{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"chainalysis","name":"Chainalysis","domain":"chainalysis.com","category":"Compliance and GRC","one_liner":"Chainalysis combines blockchain data and AI to help government agencies, crypto businesses, and financial institutions engage confidently","trust_center_url":"https://trust.chainalysis.com/","security_page_url":null,"url":"https://certreports.com/vendors/chainalysis/security","last_verified_at":"2026-09-18T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"soc-2","framework_name":"SOC 2","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states a SOC 2 Type II report on its trust centre (Vanta) as of 18 Sep 2026.","kind":"type2","status_text":"Vendor states SOC 2 Type II on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/chainalysis/soc-2","evidence":[{"source_type":"trust_center","source_name":"Chainalysis trust centre (Vanta)","url":"https://trust.chainalysis.com/","fetched_at":"2026-09-18 23:04:58.977981+00","content_hash":"e794dfd3e143186a035690d23da35c115945ccc4897cb51d3991109d00899421","wayback_url":null,"quote":"SOC 2 Type II","confidence":1}]},{"framework":"fedramp","framework_name":"FedRAMP","state":"verified_registry","state_label":"Verified","sentence":"Listed in the FedRAMP Marketplace as of 18 Sep 2026.","kind":"authorization","status_text":"FedRAMP Authorized","issued_at":"2025-09-16","expires_at":null,"period_start":null,"period_end":null,"auditor":"Fortreum, LLC","impact_level":"Moderate","as_of":"2026-09-18","under_review":false,"source":"fedramp","url":"https://certreports.com/vendors/chainalysis/fedramp","evidence":[{"source_type":"registry","source_name":"FedRAMP Marketplace","url":"https://www.fedramp.gov/marketplace/products/FR2334756650","fetched_at":"2026-09-18 22:35:17.44827+00","content_hash":"db2d03fa40cba0e5287b9cc7361e71b7c30c7ca9d51efb7b540477105fb30c7b","wayback_url":null,"quote":"Chainalysis - Reactor: FedRAMP Authorized","confidence":1},{"source_type":"registry","source_name":"FedRAMP Marketplace","url":"https://www.fedramp.gov/marketplace/products/FR2334756650","fetched_at":"2026-09-17 15:44:39.301965+00","content_hash":"395e7ad35dd25d1c547414140161c47ec22827b7ffae3bdbbd5256c38a3b940f","wayback_url":null,"quote":"Chainalysis - Reactor: FedRAMP Authorized","confidence":1}]},{"framework":"iso-27001","framework_name":"ISO/IEC 27001","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an ISO/IEC 27001 certificate on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states ISO 27001:2022 on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/chainalysis/iso-27001","evidence":[{"source_type":"trust_center","source_name":"Chainalysis trust centre (Vanta)","url":"https://trust.chainalysis.com/","fetched_at":"2026-09-18 23:04:58.977981+00","content_hash":"e794dfd3e143186a035690d23da35c115945ccc4897cb51d3991109d00899421","wayback_url":null,"quote":"ISO 27001:2022","confidence":1}]},{"framework":"cyber-essentials","framework_name":"Cyber Essentials","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an Cyber Essentials certificate on its trust centre (Vanta) as of 18 Sep 2026.","kind":null,"status_text":"Vendor states Cyber Essentials on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-18","under_review":false,"source":"vanta","url":"https://certreports.com/vendors/chainalysis/cyber-essentials","evidence":[{"source_type":"trust_center","source_name":"Chainalysis trust centre (Vanta)","url":"https://trust.chainalysis.com/","fetched_at":"2026-09-18 23:04:58.977981+00","content_hash":"e794dfd3e143186a035690d23da35c115945ccc4897cb51d3991109d00899421","wayback_url":null,"quote":"Cyber Essentials","confidence":1}]},{"framework":"dpf","framework_name":"EU-US Data Privacy Framework","state":"verified_registry","state_label":"Verified","sentence":"Listed in the Data Privacy Framework list as of 17 Sep 2026.","kind":"listing","status_text":"Active: SW-US Certification, EU-US Certification, UK Extension Certification","issued_at":"2020-01-17","expires_at":"2027-02-09","period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"dpf","url":"https://certreports.com/vendors/chainalysis/security","evidence":[{"source_type":"registry","source_name":"Data Privacy Framework list","url":"https://www.dataprivacyframework.gov/participant/6334","fetched_at":"2026-09-17 15:49:29.369285+00","content_hash":"e55ce739b286907a4db7259eed16cf9087fb6952f99e5239ba9669bb222728df","wayback_url":null,"quote":"Chainalysis: Active: SW-US Certification, EU-US Certification, UK Extension Certification","confidence":1}]}],"brief":{"summary":"As of 17 Sep 2026, FedRAMP records show Chainalysis is listed in the FedRAMP registry with a status of FedRAMP Authorized, with an issued date of 16 Sep 2025 and no expiry date recorded. As of 17 Sep 2026, the EU-US Data Privacy Framework registry lists Chainalysis as active under the SW-US Certification, EU-US Certification, and UK Extension Certification, issued 17 Jan 2020 and currently valid through 09 Feb 2027. No public evidence found for SOC 2 as of 17 Sep 2026. No public evidence found for HIPAA or a stated BAA as of 17 Sep 2026. No public evidence found regarding subprocessor disclosures as of 17 Sep 2026.","bullets":["Listed in FedRAMP registry: FedRAMP Authorized, issued 16 Sep 2025, no expiry date, as of 17 Sep 2026 (auditor: Fortreum, LLC).","Listed in EU-US Data Privacy Framework registry: Active (SW-US, EU-US, UK Extension Certifications), issued 17 Jan 2020, valid through 09 Feb 2027, as of 17 Sep 2026.","No public evidence found for SOC 2 or HIPAA/BAA status as of 17 Sep 2026."],"model":"claude-sonnet-5","generated_at":"2026-09-17 18:51:02.073464+00"},"legal_docs":[{"kind":"privacy","url":"https://www.chainalysis.com/privacy-policy/","availability":"public","detail":null,"as_of":"2026-09-18"}],"subprocessors":[],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-19T02:21:54.876Z"}