-verified by direct PDF fetch)",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "IceNetworks Hong Kong Limited",
        "citation": "https://www.cr.gov.hk/docs/wrpt/RNC063_2018.01.08-2018.01.14.pdf (HK Companies Registry weekly incorporation report, primary source, agent-verified by direct PDF fetch)"
      },
      "registrationNumber": {
        "value": "2637118",
        "citation": "https://www.cr.gov.hk/docs/wrpt/RNC063_2018.01.08-2018.01.14.pdf"
      },
      "registryUrl": {
        "value": "https://www.cr.gov.hk/ (Hong Kong Companies Registry; full company profile requires paid Cyber Search Centre lookup, not free-searchable at this pass)",
        "citation": "https://www.cr.gov.hk/docs/wrpt/RNC063_2018.01.08-2018.01.14.pdf"
      },
      "incorporationJurisdiction": {
        "value": "Hong Kong",
        "citation": "https://www.cr.gov.hk/docs/wrpt/RNC063_2018.01.08-2018.01.14.pdf"
      },
      "incorporationDate": {
        "value": "2018-01-10",
        "citation": "https://www.cr.gov.hk/docs/wrpt/RNC063_2018.01.08-2018.01.14.pdf"
      },
      "registeredAddress": {
        "value": "unknown (weekly incorporation report confirms name/CR number/date only; registered office address requires a paid Cyber Search Centre company search, not obtained in this pass)",
        "citation": "unknown"
      },
      "officers": {
        "value": [],
        "citation": "unknown (requires paid HK Cyber Search Centre company search; not obtained in this pass)"
      },
      "priorEntities": {
        "value": [
          "IceNetworks Ltd. -- Belize entity, address '60 Market Square, Belize City, Belize' per RIPE Database organisation record ORG-IL351-RIPE (a network-resource registry, not a corporate registry; created 2014-11-05, name confirmed live via RIPE REST API 2026-08-08). This is the entity historically used by OrangeWebsite prior to the Hong Kong entity; the exact redomiciliation/rename filing date and Belize IBC registration number were not located in the Belize Companies Registry (companysearch.bz) in this pass."
        ],
        "citation": "https://rest.db.ripe.net/ripe/organisation/ORG-IL351-RIPE.json (RIPE Database, official network registry record, agent-verified by direct API fetch 2026-08-08)"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://orangewebsite.com/",
            "https://orangewebsite.com/privacy-policy.php",
            "https://orangewebsite.com/domain-price-list/",
            "https://orangewebsite.com"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://orangewebsite.com/",
            "https://orangewebsite.com/privacy-policy.php",
            "https://orangewebsite.com/domain-price-list/",
            "https://orangewebsite.com"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://orangewebsite.com/",
            "https://orangewebsite.com/privacy-policy.php",
            "https://orangewebsite.com/domain-price-list/",
            "https://orangewebsite.com"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1049,
    "slug": "basicswap",
    "domain": "basicswapdex.com",
    "name": "BasicSwap",
    "type": "P2P",
    "cat": "p2p",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "no fees (atomic swap)",
    "limits": {
      "daily": null
    },
    "features": [
      "Atomic swaps (trustless)",
      "BTC/XMR native support",
      "No account, no custodian",
      "Decentralized order book (SMSG)",
      "Open source",
      "No central operator"
    ],
    "networks": [
      "BTC",
      "XMR",
      "LTC",
      "FIRO",
      "PART"
    ],
    "badge": null,
    "url": "https://basicswapdex.com",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "P2P"
    ],
    "description": "Open-source cross-chain atomic-swap protocol using a distributed order book, with no central operator or user account.",
    "cardSummary": "Trustless cross-chain atomic swap DEX.",
    "jurisdiction": "??",
    "auditedBy": [],
    "twitter": null,
    "founderIntel": null,
    "vcIntel": null,
    "privacyWarning": "BasicSwap has no central operator or legal entity identified by its current terms, so Swiss/Five-Eyes jurisdiction claims are unsupported. It remains low-liquidity software without a published independent BasicSwap code audit. July and August 2026 swap-security issues were fixed in mandatory releases; update before trading.",
    "stateActorFlag": null,
    "tagline": "Trustless atomic swap DEX. BTC ↔ XMR with no accounts, no custodian, no KYC.",
    "bestFor": [
      "Trustless BTC/XMR swaps",
      "No-counterparty-risk trading",
      "Self-custodial swaps"
    ],
    "kycNote": "No account. No email. Atomic swaps are protocol-level - no service provider can be coerced.",
    "updatedAt": "2026-08-25",
    "followTheMoney": "  Particl Stiftung - Zug, Switzerland (CH)\n  ──────────────────────────────────────\n  Lead Dev: Ryno Mathee (ZA, ex-ChainEx)\n  Funding: ~590 BTC community donation\n  Revenue: none (fee-free atomic swaps)\n  ├─ Advisor: Charlie Shrem (2014 conv.)\n  ├─ CH Crypto Valley: strong privacy law\n  └─ No VC, no institutional investors",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "https://basicswapdex.com/terms.html",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "project-no-legal-entity",
        "citation": "https://basicswapdex.com/terms.html",
        "note": "Current official terms describe open-source software and a system with no operator."
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "official terms recheck 2026-08-25",
      "reviewedAt": "2026-08-25"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://basicswapdex.com/terms.html",
            "https://x.com/BasicSwapDEX/status/2076894892786143518",
            "https://x.com/BasicSwapDEX/status/2077030033273561112",
            "https://x.com/BasicSwapDEX/status/2083562003356930454",
            "https://x.com/BasicSwapDEX/status/2084076112179609945",
            "https://basicswapdex.com"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://basicswapdex.com/terms.html",
            "https://x.com/BasicSwapDEX/status/2076894892786143518",
            "https://x.com/BasicSwapDEX/status/2077030033273561112",
            "https://x.com/BasicSwapDEX/status/2083562003356930454",
            "https://x.com/BasicSwapDEX/status/2084076112179609945",
            "https://basicswapdex.com"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://basicswapdex.com/terms.html",
            "https://x.com/BasicSwapDEX/status/2076894892786143518",
            "https://x.com/BasicSwapDEX/status/2077030033273561112",
            "https://x.com/BasicSwapDEX/status/2083562003356930454",
            "https://x.com/BasicSwapDEX/status/2084076112179609945",
            "https://basicswapdex.com"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1050,
    "slug": "encryptsim",
    "domain": "encryptsim.com",
    "name": "encryptSIM",
    "type": "Comms",
    "cat": "comms",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "monthly": null
    },
    "fee": "from $1.99",
    "limits": {
      "daily": null
    },
    "features": [
      "Global eSIM (138+ countries)",
      "No KYC, no account",
      "Crypto payments",
      "SOC2 Type II certified",
      "Instant delivery"
    ],
    "networks": [
      "Crypto"
    ],
    "badge": "NEW",
    "url": "https://encryptsim.com",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-27",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Comms"
    ],
    "description": "Global data eSIM for 200+ destinations whose terms state no account registration or personal data collection.",
    "cardSummary": "Global eSIM across 200+ destinations.",
    "jurisdiction": "US",
    "auditedBy": [],
    "twitter": null,
    "founderIntel": null,
    "vcIntel": null,
    "privacyWarning": "Lumific Labs Inc. documents account, order/payment, wallet, telecom routing/delivery, support, IP/device, location, cookie and analytics data processed through globally distributed providers. Retention varies by category and legal/operational need.",
    "stateActorFlag": null,
    "tagline": "Global eSIM, 138+ countries. No KYC. No account. Crypto payments.",
    "bestFor": [
      "Anonymous travel data",
      "Global eSIM without identity",
      "Crypto-paid mobile data"
    ],
    "kycNote": "Official terms say no KYC verification, account registration, or personal data collection for the eSIM service. Minimum activation/payment data still passes through telecom and payment providers; crypto purchases are non-refundable.",
    "updatedAt": "2026-06-22",
    "followTheMoney": "  Lumific Inc / Toolbase AI - US + SG\n  ──────────────────────────────────────\n  Team: completely anonymous\n  Funding: bootstrapped (no VC listed)\n  Revenue: eSIM data packages ($1.99+)\n  ├─ Five Eyes (US Delaware) + Singapore\n  ├─ SOC2 Type II: auditor undisclosed\n  └─ Unvetted: team identity unknown",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_8_2026-06-22",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://encryptsim.com/terms-of-service",
        "note": "Official Terms of Service state that encryptSIM is a service provided by Lumific Inc., a company incorporated in Delaware, confirming a real operating company vendor."
      },
      "legalEntity": {
        "value": "Lumific Inc.",
        "citation": "https://encryptsim.com/terms-of-service"
      },
      "incorporationJurisdiction": {
        "value": "Delaware, United States",
        "citation": "https://encryptsim.com/terms-of-service"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "extensive",
      "controlModel": "hosted-account",
      "sourceModel": "closed"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "extensive",
          "sourceUrls": [
            "https://encryptsim.com/privacy-policy"
          ],
          "reviewedAt": "2026-08-27",
          "note": "email, credentials, wallet/blockchain, activation, voice/SMS, support, IP/device, location, analytics and compliance data"
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://encryptsim.com/privacy-policy"
          ],
          "reviewedAt": "2026-08-27",
          "note": "operator-and-carrier-managed-connectivity"
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://encryptsim.com/privacy-policy"
          ],
          "reviewedAt": "2026-08-27",
          "note": "closed-service"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "Stored SOC 2 Type II claim lacks a public report/citation/date/scope; no points."
      }
    }
  },
  {
    "id": 1051,
    "slug": "machankura",
    "domain": "8333.mobi",
    "url": "https://8333.mobi",
    "name": "Machankura",
    "type": "Wallet",
    "cat": "wallet",
    "kyc": "light",
    "kycLevel": 3,
    "fees": {
      "transaction": 1
    },
    "limits": {
      "daily": null
    },
    "features": [
      "USSD Bitcoin",
      "Custodial Lightning wallet",
      "Phone-number accounts",
      "No smartphone required",
      "No internet required",
      "Africa-focused",
      "Feature phone compatible"
    ],
    "coins": [
      "BTC"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": true,
    "countries": [
      "NG",
      "GH",
      "KE",
      "ZA",
      "TZ",
      "UG",
      "ZM",
      "MW"
    ],
    "categories": [
      "Wallet"
    ],
    "description": "Custodial Bitcoin Lightning wallet over USSD, SMS and WhatsApp that works on feature phones without internet.",
    "cardSummary": "Custodial Lightning wallet over USSD and SMS.",
    "jurisdiction": "ZA",
    "auditedBy": [],
    "twitter": "https://x.com/machankura8333",
    "founderIntel": null,
    "vcIntel": null,
    "privacyWarning": "Custodial wallet operated by Port 8333 (Pty) Ltd. The South African service processes phone/account, device, transaction, identity-verification, support, and partner data. FICA identity and transaction records must be retained for at least five years and cannot be deleted on request during that period.",
    "stateActorFlag": null,
    "tagline": "Bitcoin over USSD. No smartphone. No internet. Any phone.",
    "bestFor": [
      "Feature phone users in Africa",
      "Areas with no mobile data coverage",
      "Bitcoin remittances without smartphone"
    ],
    "kycNote": "Port 8333 is a South African FICA accountable institution. It collects phone/account data and may require identity and verification information where applicable; FICA identity and transaction records are retained for at least five years.",
    "updatedAt": "2026-08-25",
    "followTheMoney": "  Machankura / Kgothatso Ngako - ZA\n  ──────────────────────────────────────\n  Founder: Kgothatso Ngako (ZA, KG)\n  Funding: Bitcoin grants, open-source\n  Revenue: none (free USSD service)\n  ├─ ZA jurisdiction (RICA SIM logging)\n  ├─ Carrier logs call metadata by law\n  └─ Not Five Eyes, community-maintained",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "https://54052.co.za/terms",
    "jurisdictionConfidence": "inferred",
    "geo": [
      "NG",
      "GH",
      "KE",
      "ZA",
      "TZ",
      "UG",
      "ZM",
      "MW",
      "NA",
      "CI"
    ],
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://play.google.com/store/apps/details?id=com.machankura.android&hl=en_US",
        "note": "Google Play lists PORT 8333 (PTY) LTD as the developer of the Machankura app; the related 54052.co.za site (linked from 8333.mobi for South Africa) states it is owned and operated by Port 8333 (Pty) Ltd as a licensed FSP, confirming a real operating company runs the custodial wallet service."
      },
      "legalEntity": {
        "value": "Port 8333 (Pty) Ltd",
        "citation": "https://54052.co.za/terms"
      },
      "registrationNumber": {
        "value": "2022/585477/07",
        "citation": "https://54052.co.za/terms"
      },
      "registryUrl": {
        "value": "https://b2bhint.com/fr/company/za/port-8333--K2022585477",
        "citation": "https://b2bhint.com/fr/company/za/port-8333--K2022585477"
      },
      "incorporationJurisdiction": {
        "value": "South Africa",
        "citation": "https://54052.co.za/terms"
      },
      "incorporationDate": {
        "value": "2022-07-05",
        "citation": "https://b2bhint.com/fr/company/za/port-8333--K2022585477"
      },
      "registeredAddress": {
        "value": "1041 Warriors Street, Nellmapius Extension 3, Pretoria, Gauteng, 0122, South Africa",
        "citation": "https://54052.co.za/terms"
      },
      "parentEntity": {
        "value": "Port 8333 Holdings Inc.",
        "citation": "https://54052.co.za/faqs"
      },
      "officers": {
        "value": [
          {
            "name": "Kgothatso Phatedi Alfred Ngako",
            "role": "Director"
          },
          {
            "name": "Kgothatso Ngako",
            "role": "Information Officer"
          }
        ],
        "citation": "https://b2bhint.com/fr/company/za/port-8333--K2022585477"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "fee": "1% transaction fee on wallet spends; network and mobile-operator charges may also apply.",
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://54052.co.za/terms",
            "https://54052.co.za/privacy",
            "https://x.com/Machankura8333/status/2086961708266881284",
            "https://8333.mobi"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://54052.co.za/terms",
            "https://54052.co.za/privacy",
            "https://x.com/Machankura8333/status/2086961708266881284",
            "https://8333.mobi"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://54052.co.za/terms",
            "https://54052.co.za/privacy",
            "https://x.com/Machankura8333/status/2086961708266881284",
            "https://8333.mobi"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1054,
    "slug": "orangefren",
    "name": "OrangeFren",
    "domain": "orangefren.com",
    "url": "https://orangefren.com/",
    "affiliate": null,
    "kyc": "none",
    "kycNote": "No OrangeFren account/KYC for browsing/comparison; listed services and swap/ramp partners can have their own KYC thresholds.",
    "fee": null,
    "limit": null,
    "categories": [
      "Swap",
      "Aggregator"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "No-KYC guarantee",
      "Rate comparison",
      "10+ exchanges",
      "No accounts"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-06-22",
    "changedAt": null,
    "description": "Comparison site and swap front-end listing no-KYC exchanges, VPNs, wallets and ramps, with Tor recommended.",
    "cardSummary": "Comparison site and front-end for no-KYC swaps.",
    "networks": [],
    "checkedAt": "2026-06-23",
    "trending": false,
    "jurisdiction": "??",
    "privacyWarning": "Aggregator/listing site rather than a regulated provider. Trust depends on the selected listed service; OrangeFren itself claims no tracking or personal-information storage.",
    "founderIntel": "Anonymous operator. No corporate entity disclosed. Privacy-first ethos - the site itself collects no data. Community-trusted in Monero circles.",
    "vcIntel": "No known funding. Likely revenue from affiliate/referral fees from listed exchanges. No VC.",
    "ownership": null,
    "auditedBy": null,
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  OrangeFren - Unknown operator\n  ──────────────────────────────────────\n  Operator: Anonymous\n  Revenue: Affiliate referral fees\n  Funding: Self-funded\n  ├─ Only lists no-KYC exchanges\n  ├─ No accounts or tracking\n  └─ No corporate entity disclosed",
    "kycLevel": 0,
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_3_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "project-no-legal-entity",
        "citation": "https://www.reddit.com/r/Monero/comments/v2kygw/orangefren_guarantee_got_scammed_ill_refund_you/",
        "note": "Operator posts in first person calling it 'my website' and personally guaranteeing refunds, with no registered legal entity named on the site, in ToS/Imprint, or in any official company registry; third-party non-profit/project descriptions and conflicting unverified country claims do not establish a company."
      },
      "governanceModel": {
        "value": "individual",
        "citation": "https://www.reddit.com/r/Monero/comments/v2kygw/orangefren_guarantee_got_scammed_ill_refund_you/"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://orangefren.com/",
            "https://github.com/orangefren"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://orangefren.com/",
            "https://github.com/orangefren"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://orangefren.com/",
            "https://github.com/orangefren"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1055,
    "slug": "intercambio",
    "name": "Intercambio",
    "domain": "intercambio.app",
    "url": "https://intercambio.app/",
    "affiliate": null,
    "kyc": "none",
    "kycNote": "No Intercambio account/KYC; partner swap services can still apply their own KYC/compliance rules.",
    "fee": null,
    "limit": null,
    "categories": [
      "Swap",
      "Aggregator"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "No-KYC",
      "Tor-friendly",
      "Rate comparison",
      "No accounts",
      "Open-source"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-06-22",
    "changedAt": null,
    "description": "Account-less swap aggregator with Tor and I2P mirrors, no JavaScript, and exchange data deleted after 30 days.",
    "cardSummary": "Account-less swap aggregator.",
    "networks": [],
    "checkedAt": "2026-06-22",
    "trending": false,
    "jurisdiction": "??",
    "privacyWarning": "Aggregator depends on third-party exchange services. Intercambio itself claims no logs and data deletion after 30 days, but selected partner policy still controls individual swaps.",
    "founderIntel": "Anonymous/pseudonymous developers. Open-source project. No corporate entity. Community project aligned with Monero ecosystem.",
    "vcIntel": "No VC funding. Open-source community project. Revenue likely from referral commissions.",
    "ownership": null,
    "auditedBy": null,
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  Intercambio - Open-source project\n  ──────────────────────────────────────\n  Operator: Anonymous/community\n  Revenue: Referral commissions\n  Funding: Self-funded\n  ├─ Open-source (GitHub)\n  ├─ Tor-friendly, no tracking\n  └─ No corporate entity",
    "kycLevel": 0,
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_3_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "project-no-legal-entity",
        "citation": "https://intercambio.app/",
        "note": "Site describes itself as created by Trusted Monero Community members with no named legal entity, ToS/Imprint, or registry details; it is the private swap interface of the OrangeFren directory, which likewise discloses no company and is presented as a non-profit community project."
      },
      "governanceModel": {
        "value": "individual",
        "citation": "https://www.reddit.com/r/Monero/comments/v2kygw/orangefren_guarantee_got_scammed_ill_refund_you/"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://intercambio.app/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://intercambio.app/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://intercambio.app/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1057,
    "slug": "cyphergoat",
    "name": "CypherGoat",
    "domain": "cyphergoat.com",
    "url": "https://cyphergoat.com/",
    "affiliate": null,
    "kyc": "light",
    "kycNote": "No CypherGoat account/KYC, but official terms say partnered exchanges may rarely require KYC for AML; privacy policy says some partners may require IP logging.",
    "fee": null,
    "limit": null,
    "categories": [
      "Swap",
      "Aggregator"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "No-KYC",
      "Rate comparison",
      "No accounts",
      "Privacy-focused"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-06-22",
    "changedAt": null,
    "description": "Open-source Monero-native swap aggregator comparing partner exchanges over non-custodial routing.",
    "cardSummary": "Monero-native open-source swap aggregator.",
    "networks": [],
    "checkedAt": "2026-08-27",
    "trending": false,
    "jurisdiction": "??",
    "privacyWarning": "CypherGoat may use affiliate-tracking cookies; for specified compliance-requiring partners it logs IP address, user agent and language, anonymizes destination-address/amount transaction data after 14 days, and may retain partner-required IP logs longer. Partner exchanges have separate policies and may require KYC.",
    "founderIntel": "Anonymous operator. No corporate entity disclosed. Focused on Monero ecosystem. Community-trusted.",
    "vcIntel": "No known VC funding. Revenue from referral fees. Self-funded.",
    "ownership": null,
    "auditedBy": [],
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  CypherGoat - Unknown operator\n  ──────────────────────────────────────\n  Operator: Anonymous\n  Revenue: Referral fees\n  Funding: Self-funded\n  ├─ No-KYC guarantee\n  ├─ No accounts or tracking\n  └─ Privacy-focused aggregator",
    "kycLevel": 1,
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_3_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "project-no-legal-entity",
        "citation": "https://4rkal.com/posts/launching-cyphergoat/",
        "note": "Individual developer 4rkal built and operates the open-source aggregator; Terms, Privacy, About, and Shield pages name only 'CypherGoat' with no registered legal entity, and no company registry records were found."
      },
      "governanceModel": {
        "value": "individual",
        "citation": "https://github.com/4rkal"
      },
      "repositoryUrl": {
        "value": "https://github.com/CypherGoat/web",
        "citation": "https://github.com/CypherGoat/web"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "noncustodial-hosted",
      "sourceModel": "partial"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://cyphergoat.com/about"
          ],
          "reviewedAt": "2026-08-27",
          "note": "wallet/transaction, IP/device and partner exchange data"
        },
        "controlModel": {
          "value": "noncustodial-hosted",
          "sourceUrls": [
            "https://cyphergoat.com/about"
          ],
          "reviewedAt": "2026-08-27",
          "note": "open-source-hosted-aggregator"
        },
        "sourceModel": {
          "value": "partial",
          "sourceUrls": [
            "https://github.com/CypherGoat/web"
          ],
          "reviewedAt": "2026-08-27",
          "note": "open-source-web-ui"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "Shield/audit claims lack a dated scoped report."
      }
    }
  },
  {
    "id": 1058,
    "slug": "wizardswap",
    "name": "WizardSwap",
    "domain": "wizardswap.io",
    "url": "https://www.wizardswap.io/",
    "affiliate": null,
    "kyc": "none",
    "kycNote": "No account or identity KYC surface found on the live swap/FAQ pages.",
    "fee": "Typically 2.2%; up to +10% on low-liquidity/excess-demand pairs; network fee deducted from refunds",
    "limit": null,
    "categories": [
      "Swap"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "No-KYC",
      "No accounts",
      "Tor-friendly",
      "Instant"
    ],
    "tagline": null,
    "status": "warning",
    "updatedAt": "2026-08-25",
    "changedAt": null,
    "description": "Registration-free swap front-end covering BTC, XMR, ETH, ZEC, DASH and LTC pairs, with URL-verification warnings.",
    "cardSummary": "Registration-free swaps for BTC, XMR and ZEC.",
    "networks": [],
    "checkedAt": "2026-08-25",
    "trending": false,
    "jurisdiction": "??",
    "privacyWarning": "Anonymous operator with no disclosed legal entity and no substantive published privacy policy or terms. The service runs its own wallets/infrastructure, may freeze or seize suspected stolen funds, warns about phishing domains, and charges a typical 2.2% fee with up to 10% extra on low-liquidity or excess-demand pairs.",
    "founderIntel": "Anonymous operator. No corporate entity. Strong privacy focus - claims zero logs. Onion mirror available.",
    "vcIntel": "No VC. Self-funded. Revenue from swap spread/fees.",
    "ownership": null,
    "auditedBy": null,
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  WizardSwap - Unknown operator\n  ───────────────────────────────────────\n  Operator: Anonymous\n  Revenue: Swap spread/fees\n  Funding: Self-funded\n  ├─ No logs, no accounts\n  ├─ Tor .onion mirror\n  └─ No corporate entity",
    "kycLevel": 0,
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "https://www.wizardswap.io/faq",
    "jurisdictionConfidence": "unknown",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "unresolved",
        "citation": "https://www.wizardswap.io/",
        "note": "Hosted no-KYC crypto swap service with own liquidity and fees operated by the LocalParticl team since 2020, but website and FAQ disclose no legal entity, ToS, privacy policy, imprint or registration details, source code is not public, and no registry records were found."
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "fees": {
      "transaction": 2.2
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.wizardswap.io/faq",
            "https://www.wizardswap.io/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.wizardswap.io/faq",
            "https://www.wizardswap.io/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.wizardswap.io/faq",
            "https://www.wizardswap.io/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1059,
    "slug": "tradeogre",
    "name": "TradeOgre",
    "domain": "tradeogre.com",
    "url": "https://tradeogre.com/",
    "affiliate": null,
    "kyc": "none",
    "kycNote": "No identity KYC source found; official indexed pages continue to describe easy registration and no trade limits.",
    "fee": "0.2%",
    "limit": null,
    "categories": [
      "Swap"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "No-KYC",
      "Order book",
      "Privacy coins",
      "XMR pairs",
      "Low fees"
    ],
    "tagline": null,
    "status": "down",
    "updatedAt": "2026-06-22",
    "changedAt": null,
    "description": "Privacy-coin friendly custodial exchange with order books, advertising easy registration and no trade limits.",
    "cardSummary": "Custodial exchange friendly to privacy coins.",
    "networks": [],
    "checkedAt": "2026-08-26",
    "trending": false,
    "jurisdiction": "??",
    "privacyWarning": "Do not deposit or trade. The RCMP says TradeOgre was dismantled, its platform and cryptoassets were seized, transaction data will be analyzed, and charges may follow.",
    "founderIntel": "Anonymous operators. No corporate entity disclosed in accessible official pages. Direct homepage is Cloudflare-challenged from the VPS.",
    "vcIntel": "No known VC. Revenue from trading fees; ownership remains opaque.",
    "ownership": null,
    "auditedBy": null,
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  TradeOgre - Unknown entity\n  ──────────────────────────────────────\n  Operator: Anonymous (since 2018)\n  Revenue: 0.2% trading fees\n  Funding: Self-funded\n  ├─ Email-only signup, no KYC\n  ├─ Custodial - counterparty risk\n  └─ Unknown jurisdiction/ownership",
    "kycLevel": 1,
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_4_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "partial",
    "riskLevel": "danger",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://rcmp.ca/en/news/2025/09/rcmp-executes-record-seizure-more-56-million-dollars-cryptocurrency",
        "note": "TradeOgre was a centralized custodial cryptocurrency exchange (hosted commercial service) operated without public disclosure of any registered legal entity; RCMP seized it as an unregistered money services business."
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-26",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://tradeogre.com/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "no current operator-controlled policy available"
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://tradeogre.com/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "no current operator-controlled product or custody source available"
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://tradeogre.com/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "no reviewed official source establishes a source model"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "no-score-points-no-cap-exception"
      }
    }
  },
  {
    "id": 1061,
    "slug": "vexl",
    "name": "Vexl",
    "domain": "vexl.it",
    "url": "https://vexl.it/",
    "affiliate": null,
    "kyc": "light",
    "kycNote": "No identity-document KYC found, but a valid phone number is required and contacts/social graph are central to matching.",
    "fee": "Free; Vexl takes no cut, while counterparties set any offer fee",
    "limit": null,
    "categories": [
      "P2P",
      "Bitcoin"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "P2P contact graph",
      "Phone verification",
      "No traditional password account",
      "Open source",
      "On-chain and Lightning offers",
      "Encrypted chat"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-08-25",
    "changedAt": null,
    "description": "Mobile P2P Bitcoin marketplace built on phone verification and a contact-graph web-of-trust rather than accounts.",
    "cardSummary": "P2P bitcoin trading through your contact graph.",
    "networks": [
      "BTC",
      "LIGHTNING"
    ],
    "checkedAt": "2026-08-25",
    "trending": false,
    "jurisdiction": "CZ",
    "privacyWarning": "A valid phone number and contact graph are required. FAQ says encrypted messages are temporarily stored on Vexl servers, FCM handles push notifications, and revealing identity shares profile/phone information; this is narrower than the homepage's absolute no-personal-data/no-message-storage claim.",
    "founderIntel": "Built by SatoshiLabs (makers of Trezor). Marek 'Slush' Palatinus (SatoshiLabs CEO) is key figure. Czech Republic based. Open-source, non-profit initiative.",
    "vcIntel": "Funded by SatoshiLabs. No external VC. SatoshiLabs is self-funded from Trezor hardware wallet sales. Czech company.",
    "ownership": null,
    "auditedBy": null,
    "stateActorFlag": null,
    "twitter": "https://x.com/vaborxlapp",
    "telegram": null,
    "followTheMoney": "  Vexl (SatoshiLabs) - Prague, CZ\n  ──────────────────────────────────────\n  Parent: SatoshiLabs s.r.o.\n  Key: Marek 'Slush' Palatinus\n  Revenue: Non-profit initiative\n  ├─ Open-source, SatoshiLabs funded\n  ├─ Phone contacts for P2P matching\n  └─ Czech jurisdiction",
    "kycLevel": 1,
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "primary_source_rereview_2026-08-25",
    "jurisdictionConfidence": "inferred",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://vexl.it/terms-privacy",
        "note": "Terms of Service state the operator is the commercial company Vexl s.r.o. (IČO 17270642) registered in the Czech commercial register under file C 369216; website and app listings confirm the same operating entity alongside a related foundation."
      },
      "governanceModel": {
        "value": "company-sponsored",
        "citation": "https://vexl.it/terms-privacy"
      },
      "repositoryUrl": {
        "value": "https://github.com/vexl-it/vexl",
        "citation": "https://github.com/vexl-it/vexl"
      },
      "legalEntity": {
        "value": "Vexl s.r.o.",
        "citation": "https://vexl.it/terms-privacy"
      },
      "registrationNumber": {
        "value": "17270642",
        "citation": "https://or.justice.cz/ias/ui/rejstrik-$firma?ico=17270642"
      },
      "registryUrl": {
        "value": "https://or.justice.cz/ias/ui/rejstrik-$firma?ico=17270642",
        "citation": "https://or.justice.cz/ias/ui/rejstrik-$firma?ico=17270642"
      },
      "incorporationJurisdiction": {
        "value": "Czech Republic",
        "citation": "https://or.justice.cz/ias/ui/rejstrik-$firma?ico=17270642"
      },
      "incorporationDate": {
        "value": "2022-06-22",
        "citation": "https://or.justice.cz/ias/ui/rejstrik-$firma?ico=17270642"
      },
      "registeredAddress": {
        "value": "Kundratka 2359/17a, Libeň, 180 00 Praha 8, Czech Republic",
        "citation": "https://or.justice.cz/ias/ui/rejstrik-$firma?ico=17270642"
      },
      "parentEntity": {
        "value": "SatoshiLabs Group a.s. (IČO 08685916, shareholder/společník)",
        "citation": "https://www.podnikatel.cz/rejstrik/vexl-s-r-o-17270642/"
      },
      "officers": {
        "value": [
          {
            "name": "Viliam Klamarčík",
            "role": "jednatel (managing director) (2025-11-25)"
          },
          {
            "name": "Lea Petrášová",
            "role": "former jednatel (managing director) and společník (shareholder) (2025-11-25)"
          }
        ],
        "citation": "https://www.podnikatel.cz/rejstrik/vexl-s-r-o-17270642/"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://vexl.it/",
            "https://vexl.it/faq",
            "https://vexl.it/terms-privacy",
            "https://api.github.com/repos/vexl-it/vexl/releases/latest"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://vexl.it/",
            "https://vexl.it/faq",
            "https://vexl.it/terms-privacy",
            "https://api.github.com/repos/vexl-it/vexl/releases/latest"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://vexl.it/",
            "https://vexl.it/faq",
            "https://vexl.it/terms-privacy",
            "https://api.github.com/repos/vexl-it/vexl/releases/latest"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1062,
    "slug": "swapzone",
    "name": "Swapzone",
    "domain": "swapzone.io",
    "url": "https://swapzone.io/",
    "affiliate": null,
    "kyc": "light",
    "kycNote": "Swapzone itself does not require an account for aggregator swaps; partner exchanges/ramps can mark KYC as often or always and may require verification.",
    "fee": null,
    "limit": null,
    "categories": [
      "Swap",
      "Aggregator"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "Rate comparison",
      "15+ exchanges",
      "No accounts",
      "Instant"
    ],
    "tagline": null,
    "status": "warning",
    "updatedAt": "2026-06-22",
    "changedAt": null,
    "description": "Accountless non-custodial aggregator comparing 18+ exchange, DEX and P2P partners that mark KYC frequency.",
    "cardSummary": "Aggregator comparing 18+ swap partners.",
    "networks": [],
    "checkedAt": "2026-08-26",
    "trending": false,
    "jurisdiction": "GE",
    "privacyWarning": "Aggregator/front-end risk: partner exchanges control custody, KYC triggers, freezes and payout execution.",
    "founderIntel": "Founded by Sergey Klinkov (CEO). Registered in Estonia (Swapzone OÜ). Small team, Tallinn-based. LinkedIn presence. Corporate entity with Estonian e-Residency.",
    "vcIntel": "No significant VC disclosed. Likely bootstrapped or angel-funded. Revenue from referral commissions from partner exchanges.",
    "ownership": null,
    "auditedBy": null,
    "stateActorFlag": null,
    "twitter": "https://x.com/swapaborzone",
    "telegram": null,
    "followTheMoney": "  Swapzone OÜ - Tallinn, Estonia (EE)\n  ──────────────────────────────────────\n  CEO: Sergey Klinkov\n  Revenue: Referral commissions\n  Funding: Bootstrapped\n  ├─ Estonian e-Residency company\n  ├─ 15+ exchange partners\n  └─ Some partners enforce KYC",
    "kycLevel": 2,
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-08-26",
    "reviewSource": "official_site_batch_4_2026-06-22",
    "jurisdictionConfidence": "inferred",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://swapzone.io/docs/privacy",
        "note": "Official Privacy Policy and Terms name Block Back LLC as the incorporated Georgian legal entity operating Swapzone."
      },
      "legalEntity": {
        "value": "Block Back LLC (შპს ბლოქ ბექ)",
        "citation": "https://swapzone.io/docs/privacy"
      },
      "registrationNumber": {
        "value": "402184710",
        "citation": "https://swapzone.io/docs/privacy"
      },
      "registryUrl": {
        "value": "https://enreg.reestri.gov.ge/main.php?m=new_index",
        "citation": "https://enreg.reestri.gov.ge/main.php?m=new_index&l=en"
      },
      "incorporationJurisdiction": {
        "value": "Georgia",
        "citation": "https://swapzone.io/docs/privacy"
      },
      "registeredAddress": {
        "value": "Georgia, Tbilisi, Saburtalo district, Bakhtrioni street, N 22, flat N 75",
        "citation": "https://swapzone.io/docs/privacy"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "limited",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-26",
      "inputs": {
        "operatorDataExposure": {
          "value": "limited",
          "sourceUrls": [
            "https://swapzone.io/docs/privacy"
          ],
          "reviewedAt": "2026-08-26",
          "note": "policy distinguishes website data from partner-controlled exchange/KYC data"
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://swapzone.io/docs/privacy",
            "https://swapzone.io/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "current reviewed sources establish aggregation and partner routing but not a durable normalized control model"
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://swapzone.io/docs/privacy",
            "https://swapzone.io/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "no reviewed official source establishes a source model"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "no-score-points-no-cap-exception"
      }
    }
  },
  {
    "id": 1063,
    "slug": "coinoswap",
    "name": "CoinoSwap",
    "domain": "coinoswap.com",
    "url": "https://coinoswap.com/",
    "affiliate": null,
    "kyc": "light",
    "kycNote": "No CoinoSwap account required for aggregator use; partner exchanges/on-ramps may request KYC or enforce thresholds independently.",
    "fee": null,
    "limit": null,
    "categories": [
      "Swap",
      "Aggregator"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "No-KYC",
      "Rate comparison",
      "No accounts",
      "Instant"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-06-22",
    "changedAt": null,
    "description": "Non-custodial swap aggregator and rate comparison site whose partner ramps apply their own KYC thresholds.",
    "cardSummary": "Non-custodial swap rate comparison site.",
    "networks": [],
    "checkedAt": "2026-08-27",
    "trending": false,
    "jurisdiction": "US",
    "privacyWarning": "Aggregator depends on third-party swap partners. CoinoSwap pages heavily promote no-KYC, but partner compliance can still trigger identity checks; treat as light KYC risk.",
    "founderIntel": "Unknown operator. No corporate entity disclosed. Minimal public information.",
    "vcIntel": "No known funding. Revenue from referral commissions.",
    "ownership": null,
    "auditedBy": [],
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  CoinoSwap - Unknown operator\n  ────────────────────────────────────────\n  Operator: Unknown\n  Revenue: Referral commissions\n  Funding: Unknown\n  ├─ No accounts required\n  └─ No corporate entity disclosed",
    "kycLevel": 1,
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_3_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://coinoswap.com/terms-of-use",
        "note": "Official Terms of Use state that CoinoSwap refers to Coinoisseurs LLC, a registered company in Wyoming, USA; site lists a Wyoming legal address and operates as a hosted swap aggregator."
      },
      "legalEntity": {
        "value": "Coinoisseurs LLC",
        "citation": "https://coinoswap.com/terms-of-use"
      },
      "registrationNumber": {
        "value": "2024-001534402",
        "citation": "https://thegrid.id/profiles/coinoswap"
      },
      "registryUrl": {
        "value": "https://wyobiz.wyo.gov/Business/FilingSearch.aspx",
        "citation": "https://wyobiz.wyo.gov/Business/FilingSearch.aspx"
      },
      "incorporationJurisdiction": {
        "value": "Wyoming, United States",
        "citation": "https://coinoswap.com/terms-of-use"
      },
      "registeredAddress": {
        "value": "1309 Coffeen Avenue, Suite 16200, Sheridan, Wyoming 82801",
        "citation": "https://coinoswap.com/about-us"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "noncustodial-hosted",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://coinoswap.com/privacy-policy"
          ],
          "reviewedAt": "2026-08-27",
          "note": "wallet addresses, transactions, IP, device/browser/OS, optional email, cookies and partner communications"
        },
        "controlModel": {
          "value": "noncustodial-hosted",
          "sourceUrls": [
            "https://coinoswap.com/privacy-policy"
          ],
          "reviewedAt": "2026-08-27",
          "note": "hosted-aggregator-over-partners"
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://coinoswap.com/privacy-policy"
          ],
          "reviewedAt": "2026-08-27",
          "note": "closed-or-undisclosed"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No audit/security disclosure evidence."
      }
    }
  },
  {
    "id": 1064,
    "slug": "clearswap",
    "name": "ClearSwap",
    "domain": "clearswap.io",
    "url": "https://clearswap.io/",
    "affiliate": null,
    "kyc": "light",
    "kycNote": "No explicit identity-KYC requirement found in official terms, but privacy policy allows collection of email, wallet address, device/browser/IP data, cookies and other personal data. Do not treat as zero-KYC.",
    "fee": null,
    "limit": null,
    "categories": [
      "Swap"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "No-KYC",
      "No accounts",
      "Instant",
      "Privacy-focused"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-06-22",
    "changedAt": null,
    "description": "Cross-network swap app with generic terms rather than a stated no-KYC policy, and Google Analytics on its site.",
    "cardSummary": "Swap app for confidential cross-network swaps.",
    "networks": [],
    "checkedAt": "2026-08-27",
    "trending": false,
    "jurisdiction": null,
    "privacyWarning": "Unvetted operator and generic legal PDFs. Privacy policy is broad, and the site loads Google Analytics; use only as a higher-risk swap frontend.",
    "founderIntel": "Anonymous operator. No corporate entity disclosed. Relatively new service.",
    "vcIntel": "No known funding. Revenue from swap spread.",
    "ownership": null,
    "auditedBy": [],
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  ClearSwap - Unknown operator\n  ──────────────────────────────────────\n  Operator: Anonymous\n  Revenue: Swap spread\n  Funding: Unknown\n  ├─ No accounts, no KYC\n  └─ No corporate entity disclosed",
    "kycLevel": 1,
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_3_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://clearswap.io/pdf/clearswap-terms-of-use.pdf",
        "note": "Hosted commercial swap interface (clearswap.io / app.clearswap.io) operated by an undisclosed 'Administration' whose Terms describe directors, members, employees and affiliates; not an open-source project without an operator."
      },
      "repositoryUrl": {
        "value": "https://github.com/Cryptorubic",
        "citation": "https://github.com/Cryptorubic"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "noncustodial-hosted",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://clearswap.io/pdf/clearswap-terms-of-use.pdf"
          ],
          "reviewedAt": "2026-08-27",
          "note": "email, wallet, device/browser/IP, cookies and Google Analytics data"
        },
        "controlModel": {
          "value": "noncustodial-hosted",
          "sourceUrls": [
            "https://clearswap.io/pdf/clearswap-terms-of-use.pdf"
          ],
          "reviewedAt": "2026-08-27",
          "note": "hosted-frontend-over-third-party-protocols"
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://clearswap.io/pdf/clearswap-terms-of-use.pdf"
          ],
          "reviewedAt": "2026-08-27",
          "note": "claimed-open-protocol-unverified-deployment"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No independent audit or vulnerability-disclosure evidence."
      }
    }
  },
  {
    "id": 1066,
    "slug": "cryptostorm",
    "name": "Cryptostorm",
    "domain": "cryptostorm.is",
    "url": "https://cryptostorm.is/",
    "affiliate": null,
    "kyc": "none",
    "kycNote": "No account KYC for token use; XMR and NOWPayments options avoid email according to official privacy policy. Card/CCBill paths retain payment processor transaction IDs.",
    "fee": "$1.86/week; $6/month; $52/year; $94/two years",
    "limit": null,
    "categories": [
      "VPN"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "Token-based",
      "No accounts",
      "No email for XMR/NOWPayments",
      "Tor and I2P access",
      "OpenVPN",
      "WireGuard",
      "Multihop",
      "Open-source tooling"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-06-22",
    "changedAt": null,
    "description": "Token-based VPN with no account or email on the XMR purchase path, plus Tor and I2P site access and multihop.",
    "cardSummary": "Token-based VPN reachable over Tor and I2P.",
    "networks": [],
    "checkedAt": "2026-08-27",
    "trending": false,
    "jurisdiction": null,
    "privacyWarning": "Official privacy policy says web logs are retained up to two weeks and that cryptostorm has no active EU business entity. Existing founder/operator opacity warning remains relevant.",
    "founderIntel": "Originally founded by Douglas Spink (controversial). Now run by anonymous/pseudonymous team after restructuring. Icelandic jurisdiction. Long-running (since 2013).",
    "vcIntel": "No VC. Self-funded from token sales. Unique model - single-use activation tokens instead of accounts.",
    "ownership": null,
    "auditedBy": [],
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  Cryptostorm - Iceland (IS)\n  ──────────────────────────────────────\n  Operator: Pseudonymous team\n  Revenue: Token-based access sales\n  Funding: Self-funded\n  ├─ No accounts or email needed\n  ├─ Icelandic jurisdiction\n  └─ Token activation model",
    "kycLevel": 0,
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_3_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://cryptostorm.is/",
        "note": "Commercial paid VPN service; site footer names Cryptostorm LLC and ToS/FAQ repeatedly refer to the company and its business entities."
      },
      "repositoryUrl": {
        "value": "https://github.com/cryptostorm",
        "citation": "https://github.com/cryptostorm"
      },
      "legalEntity": {
        "value": "Cryptostorm LLC",
        "citation": "https://cryptostorm.is/"
      },
      "incorporationJurisdiction": {
        "value": "Delaware, United States",
        "citation": "https://cryptostorm.is/"
      },
      "registeredAddress": {
        "value": "Dover, DE, US",
        "citation": "https://cryptostorm.is/"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "limited",
      "controlModel": "hosted-account",
      "sourceModel": "partial"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "limited",
          "sourceUrls": [
            "https://cryptostorm.is/privacy"
          ],
          "reviewedAt": "2026-08-27",
          "note": "short-lived web logs, token/payment references and processor-specific data"
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://cryptostorm.is/privacy"
          ],
          "reviewedAt": "2026-08-27",
          "note": "operator-hosted-vpn"
        },
        "sourceModel": {
          "value": "partial",
          "sourceUrls": [
            "https://cryptostorm.is/privacy"
          ],
          "reviewedAt": "2026-08-27",
          "note": "partial-open-source-clients-configs"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No current independent audit citation/date/scope."
      }
    }
  },
  {
    "id": 1067,
    "slug": "safing-spn",
    "name": "Safing SPN",
    "domain": "safing.io",
    "url": "https://safing.io/",
    "affiliate": null,
    "kyc": "light",
    "kycNote": "Account/payment metadata exists for paid SPN/Portmaster Pro. Privacy policy lists username, email for some payment/account contact paths, country/calling code for Austrian tax, and payment data; BTC/XMR payments reduce but do not remove account metadata.",
    "fee": "Portmaster Free: free; Plus: €40/yr; Pro with SPN: €8/mo or €80/yr",
    "limit": null,
    "categories": [
      "VPN",
      "Privacy Tools"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "SPN multi-hop routing",
      "Per-app routing",
      "Open source",
      "Portmaster firewall",
      "Bitcoin payments",
      "Monero payments",
      "Split tunneling"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-08-25",
    "changedAt": null,
    "description": "Portmaster and SPN privacy network using per-connection multi-hop routing, priced in cards, Bitcoin or Monero.",
    "cardSummary": "Multi-hop privacy network from Portmaster.",
    "networks": [],
    "checkedAt": "2026-08-25",
    "trending": false,
    "jurisdiction": "AT",
    "privacyWarning": "Not a no-account VPN. Official privacy policy details account, tax-country, payment, IP/user-agent log retention, and SPN service metadata handling; Austrian jurisdiction verified.",
    "founderIntel": "Founded by Daniel Dingeldey and Raphael Fiedler. Safing ICS Technologies GmbH, Vienna, Austria. Small team (~10). Open-source advocates.",
    "vcIntel": "Received EU funding (NGI/NLnet grants). Netidee grant (Austrian Internet Foundation). FFG (Austrian Research Promotion Agency). No traditional VC. Revenue from SPN subscriptions.",
    "ownership": null,
    "auditedBy": null,
    "stateActorFlag": null,
    "twitter": "https://x.com/SafingIO",
    "telegram": null,
    "followTheMoney": "  Safing ICS Tech GmbH - Vienna, AT\n  ──────────────────────────────────────\n  Founders: Dingeldey & Fiedler\n  Revenue: SPN subscriptions\n  Funding: EU/NGI grants, Netidee, FFG\n  ├─ Austrian jurisdiction, GDPR\n  ├─ Open-source (Portmaster + SPN)\n  └─ No traditional VC backing",
    "kycLevel": 1,
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "primary_source_rereview_2026-08-25",
    "jurisdictionConfidence": "verified",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://safing.io/ownership/",
        "note": "Official ownership and Impressum pages state Safing ICS Technologies GmbH, a private Austrian GmbH, operates Safing/SPN/Portmaster; confirmed in Austrian Firmenbuch FN 464654s."
      },
      "governanceModel": {
        "value": "company-sponsored",
        "citation": "https://safing.io/ownership/"
      },
      "repositoryUrl": {
        "value": "https://github.com/safing/portmaster",
        "citation": "https://github.com/safing/portmaster"
      },
      "legalEntity": {
        "value": "Safing ICS Technologies GmbH",
        "citation": "https://safing.io/contact/"
      },
      "registrationNumber": {
        "value": "FN 464654s",
        "citation": "https://safing.io/contact/"
      },
      "registryUrl": {
        "value": "https://www.evi.gv.at/f/464654s",
        "citation": "https://www.evi.gv.at/f/464654s"
      },
      "incorporationJurisdiction": {
        "value": "Austria",
        "citation": "https://safing.io/terms/"
      },
      "incorporationDate": {
        "value": "2017-01-13",
        "citation": "https://www.evi.gv.at/f/464654s"
      },
      "registeredAddress": {
        "value": "Heinrich Bablik-Straße 17a/4, 2345 Brunn am Gebirge, Austria",
        "citation": "https://www.evi.gv.at/f/464654s"
      },
      "ultimateOwner": {
        "value": "Nicholas Pestell",
        "citation": "https://www.evi.gv.at/f/464654s"
      },
      "officers": {
        "value": [
          "Nicholas Pestell (Geschäftsführer)"
        ],
        "citation": "https://www.evi.gv.at/f/464654s"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://safing.io/",
            "https://safing.io/blog/2026/02/24/price-update/",
            "https://safing.io/privacy/",
            "https://x.com/SafingIO/status/2065919304667693169",
            "https://x.com/SafingIO/status/2066071863667618271",
            "https://x.com/SafingIO/status/2078063649546006896"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://safing.io/",
            "https://safing.io/blog/2026/02/24/price-update/",
            "https://safing.io/privacy/",
            "https://x.com/SafingIO/status/2065919304667693169",
            "https://x.com/SafingIO/status/2066071863667618271",
            "https://x.com/SafingIO/status/2078063649546006896"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://safing.io/",
            "https://safing.io/blog/2026/02/24/price-update/",
            "https://safing.io/privacy/",
            "https://x.com/SafingIO/status/2065919304667693169",
            "https://x.com/SafingIO/status/2066071863667618271",
            "https://x.com/SafingIO/status/2078063649546006896"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1068,
    "slug": "xeovo",
    "name": "Xeovo VPN",
    "domain": "xeovo.com",
    "url": "https://xeovo.com/",
    "affiliate": null,
    "kyc": "light",
    "kycNote": "No identity KYC found; registration stores username/password, optional email, payment/order metadata, service keys and support tickets.",
    "fee": null,
    "limit": null,
    "categories": [
      "VPN"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "No logs",
      "Crypto accepted",
      "WireGuard",
      "Finnish jurisdiction"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-06-22",
    "changedAt": null,
    "description": "Finland-based no-logs VPN and stealth proxy where accounts use a username and password with optional email.",
    "cardSummary": "Finnish no-logs VPN and stealth proxy.",
    "networks": [],
    "checkedAt": "2026-08-26",
    "trending": false,
    "jurisdiction": "FI",
    "privacyWarning": "Xeovo can provide account/payment metadata for a specific user if a valid court order targets that person; it says it stores no activity logs.",
    "founderIntel": "Xeovo Oy, registration no. 3233901-7, Helsinki, Finland. Limited founder transparency beyond the legal entity.",
    "vcIntel": "No known VC. Revenue from VPN/proxy subscriptions.",
    "ownership": null,
    "auditedBy": null,
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  Xeovo OÜ - Estonia (EE)\n  ────────────────────────────────────────\n  Operator: Xeovo OÜ\n  Revenue: VPN subscriptions\n  Funding: Bootstrapped\n  ├─ Estonian jurisdiction, GDPR\n  ├─ WireGuard, no-logs\n  └─ Limited public transparency",
    "kycLevel": 1,
    "lastReviewed": "2026-08-26",
    "kycLastChecked": "2026-08-26",
    "reviewSource": "Primary-source review 2026-08-26",
    "jurisdictionConfidence": "verified",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://xeovo.com/tos/",
        "note": "Terms of Service explicitly state Xeovo is a service provided by Xeovo Oy, a company registered in Finland; website and privacy policy confirm it as an operating limited company headquartered in Finland."
      },
      "legalEntity": {
        "value": "Xeovo Oy",
        "citation": "https://xeovo.com/tos/"
      },
      "registrationNumber": {
        "value": "3233901-7",
        "citation": "https://xeovo.com/privacy/"
      },
      "registryUrl": {
        "value": "https://kontakto.fi/en/company/3233901-7",
        "citation": "https://kontakto.fi/en/company/3233901-7"
      },
      "incorporationJurisdiction": {
        "value": "Finland",
        "citation": "https://xeovo.com/privacy/"
      },
      "incorporationDate": {
        "value": "2021-09-09",
        "citation": "https://www.finder.fi/Tietoturvapalvelut/Xeovo+Oy/Helsinki/yhteystiedot/3657637"
      },
      "registeredAddress": {
        "value": "Rautiontie 5G 30, 00640 Helsinki, Finland",
        "citation": "https://xeovo.com/privacy/"
      },
      "officers": {
        "value": [
          {
            "name": "Nikita Kononov",
            "role": "Toimitusjohtaja (CEO) and Varsinainen jäsen (Board Member)"
          }
        ],
        "citation": "https://www.proff.fi/yrityksen/xeovo-oy/helsinki/tietokoneohjelmistot-ja-ohjelmistokehitys/3233901-7I009O"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "hosted-account",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-26",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://xeovo.com/privacy/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "official privacy policy explicitly enumerates account, payment and support data"
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://xeovo.com/privacy/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "official policy describes service accounts, keys, payment records and support tickets"
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://xeovo.com/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "open WireGuard/OpenVPN protocols do not establish the source model of Xeovo's complete service"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "no-score-points-no-cap-exception"
      }
    }
  },
  {
    "id": 1069,
    "slug": "privatealps",
    "name": "PrivateAlps",
    "domain": "privatealps.net",
    "url": "https://privatealps.net/",
    "affiliate": null,
    "kyc": "none",
    "kycNote": "No document identity verification was surfaced, but account login requires an email address and account-management data exists. Anonymous payment options are advertised; verify the checkout path before relying on anonymity.",
    "fee": "From €12.90/mo for Linux VPS",
    "limit": null,
    "categories": [
      "VPN",
      "Hosting"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "Swiss privacy",
      "VPN+VPS",
      "Anonymous payment options",
      "Tor-friendly"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-06-22",
    "changedAt": null,
    "description": "Swiss VPS and cloud hosting advertising privacy, no-logs infrastructure and anonymous payment options.",
    "cardSummary": "Swiss offshore web, VPS and cloud hosting.",
    "networks": [],
    "checkedAt": "2026-06-24",
    "trending": false,
    "jurisdiction": "CH",
    "privacyWarning": "PrivateAlps publishes current terms and a privacy policy claiming no VPN-session, browsing-history or access-record logs, but it will act on competent Swiss court orders. The operator’s legal entity and registry identity remain unresolved, and service deposits are generally final.",
    "founderIntel": "Anonymous operator. Claims Swiss jurisdiction. No corporate entity publicly disclosed.",
    "vcIntel": "No known funding. Self-funded. Revenue from VPN/VPS subscriptions.",
    "ownership": null,
    "auditedBy": [],
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  PrivateAlps - Switzerland (CH)\n  ──────────────────────────────────────\n  Operator: Anonymous\n  Revenue: VPN/VPS subscriptions\n  Funding: Self-funded\n  ├─ Claims Swiss jurisdiction\n  ├─ Crypto-only payments\n  └─ No corporate entity disclosed",
    "kycLevel": 0,
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_3_2026-06-22",
    "jurisdictionConfidence": "verified",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://privatealps.net/en/terms-of-service",
        "note": "Commercial paid VPN/VPS/hosting vendor; its Terms define We/Us/Provider/Company as PrivateAlps.net and sell hosted services, not an open-source project or foundation."
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "hosted-account",
      "sourceModel": "closed"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://privatealps.net/en/privacy-policy",
            "https://privatealps.net/en/login"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Account email, payments, tickets, service records and hosted infrastructure create moderate exposure despite no-logs claims for VPN/browser activity."
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://privatealps.net/en/services/linux-vps",
            "https://privatealps.net/en/login"
          ],
          "reviewedAt": "2026-08-27",
          "note": "PrivateAlps provisions VPS/VPN/cloud services through hosted accounts and retains administrative control."
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://privatealps.net/en/terms-of-service"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No official score-critical implementation or reproducible infrastructure source was published."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced; no audit points are granted."
      }
    }
  },
  {
    "id": 1070,
    "slug": "servers-guru",
    "name": "Servers Guru",
    "domain": "servers.guru",
    "url": "https://servers.guru/",
    "affiliate": null,
    "kyc": "none",
    "kycNote": "No identity KYC found; account requires a working email address and support/contact forms can collect optional contact/company fields.",
    "fee": "VPS from €4.99/month; cloud servers from €21.99/month.",
    "limit": null,
    "categories": [
      "Hosting"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "Crypto accepted",
      "VPS",
      "Cloud servers",
      "Dedicated servers",
      "S3 object storage",
      "1 Gbps ports",
      "DDoS protection",
      "24/7 support",
      "No identity-document KYC advertised"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-08-25",
    "changedAt": null,
    "description": "VPS, dedicated server and web hosting collecting only a working email, paid in BTC, XMR, LTC, cards or PayPal.",
    "cardSummary": "VPS and hosting needing only an email address.",
    "networks": [],
    "checkedAt": "2026-08-25",
    "trending": false,
    "jurisdiction": "US",
    "privacyWarning": "Moula World LLC requires an email address and processes hosting, IP, payment/billing, and support records. The service is not bulletproof hosting, may respond to valid legal process, and its Terms select New Mexico law and courts.",
    "founderIntel": "Limited public information. Official pages describe privacy-friendly anonymous hosting but do not clearly disclose a corporate entity.",
    "vcIntel": "No known funding. Revenue from hosting services.",
    "ownership": null,
    "auditedBy": null,
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  Servers Guru - Unknown jurisdiction\n  ──────────────────────────────────────\n  Operator: Unknown\n  Revenue: Hosting services\n  Funding: Self-funded\n  └─ Crypto accepted, no KYC",
    "kycLevel": 0,
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "https://servers.guru/",
    "jurisdictionConfidence": "verified",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://servers.guru/terms-conditions/",
        "note": "Official Terms of Service state that services on Servers.guru are provided by Moula World LLC, confirmed on moula.world as the operating company for the hosting brand."
      },
      "legalEntity": {
        "value": "Moula World LLC",
        "citation": "https://servers.guru/terms-conditions/"
      },
      "registrationNumber": {
        "value": "6478786",
        "citation": "https://www.city-data.com/business-entities/NM/MOULA-WORLD-LLC-6478786-NM.html"
      },
      "registryUrl": {
        "value": "https://enterprise.sos.nm.gov/search/business",
        "citation": "https://www.city-data.com/business-entities/NM/MOULA-WORLD-LLC-6478786-NM.html"
      },
      "incorporationJurisdiction": {
        "value": "New Mexico, United States",
        "citation": "https://www.city-data.com/business-entities/NM/MOULA-WORLD-LLC-6478786-NM.html"
      },
      "incorporationDate": {
        "value": "2021-05-25",
        "citation": "https://www.city-data.com/business-entities/NM/MOULA-WORLD-LLC-6478786-NM.html"
      },
      "registeredAddress": {
        "value": "8206 Louisiana Blvd NE, Ste A #625, Albuquerque, NM 87113, United States",
        "citation": "https://www.city-data.com/business-entities/NM/MOULA-WORLD-LLC-6478786-NM.html"
      },
      "officers": {
        "value": [
          {
            "name": "Lovette Dobson",
            "role": "Organizer"
          }
        ],
        "citation": "https://www.city-data.com/business-entities/NM/MOULA-WORLD-LLC-6478786-NM.html"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://servers.guru/",
            "https://servers.guru/terms-conditions/",
            "https://x.com/Servers__Guru/status/2089950740521378129"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://servers.guru/",
            "https://servers.guru/terms-conditions/",
            "https://x.com/Servers__Guru/status/2089950740521378129"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://servers.guru/",
            "https://servers.guru/terms-conditions/",
            "https://x.com/Servers__Guru/status/2089950740521378129"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1072,
    "slug": "kyun",
    "name": "KYUN",
    "domain": "kyun.sh",
    "url": "https://kyun.sh/",
    "affiliate": null,
    "kyc": "none",
    "kycNote": "Kyun says it never asks for identity documents. An account is still required and it stores contact details, service/IP history, transaction data, and Stripe identifiers when a card is linked.",
    "fee": "VMs from €1.60/month; HDD block storage from €5/TB/month.",
    "limit": null,
    "categories": [
      "Hosting"
    ],
    "countries": [
      "RO",
      "NL",
      "US"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "KVM virtual machines",
      "Linux containers",
      "One-click private apps",
      "Block storage",
      "DDoS protection",
      "Monero deposits",
      "Card payments",
      "Tor access"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-08-25",
    "changedAt": null,
    "description": "Privacy-focused cloud hosting for virtual machines, one-click apps, and block storage in Romania, the Netherlands, and the United States, with Monero and card payments.",
    "cardSummary": "Private VMs, apps, and storage with Monero or card payments.",
    "networks": [],
    "checkedAt": "2026-08-25",
    "trending": false,
    "jurisdiction": "RO",
    "privacyWarning": "Kyun stores account contact data, assigned-IP history, payments and service configuration. VM disks are not provider-encrypted or backed up. Kyoko live-chat messages go to a third-party LLM unless Ultra Private Mode is enabled. Romanian law and the host country's law apply, and uptime is not guaranteed.",
    "founderIntel": "Limited information. Small operator.",
    "vcIntel": "No known funding. Revenue from VPS sales.",
    "ownership": null,
    "auditedBy": null,
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  KYUN - Unknown jurisdiction\n  ──────────────────────────────────────\n  Operator: Unknown\n  Revenue: VPS hosting fees\n  Funding: Self-funded\n  └─ Crypto accepted, no KYC",
    "kycLevel": 1,
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "https://kyun.sh/",
    "jurisdictionConfidence": "verified",
    "geo": [
      "NL",
      "US",
      "RO"
    ],
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://kyun.sh/",
        "note": "Self-describes as an EU company bound by GDPR and publishes Kyun SRL / CUI 51514103 / J2025021445009 on site pages; confirmed as Romanian SRL in ONRC-sourced registries."
      },
      "legalEntity": {
        "value": "KYUN S.R.L. (Kyun SRL)",
        "citation": "https://listafirme.ro/kyun-srl-51514103/"
      },
      "registrationNumber": {
        "value": "J2025021445009 (CUI/CIF 51514103; EUID ROONRC.J2025021445009)",
        "citation": "https://listafirme.ro/kyun-srl-51514103/"
      },
      "registryUrl": {
        "value": "https://listafirme.ro/kyun-srl-51514103/",
        "citation": "https://listafirme.ro/kyun-srl-51514103/"
      },
      "incorporationJurisdiction": {
        "value": "Romania (Bucharest)",
        "citation": "https://termene.ro/firma/51514103-KYUN-SRL"
      },
      "incorporationDate": {
        "value": "2025-03-25",
        "citation": "https://listafirme.ro/kyun-srl-51514103/"
      },
      "registeredAddress": {
        "value": "Drum Crețeștilor 19, Sc. B, Et. 1, Ap. 15, Sector 4, București, Romania (cod 042183)",
        "citation": "https://listafirme.ro/kyun-srl-51514103/"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://kyun.sh/",
            "https://kyun.sh/docs/tos",
            "https://kyun.sh/docs/aup",
            "https://kyun.sh/docs/privacypolicy"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://kyun.sh/",
            "https://kyun.sh/docs/tos",
            "https://kyun.sh/docs/aup",
            "https://kyun.sh/docs/privacypolicy"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://kyun.sh/",
            "https://kyun.sh/docs/tos",
            "https://kyun.sh/docs/aup",
            "https://kyun.sh/docs/privacypolicy"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1073,
    "slug": "rdp-monster",
    "name": "RDP.monster",
    "domain": "rdp.monster",
    "url": "https://rdp.monster/",
    "affiliate": null,
    "kyc": "none",
    "kycNote": "Official indexed snippets claim no KYC/no ID/no credit card for crypto VPS purchase; direct policy pages were blocked by browser challenge during review.",
    "fee": null,
    "limit": null,
    "categories": [
      "Hosting"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "Remote desktop",
      "Crypto accepted",
      "No-KYC",
      "Windows VPS"
    ],
    "tagline": null,
    "status": "warning",
    "updatedAt": "2026-06-22",
    "changedAt": null,
    "description": "Remote desktop and VPS hosting advertising instant delivery, full admin access and BTC, USDT or XMR payment.",
    "cardSummary": "Remote desktop and VPS hosting.",
    "networks": [],
    "checkedAt": "2026-06-22",
    "trending": false,
    "jurisdiction": "??",
    "privacyWarning": "Direct official site was not machine-readable because of a browser check/403. Keep listed as unvetted; do not rely on no-KYC claim without manual browser verification before high-risk use.",
    "founderIntel": "Anonymous operator. No corporate entity disclosed.",
    "vcIntel": "No known funding. Revenue from RDP/VPS sales.",
    "ownership": null,
    "auditedBy": [],
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  RDP.monster - Unknown jurisdiction\n  ──────────────────────────────────────\n  Operator: Anonymous\n  Revenue: RDP/VPS sales\n  Funding: Self-funded\n  └─ Disposable RDP sessions",
    "kycLevel": 0,
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_search_snippet_blocked_batch_3_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "limited",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/16061655",
        "note": "Commercial RDP/VPS hosting vendor; UK Companies House lists RDP MONSTER LIMITED (16061655, SIC 63110 hosting), now dissolved; site legal notice names only a French publication director with no company/SIRET."
      },
      "legalEntity": {
        "value": "RDP MONSTER LIMITED (dissolved 2025-07-08)",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/16061655"
      },
      "registrationNumber": {
        "value": "16061655",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/16061655"
      },
      "registryUrl": {
        "value": "https://find-and-update.company-information.service.gov.uk/company/16061655",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/16061655"
      },
      "incorporationJurisdiction": {
        "value": "United Kingdom",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/16061655"
      },
      "incorporationDate": {
        "value": "2024-11-05",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/16061655"
      },
      "registeredAddress": {
        "value": "PO Box 4385, 16061655 - COMPANIES HOUSE DEFAULT ADDRESS, Cardiff, CF14 8LH",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/16061655"
      },
      "ultimateOwner": {
        "value": "Ashley Charles Cox (PSC, ownership 75%+ of RDP MONSTER LIMITED)",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/16061655/persons-with-significant-control"
      },
      "officers": {
        "value": [
          "Ashley Charles Cox (Director, appointed 2024-11-05)"
        ],
        "citation": "https://find-and-update.company-information.service.gov.uk/company/16061655/officers"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://rdp.monster/",
            "https://find-and-update.company-information.service.gov.uk/company/16061655"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Provider pages were blocked by a browser challenge, so data collection and retention cannot be bounded."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://rdp.monster/",
            "https://find-and-update.company-information.service.gov.uk/company/16061655"
          ],
          "reviewedAt": "2026-08-27",
          "note": "The registry confirms a company but not the live service custody/control model."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://rdp.monster/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No reachable official critical-core source, license or reproducible deployment evidence was found."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced; no audit points are granted."
      }
    }
  },
  {
    "id": 1074,
    "slug": "crypton-sh",
    "name": "Crypton.sh",
    "domain": "crypton.sh",
    "url": "https://crypton.sh/",
    "affiliate": null,
    "kyc": "none",
    "kycNote": "No name, email or identity KYC advertised for guest/no-account flows; accounts, card/bank payments and support can still collect email/payment metadata.",
    "fee": null,
    "limit": null,
    "categories": [
      "Comms"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "Anonymous SMS",
      "eSIM",
      "Crypto only",
      "No accounts",
      "No-KYC"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-06-22",
    "changedAt": null,
    "description": "Phone numbers, travel eSIMs, email aliases and SMS from Rinzler Labs, a Scotland-registered operator.",
    "cardSummary": "Phone numbers, eSIMs and email aliases.",
    "networks": [],
    "checkedAt": "2026-06-24",
    "trending": false,
    "jurisdiction": "GB",
    "privacyWarning": "Telecom numbers/eSIMs are carrier-facing services; payment, phone-number use, account login and support flows can create metadata even when identity KYC is not required.",
    "founderIntel": "Pseudonymous operator. Privacy-focused SMS service for crypto community. Running since ~2023.",
    "vcIntel": "No known VC. Self-funded. Revenue from SMS/eSIM sales.",
    "ownership": null,
    "auditedBy": null,
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  Crypton.sh - Unknown jurisdiction\n  ──────────────────────────────────────\n  Operator: Pseudonymous\n  Revenue: SMS/eSIM sales\n  Funding: Self-funded\n  ├─ Crypto-only payments\n  ├─ No accounts needed\n  └─ Disposable numbers",
    "kycLevel": 0,
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_5_2026-06-22",
    "jurisdictionConfidence": "verified",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://crypton.sh/terms-and-conditions",
        "note": "Terms and privacy state the service is operated by Rinzler Labs (SC769904), confirmed on Companies House and rinzler.ch as operator of Crypton.sh."
      },
      "legalEntity": {
        "value": "RINZLER LABS LIMITED",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/SC769904"
      },
      "registrationNumber": {
        "value": "SC769904",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/SC769904"
      },
      "registryUrl": {
        "value": "https://find-and-update.company-information.service.gov.uk/company/SC769904",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/SC769904"
      },
      "incorporationJurisdiction": {
        "value": "Scotland, United Kingdom",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/SC769904"
      },
      "incorporationDate": {
        "value": "2023-05-18",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/SC769904"
      },
      "registeredAddress": {
        "value": "5 South Charlotte Street, Edinburgh, Scotland, EH2 4AN",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/SC769904"
      },
      "ultimateOwner": {
        "value": "Aleksander Jarmoszuk",
        "citation": "https://find-and-update.company-information.service.gov.uk/company/SC769904/persons-with-significant-control"
      },
      "officers": {
        "value": [
          "Aleksander Jarmoszuk (Director)"
        ],
        "citation": "https://find-and-update.company-information.service.gov.uk/company/SC769904/officers"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://crypton.sh/",
            "https://crypton.sh/terms-and-conditions",
            "https://crypton.sh/privacy",
            "https://crypton.sh/security/ack"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://crypton.sh/",
            "https://crypton.sh/terms-and-conditions",
            "https://crypton.sh/privacy",
            "https://crypton.sh/security/ack"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://crypton.sh/",
            "https://crypton.sh/terms-and-conditions",
            "https://crypton.sh/privacy",
            "https://crypton.sh/security/ack"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1075,
    "slug": "sms4sats",
    "name": "sms4sats",
    "domain": "sms4sats.com",
    "url": "https://sms4sats.com/",
    "affiliate": null,
    "kyc": "none",
    "kycNote": "No account or identity KYC; payment is per-use over Lightning hold invoices rather than a stored user balance.",
    "fee": null,
    "limit": null,
    "categories": [
      "Comms"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "SMS for Lightning",
      "No accounts",
      "No-KYC",
      "Instant"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-06-22",
    "changedAt": null,
    "description": "Disposable SMS receive, send and rent service paid over Bitcoin Lightning, running without accounts or balances.",
    "cardSummary": "Disposable SMS paid over Bitcoin Lightning.",
    "networks": [],
    "checkedAt": "2026-06-23",
    "trending": false,
    "jurisdiction": "??",
    "privacyWarning": "One-time numbers are unsuitable as durable 2FA recovery numbers; target services may reject reused/VoIP numbers or later require phone revalidation.",
    "founderIntel": "Open-source project. Pseudonymous developer. Lightning-native payments. Popular in Bitcoin community.",
    "vcIntel": "No VC. Community/self-funded. Revenue from SMS fees paid in Lightning sats.",
    "ownership": null,
    "auditedBy": null,
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  sms4sats - Unknown operator\n  ──────────────────────────────────────\n  Operator: Pseudonymous\n  Revenue: Lightning sats per SMS\n  Funding: Self-funded\n  ├─ Lightning-native payments\n  ├─ No accounts, no KYC\n  └─ Open-source",
    "kycLevel": 0,
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_5_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://sms4sats.com/",
        "note": "Commercial hosted SMS verification vendor accepting only Bitcoin Lightning payments with no accounts; site and docs present it as an operating paid service, with no open-source repo and no disclosed registered legal entity found in public materials or registry searches."
      },
      "governanceModel": {
        "value": "individual",
        "citation": "https://docs.sms4sats.com/"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://sms4sats.com/",
            "https://sms4sats.com/faq"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://sms4sats.com/",
            "https://sms4sats.com/faq"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://sms4sats.com/",
            "https://sms4sats.com/faq"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1077,
    "slug": "simsup",
    "name": "Simsup",
    "domain": "simsup.com",
    "url": "https://simsup.com/",
    "affiliate": null,
    "kyc": "none",
    "kycNote": "No ID or account is required; email is optional and used only to send the private order link. Payment is accepted in Bitcoin or Monero.",
    "fee": null,
    "limit": null,
    "categories": [
      "Comms"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "Data eSIM",
      "Dedicated-number eSIM",
      "Bitcoin accepted",
      "Monero accepted",
      "No account",
      "No ID / No-KYC",
      "130+ destinations"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-06-22",
    "changedAt": null,
    "description": "No-account data eSIM and dedicated-number eSIM seller for 130+ destinations, paid with Bitcoin or Monero; email is optional.",
    "cardSummary": "No-account data and number eSIMs paid in Bitcoin or Monero.",
    "networks": [],
    "checkedAt": "2026-06-23",
    "trending": false,
    "jurisdiction": "??",
    "privacyWarning": "Physical SIM delivery can expose shipping metadata; carrier activation/usage still creates telecom network metadata outside Simsup.",
    "founderIntel": "Limited public information. Serves privacy community. Ships physical SIMs globally.",
    "vcIntel": "No known VC. Revenue from SIM/eSIM sales.",
    "ownership": null,
    "auditedBy": [],
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  Simsup - Unknown jurisdiction\n  ──────────────────────────────────────\n  Operator: Unknown\n  Revenue: SIM/eSIM sales\n  Funding: Self-funded\n  ├─ eSIM + physical SIM\n  ├─ Crypto accepted\n  └─ Global carrier coverage",
    "kycLevel": 0,
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_5_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "unresolved",
        "citation": "https://simsup.net/",
        "note": "The reviewed source set did not establish a current legal operator."
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "Primary-source review 2026-08-27",
      "reviewedAt": "2026-08-27"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "noncustodial-hosted",
      "sourceModel": "closed"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://simsup.com/privacy",
            "https://simsup.com/terms"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No account/ID and optional email limit identity intake, but order/activation/payment/support and carrier metadata create moderate operator exposure."
        },
        "controlModel": {
          "value": "noncustodial-hosted",
          "sourceUrls": [
            "https://simsup.com/",
            "https://simsup.com/faq"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Simsup is hosted eSIM provisioning without a persistent account or custody of user assets after delivery."
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://simsup.com/terms"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No official implementation repository or reproducible critical core was published."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced; no audit points are granted."
      }
    }
  },
  {
    "id": 1078,
    "slug": "smspool",
    "name": "SMSPool",
    "domain": "smspool.net",
    "url": "https://smspool.net/",
    "affiliate": null,
    "kyc": "light",
    "kycNote": "Signup collects username and password, with email optional; ordinary signup does not request document identity. IP addresses may be stored for DDoS/rate limiting, and cryptocurrency/card processors may require source-of-funds, purpose, identity or address verification. Direct Monero was removed on 2026-07-17 but remains available through resellers such as ProxyStore.",
    "fee": null,
    "limit": null,
    "categories": [
      "Comms"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "SMS verification",
      "150+ countries",
      "API",
      "Username/password signup; email optional",
      "Crypto accepted via processors/resellers"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-08-25",
    "changedAt": null,
    "description": "Non-VoIP SMS verification marketplace across 150+ countries with rentals, API access and username/password signup; email is optional.",
    "cardSummary": "Non-VoIP SMS verification in 150+ countries.",
    "networks": [],
    "checkedAt": "2026-08-25",
    "trending": false,
    "jurisdiction": "NL",
    "privacyWarning": "SMSPool B.V. operates a Dutch marketplace for OTP numbers. Registration collects username/password and optional email; request IPs may be stored for DDoS/rate limiting, Cloudflare monitors visitor behavior, Stripe receives user ID/payment data, AML/payment screening may request identity/address, and data can be disclosed to law enforcement.",
    "founderIntel": "Registered in Netherlands. Corporate entity present. Larger commercial operation than privacy-focused alternatives.",
    "vcIntel": "No known VC. Revenue from SMS verification fees. Commercial SaaS model.",
    "ownership": null,
    "auditedBy": null,
    "stateActorFlag": null,
    "twitter": "https://x.com/smspoolnet",
    "telegram": null,
    "followTheMoney": "  SMSPool - Netherlands (NL)\n  ──────────────────────────────────────\n  Operator: Dutch company\n  Revenue: SMS verification fees\n  Funding: Self-funded\n  ├─ Dutch jurisdiction, GDPR\n  ├─ 100+ country coverage\n  └─ Commercial SaaS model",
    "kycLevel": 2,
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "primary_source_rereview_2026-08-25",
    "jurisdictionConfidence": "verified",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://www.smspool.net/tos",
        "note": "Official Terms of Service identify the operator as SMSPool B.V., a Dutch business with KvK number 42005953; corroborated by Google Play developer listing and Dutch registry aggregators."
      },
      "legalEntity": {
        "value": "SMSPool B.V.",
        "citation": "https://www.smspool.net/tos"
      },
      "registrationNumber": {
        "value": "42005953",
        "citation": "https://www.smspool.net/tos"
      },
      "registryUrl": {
        "value": "https://www.northdata.de/SMSPool%20B.V.,%20Hilversum/KVK%2042005953",
        "citation": "https://www.northdata.de/SMSPool%20B.V.,%20Hilversum/KVK%2042005953"
      },
      "incorporationJurisdiction": {
        "value": "Netherlands",
        "citation": "https://www.smspool.net/tos"
      },
      "incorporationDate": {
        "value": "2026-03-13",
        "citation": "https://companyinfo.nl/organisatieprofiel/ontwerpen-van-computerprogrammas/smspool-b-v---42005953-000045896364"
      },
      "registeredAddress": {
        "value": "Postbus 29, 1200 AA Hilversum, Netherlands",
        "citation": "https://play.google.com/store/apps/details?id=com.smspool.app&hl=en_US"
      },
      "officers": {
        "value": [
          {
            "name": "ChenDev Holding B.V.",
            "role": "Algemeen directeur"
          }
        ],
        "citation": "https://companyinfo.nl/organisatieprofiel/ontwerpen-van-computerprogrammas/smspool-b-v---42005953-000045896364"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.smspool.net/",
            "https://www.smspool.net/tos",
            "https://www.smspool.net/privacy-policy",
            "https://status.smspool.net/",
            "https://x.com/smspoolnet/status/2078096392308846649",
            "https://smspool.net/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.smspool.net/",
            "https://www.smspool.net/tos",
            "https://www.smspool.net/privacy-policy",
            "https://status.smspool.net/",
            "https://x.com/smspoolnet/status/2078096392308846649",
            "https://smspool.net/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.smspool.net/",
            "https://www.smspool.net/tos",
            "https://www.smspool.net/privacy-policy",
            "https://status.smspool.net/",
            "https://x.com/smspoolnet/status/2078096392308846649",
            "https://smspool.net/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1079,
    "slug": "juicysms",
    "name": "JuicySMS",
    "domain": "juicysms.com",
    "url": "https://juicysms.com/",
    "affiliate": null,
    "kyc": "light",
    "kycNote": "No document-KYC policy found in official FAQ, but login/register and stored account balance are required for normal use; payment processors may add checks.",
    "fee": "From €0.50 per delivered SMS; $10 minimum account recharge; same-number reuse for the same service at half the original price",
    "limit": null,
    "categories": [
      "Comms"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "SMS verification",
      "Account balance",
      "API",
      "USA/UK/Netherlands/Philippines numbers",
      "Card and crypto payments",
      "Pay only for delivered SMS"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-08-25",
    "changedAt": null,
    "description": "SMS verification and number rental with API access, paid by card, Bitcoin, Ethereum, Litecoin or Monero.",
    "cardSummary": "SMS verification and number rental with API.",
    "networks": [],
    "checkedAt": "2026-08-25",
    "trending": false,
    "jurisdiction": "NL",
    "privacyWarning": "Account, balance, API and number-use metadata are service-side. The privacy policy also names payment processors and analytics/advertising providers including Google, Meta, Reddit and Crazy Egg; verification numbers may be rejected or recycled by target platforms.",
    "founderIntel": "Limited public information. Commercial SMS verification provider.",
    "vcIntel": "No known funding. Revenue from SMS verification fees.",
    "ownership": null,
    "auditedBy": null,
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  JuicySMS - Unknown jurisdiction\n  ──────────────────────────────────────\n  Operator: Unknown\n  Revenue: SMS verification fees\n  Funding: Self-funded\n  └─ Crypto accepted, API available",
    "kycLevel": 1,
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "primary_source_rereview_2026-08-25",
    "jurisdictionConfidence": "unknown",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://juicysms.com/",
        "note": "Commercial paid SMS verification hosted service with accounts, payments (Stripe/Mollie/crypto), API and ToS; no open-source or community-project indicators."
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://juicysms.com/",
            "https://juicysms.com/faq",
            "https://juicysms.com/terms",
            "https://juicysms.com/privacy-policy"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://juicysms.com/",
            "https://juicysms.com/faq",
            "https://juicysms.com/terms",
            "https://juicysms.com/privacy-policy"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://juicysms.com/",
            "https://juicysms.com/faq",
            "https://juicysms.com/terms",
            "https://juicysms.com/privacy-policy"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1080,
    "slug": "textverified",
    "name": "Textverified",
    "domain": "textverified.com",
    "url": "https://textverified.com/",
    "affiliate": null,
    "kyc": "none",
    "kycNote": "No document KYC requirement found in official terms. Account access uses an email address; purchases may use credit/debit cards or selected cryptocurrencies and accounts can be terminated for abuse or prohibited activity.",
    "fee": null,
    "limit": null,
    "categories": [
      "Comms"
    ],
    "countries": [
      "US"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "SMS verification",
      "US numbers",
      "Crypto accepted",
      "API"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-06-22",
    "changedAt": null,
    "description": "US non-VoIP numbers for SMS and voice verifications, with rentals, API access and card or crypto payment.",
    "cardSummary": "US non-VoIP numbers for SMS and voice codes.",
    "networks": [],
    "checkedAt": "2026-08-26",
    "trending": false,
    "jurisdiction": "US",
    "privacyWarning": "US verification-number service that collects registration name/email and may log IP address, browser, ISP, access time, pages and clicks; it uses analytics/advertising providers and retains personal information as needed for operations, records, legal obligations and disputes.",
    "founderIntel": "US-based company. Corporate entity present. Serves developers and privacy users alike.",
    "vcIntel": "No known VC. Commercial operation. Revenue from per-verification fees.",
    "ownership": null,
    "auditedBy": null,
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  Textverified - United States (US)\n  ──────────────────────────────────────\n  Operator: US company\n  Revenue: Per-verification fees\n  Funding: Self-funded\n  ├─ US jurisdiction\n  ├─ Real carrier numbers\n  └─ API for developers",
    "kycLevel": 1,
    "lastReviewed": "2026-08-26",
    "kycLastChecked": "2026-08-26",
    "reviewSource": "Primary-source review 2026-08-26",
    "jurisdictionConfidence": "verified",
    "geo": [
      "US"
    ],
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://www.textverified.com/policy",
        "note": "Privacy Policy and Terms identify the operator as Textverified LLC, a real hosted commercial SMS/voice verification service; Wyoming SOS record shows the same entity renamed to Westbold LLC which operates the service and related API tools."
      },
      "legalEntity": {
        "value": "Westbold LLC (formerly Textverified LLC)",
        "citation": "https://wyobiz.wyo.gov/Business/FilingDetails.aspx?eFNum=074070114211157065145016011044050216214057016203"
      },
      "registrationNumber": {
        "value": "2020-000952796",
        "citation": "https://wyobiz.wyo.gov/Business/FilingDetails.aspx?eFNum=074070114211157065145016011044050216214057016203"
      },
      "registryUrl": {
        "value": "https://wyobiz.wyo.gov/Business/FilingDetails.aspx?eFNum=074070114211157065145016011044050216214057016203",
        "citation": "https://wyobiz.wyo.gov/Business/FilingDetails.aspx?eFNum=074070114211157065145016011044050216214057016203"
      },
      "incorporationJurisdiction": {
        "value": "Wyoming, United States (domesticated from Indiana)",
        "citation": "https://wyobiz.wyo.gov/Business/FilingDetails.aspx?eFNum=074070114211157065145016011044050216214057016203"
      },
      "incorporationDate": {
        "value": "2018-09-13",
        "citation": "https://wyobiz.wyo.gov/Business/FilingDetails.aspx?eFNum=074070114211157065145016011044050216214057016203"
      },
      "registeredAddress": {
        "value": "30 N Gould St Ste R, Sheridan, WY 82801, USA",
        "citation": "https://wyobiz.wyo.gov/Business/FilingDetails.aspx?eFNum=074070114211157065145016011044050216214057016203"
      },
      "officers": {
        "value": [
          {
            "name": "Avishkar Luthra (Vish)",
            "role": "Member/Partner"
          },
          {
            "name": "Yi Zhang",
            "role": "Member/Partner"
          },
          {
            "name": "Kay Zhang",
            "role": "Member/Partner"
          }
        ],
        "citation": "https://search.sunbiz.org/Inquiry/CorporationSearch/SearchResults?InquiryType=EntityName&InquiryDirectionType=PreviousRecord&SearchTerm=WEST%20BOCA%20IRRIGATION%2C%20INC.&SearchNameOrder=WESTBON%20F200000031700&ListNameOrder=WESTBOCATUTORING%20L110000115400&Detail=FL.DOS.Corporations.Shared.Contracts.FilingRecord"
      },
      "priorEntities": {
        "value": [
          "Textverified LLC -- Name changed to Westbold LLC on 2022-07-12; originally formed in Indiana 2018-09-13 and domesticated to Wyoming 2020-10-20"
        ],
        "citation": "https://wyobiz.wyo.gov/Business/FilingDetails.aspx?eFNum=074070114211157065145016011044050216214057016203"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "hosted-account",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-26",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://www.textverified.com/policy"
          ],
          "reviewedAt": "2026-08-26",
          "note": "account, contact, automatic-log, order/service and payment-related data are stated"
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://www.textverified.com/policy",
            "https://www.textverified.com/terms"
          ],
          "reviewedAt": "2026-08-26",
          "note": "policy describes registered service accounts and the service controls rented verification numbers"
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.textverified.com/policy",
            "https://www.textverified.com/terms",
            "https://textverified.com/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "no reviewed official source establishes a source model"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "no-score-points-no-cap-exception"
      }
    }
  },
  {
    "id": 1081,
    "slug": "virtualsms",
    "name": "VirtualSIM",
    "domain": "virtualsim.net",
    "url": "https://virtualsim.net/",
    "affiliate": null,
    "kyc": "light",
    "kycNote": "No identity-document KYC found, but service use creates an account/profile and requires order parameters, payment and support/ticket metadata.",
    "fee": null,
    "limit": null,
    "categories": [
      "Comms"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "Virtual numbers",
      "SMS verification",
      "Crypto accepted",
      "Multiple countries"
    ],
    "tagline": null,
    "status": "warning",
    "updatedAt": "2026-06-22",
    "changedAt": null,
    "description": "Virtual phone numbers for SMS verification and automation, requiring a site profile or account created at first order.",
    "cardSummary": "Virtual numbers for SMS verification.",
    "networks": [],
    "checkedAt": "2026-08-26",
    "trending": false,
    "jurisdiction": "UA",
    "privacyWarning": "The operator may collect account credentials and optional contact details, rented-number and timestamp usage logs, transaction metadata, support communications, IP address, browser type and device information. Shared SIMs may already carry other clients' accounts for different services, and a number may eventually be reissued by a telecom operator after expiry.",
    "founderIntel": "Limited public information. Commercial SMS provider.",
    "vcIntel": "No known funding. Revenue from number rental/SMS fees.",
    "ownership": null,
    "auditedBy": null,
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  VirtualSIM - Unknown jurisdiction\n  ──────────────────────────────────────\n  Operator: Unknown\n  Revenue: Number rental/SMS fees\n  Funding: Self-funded\n  └─ Multi-country virtual numbers",
    "kycLevel": 1,
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-08-26",
    "reviewSource": "official_site_batch_5_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://virtualsim.net/about.php",
        "note": "Commercial hosted SMS/virtual-number rental service with paid plans, operators, ToS and crypto billing; established as an operating service in Ukraine, not an open-source or community project."
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "hosted-account",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-26",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://virtualsim.net/privacy_policy.php"
          ],
          "reviewedAt": "2026-08-26",
          "note": "official privacy policy enumerates account, usage, payment and support metadata"
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://virtualsim.net/faq.php"
          ],
          "reviewedAt": "2026-08-26",
          "note": "official FAQ describes provider-controlled account, numbers, orders, invoices and support"
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://virtualsim.net/privacy_policy.php",
            "https://virtualsim.net/faq.php",
            "https://virtualsim.net/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "no reviewed official source establishes a source model"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "no-score-points-no-cap-exception"
      }
    }
  },
  {
    "id": 1082,
    "slug": "shopinbit",
    "name": "SHOPINBIT",
    "domain": "shopinbit.com",
    "url": "https://shopinbit.com/",
    "affiliate": null,
    "kyc": "none",
    "kycNote": "No routine document KYC found; official pages market “no login or extra verification” / “without invasive KYC.” Orders can still require delivery, travel, vehicle, invoice or legal data depending on the product/service.",
    "fee": null,
    "limit": null,
    "categories": [
      "Merchants",
      "Agent Money"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "Crypto concierge",
      "Goods and travel",
      "Cars",
      "No login to start",
      "No invasive KYC",
      "Crypto-native payments",
      "Global sourcing",
      "Privacy-first handling"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-08-15",
    "changedAt": null,
    "description": "Crypto concierge marketplace for goods, travel and cars, advertising no login or extra verification to start.",
    "cardSummary": "Crypto concierge for goods, travel and cars.",
    "networks": [],
    "checkedAt": "2026-06-24",
    "trending": false,
    "jurisdiction": "PL",
    "privacyWarning": "Now operated by ShopinBit EU sp. z o.o. in Kraków, Poland. Privacy policy covers purchase, shipment, account, contact and legal-processing data; concierge/travel/car orders are not anonymous even when there is no routine KYC gate.",
    "founderIntel": "Founded by Lawrence Bahr, publicly known as Lando Rothbardian. The business started in Berlin in December 2018 and later moved operations to Kraków, Poland.",
    "vcIntel": "No known VC. Revenue comes from markup on proxy purchases. The current operator is SHOPINBIT EU Sp. z o.o. in Kraków, Poland.",
    "ownership": null,
    "auditedBy": null,
    "stateActorFlag": null,
    "twitter": "https://x.com/shopinbit",
    "telegram": null,
    "followTheMoney": "  SHOPINBIT EU Sp. z o.o. - Kraków, PL\n  ────────────────────────────────────────\n  Founder: Lawrence Bahr (Lando Rothbardian)\n  Revenue: Markup on proxy purchases\n  Started: Berlin, December 2018\n  ├─ Current Polish company, EU/GDPR\n  ├─ Goods, travel and car concierge\n  └─ No routine KYC; fulfillment data applies",
    "kycLevel": 1,
    "lastReviewed": "2026-08-15",
    "kycLastChecked": "2026-08-15",
    "reviewSource": "focused_record_review_2026-08-15",
    "jurisdictionConfidence": "verified",
    "geo": [
      "GLOBAL"
    ],
    "agentMoney": {
      "compatible": true,
      "controlSurfaces": [
        "manual"
      ],
      "protocols": [
        "manual"
      ],
      "authorizationModel": [
        "human-approval"
      ],
      "settlementRail": [
        "crypto",
        "manual-invoice"
      ],
      "autonomyLevel": 1,
      "custodyModel": "none",
      "spendLimits": false,
      "merchantLock": true,
      "categoryLock": false,
      "pauseClose": false,
      "transactionWebhooks": false,
      "fundingSource": "crypto-funded",
      "identitySurface": "none",
      "dataPath": [
        "AI agent",
        "operator approval",
        "SHOPINBIT order or concierge request",
        "crypto payment",
        "shipping or fulfillment partner",
        "merchant/concierge record"
      ],
      "notes": "Useful for human-approved agent purchases through a crypto concierge or merchant workflow, but not automated anonymity: order contents, delivery details, payment trail, and fulfillment records can still identify the buyer.",
      "protocolPrivacyNotes": "Keep the agent in a request-drafting role. The privacy limit is not the checkout rail alone: shipping, concierge notes, invoice details, timing, and product choice can identify the buyer.",
      "mandateLoggingRisk": "medium",
      "revocationQuality": "weak",
      "sourceLinks": [
        {
          "label": "SHOPINBIT homepage",
          "href": "https://shopinbit.com/",
          "scope": "provider"
        },
        {
          "label": "SHOPINBIT concierge",
          "href": "https://shopinbit.com/concierge/",
          "scope": "controls"
        }
      ]
    },
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://shopinbit.com/",
        "note": "The website footer and Polish KRS records identify SHOPINBIT EU Sp. z o.o. as the operating merchant/concierge company; it is a registered limited-liability company, not a foundation or informal project."
      },
      "legalEntity": {
        "value": "SHOPINBIT EU Sp. z o.o. (SHOPINBIT EU SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ)",
        "citation": "https://shopinbit.com/"
      },
      "registrationNumber": {
        "value": "KRS 0001104133 (also NIP 6751798444, REGON 528553687)",
        "citation": "https://okredo.com/en-pl/company/shopinbit-eu-spolka-z-ograniczona-odpowiedzialnoscia-krs-0001104133"
      },
      "registryUrl": {
        "value": "https://wyszukiwarka-krs.ms.gov.pl/ (search KRS 0001104133); aggregator https://www.northdata.com/Shopinbit+EU+sp.+z+o.o.,+Krak%C3%B3w/KRS0001104133",
        "citation": "https://www.northdata.com/Shopinbit+EU+sp.+z+o.o.,+Krak%C3%B3w/KRS0001104133"
      },
      "incorporationJurisdiction": {
        "value": "Poland",
        "citation": "https://okredo.com/en-pl/company/shopinbit-eu-spolka-z-ograniczona-odpowiedzialnoscia-krs-0001104133"
      },
      "incorporationDate": {
        "value": "2024-05-08",
        "citation": "https://okredo.com/en-pl/company/shopinbit-eu-spolka-z-ograniczona-odpowiedzialnoscia-krs-0001104133"
      },
      "registeredAddress": {
        "value": "Aleja Powstania Warszawskiego 15, 31-539 Kraków, Poland",
        "citation": "https://shopinbit.com/"
      },
      "ultimateOwner": {
        "value": "Mohamed Lawrence Bahr (majority shareholder, 89 shares / 4450 PLN); David Herndorf (minority shareholder, 10 shares / 500 PLN); share capital 5000 PLN",
        "citation": "https://aleo.com/int/company/shopinbit-eu-spolka-z-ograniczona-odpowiedzialnoscia"
      },
      "officers": {
        "value": [
          "Mohamed Lawrence Bahr (Prezes Zarządu / President of the Management Board)",
          "Kamila Katarzyna Knap (Prokurent / authorized proxy with separate prokura)"
        ],
        "citation": "https://aleo.com/int/company/shopinbit-eu-spolka-z-ograniczona-odpowiedzialnoscia"
      },
      "priorEntities": {
        "value": [
          "ShopinBit Schweiz AG (CHE-307.992.776 / CH-130.3.034.289-9, Freienbach, Switzerland; registered 2024-09-20, in liquidation; shared personnel including Mohamed Lawrence Bahr and Travin Keith Dy)"
        ],
        "citation": "https://www.moneyhouse.ch/en/company/shopinbit-schweiz-ag-21236069141"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://shopinbit.com/",
            "https://shopinbit.com/terms-conditions",
            "https://shopinbit.com/terms-conditions/",
            "https://shopinbit.com/privacy-policy",
            "https://shopinbit.com/privacy-policy/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://shopinbit.com/",
            "https://shopinbit.com/terms-conditions",
            "https://shopinbit.com/terms-conditions/",
            "https://shopinbit.com/privacy-policy",
            "https://shopinbit.com/privacy-policy/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://shopinbit.com/",
            "https://shopinbit.com/terms-conditions",
            "https://shopinbit.com/terms-conditions/",
            "https://shopinbit.com/privacy-policy",
            "https://shopinbit.com/privacy-policy/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1083,
    "slug": "stealths",
    "name": "Stealths",
    "domain": "stealths.net",
    "url": "https://stealths.net/",
    "affiliate": null,
    "kyc": "none",
    "kycNote": "Official terms state Stealths does not require any level of customer verification; payment provider may reject illegal/mixer-linked funds.",
    "fee": null,
    "limit": null,
    "categories": [
      "Gift Cards",
      "Comms"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "Anonymous cards",
      "eSIM",
      "Gift cards",
      "Crypto only",
      "No-KYC",
      "Tor-friendly"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-06-22",
    "changedAt": null,
    "description": "Crypto-funded prepaid card, gift card and eSIM shop tracking orders by number rather than contact details.",
    "cardSummary": "Crypto-funded prepaid cards and eSIMs.",
    "networks": [],
    "checkedAt": "2026-08-26",
    "trending": false,
    "jurisdiction": "??",
    "privacyWarning": "Prepaid-card issuers and merchants can still impose merchant/issuer checks, 3DS, blocked MCCs or transaction monitoring after delivery.",
    "founderIntel": "Pseudonymous operator. Privacy-focused service targeting crypto community. Running since ~2023. Monerica verified.",
    "vcIntel": "No known VC. Self-funded. Revenue from card/eSIM markup.",
    "ownership": null,
    "auditedBy": null,
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  Stealths - Unknown jurisdiction\n  ──────────────────────────────────────\n  Operator: Pseudonymous\n  Revenue: Card/eSIM markup\n  Funding: Self-funded\n  ├─ Crypto-only payments\n  ├─ Virtual Visa + physical cards\n  └─ eSIM + gift cards bundled",
    "kycLevel": 0,
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_5_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://stealths.net/",
        "note": "Commercial vendor/shop selling prepaid cards, gift cards, eSIMs and related products for cryptocurrency payment; no open-source project or foundation indicators."
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-26",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://stealths.net/faq"
          ],
          "reviewedAt": "2026-08-26",
          "note": "privacy policy unavailable"
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://stealths.net/faq",
            "https://stealths.net/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "no current official terms establish the card/eSIM issuer and control arrangement"
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://stealths.net/faq",
            "https://stealths.net/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "no reviewed official source establishes a source model"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "no-score-points-no-cap-exception"
      }
    }
  },
  {
    "id": 1084,
    "slug": "anonshop",
    "name": "Anon Shop",
    "domain": "anonshop.app",
    "url": "https://anonshop.app/",
    "affiliate": null,
    "kyc": "none",
    "kycNote": "No identity-KYC policy found; locker orders avoid address disclosure, while address delivery necessarily exposes shipping details to the operator.",
    "fee": null,
    "limit": null,
    "categories": [
      "Merchants"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "Proxy shopping",
      "Crypto accepted",
      "No-KYC",
      "Amazon",
      "eBay"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-06-22",
    "changedAt": null,
    "description": "Monero proxy-shopping service for Amazon, eBay and other stores, with locker, address or peer-shop delivery.",
    "cardSummary": "Monero proxy shopping for Amazon and eBay.",
    "networks": [],
    "checkedAt": "2026-08-27",
    "trending": false,
    "jurisdiction": "??",
    "privacyWarning": "Manual concierge/proxy-shopping model requires trusting the operator with order contents, chat history and any delivery/address metadata.",
    "founderIntel": "Anonymous operator. Limited public information. Proxy shopping model.",
    "vcIntel": "No known funding. Revenue from markup on purchases.",
    "ownership": null,
    "auditedBy": null,
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  Anon Shop - Unknown jurisdiction\n  ──────────────────────────────────────\n  Operator: Anonymous\n  Revenue: Markup on proxy purchases\n  Funding: Self-funded\n  └─ Proxy shopping with crypto",
    "kycLevel": 0,
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_5_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://anonshop.app/",
        "note": "Commercial hosted Monero-to-retailer proxy shopping merchant service operated as a business (not merely a software project), with founder publicly identifying as running it and site footer linking claimed business registration/license."
      },
      "governanceModel": {
        "value": "individual",
        "citation": "https://github.com/itsMikeLowrey"
      },
      "repositoryUrl": {
        "value": "https://github.com/DecentralizeJustice/anonymousLocker",
        "citation": "https://github.com/DecentralizeJustice/anonymousLocker"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "extensive",
      "controlModel": "hosted-account",
      "sourceModel": "partial"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "extensive",
          "sourceUrls": [
            "https://anonshop.app/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "order contents, chat, payment references, locker or delivery address metadata"
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://anonshop.app/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "operator-concierge"
        },
        "sourceModel": {
          "value": "partial",
          "sourceUrls": [
            "https://anonshop.app/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "partial-open-source-components"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No current independent audit evidence."
      }
    }
  },
  {
    "id": 1085,
    "slug": "proxystore",
    "name": "ProxyStore",
    "domain": "digitalgoods.proxysto.re",
    "url": "https://digitalgoods.proxysto.re/",
    "affiliate": null,
    "kyc": "none",
    "kycNote": "No document KYC found. Orders can be paid with XMR/BTC, cash by mail, or SEPA; optional email/ntfy notification exists, and some third-party products may require an email or account with the issuer.",
    "fee": null,
    "limit": null,
    "categories": [
      "Merchants"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "Digital goods",
      "Crypto accepted",
      "No-KYC",
      "Privacy-focused"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-06-22",
    "changedAt": null,
    "description": "German storefront for software, privacy services and vouchers, taking XMR, BTC, cash by mail or SEPA transfer.",
    "cardSummary": "German shop for software and privacy services.",
    "networks": [],
    "checkedAt": "2026-08-25",
    "trending": false,
    "jurisdiction": "DE",
    "privacyWarning": "Operated by Itermann & Wansing OHG in Leipzig, Germany. Online shops are hosted on Hetzner in Germany; ProxyStore says it does not log web access/errors and deletes delivered codes after 30 days, but SEPA, shipping, issuer and optional notification paths create metadata.",
    "founderIntel": "ProxySto.re collective, Germany. Privacy activist collective running since ~2017. Also runs physical stores in Germany. Part of larger privacy advocacy ecosystem.",
    "vcIntel": "No VC. Collective/community funded. Revenue from goods sales. German privacy collective.",
    "ownership": null,
    "auditedBy": null,
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  ProxySto.re - Germany (DE)\n  ──────────────────────────────────────\n  Operator: ProxySto.re collective\n  Revenue: Digital goods sales\n  Funding: Community/collective\n  ├─ German jurisdiction, GDPR\n  ├─ Physical + digital stores\n  └─ Privacy activist collective",
    "kycLevel": 0,
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "primary_source_rereview_2026-08-25",
    "jurisdictionConfidence": "verified",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://digitalgoods.proxysto.re/en/legal-notice.html",
        "note": "Official legal notice/imprint states the operator is the registered commercial partnership Itermann & Wansing OHG with Handelsregister details, operating a physical store and online merchant shop."
      },
      "legalEntity": {
        "value": "Itermann & Wansing OHG",
        "citation": "https://digitalgoods.proxysto.re/en/legal-notice.html"
      },
      "registrationNumber": {
        "value": "HRA 19855",
        "citation": "https://digitalgoods.proxysto.re/en/legal-notice.html"
      },
      "incorporationJurisdiction": {
        "value": "Germany (Amtsgericht Leipzig)",
        "citation": "https://digitalgoods.proxysto.re/en/legal-notice.html"
      },
      "registeredAddress": {
        "value": "Wolfgang-Heinze-Straße 14, 04277 Leipzig, Germany",
        "citation": "https://digitalgoods.proxysto.re/en/legal-notice.html"
      },
      "officers": {
        "value": [
          "Sten Itermann (persönlich haftender Gesellschafter)"
        ],
        "citation": "https://www.companyhouse.de/l/p/Sten-Itermann"
      },
      "priorEntities": {
        "value": [
          "Itermann & Wansing GbR"
        ],
        "citation": "https://www.ebay.co.uk/usr/proxystore_le"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://proxysto.re/",
            "https://proxysto.re/index.php?title=Privacy",
            "https://proxysto.re/index.php?title=Legal_notice",
            "https://status.proxysto.re/api/status-page/heartbeat/main",
            "https://digitalgoods.proxysto.re/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://proxysto.re/",
            "https://proxysto.re/index.php?title=Privacy",
            "https://proxysto.re/index.php?title=Legal_notice",
            "https://status.proxysto.re/api/status-page/heartbeat/main",
            "https://digitalgoods.proxysto.re/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://proxysto.re/",
            "https://proxysto.re/index.php?title=Privacy",
            "https://proxysto.re/index.php?title=Legal_notice",
            "https://status.proxysto.re/api/status-page/heartbeat/main",
            "https://digitalgoods.proxysto.re/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1086,
    "slug": "cake-pay",
    "name": "Cake Pay",
    "domain": "cakepay.com",
    "url": "https://cakepay.com/",
    "affiliate": null,
    "kyc": "light",
    "kycNote": "Baseline Cake Pay Web checkout requires a valid email and crypto payment. Terms say users can complete KYC for higher limits, and issuing merchants/card programs may require personal information for some products.",
    "fee": null,
    "limit": null,
    "categories": [
      "Gift Cards"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "Gift cards",
      "150+ brands",
      "XMR/BTC",
      "No-KYC",
      "Instant delivery"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-06-22",
    "changedAt": null,
    "description": "Cake Labs service buying merchant gift cards and payment cards with crypto, requiring a valid email address.",
    "cardSummary": "Merchant gift cards bought with crypto.",
    "networks": [],
    "checkedAt": "2026-08-27",
    "trending": false,
    "jurisdiction": "KN",
    "privacyWarning": "US/Cake Labs LLC service. Terms allow collection/use of email, IP address, browser and payment-method data; information may be shared with purchase-processing third parties, merchants/card operators, law enforcement, or for fraud/legal compliance.",
    "founderIntel": "Built by Cake Labs LLC (same team as Cake Wallet). Vik Sharma (CEO). US company, St. Louis. Transparent team - Vik is public-facing advocate for Monero privacy.",
    "vcIntel": "Cake Labs has received minor grants from Monero CCS (Community Crowdfunding System). Primarily self-funded from Cake Wallet revenue. No traditional VC.",
    "ownership": null,
    "auditedBy": null,
    "stateActorFlag": null,
    "twitter": "https://x.com/AborCakePayApp",
    "telegram": null,
    "followTheMoney": "  Cake Labs LLC - St. Louis, US\n  ──────────────────────────────────────\n  CEO: Vik Sharma\n  Revenue: Gift card markup\n  Funding: Self-funded + Monero CCS\n  ├─ US jurisdiction\n  ├─ Same team as Cake Wallet\n  └─ 150+ brands, instant delivery",
    "kycLevel": 1,
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_8_2026-06-22",
    "jurisdictionConfidence": "verified",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://cakepay.com/terms/",
        "note": "Terms of Service and Privacy Policy explicitly state the Cake Pay service is operated by Cake Labs LLC, a real operating company that also runs Cake Wallet."
      },
      "legalEntity": {
        "value": "Cake Labs LLC",
        "citation": "https://cakepay.com/terms/"
      },
      "incorporationJurisdiction": {
        "value": "Nevis, Saint Kitts and Nevis",
        "citation": "https://cakewallet.com/terms/"
      },
      "registeredAddress": {
        "value": "Hunkin Waterfront Plaza, Suite 556, Main Street, Charlestown, Saint Kitts and Nevis",
        "citation": "https://www.info-clipper.com/en/company/saint-kitts-and-nevis/cake-labs-llc.kndb5zaen.html"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "hosted-account",
      "sourceModel": "closed"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://cakewallet.com/security/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "email, order, IP/browser, payment and merchant/card-program data"
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://cakewallet.com/security/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "operator-purchase-inside-open-wallet"
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://github.com/cake-tech/cake_wallet"
          ],
          "reviewedAt": "2026-08-27",
          "note": "partial-open-source-wallet-client"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "Security disclosure channel exists; no current Cake Pay product audit report with date/scope found."
      }
    }
  },
  {
    "id": 1087,
    "slug": "xmr-cards",
    "name": "XMR Cards",
    "domain": "xmr.cards",
    "url": "https://xmr.cards/",
    "affiliate": null,
    "kyc": "none",
    "kycNote": "Official FAQ says no client identification or KYC verification.",
    "fee": null,
    "limit": null,
    "categories": [
      "Gift Cards"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "Gift cards",
      "XMR only",
      "No-KYC",
      "Tor-friendly",
      "No JavaScript/cookies"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-06-22",
    "changedAt": null,
    "description": "Gift-card marketplace funded with Monero, offering Tor access and catalogues without JavaScript or cookies.",
    "cardSummary": "Gift-card marketplace funded with Monero.",
    "networks": [],
    "checkedAt": "2026-08-26",
    "trending": false,
    "jurisdiction": "??",
    "privacyWarning": "Anonymous operator and no published terms. FAQ claims no JavaScript, cookies or collected/logged data, but acknowledges the web server can see IP addresses; no refunds after issuance and order recovery depends on the order page or transaction details.",
    "founderIntel": "Anonymous operator. Official support is site-based; no corporate entity disclosed.",
    "vcIntel": "No known funding. Revenue from 1-5% gift-card fees or brand spread.",
    "ownership": null,
    "auditedBy": null,
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  XMR Cards - Unknown jurisdiction\n  ──────────────────────────────────────\n  Operator: Anonymous\n  Revenue: Card markup/fees\n  Funding: Self-funded\n  ├─ Monero-only payment\n  ├─ Virtual + physical Visa\n  └─ EU-focused coverage",
    "kycLevel": 0,
    "lastReviewed": "2026-08-26",
    "kycLastChecked": "2026-08-26",
    "reviewSource": "Primary-source review 2026-08-26",
    "jurisdictionConfidence": "unknown",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "unresolved",
        "citation": "https://cunicula.com/en/provider/xmr-cards",
        "note": "Commercial gift-card shop with no legal entity, company name, registration details, imprint, terms naming an operator, or jurisdiction disclosed on the official site, FAQ, support page, or interviews; independent reviews explicitly note an anonymous operator and unknown jurisdiction."
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "limited",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-26",
      "inputs": {
        "operatorDataExposure": {
          "value": "limited",
          "sourceUrls": [
            "https://xmr.cards/faq"
          ],
          "reviewedAt": "2026-08-26",
          "note": "official FAQ asserts no stored data/cookies while acknowledging web-server IP visibility"
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://xmr.cards/faq",
            "https://xmr.cards/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "official material does not establish gift-card issuer and fulfillment control arrangement"
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://xmr.cards/faq",
            "https://xmr.cards/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "no reviewed official source establishes a source model"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "no-score-points-no-cap-exception"
      }
    }
  },
  {
    "id": 1088,
    "slug": "trocador-gift-cards",
    "name": "Trocador Gift Cards",
    "domain": "trocador.app",
    "url": "https://trocador.app/en/giftcard/",
    "affiliate": null,
    "kyc": "light",
    "kycNote": "Gift-card page requires an email limit surface; Trocador terms warn partner providers may sometimes require KYC/AML checks depending on transaction risk.",
    "fee": null,
    "limit": null,
    "categories": [
      "Gift Cards"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "Gift cards via Trocador",
      "Crypto",
      "No-KYC",
      "Instant",
      "Multiple brands"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-06-22",
    "changedAt": null,
    "description": "Trocador store gift cards bought with crypto, with a stated daily limit of $5,000 per email address.",
    "cardSummary": "Store gift cards bought with crypto.",
    "networks": [],
    "checkedAt": "2026-08-26",
    "trending": false,
    "jurisdiction": "??",
    "privacyWarning": "Partner gift-card providers, issuer terms and email-based limits can create KYC/AML or redemption risk even when Trocador itself is only routing the purchase.",
    "founderIntel": "Same team as Trocador swap aggregator. Pseudonymous operators. Privacy-first.",
    "vcIntel": "No VC. Revenue from gift card markup + exchange referral fees.",
    "ownership": null,
    "auditedBy": null,
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  Trocador - Unknown entity\n  ──────────────────────────────────────\n  Operator: Trocador team (pseudonymous)\n  Revenue: Gift card markup\n  Funding: Self-funded\n  ├─ Same team as Trocador swaps\n  ├─ Pay with any crypto\n  └─ No KYC required",
    "kycLevel": 1,
    "lastReviewed": "2026-08-26",
    "kycLastChecked": "2026-08-26",
    "reviewSource": "Primary-source review 2026-08-26",
    "jurisdictionConfidence": "unknown",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://noscript.trocador.app/en/termsofuse/",
        "note": "Terms of Use explicitly state the App is owned and managed by Reta Development Assets LLC; site footers copyright the same entity."
      },
      "legalEntity": {
        "value": "Reta Development Assets LLC",
        "citation": "https://noscript.trocador.app/en/termsofuse/"
      },
      "incorporationJurisdiction": {
        "value": "Saint Kitts and Nevis (Nevis)",
        "citation": "https://www.trademarkia.com/trocador-99720500"
      },
      "registeredAddress": {
        "value": "Main Street, Hunkins Waterfront Plaza, Suite 556, Charlestown, KN 00265",
        "citation": "https://www.trademarkia.com/trocador-99720500"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "limited",
      "controlModel": "noncustodial-hosted",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-26",
      "inputs": {
        "operatorDataExposure": {
          "value": "limited",
          "sourceUrls": [
            "https://noscript.trocador.app/en/giftcard/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "email-based daily limit is directly stated"
        },
        "controlModel": {
          "value": "noncustodial-hosted",
          "sourceUrls": [
            "https://noscript.trocador.app/en/termsofuse/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "official terms say Trocador never takes custody and connects users to third-party providers"
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://noscript.trocador.app/en/giftcard/",
            "https://noscript.trocador.app/en/termsofuse/",
            "https://trocador.app/en/giftcard/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "no reviewed official source establishes a source model"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "no-score-points-no-cap-exception"
      }
    }
  },
  {
    "id": 1089,
    "slug": "trocador-prepaid",
    "name": "Trocador Prepaid Cards",
    "domain": "trocador.app",
    "url": "https://trocador.app/en/prepaidcards/",
    "affiliate": null,
    "kyc": "light",
    "kycNote": "Card checkout requires email; activation may ask for name, address and phone. Official FAQ says no document upload is needed, but provider restrictions and blocked countries apply.",
    "fee": null,
    "limit": null,
    "categories": [
      "Virtual/Physical Card"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "Prepaid Visa",
      "Crypto",
      "No-KYC",
      "Via Trocador"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-06-22",
    "changedAt": null,
    "description": "Prepaid Visa and Mastercard through Trocador, where activation can require name, address and phone but no documents.",
    "cardSummary": "Prepaid Visa and Mastercard paid in crypto.",
    "networks": [],
    "checkedAt": "2026-08-26",
    "trending": false,
    "jurisdiction": "??",
    "privacyWarning": "Cards are nonrefundable; restricted-country or VPN/proxy redemption attempts can block the redeem code. Trocador collects the checkout email, providers collect activation identity/contact data, and the published Trocador privacy policy excludes third-party collection.",
    "founderIntel": "Same Trocador team; footer identifies Reta Development Assets LLC, but jurisdiction was not source-confirmed in this pass.",
    "vcIntel": "No VC found. Revenue likely from card/provider markup and swap/referral spread.",
    "ownership": null,
    "auditedBy": null,
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  Trocador - Unknown entity\n  ──────────────────────────────────────\n  Operator: Trocador team (pseudonymous)\n  Revenue: Prepaid card markup\n  Funding: Self-funded\n  ├─ Same team as Trocador swaps\n  └─ No KYC, virtual Visa",
    "kycLevel": 1,
    "lastReviewed": "2026-08-26",
    "kycLastChecked": "2026-08-26",
    "reviewSource": "Primary-source review 2026-08-26",
    "jurisdictionConfidence": "unknown",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://noscript.trocador.app/en/termsofuse/",
        "note": "Terms of Use explicitly state that the Trocador App is owned and managed by Reta Development Assets LLC, and site footers carry the copyright of that LLC."
      },
      "legalEntity": {
        "value": "Reta Development Assets LLC",
        "citation": "https://noscript.trocador.app/en/termsofuse/"
      },
      "incorporationJurisdiction": {
        "value": "Saint Kitts and Nevis",
        "citation": "https://www.whois.com/whois/trocador.app"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-26",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://noscript.trocador.app/en/privacypolicy/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "current policy establishes collection categories but does not establish a complete normalized card-issuer data exposure value"
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://noscript.trocador.app/en/termsofuse/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "Trocador non-custody is stated, but current issuer custody/control for each prepaid card is not established"
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://noscript.trocador.app/en/privacypolicy/",
            "https://noscript.trocador.app/en/termsofuse/",
            "https://trocador.app/en/prepaidcards/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "no reviewed official source establishes a source model"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "no-score-points-no-cap-exception"
      }
    }
  },
  {
    "id": 1090,
    "slug": "cheapgpt",
    "name": "CheapGPT",
    "domain": "cheapgp.selly.store",
    "url": "https://cheapgp.selly.store/",
    "affiliate": null,
    "kyc": "light",
    "kycNote": "No identity-KYC policy found, but delivery is by email and payments are handled through Selly/fiat/crypto processors.",
    "fee": null,
    "limit": null,
    "categories": [
      "Developer Tools"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "AI access",
      "Crypto accepted",
      "No-KYC",
      "GPT API",
      "Low cost"
    ],
    "tagline": null,
    "status": "warning",
    "updatedAt": "2026-06-22",
    "changedAt": null,
    "description": "Selly-hosted storefront selling AI subscription and voucher products such as Perplexity, Grammarly and Picsart.",
    "cardSummary": "Storefront for AI subscriptions and vouchers.",
    "networks": [],
    "checkedAt": "2026-08-27",
    "trending": false,
    "jurisdiction": "??",
    "privacyWarning": "Gray-market reseller storefront with platform/payment-processor dependence; product legitimacy, warranty and account-voucher durability are counterparty risks.",
    "founderIntel": "Anonymous operator. Resells AI API access. No corporate entity disclosed.",
    "vcIntel": "No known funding. Revenue from API markup.",
    "ownership": null,
    "auditedBy": [],
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  CheapGPT - Unknown operator\n  ──────────────────────────────────────\n  Operator: Anonymous\n  Revenue: AI API resale markup\n  Funding: Self-funded\n  ├─ Crypto-only payments\n  ├─ GPT-4/Claude access\n  └─ No corporate entity disclosed",
    "kycLevel": 1,
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "official_site_batch_5_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "unresolved",
        "citation": "https://cunicula.com/en/provider/cheapgpt",
        "note": "Selly-hosted independent online storefront reselling AI vouchers/subscriptions; site FAQ and secondary reviews state no corporate entity or jurisdiction is disclosed for the operator."
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "hosted-account",
      "sourceModel": "closed"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://cheapgp.selly.store/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "email, IP/browser/OS and payment gateway data available to Selly and merchant"
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://cheapgp.selly.store/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "hosted-reseller-storefront"
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://cheapgp.selly.store/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "closed-storefront"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No audit evidence."
      }
    }
  },
  {
    "id": 1091,
    "slug": "nanogpt",
    "name": "NanoGPT",
    "domain": "nano-gpt.com",
    "url": "https://nano-gpt.com/",
    "affiliate": null,
    "kyc": "light",
    "kycNote": "Anonymous/no-account use is available, but terms say card and crypto processors may perform KYC, transaction monitoring and sanctions screening; accounts are optional for sync/enhanced features.",
    "fee": null,
    "limit": null,
    "categories": [
      "Developer Tools"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "Pay-per-query AI",
      "Crypto accepted",
      "Multiple models",
      "No subscription"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-08-27",
    "changedAt": "2026-08-27",
    "description": "Pay-per-use AI platform for chat, image, video and API access, with local conversations and prepaid balances.",
    "cardSummary": "Pay-per-use access to many AI models.",
    "networks": [],
    "checkedAt": "2026-08-27",
    "trending": false,
    "jurisdiction": "US",
    "privacyWarning": "Prompts, attachments, tool context, media inputs and required settings are sent to selected model/provider routes; provider retention claims are not independently auditable, optional cloud/storage features create additional retention paths, and payment/abuse systems process metadata.",
    "founderIntel": "Anonymous operator. Pay-per-query model. Growing user base in crypto community.",
    "vcIntel": "No known VC. Revenue from per-query markup over API costs.",
    "ownership": null,
    "auditedBy": [],
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  NanoGPT - Unknown operator\n  ──────────────────────────────────────\n  Operator: Anonymous\n  Revenue: Per-query markup\n  Funding: Self-funded\n  ├─ Pay-per-query, no subscription\n  ├─ Multiple AI models\n  └─ Crypto accepted",
    "kycLevel": 2,
    "lastReviewed": "2026-08-27",
    "kycLastChecked": "2026-08-27",
    "reviewSource": "Primary-source review 2026-08-27",
    "jurisdictionConfidence": "verified",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://nano-gpt.com/legal/terms-of-service",
        "note": "Official Terms state Nano-GPT.com is a U.S.-incorporated company operating a commercial hosted AI API; LinkedIn lists a privately held company headquartered in Dover, Delaware founded 2024; co-founder publicly stated it is a US LLC registered in Delaware."
      },
      "incorporationJurisdiction": {
        "value": "Delaware, United States",
        "citation": "https://www.linkedin.com/company/nano-gpt"
      },
      "officers": {
        "value": [
          "Milan de Reede (CEO and Co-Founder)"
        ],
        "citation": "https://www.linkedin.com/company/nano-gpt"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "moderate",
      "controlModel": "hosted-account",
      "sourceModel": "closed"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "moderate",
          "sourceUrls": [
            "https://nano-gpt.com/privacy"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Prompts are routed to selected providers and the service processes balances, requests, IP/security and optional sync/share/support data; exposure is moderate despite local chat history defaults."
        },
        "controlModel": {
          "value": "hosted-account",
          "sourceUrls": [
            "https://nano-gpt.com/",
            "https://nano-gpt.com/legal/terms-of-service"
          ],
          "reviewedAt": "2026-08-27",
          "note": "NanoGPT operates hosted model routing, account/balance and API infrastructure."
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://nano-gpt.com/legal/terms-of-service"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Terms restrict discovery/distribution of service source and no official critical-core repository is disclosed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "The prior audit candidate is a privacy statement that NanoGPT cannot inspect third-party provider infrastructure; it is not an audit and earns no points."
      }
    }
  },
  {
    "id": 1092,
    "slug": "ppq-ai",
    "name": "PayPerQ",
    "domain": "ppq.ai",
    "url": "https://ppq.ai/",
    "affiliate": null,
    "kyc": "none",
    "kycNote": "No signup required for basic use; optional account and credit-card deposits can add account/payment metadata.",
    "fee": "Usage-based; average web query stated as about 1.5¢; no subscriptions",
    "limit": null,
    "categories": [
      "Developer Tools"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Privacy"
    ],
    "features": [
      "No registration for basic use",
      "Pay per use",
      "Hundreds of AI models",
      "Optional account",
      "Crypto and card funding",
      "Anon/ZDR/E2EE privacy labels"
    ],
    "tagline": null,
    "status": "ok",
    "updatedAt": "2026-08-25",
    "changedAt": null,
    "description": "Pay-per-use web app and API for hundreds of chat, image, video and voice AI models, with no registration required for basic use.",
    "cardSummary": "Pay-per-prompt AI with web app and API.",
    "networks": [],
    "checkedAt": "2026-08-25",
    "trending": false,
    "jurisdiction": "??",
    "privacyWarning": "Prompts are sent to model providers. PPQ does not store prompt content, but provider retention depends on the selected Anon/ZDR/E2EE tier; API ZDR is opt-in per request, OpenAI-developed models receive a pseudonymous abuse-prevention identifier, and optional accounts/card payments add email/payment metadata.",
    "founderIntel": "Anonymous operator. Privacy-focused AI access. Monero-first payment.",
    "vcIntel": "No known funding. Revenue from per-query fees.",
    "ownership": null,
    "auditedBy": null,
    "stateActorFlag": null,
    "twitter": null,
    "telegram": null,
    "followTheMoney": "  PayPerQ - Unknown operator\n  ──────────────────────────────────────\n  Operator: Anonymous\n  Revenue: Per-query fees\n  Funding: Self-funded\n  ├─ XMR/BTC payments\n  ├─ No accounts needed\n  └─ Multiple AI models",
    "kycLevel": 0,
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "primary_source_rereview_2026-08-25",
    "jurisdictionConfidence": "unknown",
    "geo": [
      "GLOBAL"
    ],
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://www.linkedin.com/company/payperq",
        "note": "Hosted pay-per-use AI vendor operated as a privately held business with named founder/CEO and CTO, VC funding, and LinkedIn company page; Terms name PPQ.AI as the service provider."
      },
      "legalEntity": {
        "value": "PPQ.AI",
        "citation": "https://ppq.ai/terms"
      },
      "officers": {
        "value": [
          {
            "name": "Matt Ahlborg",
            "role": "Founder"
          },
          {
            "name": "Rafael Valverde",
            "role": "CTO"
          }
        ],
        "citation": "https://ppq.ai/"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://ppq.ai/",
            "https://ppq.ai/pricing",
            "https://ppq.ai/privacy"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://ppq.ai/",
            "https://ppq.ai/pricing",
            "https://ppq.ai/privacy"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://ppq.ai/",
            "https://ppq.ai/pricing",
            "https://ppq.ai/privacy"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1093,
    "slug": "eigenwallet",
    "domain": "eigenwallet.org",
    "name": "eigenwallet",
    "type": "P2P Wallet",
    "cat": "p2p",
    "kyc": "none",
    "kycLevel": 0,
    "features": [
      "BTC to XMR atomic swaps",
      "No account",
      "Non-custodial Monero wallet",
      "Built-in Tor",
      "Open source",
      "Onion site"
    ],
    "networks": [
      "BTC",
      "XMR"
    ],
    "badge": "ATOMIC",
    "url": "https://eigenwallet.org/",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-24",
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "P2P",
      "Wallet",
      "Swap"
    ],
    "description": "Open-source Monero wallet and BTC to XMR atomic swap DEX, formerly UnstoppableSwap, with built-in Tor.",
    "cardSummary": "Monero wallet with BTC to XMR atomic swaps.",
    "jurisdiction": null,
    "tagline": "BTC to XMR atomic swaps with no account, no custodian, and no KYC.",
    "kycNote": "Official site says Bitcoin-to-Monero swaps have protocol-guaranteed safety, no accounts, zero frozen-fund risk and no KYC ever. KYCnot lists level 0 guaranteed no-KYC; EUR/SEPA buying and external makers remain separate operational paths.",
    "bestFor": [
      "BTC to XMR swaps",
      "No-account Monero acquisition",
      "Tor-routed self-custody"
    ],
    "affiliate": "",
    "updatedAt": "2026-06-22",
    "fee": "Varies by maker offer",
    "limit": "Varies by live liquidity",
    "privacyWarning": "No verified legal entity or jurisdiction found. Liquidity is maker-dependent; KYCnot records a resolved May 2026 maker-side ASB griefing incident affecting roughly 0.657 BTC, patched in v4.6.7. Direct EUR/SEPA purchase path is outside the pure BTC-to-XMR atomic-swap flow.",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "candidate_eigenwallet_2026-06-22",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "unresolved",
        "citation": "unknown",
        "note": "Pass 1 researched this service but established no registry facts."
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://eigenwallet.org/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://eigenwallet.org/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://eigenwallet.org/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1094,
    "slug": "mynymbox",
    "domain": "mynymbox.io",
    "name": "MyNymBox",
    "type": "Hosting",
    "cat": "hosting",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Shared from €3.50/mo; VPS from €4/mo",
    "limits": {
      "daily": null
    },
    "features": [
      "BTC/Lightning/XMR payments",
      "Email alias accepted",
      "Tor/VPN access allowed",
      "KVM VPS",
      "Dedicated servers",
      "Anonymous domains",
      "WHOIS privacy",
      "NL/FI locations"
    ],
    "networks": [
      "BTC",
      "LIGHTNING",
      "XMR",
      "LTC",
      "ZEC"
    ],
    "badge": "HOSTING",
    "url": "https://mynymbox.io/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-24",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Hosting"
    ],
    "description": "Hosting and domain registration needing only a working email, paid in BTC, Lightning, XMR, LTC or ZEC.",
    "cardSummary": "Hosting and domains registered anonymously.",
    "jurisdiction": "US",
    "auditedBy": [],
    "twitter": "https://x.com/mynymbox",
    "telegram": null,
    "founderIntel": "Operator/founders not publicly identified. Official structured data and RIPE-style records identify Mynymbox Hosting LLC/Mynymbox LLC with an address at Hamilton Development, Unit B, Charlestown, Nevis; servers/products are advertised in the Netherlands, Finland and Germany.",
    "vcIntel": "No VC funding or institutional investors found. Revenue appears to come from hosting, domain, DNS, email hosting and dedicated-server subscriptions paid mostly through crypto rails.",
    "privacyWarning": "Account is required and the username is an email address, though aliases are allowed. Privacy policy says IP addresses may be logged for client portal, service management panels and administrative/service interfaces for security and abuse handling. Mynymbox says it is not bulletproof hosting and will comply with valid legal orders; altcoin swaps use Trocador and fiat/onramp paths use Malum/PayPal/Stripe-style rails.",
    "stateActorFlag": null,
    "tagline": "Privacy-friendly VPS, hosting and domain registration with email-alias signup and XMR/BTC/Lightning payments.",
    "bestFor": [
      "Crypto-paid VPS hosting",
      "Anonymous domain registration",
      "Email-alias hosting account setup"
    ],
    "kycNote": "Official homepage, privacy policy and ToS say no personal details are required beyond a working email address; aliases are accepted and Tor/I2P/VPN signup/access are allowed. KYCnot lists MyNymBox as verified, level 0 guaranteed no-KYC, score 9/10. Domain registrations are manually reviewed for fraud/phishing and can be registered under Mynymbox/privacy-shield details.",
    "updatedAt": "2026-06-22",
    "followTheMoney": "  Mynymbox Hosting LLC - Nevis (KN)\n  ──────────────────────────────────────\n  Operators: undisclosed\n  Funding: no VC or investors found\n  Revenue: VPS, hosting, domains, DNS/email\n  ├─ Legal address: Charlestown, Nevis\n  ├─ Infra/products: NL, FI and DE servers\n  ├─ Self-hosted BTCPay for BTC/Lightning/XMR/LTC/ZEC\n  └─ Legal/abuse policy: not bulletproof; valid orders honored",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "reviewSource": "candidate_mynymbox_2026-06-22",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://mynymbox.io/aboutus",
        "note": "Official About and Terms pages identify the operator as the registered company Mynymbox Hosting LLC providing commercial hosting/VPS/domain services."
      },
      "legalEntity": {
        "value": "Mynymbox Hosting LLC",
        "citation": "https://mynymbox.io/aboutus"
      },
      "registrationNumber": {
        "value": "L23549",
        "citation": "https://www.cidr-report.org/cgi-bin/as-report?as=211673&view=2.0&v=4"
      },
      "incorporationJurisdiction": {
        "value": "Saint Kitts and Nevis (Nevis)",
        "citation": "https://mynymbox.io/aboutus"
      },
      "registeredAddress": {
        "value": "Hamilton Development Unit B, Charlestown, Nevis, KN0802, St. Kitts & Nevis",
        "citation": "https://mynymbox.io/aboutus"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://mynymbox.io/termsofservice",
            "https://mynymbox.io/privacypolicy",
            "https://mynymbox.io/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://mynymbox.io/termsofservice",
            "https://mynymbox.io/privacypolicy",
            "https://mynymbox.io/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://mynymbox.io/termsofservice",
            "https://mynymbox.io/privacypolicy",
            "https://mynymbox.io/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1095,
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "warning",
    "checkedAt": "2026-08-05",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "updatedAt": "2026-08-05",
    "changedAt": "2026-08-05",
    "lastReviewed": "2026-08-05",
    "kycLastChecked": "2026-08-05",
    "jurisdictionConfidence": "verified",
    "slug": "solvocard",
    "domain": "solvocard.com",
    "name": "SolvoCard",
    "type": "Virtual Cards",
    "cat": "cards",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 4
    },
    "fee": "4% crypto deposit; $99 virtual card; terms list $1 per top-up",
    "limit": "No maximum single top-up claimed; $25,000 monthly per card on several pages; EURO page also claims EUR50,000",
    "limits": {
      "daily": null
    },
    "features": [
      "No identity documents",
      "Email-only account",
      "XMR/BTC/ETH/stablecoin funding",
      "Virtual Visa/Mastercard",
      "Google Pay",
      "Apple Pay on USD card",
      "3DS",
      "Physical card pre-order"
    ],
    "networks": [
      "VISA",
      "MASTERCARD",
      "BTC",
      "ETH",
      "USDT",
      "USDC",
      "XMR",
      "SOL"
    ],
    "badge": "ACTIVE INCIDENT",
    "url": "https://www.solvocard.com/",
    "categories": [
      "Virtual/Physical Card"
    ],
    "description": "Crypto-funded virtual cards claiming email-only signup, with a June 2026 refund-delay incident still unresolved.",
    "cardSummary": "Crypto-funded virtual cards, email-only signup.",
    "jurisdiction": "SC",
    "auditedBy": [],
    "twitter": "https://x.com/solvocard",
    "telegram": null,
    "founderIntel": "Terms identify TivoLabs LTD, Seychelles company number 246356. The privacy policy calls SolvoCard a United States-based company. Operators, founders, card issuers, and payment processors are not named on the public pages checked.",
    "vcIntel": "No VC or institutional funding found in this pass. Revenue appears to come from deposit conversion fees, card issue fees and top-up fees.",
    "privacyWarning": "Active refund-delay incident remains unresolved in the existing record and the official site publishes no incident notice. Current sources also conflict: terms name Seychelles-based TivoLabs LTD but are governed by US law, while the privacy page calls SolvoCard United States-based. Card partners remain unnamed; treat issuer-level no-KYC and refund claims as unverified.",
    "stateActorFlag": null,
    "tagline": "Email-only crypto-funded virtual cards. No identity documents are requested.",
    "bestFor": [
      "Comparing published no-KYC card terms",
      "Reviewing crypto-funded card limits",
      "Monitoring the June 2026 card-program incident"
    ],
    "kycNote": "Terms and card pages say no identity documents, proof of address, selfies or extensive personal verification; only a valid email is required. This is an official claim, not independently verified issuer-level policy.",
    "followTheMoney": "  TivoLabs LTD / SolvoCard - Seychelles claim\n  ----------------------------------------\n  Terms: Seychelles company no. 246356\n  Privacy policy: calls company US-based\n  Issuers/processors: not named\n  Revenue: deposit, issue, and top-up fees\n  |- Crypto converted by payment partners\n  |- Card balance held by banking partners\n  `- June 2026 refund incident reported",
    "reviewSource": "official_terms_privacy_kycnot_incident_2026-08-05",
    "evidenceStatus": "verified",
    "riskLevel": "danger",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://www.solvocard.com/terms",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "TivoLabs LTD",
        "citation": "https://www.solvocard.com/terms"
      },
      "registrationNumber": {
        "value": "246356",
        "citation": "https://www.solvocard.com/terms"
      },
      "incorporationJurisdiction": {
        "value": "Seychelles",
        "citation": "https://www.solvocard.com/terms"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.solvocard.com/no-kyc-virtual-card",
            "https://www.solvocard.com/terms",
            "https://www.solvocard.com/privacy",
            "https://kycnot.me/service/solvocardcom",
            "https://www.solvocard.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.solvocard.com/no-kyc-virtual-card",
            "https://www.solvocard.com/terms",
            "https://www.solvocard.com/privacy",
            "https://kycnot.me/service/solvocardcom",
            "https://www.solvocard.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.solvocard.com/no-kyc-virtual-card",
            "https://www.solvocard.com/terms",
            "https://www.solvocard.com/privacy",
            "https://kycnot.me/service/solvocardcom",
            "https://www.solvocard.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1096,
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-24",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "updatedAt": "2026-06-22",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "jurisdictionConfidence": "unknown",
    "slug": "sageswap",
    "domain": "sageswap.io",
    "name": "SageSwap",
    "type": "Swap",
    "cat": "swap",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 2
    },
    "fee": "1–2% standard; AML-swap mode usually 3–4% total",
    "limits": {
      "daily": null
    },
    "features": [
      "No account",
      "Never-KYC claim",
      "XMR support",
      "BTC Lightning support",
      "Fixed and floating rates",
      "AML-swap mode",
      "Refund address option"
    ],
    "networks": [
      "BTC",
      "LIGHTNING",
      "BCH",
      "ETH",
      "DASH",
      "USDT",
      "USDC",
      "XMR",
      "ZANO",
      "SOL",
      "LTC",
      "DOGE",
      "BNB"
    ],
    "badge": "NEVER KYC",
    "url": "https://sageswap.io/",
    "categories": [
      "Swap"
    ],
    "description": "No-account crypto swaps supporting Monero and Lightning, with a separate AML-swap mode for high-risk coins.",
    "cardSummary": "No-account swaps supporting Monero.",
    "jurisdiction": null,
    "auditedBy": [],
    "twitter": null,
    "telegram": null,
    "founderIntel": "No public founder, company or jurisdiction details found on the official pages checked.",
    "vcIntel": "No VC or institutional funding found. Revenue appears to come from swap spread and extra AML-swap fees.",
    "privacyWarning": "Official pages claim no IP or identifying-data collection and automatic permanent deletion of successful swap records after 7 days. The separate AML Swap mode accepts high-risk coins for an extra 2.2% and the operator/jurisdiction remain opaque; these are operator assertions without published legal/privacy terms.",
    "stateActorFlag": null,
    "tagline": "No-account swaps with an official never-KYC claim and XMR support.",
    "bestFor": [
      "Small XMR swaps",
      "No-account crypto-to-crypto exchange",
      "Users who understand AML-score route risk"
    ],
    "kycNote": "Official FAQ says no KYC is ever required under any circumstances; no account is needed for crypto-to-crypto swaps.",
    "followTheMoney": "  SageSwap - Unknown jurisdiction\n  ──────────────────────────────────────\n  Operators: undisclosed\n  Funding: no VC found\n  Revenue: 1–2% standard spread; higher AML-swap fees\n  ├─ Supports XMR and Lightning\n  ├─ No account/KYC claim\n  └─ AML-swap mode is a major risk flag to disclose",
    "reviewSource": "candidate_sageswap_official_2026-06-22",
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "unresolved",
        "citation": "unknown",
        "note": "Pass 1 researched this service but established no registry facts."
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "limited",
      "controlModel": "noncustodial-hosted",
      "sourceModel": "closed"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "limited",
          "sourceUrls": [
            "https://sageswap.io/faq",
            "https://sageswap.io/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No account is required, but deposit/output addresses, swap state and support records remain visible to the hosted exchanger."
        },
        "controlModel": {
          "value": "noncustodial-hosted",
          "sourceUrls": [
            "https://sageswap.io/",
            "https://sageswap.io/faq"
          ],
          "reviewedAt": "2026-08-27",
          "note": "SageSwap coordinates noncustodial hosted swaps without persistent customer accounts."
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://sageswap.io/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No official critical-core source or reproducible deployment was located."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced; no audit points are granted."
      }
    }
  },
  {
    "id": 1097,
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-24",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "updatedAt": "2026-06-22",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "jurisdictionConfidence": "unknown",
    "slug": "silent-exchange",
    "domain": "silent.exchange",
    "name": "Silent Exchange",
    "type": "Swap",
    "cat": "swap",
    "kyc": "light",
    "kycLevel": 1,
    "fees": {
      "transaction": 0
    },
    "fee": "Included in the final exchange rate; miner fees and exceptional recovery charges may apply",
    "limits": {
      "daily": null
    },
    "features": [
      "No account",
      "Fixed and floating rates",
      "Anonymous-exchange marketing",
      "Telegram exchange bot",
      "Many crypto pairs"
    ],
    "networks": [
      "BTC",
      "XMR",
      "ETH",
      "USDT",
      "LTC",
      "DASH",
      "DOGE"
    ],
    "badge": "NO ACCOUNT",
    "url": "https://silent.exchange/",
    "categories": [
      "Swap"
    ],
    "description": "No-account crypto exchange with a Telegram bot, where screening can trigger AML or KYC requests in flagged cases.",
    "cardSummary": "No-account swaps with a Telegram bot.",
    "jurisdiction": null,
    "auditedBy": [],
    "twitter": null,
    "telegram": "https://t.me/silentexchangerobot",
    "founderIntel": "No public founders, company registration or operating jurisdiction found in the official pages checked.",
    "vcIntel": "No VC or institutional funding found. Revenue appears to be swap spread.",
    "privacyWarning": "Not true zero-KYC. Terms say an automated risk system checks transactions and Silent Exchange may freeze transactions and request origin-of-funds documents or identity verification for AML/KYC review. Privacy policy enumerates possible collection of name, date of birth, nationality, address, email, tax IDs, passport/driver-license/national-ID details, payment-card/bank data and transaction history.",
    "stateActorFlag": null,
    "tagline": "No-account crypto swaps, but with explicit AML/KYC trigger risk.",
    "bestFor": [
      "Users who need no-account swaps but accept possible AML review",
      "Small non-risk-flagged swaps only"
    ],
    "kycNote": "No account is required, but official terms reserve AML/KYC procedures and transaction freezes. Classified as light KYC risk, not zero-KYC.",
    "followTheMoney": "  Silent Exchange - Unknown jurisdiction\n  ──────────────────────────────────────\n  Operators: undisclosed\n  Funding: no VC found\n  Revenue: swap spread\n  ├─ No account needed for normal flow\n  ├─ Telegram bot: @silentexchangerobot\n  └─ AML/KYC procedures can be triggered by risk scoring",
    "reviewSource": "candidate_silent_exchange_official_2026-06-22",
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "unresolved",
        "citation": "unknown",
        "note": "Pass 1 researched this service but established no registry facts."
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "limited",
      "controlModel": "noncustodial-hosted",
      "sourceModel": "closed"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "limited",
          "sourceUrls": [
            "https://silent.exchange/privacy-policy-2/",
            "https://silent.exchange/terms-of-use/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No persistent account is required, but swap identifiers, addresses, transaction and support data are operator-visible."
        },
        "controlModel": {
          "value": "noncustodial-hosted",
          "sourceUrls": [
            "https://silent.exchange/",
            "https://silent.exchange/terms-of-use/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "Silent Exchange runs hosted noncustodial exchange workflows and recovery/refund handling."
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://silent.exchange/terms-of-use/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No official implementation repository or reproducible core was published."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced; no audit points are granted."
      }
    }
  },
  {
    "id": 1098,
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-06-24",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "updatedAt": "2026-06-22",
    "lastReviewed": "2026-06-22",
    "kycLastChecked": "2026-06-22",
    "jurisdictionConfidence": "unknown",
    "slug": "infinity-exchanger",
    "domain": "exchanger.infinity.taxi",
    "name": "Infinity Exchanger",
    "type": "Swap",
    "cat": "swap",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Included in exchange rate",
    "limits": {
      "daily": null
    },
    "features": [
      "No account",
      "No KYC/AML screening claim",
      "Own reserve",
      "Quick swap",
      "Onion endpoint",
      "Monero and Bitcoin support",
      "KYCnot score 9/10"
    ],
    "networks": [
      "BTC",
      "XMR",
      "LIGHTNING"
    ],
    "badge": "NO-KYC",
    "url": "https://exchanger.infinity.taxi/",
    "categories": [
      "Swap"
    ],
    "description": "No-account crypto exchanger on clearnet and onion, listed by KYCnot as guaranteed no-KYC with a 9/10 score.",
    "cardSummary": "No-account exchanger with an onion mirror.",
    "jurisdiction": null,
    "auditedBy": [],
    "twitter": null,
    "telegram": null,
    "founderIntel": "No public founders, company registration or operating jurisdiction found in this pass. KYCnot and official pages present it as Tor/onion-capable and privacy-first.",
    "vcIntel": "No VC or institutional funding found. Revenue appears to be exchanger spread from reserve-based swaps.",
    "privacyWarning": "Opaque Tor-first exchanger with unknown operators and jurisdiction. KYCnot shows limited recent checks and 11 ratings averaging about 3.2/5. Use small test amounts; own-reserve exchangers carry custody/liquidity risk during the transaction window.",
    "stateActorFlag": null,
    "tagline": "No-account reserve exchanger with KYCnot level-0 no-KYC rating.",
    "bestFor": [
      "Small BTC/XMR swaps",
      "Tor/onion-capable no-account swaps",
      "Users comfortable with opaque operator risk"
    ],
    "kycNote": "Official site says it does not collect personal information or screen users for KYC/AML-related data. KYCnot lists level 0 guaranteed no-KYC and says refunds do not require KYC.",
    "followTheMoney": "  Infinity Exchanger - Unknown jurisdiction\n  ──────────────────────────────────────\n  Operators: undisclosed\n  Funding: no VC found\n  Revenue: reserve-exchanger spread\n  ├─ Clearnet and onion endpoint\n  ├─ No account/KYC claim\n  └─ Opaque ownership and limited rating history",
    "reviewSource": "candidate_infinity_exchanger_official_kycnot_2026-06-22",
    "evidenceStatus": "limited",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "unresolved",
        "citation": "unknown",
        "note": "Pass 1 researched this service but established no registry facts."
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://exchanger.infinity.taxi/",
            "https://infinity.taxi/privacy-policy"
          ],
          "reviewedAt": "2026-08-27",
          "note": "The live exchange page claims no account/KYC, but current privacy/legal routes return a rotation-gateway error page, so operator handling cannot be independently bounded."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://exchanger.infinity.taxi/",
            "https://infinity.taxi/terms-of-service"
          ],
          "reviewedAt": "2026-08-27",
          "note": "The live page advertises an own-reserve exchanger, but failed legal documentation prevents a verified custody/control classification."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://infinity.taxi/terms-of-service"
          ],
          "reviewedAt": "2026-08-27",
          "note": "The only source-code link concerns the rotation system, not the exchange core; the critical-core source model is unknown."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced in the reopened first-party source family."
      }
    }
  },
  {
    "id": 1099,
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-27",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "updatedAt": "2026-08-27",
    "lastReviewed": "2026-08-27",
    "kycLastChecked": "2026-08-27",
    "auditedBy": [],
    "twitter": null,
    "telegram": null,
    "stateActorFlag": null,
    "slug": "pegasusswap",
    "domain": "pegasusswap.com",
    "name": "PegasusSwap",
    "type": "Swap",
    "cat": "swap",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Included in displayed swap rate",
    "limits": {
      "daily": null
    },
    "features": [
      "No account",
      "No KYC claim",
      "No personal data collection claim",
      "XMR support",
      "Fixed and floating rates",
      "Refund address option",
      "KYCnot score 9/10"
    ],
    "networks": [
      "BTC",
      "XMR",
      "ETH",
      "USDT",
      "USDC",
      "TRX",
      "SOL",
      "XRP",
      "LTC",
      "ZANO"
    ],
    "badge": "NO-KYC",
    "url": "https://pegasusswap.com/",
    "categories": [
      "Swap"
    ],
    "description": "No-account crypto swap platform supporting Monero, offering fixed or floating rates and a KYCnot guaranteed level-0 listing.",
    "cardSummary": "No-account swaps with Monero support.",
    "jurisdiction": null,
    "jurisdictionConfidence": "unknown",
    "founderIntel": "No public founder, company registration or operator jurisdiction found on the official pages checked.",
    "vcIntel": "No VC or institutional funding found. Revenue appears to come from swap spread included in displayed rates.",
    "privacyWarning": "Official privacy policy says PegasusSwap does not collect, request, or verify identity-related information under any circumstances. Terms still allow refunds to depend on technical feasibility, and operator/jurisdiction are opaque; use small test swaps first.",
    "tagline": "No-account, no-KYC crypto swaps with Monero support and KYCnot level-0 listing.",
    "bestFor": [
      "Small no-account XMR swaps",
      "Users comparing KYCnot-listed instant exchangers",
      "Fixed/floating crypto-to-crypto swaps"
    ],
    "kycNote": "Official privacy policy says PegasusSwap operates as a non-KYC service and does not collect, request, or verify identity-related information under any circumstances. KYCnot lists it as guaranteed no-KYC, level 0, score 9/10.",
    "followTheMoney": "  PegasusSwap - Unknown jurisdiction\n  ──────────────────────────────────────\n  Operators: undisclosed\n  Funding: no VC found\n  Revenue: swap spread in displayed rate\n  ├─ Official no-KYC/no-registration claim\n  ├─ KYCnot level-0 guaranteed no-KYC listing\n  └─ Opaque legal entity: caution tier",
    "reviewSource": "Primary-source review 2026-08-27",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "unresolved",
        "citation": "unknown",
        "note": "Pass 1 researched this service but established no registry facts."
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "limited",
      "controlModel": "noncustodial-hosted",
      "sourceModel": "closed"
    },
    "changedAt": "2026-08-27",
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "limited",
          "sourceUrls": [
            "https://pegasusswap.com/privacy-policy",
            "https://pegasusswap.com/faq"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No account or KYC is requested, but swap IDs, transaction addresses, refund details and support exchanges remain operator-visible."
        },
        "controlModel": {
          "value": "noncustodial-hosted",
          "sourceUrls": [
            "https://pegasusswap.com/",
            "https://pegasusswap.com/terms-of-use"
          ],
          "reviewedAt": "2026-08-27",
          "note": "PegasusSwap coordinates hosted swaps/refunds without a persistent customer account."
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://pegasusswap.com/terms-of-use"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No official implementation repository or reproducible critical-core build was published."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced; no audit points are granted."
      }
    }
  },
  {
    "id": 1100,
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-27",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "updatedAt": "2026-08-27",
    "lastReviewed": "2026-08-27",
    "kycLastChecked": "2026-08-27",
    "auditedBy": [],
    "twitter": null,
    "telegram": null,
    "stateActorFlag": null,
    "slug": "ghostswap",
    "domain": "ghostswap.io",
    "name": "GhostSwap",
    "type": "Swap",
    "cat": "swap",
    "kyc": "light",
    "kycLevel": 1,
    "fees": {
      "transaction": 0
    },
    "fee": "Included in swap rate",
    "limits": {
      "daily": null
    },
    "features": [
      "No account for standard swaps",
      "No signup/no email marketing claim",
      "1,600+ coins",
      "XMR support",
      "Tor browser support content",
      "AML partner screening disclosure"
    ],
    "networks": [
      "BTC",
      "ETH",
      "XMR",
      "ZEC",
      "SOL",
      "USDT",
      "XRP",
      "DOGE",
      "LTC"
    ],
    "badge": "NO ACCOUNT",
    "url": "https://ghostswap.io/",
    "categories": [
      "Swap",
      "Aggregator"
    ],
    "description": "No-account swap aggregator for BTC, ETH, XMR and 1,600+ coins, with automated AML checks by licensed processing partners.",
    "cardSummary": "Swap aggregator covering 1,600+ coins.",
    "jurisdiction": null,
    "jurisdictionConfidence": "unknown",
    "founderIntel": "No public founder, company registration or explicit operating jurisdiction found in official pages checked.",
    "vcIntel": "No VC or institutional funding found. Revenue appears to come from swap spread/partner processing margin.",
    "privacyWarning": "GhostSwap does not require an account for standard swaps, but its terms say licensed processing partners run AML/sanctions checks and may block, reject, or refund flagged transactions. Not a pure zero-risk no-KYC venue.",
    "tagline": "No-account XMR-capable swap aggregator with explicit AML-partner screening caveat.",
    "bestFor": [
      "Fast no-account crypto swaps",
      "XMR/major-coin swaps where partner screening risk is acceptable",
      "Users who prefer no signup over exchange accounts"
    ],
    "kycNote": "Homepage markets no signup, no email, no account and no KYC. Terms disclose automated AML/sanctions procedures by licensed processing partners, with block/reject/refund outcomes for flagged transactions; classified as light KYC risk.",
    "followTheMoney": "  GhostSwap - Unknown jurisdiction\n  ──────────────────────────────────────\n  Operators: undisclosed\n  Funding: no VC found\n  Revenue: swap/partner spread\n  ├─ No account required for standard swaps\n  ├─ Licensed processing partners handle compliance\n  └─ AML/sanctions screening risk: caution tier",
    "reviewSource": "Primary-source review 2026-08-27",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "unresolved",
        "citation": "unknown",
        "note": "Pass 1 researched this service but established no registry facts."
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "limited",
      "controlModel": "noncustodial-hosted",
      "sourceModel": "closed"
    },
    "changedAt": "2026-08-27",
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-27",
      "inputs": {
        "operatorDataExposure": {
          "value": "limited",
          "sourceUrls": [
            "https://ghostswap.io/privacy-policy/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No account is required, but GhostSwap and processing partners handle wallet addresses, amounts, transaction identifiers and technical/compliance data."
        },
        "controlModel": {
          "value": "noncustodial-hosted",
          "sourceUrls": [
            "https://ghostswap.io/terms-of-use/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "GhostSwap states it provides a non-custodial interface and does not hold funds; users control wallets and private keys."
        },
        "sourceModel": {
          "value": "closed",
          "sourceUrls": [
            "https://ghostswap.io/terms-of-use/"
          ],
          "reviewedAt": "2026-08-27",
          "note": "No official implementation repository is disclosed and the terms reserve the hosted service technology."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped independent audit of the score-critical core was evidenced in the reopened first-party source family."
      }
    }
  },
  {
    "id": 1101,
    "affiliate": "",
    "geo": [
      "GLOBAL",
      "NL",
      "LT"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "GLOBAL",
      "NL",
      "LT"
    ],
    "updatedAt": "2026-08-25",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "auditedBy": [],
    "twitter": "https://x.com/btcvps",
    "telegram": null,
    "stateActorFlag": null,
    "slug": "btcvps",
    "domain": "btcvps.com",
    "name": "BTCVPS",
    "type": "Hosting",
    "cat": "hosting",
    "kyc": "none",
    "kycLevel": 1,
    "fees": {
      "transaction": 0
    },
    "fee": "KVM VPS from €6/mo or €64.80/yr",
    "limits": {
      "daily": null
    },
    "features": [
      "Email-only signup",
      "No identity verification",
      "KVM VPS",
      "Full root access",
      "Encrypted storage",
      "Netherlands and Lithuania locations",
      "Monero and Bitcoin payments"
    ],
    "networks": [
      "BTC",
      "XMR",
      "BCH",
      "DASH",
      "LTC",
      "WOW",
      "DGB"
    ],
    "badge": "VPS",
    "url": "https://btcvps.com/",
    "categories": [
      "Hosting"
    ],
    "description": "KVM VPS provider with email-only signup and Monero or Bitcoin payment, on server locations in the Netherlands and Lithuania.",
    "cardSummary": "KVM VPS with email-only signup.",
    "jurisdiction": "NL",
    "jurisdictionConfidence": "verified",
    "founderIntel": "No individual founder information found. Official terms state BTCVPS operates under Netherlands jurisdiction.",
    "vcIntel": "No VC or institutional funding found. Revenue appears to come from VPS subscriptions paid through crypto rails.",
    "privacyWarning": "Not bulletproof hosting. Terms say BTCVPS complies with Dutch law and valid court orders. Privacy policy says app-level IP tracking is not used, but default Nginx access logs may include IP, path, timestamp, user agent and status for operations/security.",
    "tagline": "Email-only no-ID VPS hosting with Monero/Bitcoin payments and NL/LT server locations.",
    "bestFor": [
      "Crypto-paid VPS hosting",
      "Email-only server signup",
      "Users who need disclosed Netherlands jurisdiction"
    ],
    "kycNote": "Official terms say BTCVPS does not verify user identities and registration does not require personal documentation. Privacy policy says it does not collect government ID, full legal name, home address, phone, billing address, credit card information, or KYC documents.",
    "followTheMoney": "  BTCVPS - Netherlands\n  ──────────────────────────────────────\n  Operators: undisclosed\n  Funding: no VC found\n  Revenue: VPS subscriptions\n  ├─ Email-only signup\n  ├─ Crypto payments incl. BTC/XMR\n  ├─ NL/LT server locations\n  └─ Dutch law / valid court-order compliance",
    "reviewSource": "primary_source_rereview_2026-08-25",
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://btcvps.com/",
        "note": "BTCVPS is a commercial paid VPS hosting vendor (crypto payments, plans, ToS/AUP); not an open-source project, foundation, or unresolved type."
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://btcvps.com/",
            "https://btcvps.com/privacy-policy",
            "https://status.btcvps.com/api/getMonitorList/KGzIQFcCuv",
            "https://btcvps.com/blog/maintenance-on-netherlands-node01-wednesday-aug-19",
            "https://x.com/btcvps/status/2088795270868005105"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://btcvps.com/",
            "https://btcvps.com/privacy-policy",
            "https://status.btcvps.com/api/getMonitorList/KGzIQFcCuv",
            "https://btcvps.com/blog/maintenance-on-netherlands-node01-wednesday-aug-19",
            "https://x.com/btcvps/status/2088795270868005105"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://btcvps.com/",
            "https://btcvps.com/privacy-policy",
            "https://status.btcvps.com/api/getMonitorList/KGzIQFcCuv",
            "https://btcvps.com/blog/maintenance-on-netherlands-node01-wednesday-aug-19",
            "https://x.com/btcvps/status/2088795270868005105"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1102,
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-26",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "updatedAt": "2026-06-24",
    "lastReviewed": "2026-06-24",
    "kycLastChecked": "2026-06-24",
    "auditedBy": [],
    "twitter": null,
    "telegram": null,
    "stateActorFlag": null,
    "slug": "xchange-me",
    "domain": "xchange.me",
    "name": "xChange.me",
    "type": "Swap",
    "cat": "swap",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Included in exchange rate / table of fees",
    "limits": {
      "daily": null
    },
    "features": [
      "Accountless exchange flow",
      "Anonymous exchange terms",
      "200+ cryptocurrencies",
      "XMR support",
      "Onion mirror",
      "Marshall Islands controller disclosed"
    ],
    "networks": [
      "BTC",
      "XMR",
      "ETH",
      "LTC",
      "USDT"
    ],
    "badge": "ANON SWAP",
    "url": "https://xchange.me/",
    "categories": [
      "Swap"
    ],
    "description": "Accountless exchanger for 200+ coins including Monero, with an onion mirror and Pacific Ventures LTD named as controller.",
    "cardSummary": "Accountless exchanger for 200+ coins.",
    "jurisdiction": "MH",
    "jurisdictionConfidence": "verified",
    "founderIntel": "No public founders found. Privacy policy identifies Pacific Ventures LTD, registered in the Marshall Islands, as data controller.",
    "vcIntel": "No VC or institutional funding found. Revenue appears to come from exchange fees/spread.",
    "privacyWarning": "The accountless flow does not guarantee no identity checks: the terms permit requests for identity, source-of-wealth and source-of-funds documentation, wallet scanning, location investigation, order blocking and reporting to authorities. Iran, North Korea, Russia and Belarus are expressly restricted. Support communications may be retained, and the privacy policy permits lawful and legitimate-business disclosures.",
    "tagline": "Accountless Monero-capable crypto swaps with onion mirror and Marshall Islands controller.",
    "bestFor": [
      "Anonymous crypto-to-crypto swaps",
      "XMR swaps with onion mirror access",
      "Users avoiding exchange account registration"
    ],
    "kycNote": "Terms say the platform enables anonymous digital-currency exchange and the user identity remains anonymous. Privacy policy says users are not required to provide personal data unless voluntarily contacting the service.",
    "followTheMoney": "  xChange.me - Marshall Islands\n  ──────────────────────────────────────\n  Operator/controller: Pacific Ventures LTD\n  Funding: no VC found\n  Revenue: exchange fees/spread\n  ├─ Accountless exchange flow\n  ├─ Onion mirror disclosed\n  └─ AML/CFT/prohibited-use terms: caution tier",
    "reviewSource": "expansion_batch_2026-06-24_official_terms_privacy",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://xchange.me/terms-of-service",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Pacific Ventures LTD",
        "citation": "https://xchange.me/terms-of-service"
      },
      "registrationNumber": {
        "value": "112820",
        "citation": "https://xchange.me/terms-of-service"
      },
      "incorporationJurisdiction": {
        "value": "Marshall Islands",
        "citation": "https://xchange.me/terms-of-service"
      },
      "registeredAddress": {
        "value": "Ajeltake Road, Ajeltake Island, MH96960, Majuro, Marshall Islands",
        "citation": "https://xchange.me/terms-of-service"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-26",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://xchange.me/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "current privacy policy unavailable"
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://xchange.me/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "current terms and operating flow unavailable"
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://xchange.me/"
          ],
          "reviewedAt": "2026-08-26",
          "note": "no reviewed official source establishes a source model"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "no-score-points-no-cap-exception"
      }
    }
  },
  {
    "id": 1103,
    "affiliate": "",
    "geo": [
      "US"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": true,
    "countries": [
      "US"
    ],
    "updatedAt": "2026-08-25",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "auditedBy": [],
    "twitter": "https://twitter.com/privacyhq",
    "telegram": null,
    "stateActorFlag": "US jurisdiction and regulated bank/card rails. Privacy developer docs cite BSA, OFAC, FinCEN rules, USA PATRIOT Act obligations, and mandatory Customer Identification Program checks.",
    "slug": "privacy-com",
    "domain": "privacy.com",
    "name": "Privacy.com",
    "type": "Bank-linked Virtual Cards",
    "cat": "cards",
    "kyc": "full",
    "kycLevel": 4,
    "fees": {
      "transaction": 0
    },
    "fee": "Free domestic personal plan; paid plans from $5/mo; Personal foreign transactions incur fees",
    "limits": {
      "daily": null
    },
    "features": [
      "Virtual cards",
      "Single-use cards",
      "Merchant-locked cards",
      "Category-locked cards",
      "Spend limits",
      "Pause and close cards",
      "Transaction listing",
      "Developer API",
      "CLI",
      "MCP server",
      "ACH funding"
    ],
    "networks": [
      "VISA",
      "MASTERCARD",
      "ACH",
      "API",
      "MCP"
    ],
    "badge": "KYC CONTROL",
    "url": "https://www.privacy.com/",
    "categories": [
      "Virtual/Physical Card",
      "Developer Tools",
      "Private Payments",
      "Agent Money"
    ],
    "description": "US bank-linked virtual cards with merchant locks and spend limits, requiring KYC and a US checking account.",
    "cardSummary": "US virtual cards locked to a single merchant.",
    "jurisdiction": "US",
    "jurisdictionConfidence": "verified",
    "founderIntel": "Public materials identify Privacy.com as the consumer virtual-card product; card issuance is through Patriot Bank, N.A. Official developer docs require successful Customer Identification Program verification before transacting.",
    "vcIntel": "Revenue comes from merchant interchange and paid plans; public homepage says Privacy does not sell customer data. Funding history was not re-audited in this pass.",
    "privacyWarning": "Strong spend-control surface, weak identity privacy. Privacy.com, its issuing bank, linked bank account, merchants, API/MCP usage, and transaction logs remain in the payment data path. Use for card-number isolation and hard caps, not for no-KYC financial privacy.",
    "tagline": "KYC bank-linked virtual cards with spend limits and API/MCP controls for AI agents.",
    "bestFor": [
      "Capping AI-agent spend",
      "Merchant-locked subscriptions",
      "Reducing merchant card-number exposure"
    ],
    "kycNote": "Official FAQ says personal information is required for mandatory KYC before using virtual cards. Developer docs say all end users must pass Customer Identification Program checks before they can transact.",
    "agentMoney": {
      "compatible": true,
      "controlSurfaces": [
        "api",
        "cli",
        "mcp",
        "dashboard"
      ],
      "protocols": [
        "virtual-card",
        "mcp",
        "merchant-api"
      ],
      "authorizationModel": [
        "api-key",
        "merchant-lock",
        "category-lock",
        "session-budget"
      ],
      "settlementRail": [
        "bank",
        "card"
      ],
      "autonomyLevel": 3,
      "custodyModel": "issuer-custody",
      "spendLimits": true,
      "merchantLock": true,
      "categoryLock": true,
      "pauseClose": true,
      "transactionWebhooks": true,
      "fundingSource": "bank-linked",
      "identitySurface": "full-kyc",
      "dataPath": [
        "AI agent",
        "Privacy API/CLI/MCP",
        "Privacy.com",
        "Patriot Bank issuer",
        "linked US bank account",
        "card network",
        "merchant"
      ],
      "notes": "Useful for bounding autonomous spend and isolating merchant card numbers, but not anonymous: KYC, US banking, issuer logs, API/MCP activity, and transaction metadata remain linkable.",
      "protocolPrivacyNotes": "This is the clearest agent-spend control rail in the set, but it is also the clearest identity-bearing rail: legal identity, linked bank funding, issuer records, card-network records, API/MCP logs, and merchant data all remain in scope.",
      "mandateLoggingRisk": "high",
      "revocationQuality": "strong",
      "sourceLinks": [
        {
          "label": "Privacy.com homepage",
          "href": "https://www.privacy.com/",
          "scope": "provider"
        },
        {
          "label": "Privacy agent controls",
          "href": "https://agents.privacy.com/",
          "scope": "controls"
        },
        {
          "label": "Privacy MCP announcement",
          "href": "https://www.privacy.com/blog/privacy-mcp-connect-ai-assistant-privacy-account",
          "scope": "protocol"
        }
      ]
    },
    "followTheMoney": "  Privacy.com - United States\n  ──────────────────────────────────────\n  Product: bank-linked virtual cards\n  Issuer: Patriot Bank, N.A.\n  Revenue: interchange + paid plans\n  Rails: ACH, Visa/Mastercard, API/CLI/MCP\n  ├─ Strong spend caps and card isolation\n  ├─ Mandatory KYC/CIP before transacting\n  └─ Use as control tooling, not anonymity",
    "reviewSource": "primary_source_rereview_2026-08-25",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://www.privacy.com/terms",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Lithic, Inc. (d/b/a Privacy.com)",
        "citation": "https://www.privacy.com/terms"
      },
      "incorporationJurisdiction": {
        "value": "Delaware",
        "citation": "https://search.sunbiz.org/Inquiry/CorporationSearch/SearchResultDetail?inquirytype=EntityName&directionType=CurrentList&searchNameOrder=LITHIC%20F250000069030&aggregateId=forp-f25000006903-0dc0c9d4-f3fc-4b19-b262-1cedef495edc"
      },
      "registeredAddress": {
        "value": "228 Park Ave S, PMB 57488, New York, NY 10003-1502, United States",
        "citation": "https://www.privacy.com/terms"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.privacy.com/",
            "https://www.privacy.com/terms",
            "https://www.privacy.com/privacy-policy",
            "https://www.privacy.com/pricing",
            "https://www.privacy.com/security",
            "https://status.privacy.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.privacy.com/",
            "https://www.privacy.com/terms",
            "https://www.privacy.com/privacy-policy",
            "https://www.privacy.com/pricing",
            "https://www.privacy.com/security",
            "https://status.privacy.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.privacy.com/",
            "https://www.privacy.com/terms",
            "https://www.privacy.com/privacy-policy",
            "https://www.privacy.com/pricing",
            "https://www.privacy.com/security",
            "https://status.privacy.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1104,
    "slug": "unbroker",
    "domain": "github.com",
    "name": "unbroker",
    "type": "Agent Privacy Tool",
    "cat": "privacy-tools",
    "kyc": "none",
    "kycLevel": 0,
    "fee": "Free",
    "limits": {
      "daily": null
    },
    "features": [
      "Open source",
      "Hermes skill",
      "Data broker opt-outs",
      "Consent gate",
      "Local ledger",
      "Least-disclosure planning",
      "Email verification polling",
      "Recurring re-scan queue",
      "California DROP workflow",
      "BADBOOL broker list ingestion"
    ],
    "networks": [
      "CLI",
      "Browser",
      "Email",
      "Cron"
    ],
    "badge": "AGENT PRIVACY",
    "url": "https://github.com/NousResearch/hermes-agent/tree/main/optional-skills/security/unbroker",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-26",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Privacy Tools",
      "Developer Tools",
      "Frameworks"
    ],
    "description": "Open-source Hermes Agent skill for consent-gated data broker removal, run through a local CLI and ledger.",
    "cardSummary": "Open-source tool for data broker removal.",
    "jurisdiction": null,
    "jurisdictionConfidence": "unknown",
    "auditedBy": [],
    "twitter": null,
    "telegram": null,
    "founderIntel": "The unbroker skill is distributed in the NousResearch/hermes-agent repository and lists SHL0MS as author in SKILL.md. The skill is an optional Hermes security skill, not a standalone broker-removal company.",
    "vcIntel": "Code is MIT-licensed. The broker dataset is adapted from Yael Grauer's Big-Ass Data Broker Opt-Out List under CC BY-NC-SA 4.0, so attribution and non-commercial license constraints matter for reuse.",
    "privacyWarning": "The person must consent before a scan. The workflow keeps local records and limits fields sent to broker forms. A later re-scan verifies removal; a broker confirmation does not.",
    "stateActorFlag": null,
    "tagline": "Open-source agent workflow for data-broker opt-outs, consent, ledgering, and re-scans.",
    "bestFor": [
      "Self-hosted data broker removal",
      "Doxxing cleanup with consent",
      "Recurring broker re-scan workflows"
    ],
    "kycNote": "No KYC account is required for the open-source skill itself. Broker opt-out forms may still request identifying fields to match and remove records.",
    "updatedAt": "2026-07-05",
    "lastReviewed": "2026-08-26",
    "kycLastChecked": "2026-08-26",
    "reviewSource": "Primary-source review 2026-08-26",
    "agentPrivacy": {
      "compatible": true,
      "useCase": "data-broker-removal",
      "controlSurfaces": [
        "cli",
        "browser",
        "email",
        "cron",
        "manual-digest"
      ],
      "automationModel": [
        "consent-gated",
        "deterministic-queue",
        "human-fallback",
        "recurring-recheck",
        "least-disclosure",
        "local-ledger"
      ],
      "autonomyLevel": 3,
      "consentRequired": true,
      "piiResidency": "local-by-default",
      "disclosureMode": "least-disclosure",
      "verificationModel": "rescan-before-confirmed",
      "humanFallbacks": [
        "hard-captcha",
        "government-id",
        "phone-call",
        "fax"
      ],
      "recheckCadence": "scheduled re-scan queue",
      "dataPath": [
        "consenting subject intake",
        "local unbroker record and ledger",
        "agent browser or web extraction pass",
        "broker opt-out form or rights email",
        "email verification link",
        "scheduled removal re-scan"
      ],
      "notes": "A local workflow with a deterministic queue, ledger, human fallback digest, and recurring re-checks.",
      "privacyNotes": "The privacy gain is control and auditability. The risk is PII handling: names, addresses, phone numbers, aliases, and emails are still processed locally and disclosed to broker-controlled removal channels when needed."
    },
    "followTheMoney": "  unbroker - Hermes Agent skill\n  --------------------------------------\n  Repo: NousResearch/hermes-agent\n  Author: SHL0MS\n  License: MIT code\n  Dataset: BADBOOL, CC BY-NC-SA\n  Cost: free, self-hosted\n  |- Records stay with the operator\n  |- PII still touches broker opt-out flows\n  `- Disclosure and re-scans are controls",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "project-no-legal-entity",
        "citation": "https://github.com/NousResearch/hermes-agent/tree/main/optional-skills/security/unbroker",
        "note": "unbroker is an open-source MIT-licensed optional skill inside the hermes-agent repository; it is self-hosted software run by the user's own agent, not a company-operated hosted service or separate legal entity."
      },
      "governanceModel": {
        "value": "company-sponsored",
        "citation": "https://github.com/NousResearch/hermes-agent"
      },
      "repositoryUrl": {
        "value": "https://github.com/NousResearch/hermes-agent/tree/main/optional-skills/security/unbroker",
        "citation": "https://github.com/NousResearch/hermes-agent/tree/main/optional-skills/security/unbroker"
      },
      "parentEntity": {
        "value": "Nous Research, Inc.",
        "citation": "https://portal.nousresearch.com/terms"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "none",
      "controlModel": "local-self-custody",
      "sourceModel": "open"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-26",
      "inputs": {
        "operatorDataExposure": {
          "value": "none",
          "sourceUrls": [
            "https://raw.githubusercontent.com/NousResearch/hermes-agent/main/optional-skills/security/unbroker/SKILL.md"
          ],
          "reviewedAt": "2026-08-26",
          "note": "official documentation states data and ledger handling are local to the self-hosted tool"
        },
        "controlModel": {
          "value": "local-self-custody",
          "sourceUrls": [
            "https://github.com/NousResearch/hermes-agent/tree/main/optional-skills/security/unbroker"
          ],
          "reviewedAt": "2026-08-26",
          "note": "official documentation calls it self-hosted and user-agent run"
        },
        "sourceModel": {
          "value": "open",
          "sourceUrls": [
            "https://github.com/NousResearch/hermes-agent/tree/main/optional-skills/security/unbroker"
          ],
          "reviewedAt": "2026-08-26",
          "note": "official public source repository"
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "no-score-points-no-cap-exception"
      }
    }
  },
  {
    "id": 1105,
    "slug": "proton-pass",
    "domain": "proton.me",
    "name": "Proton Pass",
    "type": "Password Manager",
    "cat": "privacy-tools",
    "kyc": "none",
    "kycLevel": 0,
    "fee": "Free plan; Pass Plus advertised from $1.99/month; paid pricing varies by billing cycle and plan",
    "features": [
      "End-to-end encrypted vaults",
      "Encrypted metadata",
      "Open-source apps",
      "Independent Cure53 audit",
      "Passkeys",
      "Hide-my-email aliases",
      "Secure vault and item sharing",
      "Dark web monitoring",
      "Emergency access",
      "Command line interface"
    ],
    "networks": [
      "Web",
      "Browser extensions",
      "Windows",
      "macOS",
      "Linux",
      "Android",
      "iOS",
      "CLI"
    ],
    "badge": "AUDITED",
    "url": "https://proton.me/pass",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": true,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Privacy Tools"
    ],
    "description": "End-to-end encrypted password and identity manager from Proton AG with encrypted vault fields and metadata, open-source clients, passkeys, sharing and hide-my-email aliases.",
    "cardSummary": "Audited open-source password manager with encrypted vaults.",
    "jurisdiction": "CH",
    "jurisdictionConfidence": "verified",
    "auditedBy": [
      "Cure53"
    ],
    "privacyWarning": "A Proton account still creates account and activity metadata. Hide-my-email alias addresses are not encrypted, and paid subscriptions add payment records. Vault content and vault metadata are end-to-end encrypted.",
    "bestFor": [
      "Password and passkey storage",
      "Email aliases",
      "Cross-device password management"
    ],
    "kycNote": "The free plan needs a Proton account but no document identity check. Paid plans can add card, PayPal, Apple Pay, Google Pay, Bitcoin, cash, or bank-payment records depending on the checkout path.",
    "updatedAt": "2026-08-05",
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-05",
    "reviewSource": "official_proton_pass_security_privacy_payment_audit_2026-08-05",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://proton.me/legal/terms",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Proton AG",
        "citation": "https://proton.me/legal/terms"
      },
      "registrationNumber": {
        "value": "CHE-354.686.492",
        "citation": "https://auditorstats.ch/firms/CHE-354.686.492"
      },
      "registryUrl": {
        "value": "https://www.zefix.ch/",
        "citation": "https://auditorstats.ch/firms/CHE-354.686.492"
      },
      "incorporationJurisdiction": {
        "value": "Switzerland",
        "citation": "https://proton.me/legal/terms"
      },
      "incorporationDate": {
        "value": "18.07.2014",
        "citation": "https://auditorstats.ch/firms/CHE-354.686.492"
      },
      "registeredAddress": {
        "value": "Route de la Galaise 32, 1228 Plan-les-Ouates, Geneva, Switzerland",
        "citation": "https://proton.me/legal/terms"
      },
      "ultimateOwner": {
        "value": "Proton Foundation",
        "citation": "https://proton.me/legal/terms"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [
          "Proton Technologies AG"
        ],
        "citation": "https://en.wikipedia.org/wiki/Proton_AG"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://proton.me/pass",
            "https://proton.me/legal/terms",
            "https://proton.me/pass/privacy-policy",
            "https://proton.me/legal/privacy",
            "https://proton.me/pass/security",
            "https://proton.me/blog/pass-open-source-security-audit",
            "https://status.proton.me/",
            "https://github.com/protonpass/android-pass"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://proton.me/pass",
            "https://proton.me/legal/terms",
            "https://proton.me/pass/privacy-policy",
            "https://proton.me/legal/privacy",
            "https://proton.me/pass/security",
            "https://proton.me/blog/pass-open-source-security-audit",
            "https://status.proton.me/",
            "https://github.com/protonpass/android-pass"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://proton.me/pass",
            "https://proton.me/legal/terms",
            "https://proton.me/pass/privacy-policy",
            "https://proton.me/legal/privacy",
            "https://proton.me/pass/security",
            "https://proton.me/blog/pass-open-source-security-audit",
            "https://status.proton.me/",
            "https://github.com/protonpass/android-pass"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1106,
    "slug": "trezor",
    "domain": "trezor.io",
    "name": "Trezor",
    "type": "Wallet",
    "cat": "wallet",
    "kyc": "none",
    "kycLevel": 2,
    "fees": {
      "transaction": 0
    },
    "fee": "From EUR 47 (one-time hardware)",
    "limits": {
      "daily": null
    },
    "features": [
      "Multi-coin hardware signer",
      "Bitcoin-only firmware option",
      "Open source firmware",
      "Secure Element on Safe models",
      "PIN and passphrase",
      "On-device confirmation",
      "Coin control in Trezor Suite",
      "Tor support in Trezor Suite",
      "Bitcoin and crypto checkout"
    ],
    "networks": [
      "BTC",
      "ETH",
      "LTC"
    ],
    "badge": "HARDWARE",
    "url": "https://trezor.io/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-23",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Wallet"
    ],
    "description": "Czech hardware wallet vendor. The shop accepts Bitcoin, Litecoin, and Ethereum alongside cards and PayPal, and ships worldwide.",
    "cardSummary": "Multi-coin hardware signer, crypto checkout.",
    "jurisdiction": "CZ",
    "auditedBy": [],
    "twitter": "https://x.com/Trezor",
    "tagline": "Multi-coin hardware signer with an open source firmware and crypto checkout.",
    "bestFor": [
      "Cold storage",
      "Multi-coin self-custody",
      "Buying hardware without an account"
    ],
    "kycNote": "No document identity check is required to buy a device. The shop states it supports Google Pay, Apple Pay, debit and credit card, Bitcoin, and selected cryptocurrencies. Paying with Bitcoin removes the card trail but a delivery address is still recorded, and the shop ships to over 200 countries and territories.",
    "updatedAt": "2026-08-23",
    "privacyWarning": "Hardware-wallet keys remain self-custodied, but Trezor's 2024 third-party support portal incident exposed email/name and limited support data for 66,000 users; 41 received recovery-seed phishing contacts. Treat support/shipping messages as phishing-sensitive and never enter a recovery seed outside the device flow.",
    "stateActorFlag": null,
    "lastReviewed": "2026-08-23",
    "kycLastChecked": "2026-08-07",
    "reviewSource": "official_trezor_support_and_newsletter_incidents_2026-08-23",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://data.trezor.io/legal/privacy-policy.html",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Trezor Company s.r.o.",
        "citation": "https://data.trezor.io/legal/privacy-policy.html"
      },
      "registrationNumber": {
        "value": "02440032",
        "citation": "https://data.trezor.io/legal/privacy-policy.html"
      },
      "registryUrl": {
        "value": "https://or.justice.cz/ias/ui/rejstrik (file C 219483, Městský soud v Praze)",
        "citation": "https://www.podnikatel.cz/rejstrik/trezor-company-s-r-o-02440032/"
      },
      "incorporationJurisdiction": {
        "value": "Czech Republic",
        "citation": "https://data.trezor.io/legal/privacy-policy.html"
      },
      "incorporationDate": {
        "value": "2013-12-12",
        "citation": "https://www.lei-lookup.com/record/3157009C7CTD3LVQLV28/"
      },
      "registeredAddress": {
        "value": "Kundratka 2359/17a, Libeň, 180 00 Prague 8, Czech Republic",
        "citation": "https://data.trezor.io/legal/privacy-policy.html"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://trezor.io/",
            "https://data.trezor.io/legal/privacy-policy.html",
            "https://trezor.io/terms-of-use",
            "https://api.github.com/repos/trezor/trezor-suite/releases/latest",
            "https://medium.com/@trezor/security-incident-update-january-2024-66c1bdd37d2e",
            "https://web.archive.org/web/20240123150319/https://blog.trezor.io/security-incident-update-january-2024-66c1bdd37d2e"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://trezor.io/",
            "https://data.trezor.io/legal/privacy-policy.html",
            "https://trezor.io/terms-of-use",
            "https://api.github.com/repos/trezor/trezor-suite/releases/latest",
            "https://medium.com/@trezor/security-incident-update-january-2024-66c1bdd37d2e",
            "https://web.archive.org/web/20240123150319/https://blog.trezor.io/security-incident-update-january-2024-66c1bdd37d2e"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://trezor.io/",
            "https://data.trezor.io/legal/privacy-policy.html",
            "https://trezor.io/terms-of-use",
            "https://api.github.com/repos/trezor/trezor-suite/releases/latest",
            "https://medium.com/@trezor/security-incident-update-january-2024-66c1bdd37d2e",
            "https://web.archive.org/web/20240123150319/https://blog.trezor.io/security-incident-update-january-2024-66c1bdd37d2e"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1107,
    "slug": "bitbox02",
    "domain": "bitbox.swiss",
    "name": "BitBox02",
    "type": "Wallet",
    "cat": "wallet",
    "kyc": "none",
    "kycLevel": 2,
    "fees": {
      "transaction": 0
    },
    "fee": "One-time hardware purchase",
    "limits": {
      "daily": null
    },
    "features": [
      "Bitcoin-only edition",
      "Multi-coin edition",
      "Open source firmware",
      "Swiss operator",
      "On-chain Bitcoin checkout",
      "Lightning checkout",
      "microSD backup",
      "BitBoxApp companion"
    ],
    "networks": [
      "BTC",
      "LN"
    ],
    "badge": "HARDWARE",
    "url": "https://bitbox.swiss/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-07",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Wallet"
    ],
    "description": "Swiss hardware wallet from Shift Crypto. The shop takes on-chain Bitcoin and Lightning through BTCPay, plus cards via Stripe.",
    "cardSummary": "Swiss hardware signer taking BTC and Lightning.",
    "jurisdiction": "CH",
    "auditedBy": [],
    "twitter": "https://x.com/BitBoxSwiss",
    "tagline": "Swiss hardware signer with Bitcoin-only firmware and Lightning checkout.",
    "bestFor": [
      "Cold storage",
      "Bitcoin-only self-custody",
      "Paying for hardware in Bitcoin"
    ],
    "kycNote": "No document identity check is required to buy a device. The payment policy lists two processors: BTCPay for on-chain Bitcoin and Lightning, and Stripe for cards, bank transfers, PayPal, Apple Pay, and Google Pay. Available methods vary by country, so the checkout page decides which rails apply.",
    "updatedAt": "2026-08-07",
    "privacyWarning": "BitBox02 is a physical product. Shift Crypto AG holds order and shipping data even when payment settles in Bitcoin or over Lightning. Orders ship from Swiss and German warehouses, and duties and taxes are prepaid on some routes, which adds a customs record.",
    "stateActorFlag": null,
    "lastReviewed": "2026-08-07",
    "kycLastChecked": "2026-08-07",
    "reviewSource": "official_bitbox_payment_shipping_policy_intake_2026-08-07",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://bitbox.swiss/imprint/",
        "note": "Official imprint, terms of service, and privacy policy state that BitBox is created and the website operated by Shift Crypto AG, a Swiss Aktiengesellschaft selling hardware wallets."
      },
      "governanceModel": {
        "value": "company-sponsored",
        "citation": "https://bitbox.swiss/dev/"
      },
      "repositoryUrl": {
        "value": "https://github.com/BitBoxSwiss",
        "citation": "https://github.com/BitBoxSwiss"
      },
      "legalEntity": {
        "value": "Shift Crypto AG",
        "citation": "https://bitbox.swiss/imprint/"
      },
      "registrationNumber": {
        "value": "CHE-498.818.196 (commercial register CH-020.3.048.536-0; imprint also lists CH-498.818.196)",
        "citation": "https://www.uid.admin.ch/Detail.aspx?uid_id=CHE-498.818.196"
      },
      "registryUrl": {
        "value": "https://www.uid.admin.ch/Detail.aspx?uid_id=CHE-498.818.196",
        "citation": "https://www.uid.admin.ch/Detail.aspx?uid_id=CHE-498.818.196"
      },
      "incorporationJurisdiction": {
        "value": "Switzerland (Canton of Zurich)",
        "citation": "https://bitbox.swiss/imprint/"
      },
      "incorporationDate": {
        "value": "2020-04-01",
        "citation": "https://www.moneyhouse.ch/en/company/shift-crypto-ag-2790108461"
      },
      "registeredAddress": {
        "value": "Soodmattenstrasse 4, 8134 Adliswil, Switzerland",
        "citation": "https://bitbox.swiss/imprint/"
      },
      "officers": {
        "value": [
          "Douglas Bakkum (Member of the Board, CEO)"
        ],
        "citation": "https://bitbox.swiss/imprint/"
      },
      "priorEntities": {
        "value": [
          "Shift Cryptosecurity AG in Liquidation (formerly Shift Devices AG), UID CHE-149.201.586, commercial register CH-280.3.019.469-1; trademarks/domains/assets transferred into Shift Crypto AG on foundation"
        ],
        "citation": "https://www.uid.admin.ch/Detail.aspx?uid_id=CHE-149.201.586"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://bitbox.swiss/",
            "https://bitbox.swiss/policies/payment-policy/",
            "https://bitbox.swiss/policies/privacy-policy",
            "https://bitbox.swiss/policies/privacy-policy/",
            "https://bitbox.swiss/imprint",
            "https://bitbox.swiss/imprint/",
            "https://github.com/BitBoxSwiss/bitbox02-firmware/releases"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://bitbox.swiss/",
            "https://bitbox.swiss/policies/payment-policy/",
            "https://bitbox.swiss/policies/privacy-policy",
            "https://bitbox.swiss/policies/privacy-policy/",
            "https://bitbox.swiss/imprint",
            "https://bitbox.swiss/imprint/",
            "https://github.com/BitBoxSwiss/bitbox02-firmware/releases"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://bitbox.swiss/",
            "https://bitbox.swiss/policies/payment-policy/",
            "https://bitbox.swiss/policies/privacy-policy",
            "https://bitbox.swiss/policies/privacy-policy/",
            "https://bitbox.swiss/imprint",
            "https://bitbox.swiss/imprint/",
            "https://github.com/BitBoxSwiss/bitbox02-firmware/releases"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1108,
    "slug": "startmail",
    "domain": "startmail.com",
    "name": "StartMail",
    "type": "Email",
    "cat": "email",
    "kyc": "none",
    "kycLevel": 1,
    "fees": {
      "transaction": 0
    },
    "fee": "$4.99/mo Personal, $6.99/mo Business (billed annually)",
    "limits": {
      "daily": null
    },
    "features": [
      "Unlimited email aliases",
      "PGP encryption",
      "Custom domain support",
      "20GB storage on Personal",
      "30GB storage on Business",
      "Netherlands servers",
      "No ads and no tracking",
      "Instant email deletion",
      "Bitcoin on annual plans"
    ],
    "networks": [
      "BTC"
    ],
    "badge": "EMAIL",
    "url": "https://www.startmail.com/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-07",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Email"
    ],
    "description": "Dutch encrypted mail with unlimited aliases and PGP. Bitcoin is accepted on annual plans by contacting support before renewal.",
    "cardSummary": "Dutch encrypted mail, Bitcoin on annual plans.",
    "jurisdiction": "NL",
    "auditedBy": [],
    "twitter": "https://x.com/mystartmail",
    "tagline": "Dutch encrypted email with unlimited aliases and Bitcoin on annual billing.",
    "bestFor": [
      "Encrypted email with custom domains",
      "Unlimited aliases",
      "Paying for mail in Bitcoin"
    ],
    "kycNote": "No document identity check. The pricing page states Bitcoin payment is possible on annual plans only, and that you must contact StartMail to receive the Bitcoin price and payment address. That contact step is a manual exchange, so it is not an anonymous self-serve checkout.",
    "updatedAt": "2026-08-07",
    "privacyWarning": "Bitcoin is limited to annual plans and requires contacting support to obtain an address, so a support thread ties the payment to the account. StartMail states offices and servers are in the Netherlands under GDPR, which means Dutch legal process still applies to stored account data.",
    "stateActorFlag": null,
    "lastReviewed": "2026-08-07",
    "kycLastChecked": "2026-08-07",
    "reviewSource": "official_startmail_pricing_intake_2026-08-07",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://www.startmail.com/terms-of-service/",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "StartMail B.V.",
        "citation": "https://www.startmail.com/terms-of-service/"
      },
      "registrationNumber": {
        "value": "67176925",
        "citation": "https://www.startmail.com/terms-of-service/"
      },
      "registryUrl": {
        "value": "https://www.kvk.nl/",
        "citation": "https://www.startmail.com/terms-of-service/"
      },
      "incorporationJurisdiction": {
        "value": "Netherlands",
        "citation": "https://www.startmail.com/terms-of-service/"
      },
      "registeredAddress": {
        "value": "Boulevard 11, 3707 BK Zeist, The Netherlands",
        "citation": "https://www.startmail.com/terms-of-service/"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.startmail.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.startmail.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.startmail.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1109,
    "slug": "standard-notes",
    "domain": "standardnotes.com",
    "name": "Standard Notes",
    "type": "Encrypted Notes",
    "cat": "privacy-tools",
    "kyc": "none",
    "kycLevel": 1,
    "fees": {
      "transaction": 0
    },
    "fee": "Free tier, $90/yr Productivity, $120/yr Professional",
    "limits": {
      "daily": null
    },
    "features": [
      "End-to-end encrypted notes",
      "XChaCha20-Poly1305 encryption",
      "Unlimited device sync",
      "Offline access",
      "Open source clients",
      "Two-factor authentication",
      "Full encrypted export",
      "Self-hostable sync server",
      "100GB encrypted files on Professional"
    ],
    "networks": [],
    "badge": "OPEN SOURCE",
    "url": "https://standardnotes.com/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Privacy Tools"
    ],
    "description": "Proton-owned end-to-end encrypted notes and productivity suite operated by Standard Notes Ltd in the United States.",
    "cardSummary": "U.S.-operated, end-to-end encrypted notes owned by Proton.",
    "jurisdiction": "US",
    "ownership": "Proton AG (Geneva, Switzerland), announced 10 April 2024",
    "auditedBy": [],
    "twitter": "https://x.com/StandardNotes",
    "tagline": "End-to-end encrypted notes with open source clients and a self-hostable server.",
    "bestFor": [
      "Encrypted note taking",
      "Self-hosted sync",
      "Long-term plain text notes"
    ],
    "kycNote": "No document identity check. The plans page states the accepted payment methods are all major debit and credit cards, Apple Pay, Google Pay, and PayPal. There is no cryptocurrency option, so a paid subscription always carries a card or PayPal identity trail. The free tier avoids payment data entirely.",
    "updatedAt": "2026-08-25",
    "privacyWarning": "Note content is end-to-end encrypted, but Standard Notes Ltd is the U.S. service operator and contracting entity under U.S. law. Account, billing, support, IP/device, and third-party payment metadata remain outside note-content encryption; Proton ownership does not make the service operator Swiss.",
    "stateActorFlag": null,
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "https://standardnotes.com/legal/terms",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://standardnotes.com/legal/dpa",
        "note": "Registry-sourced corporate record established in pass 1 via legalEntity."
      },
      "legalEntity": {
        "value": "Standard Notes Ltd.",
        "citation": "https://standardnotes.com/legal/dpa"
      },
      "registrationNumber": {
        "value": "82-3619093",
        "citation": "https://standardnotes.com/legal/dpa"
      },
      "registeredAddress": {
        "value": "350 N Orleans St, Ste 9000N, Chicago, Illinois 60654, USA",
        "citation": "https://standardnotes.com/legal/dpa"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://standardnotes.com/legal/terms",
            "https://standardnotes.com/legal/privacy",
            "https://standardnotes.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://standardnotes.com/legal/terms",
            "https://standardnotes.com/legal/privacy",
            "https://standardnotes.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://standardnotes.com/legal/terms",
            "https://standardnotes.com/legal/privacy",
            "https://standardnotes.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1110,
    "slug": "ente",
    "domain": "ente.com",
    "name": "Ente",
    "type": "Cloud Storage",
    "cat": "cloud",
    "kyc": "none",
    "kycLevel": 1,
    "fees": {
      "transaction": 0
    },
    "fee": "10GB free, $2.49/mo 50GB, $4.99/mo 200GB, $9.99/mo 1TB",
    "limits": {
      "daily": null
    },
    "features": [
      "End-to-end encrypted photo backup",
      "Open source clients and server",
      "Self-hostable",
      "Stored in 3 locations",
      "On-device face recognition",
      "Family plan sharing",
      "Public links",
      "Independently audited",
      "10GB free tier"
    ],
    "networks": [],
    "badge": "E2EE",
    "url": "https://ente.com/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Cloud Storage"
    ],
    "description": "End-to-end encrypted photo storage with a 10GB free tier. Paid plans run through Stripe or PayPal, with no crypto option.",
    "cardSummary": "E2EE photo storage, self-hostable, card only.",
    "jurisdiction": "US",
    "ownership": "Ente Technologies, Inc.",
    "auditedBy": [
      "Symbolic Software"
    ],
    "twitter": "https://x.com/enteio",
    "tagline": "End-to-end encrypted photo storage with a free tier and a self-hostable server.",
    "bestFor": [
      "Encrypted photo backup",
      "Self-hosted storage",
      "Leaving Google Photos"
    ],
    "kycNote": "No document identity check. The help centre lists payment methods as credit cards via Stripe and PayPal, with card details held by Stripe rather than Ente. There is no cryptocurrency rail, so any paid plan carries a card or PayPal identity trail. The 10GB free tier and self-hosting avoid payment data entirely.",
    "updatedAt": "2026-08-25",
    "privacyWarning": "Paid plans cannot be bought privately: Stripe and PayPal are the only rails and both link a real identity to the account. The terms name Ente Technologies, Inc. and set Delaware governing law with venue in Santa Clara County, so US legal process reaches account metadata even though file contents are end-to-end encrypted.",
    "stateActorFlag": null,
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "primary_source_rereview_2026-08-25",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://ente.com/privacy/",
        "note": "The Privacy Policy and Terms of Service explicitly name Ente Technologies, Inc. as the operating entity providing the services."
      },
      "repositoryUrl": {
        "value": "https://github.com/ente/ente",
        "citation": "https://github.com/ente/ente"
      },
      "legalEntity": {
        "value": "Ente Technologies, Inc.",
        "citation": "https://ente.com/privacy/"
      },
      "registrationNumber": {
        "value": "6668754",
        "citation": "https://discuss.privacyguides.net/t/should-ente-auth-really-be-recommended-particularly-the-e2ee/20242"
      },
      "registryUrl": {
        "value": "https://icis.corp.delaware.gov/Ecorp/EntitySearch/NameSearch.aspx",
        "citation": "https://discuss.privacyguides.net/t/should-ente-auth-really-be-recommended-particularly-the-e2ee/20242"
      },
      "incorporationJurisdiction": {
        "value": "Delaware, United States",
        "citation": "https://ente.com/privacy/"
      },
      "registeredAddress": {
        "value": "1111B S Governors Ave #6032, Dover, DE 19904",
        "citation": "https://ente.com/privacy/"
      },
      "officers": {
        "value": [
          "Manav Rathi (Data Protection Officer)"
        ],
        "citation": "https://ente.com/privacy/"
      },
      "priorEntities": {
        "value": [
          "DRIZZLE TECHNOLOGIES PRIVATE LIMITED (CIN U72900KA2020PTC133651)",
          "ENTEIO TECHNOLOGIES PRIVATE LIMITED (CIN U72900KA2022FTC162419)"
        ],
        "citation": "https://tracxn.com/d/companies/ente/__C-WQjshq6TQzDPYVFj0rV6sIcwCHPP3LRoj9gHAT030"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://ente.com/",
            "https://ente.com/#pricing",
            "https://ente.com/privacy/",
            "https://x.com/enteio/status/2091888746496917975"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://ente.com/",
            "https://ente.com/#pricing",
            "https://ente.com/privacy/",
            "https://x.com/enteio/status/2091888746496917975"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://ente.com/",
            "https://ente.com/#pricing",
            "https://ente.com/privacy/",
            "https://x.com/enteio/status/2091888746496917975"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1111,
    "slug": "cryptomator",
    "domain": "cryptomator.org",
    "name": "Cryptomator",
    "type": "Encryption Tool",
    "cat": "privacy-tools",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Free on desktop, EUR 29.99 one-time per mobile platform",
    "limits": {
      "daily": null
    },
    "features": [
      "Client-side vault encryption",
      "Works with any cloud storage",
      "Unlimited vaults",
      "Open source",
      "Independently audited",
      "Free on Windows, macOS, and Linux",
      "No account required",
      "Filename encryption",
      "Cryptomator Hub for teams"
    ],
    "networks": [],
    "badge": "OPEN SOURCE",
    "url": "https://cryptomator.org/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-25",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Privacy Tools"
    ],
    "noOperatorData": true,
    "description": "Client-side encryption for files you keep in any cloud. Free on desktop, one-time purchase on mobile, no account needed.",
    "cardSummary": "Local vault encryption for any cloud, no account.",
    "jurisdiction": "DE",
    "ownership": "Skymatic GmbH, Bonn, Germany",
    "auditedBy": [],
    "tagline": "Client-side vault encryption for any cloud storage, free on desktop.",
    "bestFor": [
      "Encrypting files before cloud upload",
      "Using untrusted cloud storage",
      "No-account local encryption"
    ],
    "kycNote": "No account and no identity check for the desktop app. Encryption runs locally, so Skymatic never receives file contents or a user account. Buying a mobile licence or Hub seat is a normal commercial purchase and does create a payment record with Skymatic and its processors.",
    "updatedAt": "2026-08-25",
    "privacyWarning": "Cryptomator protects file contents and filenames inside a vault, but it does not hide the vault itself: the cloud provider still sees vault size, file count, and modification times. Mobile apps are free only in read-only mode, and a paid licence is tied to one platform.",
    "stateActorFlag": null,
    "lastReviewed": "2026-08-25",
    "kycLastChecked": "2026-08-25",
    "reviewSource": "official_cryptomator_site_legal_pricing_repo_advisories_2026-08-25",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://cryptomator.org/impressum/",
        "note": "Official Impressum and Privacy Policy identify Skymatic GmbH as the responsible operating company for Cryptomator and related services."
      },
      "governanceModel": {
        "value": "company-sponsored",
        "citation": "https://github.com/cryptomator"
      },
      "repositoryUrl": {
        "value": "https://github.com/cryptomator/cryptomator",
        "citation": "https://github.com/cryptomator/cryptomator"
      },
      "legalEntity": {
        "value": "Skymatic GmbH",
        "citation": "https://cryptomator.org/impressum/"
      },
      "registrationNumber": {
        "value": "HRB 22635",
        "citation": "https://cryptomator.org/impressum/"
      },
      "incorporationJurisdiction": {
        "value": "Germany (Amtsgericht Bonn)",
        "citation": "https://cryptomator.org/impressum/"
      },
      "registeredAddress": {
        "value": "Am Hauptbahnhof 6, 53111 Bonn, Germany",
        "citation": "https://cryptomator.org/impressum/"
      },
      "officers": {
        "value": [
          "Tobias Hagemann (Geschäftsführer)",
          "Sebastian Stenzel (Geschäftsführer)"
        ],
        "citation": "https://cryptomator.org/impressum/"
      },
      "source": "official Cryptomator Impressum, privacy policy, terms, pricing, and repository",
      "reviewedAt": "2026-08-25"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://cryptomator.org/",
            "https://cryptomator.org/pricing/",
            "https://cryptomator.org/privacy/",
            "https://cryptomator.org/impressum/",
            "https://cryptomator.org/terms/",
            "https://docs.cryptomator.org/security/security-target/",
            "https://github.com/cryptomator/cryptomator/releases/tag/1.19.3",
            "https://github.com/cryptomator/cryptomator/security/advisories/GHSA-9q8x-whrw-x44p",
            "https://github.com/cryptomator/cryptomator/security/advisories/GHSA-34rf-rwr3-7g43"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://cryptomator.org/",
            "https://cryptomator.org/pricing/",
            "https://cryptomator.org/privacy/",
            "https://cryptomator.org/impressum/",
            "https://cryptomator.org/terms/",
            "https://docs.cryptomator.org/security/security-target/",
            "https://github.com/cryptomator/cryptomator/releases/tag/1.19.3",
            "https://github.com/cryptomator/cryptomator/security/advisories/GHSA-9q8x-whrw-x44p",
            "https://github.com/cryptomator/cryptomator/security/advisories/GHSA-34rf-rwr3-7g43"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://cryptomator.org/",
            "https://cryptomator.org/pricing/",
            "https://cryptomator.org/privacy/",
            "https://cryptomator.org/impressum/",
            "https://cryptomator.org/terms/",
            "https://docs.cryptomator.org/security/security-target/",
            "https://github.com/cryptomator/cryptomator/releases/tag/1.19.3",
            "https://github.com/cryptomator/cryptomator/security/advisories/GHSA-9q8x-whrw-x44p",
            "https://github.com/cryptomator/cryptomator/security/advisories/GHSA-34rf-rwr3-7g43"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1112,
    "slug": "obtainium",
    "domain": "github.com",
    "name": "Obtainium",
    "type": "App Updater",
    "cat": "privacy-tools",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Free (GPL-3.0)",
    "limits": {
      "daily": null
    },
    "features": [
      "Installs Android apps from source releases",
      "Update notifications",
      "GitHub and GitLab sources",
      "Forgejo and Codeberg sources",
      "F-Droid and third-party repos",
      "IzzyOnDroid support",
      "HTML fallback source",
      "No account required",
      "GPL-3.0 licensed"
    ],
    "networks": [],
    "badge": "OPEN SOURCE",
    "url": "https://github.com/ImranR98/Obtainium",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-07",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Privacy Tools"
    ],
    "noOperatorData": true,
    "description": "Android app that installs and updates apps straight from their own release pages, so you can skip Google Play entirely.",
    "cardSummary": "Android updates straight from source releases.",
    "jurisdiction": "??",
    "auditedBy": [],
    "tagline": "Install and update Android apps directly from their release pages.",
    "bestFor": [
      "Avoiding Google Play",
      "Tracking upstream releases",
      "Sideloading with update notifications"
    ],
    "kycNote": "No account and no identity check. Obtainium is a local Android client that fetches release artifacts from sources you configure, so there is no Obtainium account and no central store tied to your identity.",
    "updatedAt": "2026-08-07",
    "privacyWarning": "Obtainium removes the Google Play account link, but it does not anonymise downloads: each configured source still sees your IP address when the app checks for updates. Trust moves to whoever publishes the release, and the project recommends pairing it with an app verification tool.",
    "stateActorFlag": null,
    "lastReviewed": "2026-08-07",
    "kycLastChecked": "2026-08-07",
    "reviewSource": "official_obtainium_repository_intake_2026-08-07",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "project-no-legal-entity",
        "citation": "https://github.com/ImranR98/Obtainium",
        "note": "Open-source FOSS Android app (GPL-3.0) published solely by individual developer ImranR98 / Imran Remtulla under personal GitHub account and imranr.dev domains, with no company, foundation, or legal entity referenced in the repository, website, F-Droid listing, or APK signing certificate (CN=Imran Remtulla, O=Unknown)."
      },
      "governanceModel": {
        "value": "individual",
        "citation": "https://github.com/ImranR98/Obtainium"
      },
      "repositoryUrl": {
        "value": "https://github.com/ImranR98/Obtainium",
        "citation": "https://github.com/ImranR98/Obtainium"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://github.com/ImranR98/Obtainium"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://github.com/ImranR98/Obtainium"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://github.com/ImranR98/Obtainium"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1113,
    "slug": "keepassxc",
    "domain": "keepassxc.org",
    "name": "KeePassXC",
    "type": "Password Manager",
    "cat": "privacy-tools",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Free (GPLv3)",
    "limits": {
      "daily": null
    },
    "features": [
      "Offline encrypted database",
      "No cloud and no account",
      "Windows, macOS, and Linux",
      "Browser integration",
      "Auto-type",
      "Attachments and notes",
      "ANSSI Security Visa",
      "GPLv3 licensed",
      "No ads, trackers, or subscriptions"
    ],
    "networks": [],
    "badge": "OPEN SOURCE",
    "url": "https://keepassxc.org/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-07",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Privacy Tools"
    ],
    "noOperatorData": true,
    "description": "Offline password manager keeping credentials in a local encrypted file. No account, no cloud, no subscription. GPLv3.",
    "cardSummary": "Offline password vault, no account, no cloud.",
    "jurisdiction": "??",
    "auditedBy": [],
    "tagline": "Offline encrypted password manager with no cloud and no subscription.",
    "bestFor": [
      "Offline password storage",
      "Avoiding subscription password managers",
      "Local encrypted credential vaults"
    ],
    "kycNote": "No account and no identity check. The database is a local encrypted file, so there is no signup, no subscription, and no operator holding credentials.",
    "updatedAt": "2026-08-07",
    "privacyWarning": "The app and password database remain local. The website collects anonymized IP address, user-agent, referrer, screen, and geolocation metrics through self-hosted Matomo; visitor logs are retained for 90 days and detailed reports for 12 months. GitHub update checks and user-requested favicon downloads create optional network connections. CVE-2026-4158 affected Windows releases through 2.7.11 and is patched in the current 2.7.12 release.",
    "stateActorFlag": null,
    "lastReviewed": "2026-08-07",
    "kycLastChecked": "2026-08-07",
    "reviewSource": "official_keepassxc_site_privacy_intake_2026-08-07",
    "jurisdictionConfidence": "unknown",
    "evidenceStatus": "verified",
    "riskLevel": "standard",
    "corporate": {
      "entityType": {
        "value": "unresolved",
        "citation": "unknown",
        "note": "Pass 1 researched this service but established no registry facts."
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "priorEntities": {
        "value": [],
        "citation": "unknown"
      },
      "source": "registry research 2026-08-08, task t_047dfd90",
      "reviewedAt": "2026-08-08"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://keepassxc.org/",
            "https://keepassxc.org/privacy/",
            "https://keepassxc.org/download/",
            "https://keepassxc.org/audits/",
            "https://keepassxc.org/team/#legal",
            "https://github.com/keepassxreboot/keepassxc/security/advisories/GHSA-4gr2-cr97-q9fx",
            "https://keepassxc.org/blog/2026-03-10-2.7.12-released/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://keepassxc.org/",
            "https://keepassxc.org/privacy/",
            "https://keepassxc.org/download/",
            "https://keepassxc.org/audits/",
            "https://keepassxc.org/team/#legal",
            "https://github.com/keepassxreboot/keepassxc/security/advisories/GHSA-4gr2-cr97-q9fx",
            "https://keepassxc.org/blog/2026-03-10-2.7.12-released/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://keepassxc.org/",
            "https://keepassxc.org/privacy/",
            "https://keepassxc.org/download/",
            "https://keepassxc.org/audits/",
            "https://keepassxc.org/team/#legal",
            "https://github.com/keepassxreboot/keepassxc/security/advisories/GHSA-4gr2-cr97-q9fx",
            "https://keepassxc.org/blog/2026-03-10-2.7.12-released/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1114,
    "slug": "electrum",
    "domain": "electrum.org",
    "name": "Electrum",
    "type": "Wallet",
    "cat": "wallet",
    "kyc": "none",
    "kycLevel": 0,
    "fees": {
      "transaction": 0
    },
    "fee": "Free",
    "limits": {
      "daily": null
    },
    "features": [
      "Bitcoin only",
      "No account and no signup",
      "Keys stay on the device",
      "Seed phrase recovery",
      "Reproducible builds",
      "Multisig wallets",
      "Cold storage and watch-only",
      "Hardware wallet support",
      "Tor and custom server support"
    ],
    "networks": [],
    "badge": "OPEN SOURCE",
    "url": "https://electrum.org/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "warning",
    "checkedAt": "2026-08-07",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Wallet"
    ],
    "noOperatorData": true,
    "description": "Bitcoin desktop and Android wallet running since 2011. No account, keys stay local, and releases are reproducible and signed.",
    "cardSummary": "Bitcoin wallet, no account, reproducible builds.",
    "jurisdiction": "DE",
    "ownership": "Electrum Technologies GmbH, Berlin, Germany",
    "auditedBy": [],
    "tagline": "Long-running Bitcoin wallet with no account and locally held keys.",
    "bestFor": [
      "Bitcoin self-custody",
      "Cold storage and multisig",
      "Running against your own node"
    ],
    "kycNote": "No account, no signup, and no identity check. The software is downloaded and run locally, so there is no operator holding a customer record. The site states the wallet is distributed under the MIT licence by Electrum Technologies GmbH and that it does not store user account data.",
    "updatedAt": "2026-08-07",
    "privacyWarning": "Electrum is a light client. Its own FAQ states the client subscribes its addresses to one main server, so that server can reasonably guess the addresses belong to the same entity, and all connected servers see the client IP address unless a proxy, VPN, or Tor is used. Confirmed transactions are checked with SPV, but the server is trusted for unconfirmed transactions and can lie by omission. Running your own server or connecting over Tor removes most of that exposure. The site also warns to download only from electrum.org and verify GPG signatures. Electrum 4.8.1 says it contains important security fixes whose details will be disclosed later, so the unresolved disclosure should be monitored.",
    "stateActorFlag": null,
    "followTheMoney": "Electrum\n────────────────────────\nCreated by: Thomas Voegtlin, November 2011\nPublisher: Electrum Technologies GmbH, Berlin (founded 2013)\nModel: free MIT-licensed software\nReleases: reproducible, signed by several builders",
    "publicClaims": {
      "followTheMoney": {
        "value": "Electrum\n────────────────────────\nCreated by: Thomas Voegtlin, November 2011\nPublisher: Electrum Technologies GmbH, Berlin (founded 2013)\nModel: free MIT-licensed software\nReleases: reproducible, signed by several builders",
        "reviewedAt": "2026-08-07",
        "sources": [
          {
            "label": "Electrum - About and Impressum",
            "href": "https://electrum.org/#about",
            "type": "official"
          },
          {
            "label": "Electrum source repository (MIT licence)",
            "href": "https://github.com/spesmilo/electrum",
            "type": "official"
          }
        ]
      }
    },
    "lastReviewed": "2026-08-07",
    "kycLastChecked": "2026-08-07",
    "reviewSource": "official_electrum_site_faq_repo_intake_2026-08-07",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://electrum.org/",
        "note": "Official website Impressum and Privacy Policy state that Electrum Technologies GmbH hosts the site, built and provides the Electrum Wallet app/service, and distributes the software under MIT license."
      },
      "governanceModel": {
        "value": "company-sponsored",
        "citation": "https://electrum.org/"
      },
      "repositoryUrl": {
        "value": "https://github.com/spesmilo/electrum",
        "citation": "https://github.com/spesmilo/electrum"
      },
      "legalEntity": {
        "value": "Electrum Technologies GmbH",
        "citation": "https://electrum.org/"
      },
      "registrationNumber": {
        "value": "HRB 164636 B",
        "citation": "https://www.northdata.com/Electrum%20Technologies%20GmbH,%20Berlin/Amtsgericht%20Charlottenburg%20(Berlin)%20HRB%20164636%20B"
      },
      "registryUrl": {
        "value": "https://www.northdata.com/Electrum%20Technologies%20GmbH,%20Berlin/Amtsgericht%20Charlottenburg%20(Berlin)%20HRB%20164636%20B",
        "citation": "https://www.northdata.com/Electrum%20Technologies%20GmbH,%20Berlin/Amtsgericht%20Charlottenburg%20(Berlin)%20HRB%20164636%20B"
      },
      "incorporationJurisdiction": {
        "value": "Germany",
        "citation": "https://lei.bloomberg.com/leis/view/984500AFC0FB96E0CB95"
      },
      "incorporationDate": {
        "value": "2015-02-03",
        "citation": "https://lei.bloomberg.com/leis/view/984500AFC0FB96E0CB95"
      },
      "registeredAddress": {
        "value": "Paul-Lincke-Ufer 8 D, 10999 Berlin, Germany",
        "citation": "https://electrum.org/"
      },
      "parentEntity": {
        "value": "Voegtlin Holding GmbH",
        "citation": "https://www.northdata.com/Electrum%20Technologies%20GmbH,%20Berlin/Amtsgericht%20Charlottenburg%20(Berlin)%20HRB%20164636%20B"
      },
      "officers": {
        "value": [
          "Thomas Voegtlin (Geschäftsführer)"
        ],
        "citation": "https://www.northdata.com/Electrum%20Technologies%20GmbH,%20Berlin/Amtsgericht%20Charlottenburg%20(Berlin)%20HRB%20164636%20B"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://electrum.org/",
            "https://github.com/spesmilo/electrum/blob/master/RELEASE-NOTES",
            "https://github.com/spesmilo/electrum/security/advisories/GHSA-vw94-r84p-66qf",
            "https://github.com/spesmilo/electrum",
            "https://github.com/spesmilo/electrum/security/advisories/GHSA-q7m2-785w-r585"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://electrum.org/",
            "https://github.com/spesmilo/electrum/blob/master/RELEASE-NOTES",
            "https://github.com/spesmilo/electrum/security/advisories/GHSA-vw94-r84p-66qf",
            "https://github.com/spesmilo/electrum",
            "https://github.com/spesmilo/electrum/security/advisories/GHSA-q7m2-785w-r585"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://electrum.org/",
            "https://github.com/spesmilo/electrum/blob/master/RELEASE-NOTES",
            "https://github.com/spesmilo/electrum/security/advisories/GHSA-vw94-r84p-66qf",
            "https://github.com/spesmilo/electrum",
            "https://github.com/spesmilo/electrum/security/advisories/GHSA-q7m2-785w-r585"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1115,
    "slug": "forward-email",
    "domain": "forwardemail.net",
    "name": "Forward Email",
    "type": "Email",
    "cat": "email",
    "kyc": "none",
    "kycLevel": 1,
    "fees": {
      "monthly": 3
    },
    "fee": "Free forwarding, $3/mo Enhanced Protection, $9/mo Team",
    "limits": {
      "daily": null
    },
    "features": [
      "Email forwarding on your own domain",
      "Unlimited domains and aliases",
      "Free forwarding tier",
      "Crypto checkout through Stripe",
      "Open source service code",
      "Self-hostable",
      "IMAP, POP3, CalDAV, and CardDAV",
      "Outbound SMTP on paid plans",
      "No third-party analytics"
    ],
    "networks": [
      "USDC"
    ],
    "badge": "ALIASES",
    "url": "https://forwardemail.net/",
    "affiliate": "",
    "geo": [
      "GLOBAL"
    ],
    "status": "ok",
    "checkedAt": "2026-08-07",
    "trending": false,
    "countries": [
      "GLOBAL"
    ],
    "categories": [
      "Email"
    ],
    "description": "Custom-domain email forwarding with a free tier and paid inboxes from $3/mo. Checkout accepts USDC crypto alongside cards and PayPal.",
    "cardSummary": "Domain email forwarding, crypto checkout.",
    "jurisdiction": "US",
    "ownership": "Forward Email LLC",
    "auditedBy": [],
    "twitter": "https://x.com/fwdemail",
    "tagline": "Custom-domain email forwarding with a free tier and a crypto payment option.",
    "bestFor": [
      "Email aliases on your own domain",
      "Paying for email without a card",
      "Self-hosted email"
    ],
    "kycNote": "No document identity check. The free plan is forwarding only and is configured through DNS records. Paid checkout lists crypto alongside PayPal and the major card networks, and the crypto route pays in USDC over Ethereum, Solana, or Polygon through Stripe crypto rather than a native chain payment. An account still stores the email address, domains, and aliases you provide.",
    "updatedAt": "2026-08-07",
    "privacyWarning": "Forward Email LLC is a United States company and its terms set Delaware governing law, so US legal process reaches stored account data. The privacy policy states forwarded email and its metadata are not written to disk or database, but the service does store your account email address, domains, aliases, 4xx and 5xx SMTP error logs for 7 days, and outbound SMTP records for about 30 days. Paying in USDC still runs through Stripe, so the crypto option reduces the card trail rather than removing an intermediary.",
    "stateActorFlag": null,
    "followTheMoney": "Forward Email LLC - United States\n────────────────────────\nModel: free forwarding tier plus paid plans\nRevenue: $3/mo Enhanced Protection, $9/mo Team, $250/mo Enterprise\nSoftware: open source with a self-hosted option\nPayment: cards, PayPal, and USDC crypto through Stripe",
    "publicClaims": {
      "followTheMoney": {
        "value": "Forward Email LLC - United States\n────────────────────────\nModel: free forwarding tier plus paid plans\nRevenue: $3/mo Enhanced Protection, $9/mo Team, $250/mo Enterprise\nSoftware: open source with a self-hosted option\nPayment: cards, PayPal, and USDC crypto through Stripe",
        "reviewedAt": "2026-08-07",
        "sources": [
          {
            "label": "Forward Email - features and pricing",
            "href": "https://forwardemail.net/en/private-business-email?pricing=true",
            "type": "official"
          },
          {
            "label": "Forward Email - crypto payments announcement",
            "href": "https://forwardemail.net/en/blog/docs/crypto-payments-privacy-email-service",
            "type": "official"
          },
          {
            "label": "Forward Email - privacy policy",
            "href": "https://forwardemail.net/en/privacy",
            "type": "official"
          },
          {
            "label": "Forward Email - terms and governing law",
            "href": "https://forwardemail.net/en/terms",
            "type": "official"
          }
        ]
      }
    },
    "lastReviewed": "2026-08-07",
    "kycLastChecked": "2026-08-07",
    "reviewSource": "official_forwardemail_pricing_crypto_privacy_terms_intake_2026-08-07",
    "jurisdictionConfidence": "verified",
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://forwardemail.net/en/dpa",
        "note": "Official site copyright, DPA (Governing State: Delaware), Terms, technical whitepaper, and LICENSE identify the operator as Forward Email LLC, a real hosted commercial email service."
      },
      "governanceModel": {
        "value": "company-sponsored",
        "citation": "https://forwardemail.net/en/about"
      },
      "repositoryUrl": {
        "value": "https://github.com/forwardemail/forwardemail.net",
        "citation": "https://github.com/forwardemail/forwardemail.net"
      },
      "legalEntity": {
        "value": "Forward Email LLC",
        "citation": "https://forwardemail.net/en/dpa"
      },
      "incorporationJurisdiction": {
        "value": "Delaware, United States",
        "citation": "https://forwardemail.net/en/dpa"
      },
      "ultimateOwner": {
        "value": "Nicholas Baugh",
        "citation": "https://discuss.privacyguides.net/t/forward-email-email-provider/13370/299"
      },
      "officers": {
        "value": [
          {
            "name": "Nicholas Baugh",
            "role": "Founder"
          }
        ],
        "citation": "https://forwardemail.net/technical-whitepaper.pdf"
      },
      "source": "corporate identity pass 2 (t_d7269d23), cited web research via grok web search",
      "reviewedAt": "2026-08-09"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://forwardemail.net/",
            "https://forwardemail.net/en",
            "https://forwardemail.net/en/pricing",
            "https://forwardemail.net/en/private-business-email",
            "https://forwardemail.net/en/privacy",
            "https://forwardemail.net/en/security",
            "https://forwardemail.net/en/dpa"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://forwardemail.net/",
            "https://forwardemail.net/en",
            "https://forwardemail.net/en/pricing",
            "https://forwardemail.net/en/private-business-email",
            "https://forwardemail.net/en/privacy",
            "https://forwardemail.net/en/security",
            "https://forwardemail.net/en/dpa"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://forwardemail.net/",
            "https://forwardemail.net/en",
            "https://forwardemail.net/en/pricing",
            "https://forwardemail.net/en/private-business-email",
            "https://forwardemail.net/en/privacy",
            "https://forwardemail.net/en/security",
            "https://forwardemail.net/en/dpa"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 900001,
    "slug": "unredacted",
    "domain": "unredacted.org",
    "name": "Unredacted",
    "url": "https://unredacted.org/",
    "affiliate": "",
    "kyc": "none",
    "kycLevel": 0,
    "kycNote": "The provider hub has no shared account or KYC flow. Account and recovery data differ by hosted child; XMPP and Matrix accounts have their own data fields.",
    "fee": "Free public services; FreeSocks also offers paid Membership",
    "categories": [
      "Privacy Tools",
      "Infrastructure",
      "Censorship"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Censorship-resistance resources",
      "Hosted privacy tools",
      "Public-interest infrastructure"
    ],
    "features": [
      "FreeSocks",
      "Tor relays and bridges",
      "Unredacted Door and Snowflake",
      "Signal and Telegram proxies",
      "XMPP.is",
      "Matrix",
      "CryptPad",
      "Etherpad",
      "Jitsi",
      "Excalidraw",
      "PrivateBin",
      "Cryptgeon",
      "Monero remote node",
      "Unredacted Social (instance policy capture deferred)",
      "Guides",
      "Unredacted Labs"
    ],
    "tagline": "A US nonprofit operating privacy, communications, collaboration, and anti-censorship infrastructure.",
    "status": "ok",
    "description": "Provider hub for Unredacted Inc's anti-censorship, messaging, collaboration, network, and education services.",
    "cardSummary": "Nonprofit privacy and anti-censorship service hub.",
    "networks": [
      "Tor",
      "Matrix",
      "XMPP",
      "Monero"
    ],
    "checkedAt": "2026-08-17",
    "updatedAt": "2026-08-17",
    "lastReviewed": "2026-08-17",
    "reviewSource": "primary_unredacted_policy_terms_services_and_child_recheck_2026-08-18",
    "jurisdictionConfidence": "verified",
    "kycLastChecked": "2026-08-17",
    "trending": false,
    "jurisdiction": "US",
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "privacyWarning": "Unredacted's policy does not support a blanket no-logs or end-to-end-encryption claim. It discloses rule-triggered website IP and user-agent processing, Cloudflare use, 24-hour proxy-retrieval metadata, and service-specific Matrix and XMPP account, room, contact, message, and upload fields. FreeSocks' live config enables anonymous analytics and paid Membership, while XMPP.is publishes authentication logging, server-side message/archive storage, third-party Romanian hosting, off-site backups, and no self-service deletion; its former emailed manual procedure is struck through and current deletion availability is unclear. Delaware law and US legal process apply to the operator.",
    "ownership": "Unredacted Inc, Delaware 501(c)(3)",
    "auditedBy": [],
    "corporate": {
      "entityType": {
        "value": "foundation",
        "citation": "https://unredacted.org/about/us/",
        "note": "The operator publishes its incorporation and IRS records and identifies itself as a Delaware 501(c)(3)."
      },
      "governanceModel": {
        "value": "foundation",
        "citation": "https://unredacted.org/about/us/"
      },
      "repositoryUrl": {
        "value": "https://github.com/unredacted",
        "citation": "https://github.com/unredacted"
      },
      "legalEntity": {
        "value": "Unredacted Inc",
        "citation": "https://unredacted.org/terms-of-service/"
      },
      "incorporationJurisdiction": {
        "value": "Delaware, United States",
        "citation": "https://unredacted.org/about/us/"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "source": "Primary operator terms, incorporation documents, transparency report and repository review",
      "reviewedAt": "2026-08-17"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://unredacted.org/",
            "https://unredacted.org/privacy-policy/",
            "https://unredacted.org/terms-of-service/",
            "https://unredacted.org/about/us/",
            "https://unredacted.org/about/transparency/",
            "https://unredacted.org/about/security/",
            "https://unredacted.org/about/network/",
            "https://unredacted.org/services/si/matrix/",
            "https://status.unredacted.org/",
            "https://github.com/unredacted/freesocks-control-plane/blob/68f025a76ff91fbd92a4cefb9eaa17838ee2c70a/docs/billing.md",
            "https://github.com/unredacted/freesocks-control-plane/commit/333b7c65416cdf48fd1bb402fb20b8e49c6678ed",
            "https://github.com/unredacted/xmpp.is"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://unredacted.org/",
            "https://unredacted.org/privacy-policy/",
            "https://unredacted.org/terms-of-service/",
            "https://unredacted.org/about/us/",
            "https://unredacted.org/about/transparency/",
            "https://unredacted.org/about/security/",
            "https://unredacted.org/about/network/",
            "https://unredacted.org/services/si/matrix/",
            "https://status.unredacted.org/",
            "https://github.com/unredacted/freesocks-control-plane/blob/68f025a76ff91fbd92a4cefb9eaa17838ee2c70a/docs/billing.md",
            "https://github.com/unredacted/freesocks-control-plane/commit/333b7c65416cdf48fd1bb402fb20b8e49c6678ed",
            "https://github.com/unredacted/xmpp.is"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://unredacted.org/",
            "https://unredacted.org/privacy-policy/",
            "https://unredacted.org/terms-of-service/",
            "https://unredacted.org/about/us/",
            "https://unredacted.org/about/transparency/",
            "https://unredacted.org/about/security/",
            "https://unredacted.org/about/network/",
            "https://unredacted.org/services/si/matrix/",
            "https://status.unredacted.org/",
            "https://github.com/unredacted/freesocks-control-plane/blob/68f025a76ff91fbd92a4cefb9eaa17838ee2c70a/docs/billing.md",
            "https://github.com/unredacted/freesocks-control-plane/commit/333b7c65416cdf48fd1bb402fb20b8e49c6678ed",
            "https://github.com/unredacted/xmpp.is"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 900002,
    "slug": "freesocks",
    "domain": "freesocks.org",
    "name": "FreeSocks",
    "url": "https://freesocks.org/",
    "affiliate": "",
    "kyc": "none",
    "kycLevel": 0,
    "kycNote": "The live service creates an anonymous, captcha-gated account number without email, phone, password, or document KYC. Payment processors can collect payer data for optional Membership purchases on their own hosted pages.",
    "fee": "Free tier: 50 GB/month for 90 days; Membership: $5/1 month, $14/3 months, $27/6 months, or $50/12 months",
    "categories": [
      "Censorship",
      "Privacy Tools"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Reaching blocked sites",
      "Xray/VLESS access",
      "Dated free or paid censorship-circumvention access"
    ],
    "features": [
      "50 GB/month free tier for 90 days",
      "Optional paid Membership",
      "Xray through Remnawave enabled",
      "Outline code path present but live backend disabled",
      "Self-hosted control plane",
      "Public source code",
      "Access-key rotation"
    ],
    "tagline": "Free-tier and paid censorship-circumvention proxy access operated by Unredacted Inc.",
    "status": "ok",
    "description": "FreeSocks v2 distributes dated free-tier and paid Membership proxy access through an Unredacted-operated control plane.",
    "cardSummary": "Free and paid Xray access for censorship circumvention.",
    "networks": [
      "Xray",
      "VLESS"
    ],
    "checkedAt": "2026-08-17",
    "updatedAt": "2026-08-17",
    "lastReviewed": "2026-08-17",
    "reviewSource": "freesocks_live_config_privacy_retention_and_billing_2026-08-18",
    "jurisdictionConfidence": "verified",
    "kycLastChecked": "2026-08-17",
    "trending": false,
    "jurisdiction": "US",
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "privacyWarning": "FreeSocks is a censorship-circumvention proxy, not a VPN anonymity guarantee. Live anonymous analytics remain enabled, while the public configuration does not expose analytics.forwardIp or geo-mode settings. Unredacted's privacy policy says FreeSocks encrypted content is encrypted in transit and not stored, while the public control-plane documentation describes additional retention defaults; neither independently verifies production node logging or retention. CDN-delivered JavaScript remains an accepted active-CDN threat despite HPKE and proof-of-possession mitigations.",
    "ownership": "Operated by Unredacted Inc",
    "auditedBy": [],
    "corporate": {
      "entityType": {
        "value": "foundation",
        "citation": "https://unredacted.org/about/us/",
        "note": "FreeSocks is a service of Unredacted Inc, not a separate legal entity."
      },
      "governanceModel": {
        "value": "foundation",
        "citation": "https://unredacted.org/about/us/"
      },
      "repositoryUrl": {
        "value": "https://github.com/unredacted/freesocks-control-plane",
        "citation": "https://github.com/unredacted/freesocks-control-plane"
      },
      "legalEntity": {
        "value": "Unredacted Inc",
        "citation": "https://unredacted.org/terms-of-service/"
      },
      "incorporationJurisdiction": {
        "value": "Delaware, United States",
        "citation": "https://unredacted.org/about/us/"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "source": "Primary live FreeSocks configuration, pinned control-plane source, and Unredacted legal documents",
      "reviewedAt": "2026-08-17"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "HOLD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://freesocks.org/api/v1/config",
            "https://unredacted.org/privacy-policy/",
            "https://unredacted.org/blog/2026/07/internet-freedom-is-here-freesocks-v2/",
            "https://unredacted.org/terms-of-service/",
            "https://unredacted.org/about/us/",
            "https://github.com/unredacted/freesocks-control-plane/commit/68f025a76ff91fbd92a4cefb9eaa17838ee2c70a",
            "https://freesocks.org/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://freesocks.org/api/v1/config",
            "https://unredacted.org/privacy-policy/",
            "https://unredacted.org/blog/2026/07/internet-freedom-is-here-freesocks-v2/",
            "https://unredacted.org/terms-of-service/",
            "https://unredacted.org/about/us/",
            "https://github.com/unredacted/freesocks-control-plane/commit/68f025a76ff91fbd92a4cefb9eaa17838ee2c70a",
            "https://freesocks.org/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://freesocks.org/api/v1/config",
            "https://unredacted.org/privacy-policy/",
            "https://unredacted.org/blog/2026/07/internet-freedom-is-here-freesocks-v2/",
            "https://unredacted.org/terms-of-service/",
            "https://unredacted.org/about/us/",
            "https://github.com/unredacted/freesocks-control-plane/commit/68f025a76ff91fbd92a4cefb9eaa17838ee2c70a",
            "https://freesocks.org/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 900003,
    "slug": "xmpp-is",
    "domain": "xmpp.is",
    "name": "XMPP.is",
    "url": "https://xmpp.is/",
    "affiliate": "",
    "kyc": "none",
    "kycLevel": 0,
    "kycNote": "Registration creates an XMPP account. An email address is optional for recovery; no document KYC commitment was found.",
    "fee": "Free",
    "categories": [
      "Messaging",
      "Privacy Tools"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Federated XMPP messaging",
      "Accounts without phone numbers",
      "Client-selected OMEMO encryption"
    ],
    "features": [
      "XMPP federation",
      "Optional OMEMO",
      "Optional OTR",
      "MAM off by default",
      "100 MB uploads expiring after one week",
      "Daily encrypted off-site backups",
      "Public configuration source",
      "Optional recovery email"
    ],
    "tagline": "A free XMPP account service operated as an Unredacted sister project.",
    "status": "ok",
    "description": "A separately branded XMPP account and federation service operated by Unredacted Inc.",
    "cardSummary": "Free federated XMPP accounts without phone registration.",
    "networks": [
      "XMPP",
      "OMEMO",
      "OTR"
    ],
    "checkedAt": "2026-08-25",
    "updatedAt": "2026-08-17",
    "lastReviewed": "2026-08-25",
    "reviewSource": "primary_source_rereview_2026-08-25",
    "jurisdictionConfidence": "verified",
    "kycLastChecked": "2026-08-25",
    "trending": false,
    "jurisdiction": "US",
    "evidenceStatus": "partial",
    "riskLevel": "caution",
    "privacyWarning": "OMEMO and OTR are client-selected, not server-wide guarantees. XMPP.is says its info log records authentication but not user IP addresses, and names stored hashed passwords, offline messages, MAM archives, vCards, rosters, and enabled-module data. Its server page says uploads are limited to 100 MB and expire after one week, MAM is off by default with a published 30-day expiry, encrypted backups sync off-site daily, and a donated FlokiNET server is located in Romania; Unredacted Inc remains the US/Delaware operator. The current public Prosody config agrees on authentication/info logging and one-week uploads but sets MAM expiry to 90 days and PostgreSQL storage, conflicting with the site's 30-day and flat-file statements, so the running values are not independently confirmed. The deletion page says automated deletion is unavailable and strikes through its former emailed manual soft/hard procedure, so current deletion availability is unclear. Federation and XEP-0384 also leave traffic-analysis metadata outside client E2EE.",
    "ownership": "Operated by Unredacted Inc",
    "auditedBy": [],
    "corporate": {
      "entityType": {
        "value": "foundation",
        "citation": "https://unredacted.org/about/us/",
        "note": "XMPP.is is operated by Unredacted Inc and is not presented as a separate legal entity."
      },
      "governanceModel": {
        "value": "foundation",
        "citation": "https://unredacted.org/about/us/"
      },
      "repositoryUrl": {
        "value": "https://github.com/unredacted/xmpp.is",
        "citation": "https://github.com/unredacted/xmpp.is"
      },
      "legalEntity": {
        "value": "Unredacted Inc",
        "citation": "https://unredacted.org/terms-of-service/"
      },
      "incorporationJurisdiction": {
        "value": "Delaware, United States",
        "citation": "https://unredacted.org/about/us/"
      },
      "officers": {
        "value": [],
        "citation": "unknown"
      },
      "source": "Primary XMPP.is security, server, deletion and transparency pages; pinned public configuration; and Unredacted legal documents",
      "reviewedAt": "2026-08-17"
    },
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "PASS",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://xmpp.is/",
            "https://xmpp.is/about/security/",
            "https://xmpp.is/about/server/",
            "https://status.unredacted.org/api/status-page/heartbeat/unredacted",
            "https://github.com/UnredactedVPN/xmpp.is"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://xmpp.is/",
            "https://xmpp.is/about/security/",
            "https://xmpp.is/about/server/",
            "https://status.unredacted.org/api/status-page/heartbeat/unredacted",
            "https://github.com/UnredactedVPN/xmpp.is"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://xmpp.is/",
            "https://xmpp.is/about/security/",
            "https://xmpp.is/about/server/",
            "https://status.unredacted.org/api/status-page/heartbeat/unredacted",
            "https://github.com/UnredactedVPN/xmpp.is"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  },
  {
    "id": 1116,
    "slug": "ledger",
    "name": "Ledger",
    "domain": "ledger.com",
    "url": "https://www.ledger.com/",
    "affiliate": null,
    "kyc": "none",
    "kycLevel": 2,
    "kycNote": "A standard hardware order requires contact, billing/shipping and payment/order data, and is screened for fraud and sanctions. The current sales terms do not state a routine identity-document requirement, but Global-e may request additional verification. Buy, sell, swap and similar Ledger Wallet integrations are third-party services and may apply KYC/KYT.",
    "fee": "Current official comparison payload showed base USD prices from $59 to $399 (Nano S Plus $59; Nano X $79; Nano Gen5 $179; Flex $249; Stax + Recovery Key $399). Final checkout pricing, taxes, delivery, import charges, partner fees and network fees vary.",
    "limit": "No device-level transaction limit stated; blockchain rules and integrated third-party provider limits apply.",
    "categories": [
      "Hardware wallet"
    ],
    "countries": [
      "GLOBAL"
    ],
    "bestFor": [
      "Self-custody cold storage",
      "On-device transaction verification",
      "Multi-chain portfolio management",
      "Human-approved agent signing"
    ],
    "features": [
      "Current hardware line: Ledger Stax, Ledger Flex, Ledger Nano Gen5, Ledger Nano X and Ledger Nano S Plus",
      "Certified Secure Element (CC EAL6+ on the current comparison page)",
      "Ledger Wallet desktop and mobile companion apps",
      "500+ coins directly in Ledger Wallet; 15,000+ crypto and 100+ chains advertised across supported integrations",
      "Buy, sell, swap and stake integrations through third-party service providers",
      "Ledger Wallet CLI and Agent Stack with physical signer approval for every signing step",
      "Public Ledger Wallet source repository; most projects MIT-licensed",
      "Proprietary Ledger OS firmware with separately developed device applications"
    ],
    "tagline": "Self-custody hardware signers with human-approved transactions.",
    "status": "ok",
    "updatedAt": "2026-08-26",
    "changedAt": "2026-08-26",
    "description": "Ledger sells self-custody hardware signers and provides the Ledger Wallet desktop/mobile application. Private keys remain under user control on the signer; buying, selling, swapping and some staking functions route through separate providers with their own terms, fees, availability and KYC/KYT rules.",
    "cardSummary": "Hardware signers with broad asset and app support.",
    "networks": [
      "BTC",
      "ETH",
      "BNB",
      "XRP",
      "SOL",
      "TRX"
    ],
    "checkedAt": "2026-08-25T23:48:26Z",
    "lastReviewed": "2026-08-26",
    "reviewSource": "Primary-source lock t_96b7c935; official Ledger legal, privacy, product, incident and source-repository materials accessed 2026-08-26.",
    "jurisdictionConfidence": "verified",
    "kycLastChecked": "2026-08-26",
    "trending": false,
    "jurisdiction": "FR",
    "noOperatorData": false,
    "evidenceStatus": "verified",
    "riskLevel": "caution",
    "privacyWarning": "Hardware purchases expose name, email, billing/shipping address, phone, order and payment-method metadata to Ledger and Global-e; Ledger says order data is retained ten years and archived after three months. Ledger Wallet generates equipment/signer IDs and may retain wallet-address/on-chain analytics for five years; optional features and third-party financial services create additional data flows. The 2020 customer-data breach materially increases phishing and physical-targeting risk.",
    "founderIntel": null,
    "vcIntel": null,
    "ownership": "Ledger SAS",
    "auditedBy": [],
    "stateActorFlag": null,
    "publicClaims": null,
    "corporate": {
      "entityType": {
        "value": "company",
        "citation": "https://shop.ledger.com/pages/ledger-live-terms-of-use",
        "note": "Corporate identity verified from official Ledger terms; the underlying registry record was not directly queried in this task."
      },
      "repositoryUrl": {
        "value": "https://github.com/LedgerHQ/ledger-live",
        "citation": "https://raw.githubusercontent.com/LedgerHQ/ledger-live/develop/README.md"
      },
      "legalEntity": {
        "value": "Ledger SAS",
        "citation": "https://shop.ledger.com/pages/ledger-live-terms-of-use"
      },
      "registrationNumber": {
        "value": "529 991 119",
        "citation": "https://shop.ledger.com/pages/ledger-live-terms-of-use"
      },
      "incorporationJurisdiction": {
        "value": "France",
        "citation": "https://shop.ledger.com/pages/ledger-live-terms-of-use"
      },
      "registeredAddress": {
        "value": "106 rue du Temple, 75003 Paris, France",
        "citation": "https://shop.ledger.com/pages/ledger-live-terms-of-use"
      },
      "source": "agent-verified official Ledger Wallet Terms of Use, 2026-08-26",
      "reviewedAt": "2026-08-26"
    },
    "agentMoney": {
      "compatible": true,
      "controlSurfaces": [
        "cli",
        "manual"
      ],
      "protocols": [
        "manual"
      ],
      "authorizationModel": [
        "human-approval"
      ],
      "settlementRail": [
        "crypto"
      ],
      "autonomyLevel": 1,
      "custodyModel": "self-custody",
      "mandateLoggingRisk": "unknown",
      "revocationQuality": "unknown",
      "spendLimits": false,
      "merchantLock": false,
      "categoryLock": false,
      "fundingSource": "crypto-funded",
      "identitySurface": "unknown",
      "sourceLinks": [
        {
          "label": "Ledger Agent Stack",
          "href": "https://shop.ledger.com/pages/ledger-agent-stack",
          "scope": "controls"
        },
        {
          "label": "Ledger Wallet repository README",
          "href": "https://raw.githubusercontent.com/LedgerHQ/ledger-live/develop/README.md",
          "scope": "docs"
        }
      ],
      "dataPath": [
        "Agent prepares or queries",
        "Ledger Wallet CLI",
        "Ledger signer trusted display",
        "Human physical approval",
        "Blockchain"
      ],
      "notes": "Current v1 tooling supports read-only agent actions and transaction preparation, but every signing step requires affirmative physical confirmation. This is human-approved execution, not unattended autonomy; Ledger labels bounded autonomy and policy features as coming soon.",
      "protocolPrivacyNotes": "The signer remains self-custodial, but Ledger Wallet and integrated third parties may process equipment IDs, wallet addresses, on-chain/transaction data and provider-required identity data as described in the privacy policy."
    },
    "followTheMoney": null,
    "twitter": "https://x.com/Ledger",
    "telegram": null,
    "scoreAssessment": {
      "operatorDataExposure": "unknown",
      "controlModel": "unknown",
      "sourceModel": "unknown"
    },
    "scoreReview": {
      "outcome": "ADD",
      "checkedAt": "2026-08-25",
      "inputs": {
        "operatorDataExposure": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.ledger.com/addressing-the-july-2020-e-commerce-and-marketing-data-breach",
            "https://www.ledger.com/message-ledgers-ceo-data-leak",
            "https://www.ledger.com/blog/security-incident-report",
            "https://shop.ledger.com/pages/privacy-policy",
            "https://shop.ledger.com/pages/privacy-policy-what-website",
            "https://shop.ledger.com/pages/privacy-policy-what-ledger-wallet",
            "https://shop.ledger.com/pages/with-whom-do-we-share-your-data-privacy-policy-linked-page",
            "https://shop.ledger.com/pages/how-do-we-keep-your-data-safe-privacy-policy",
            "https://shop.ledger.com/pages/terms-and-conditions",
            "https://shop.ledger.com/pages/ledger-live-terms-of-use",
            "https://shop.ledger.com/pages/hardware-wallets-comparison",
            "https://shop.ledger.com/pages/ledger-wallet",
            "https://www.ledger.com/supported-crypto-assets",
            "https://shop.ledger.com/pages/ledger-os-and-device-apps-policy",
            "https://raw.githubusercontent.com/LedgerHQ/ledger-live/develop/README.md",
            "https://raw.githubusercontent.com/LedgerHQ/ledger-live/develop/LICENSE.txt",
            "https://shop.ledger.com/pages/ledger-agent-stack",
            "https://www.ledger.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "controlModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.ledger.com/addressing-the-july-2020-e-commerce-and-marketing-data-breach",
            "https://www.ledger.com/message-ledgers-ceo-data-leak",
            "https://www.ledger.com/blog/security-incident-report",
            "https://shop.ledger.com/pages/privacy-policy",
            "https://shop.ledger.com/pages/privacy-policy-what-website",
            "https://shop.ledger.com/pages/privacy-policy-what-ledger-wallet",
            "https://shop.ledger.com/pages/with-whom-do-we-share-your-data-privacy-policy-linked-page",
            "https://shop.ledger.com/pages/how-do-we-keep-your-data-safe-privacy-policy",
            "https://shop.ledger.com/pages/terms-and-conditions",
            "https://shop.ledger.com/pages/ledger-live-terms-of-use",
            "https://shop.ledger.com/pages/hardware-wallets-comparison",
            "https://shop.ledger.com/pages/ledger-wallet",
            "https://www.ledger.com/supported-crypto-assets",
            "https://shop.ledger.com/pages/ledger-os-and-device-apps-policy",
            "https://raw.githubusercontent.com/LedgerHQ/ledger-live/develop/README.md",
            "https://raw.githubusercontent.com/LedgerHQ/ledger-live/develop/LICENSE.txt",
            "https://shop.ledger.com/pages/ledger-agent-stack",
            "https://www.ledger.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        },
        "sourceModel": {
          "value": "unknown",
          "sourceUrls": [
            "https://www.ledger.com/addressing-the-july-2020-e-commerce-and-marketing-data-breach",
            "https://www.ledger.com/message-ledgers-ceo-data-leak",
            "https://www.ledger.com/blog/security-incident-report",
            "https://shop.ledger.com/pages/privacy-policy",
            "https://shop.ledger.com/pages/privacy-policy-what-website",
            "https://shop.ledger.com/pages/privacy-policy-what-ledger-wallet",
            "https://shop.ledger.com/pages/with-whom-do-we-share-your-data-privacy-policy-linked-page",
            "https://shop.ledger.com/pages/how-do-we-keep-your-data-safe-privacy-policy",
            "https://shop.ledger.com/pages/terms-and-conditions",
            "https://shop.ledger.com/pages/ledger-live-terms-of-use",
            "https://shop.ledger.com/pages/hardware-wallets-comparison",
            "https://shop.ledger.com/pages/ledger-wallet",
            "https://www.ledger.com/supported-crypto-assets",
            "https://shop.ledger.com/pages/ledger-os-and-device-apps-policy",
            "https://raw.githubusercontent.com/LedgerHQ/ledger-live/develop/README.md",
            "https://raw.githubusercontent.com/LedgerHQ/ledger-live/develop/LICENSE.txt",
            "https://shop.ledger.com/pages/ledger-agent-stack",
            "https://www.ledger.com/"
          ],
          "reviewedAt": "2026-08-25",
          "note": "The reviewed packet did not map this normalized Score 4.0 input to a field-level source; unknown is preserved until that mapping is completed."
        }
      },
      "audit": {
        "scoreEligible": false,
        "reason": "No dated, scoped, current audit citation was normalized in the reviewed packet; legacy auditedBy labels receive no score credit."
      }
    }
  }
]
