Skip to content

What's New

What's shipping in CryptoComply, newest first. Each entry calls out new features, improvements, fixes, and anything to watch for.

A few acronyms used below: RFI (Request for Information), PEP (Politically Exposed Person), MCP (Model Context Protocol — the standard for connecting AI tools), KYC/AML (Know Your Customer / Anti-Money Laundering), and SSO (Single Sign-On).

What's new

  • Adding a related party now offers everything creating a profile does. The Add Related Party dialog used to ask for a fixed handful of identity details; it now shows the same sections your group defines — including your organization's own custom fields — and lets you tag the party, write its first internal note, and attach blockchain addresses while creating it, all in one step. Which fields appear (and which are required) follow the group's configuration, so it no longer insists on details you don't collect.

What's fixed

  • The Add Related Party dialog fits on the screen. The form used to run past the bottom of the window with its save button out of sight; it now scrolls inside the dialog with the buttons always in view, on phones too.
  • A related party that can't be saved says why, instead of a generic "please try again," and the relation type and person/company choice you made are carried into the form — switching between person and company keeps what you've already typed.
  • Recording a beneficial owner, control person, or parent for the first time no longer asks for a rationale. In organizations that require a rationale for profile changes, first-time entry of these details was wrongly rejected as an edit; recording new information is now accepted, while changing or clearing an existing value still requires a rationale.

11 August 2026 — Reliable updates and clearer intake questions

What's fixed

  • The app no longer gets stuck refreshing after an update. When a new version was deployed while you had the app open, the automatic reload could keep serving the old copy and spin in an endless refresh; the reload now fetches the fresh version, and a Retry screen appears in the rare case a stubborn cache serves the old one twice.
  • Faster repeat visits. The app's unchanged files are cached properly again, so returning to the app re-downloads only what actually changed.
  • A form open to both people and companies asks each for its own name. On a form where the applicant chooses individual or company, the name question is now worded for that choice — a person is asked for their full legal name, a company for the entity's legal name — instead of one wording that could leave companies unasked (and their submissions unable to become a profile).

10 August 2026 — Revisit decisions, step through alerts, and hide empty fields

What's new

  • Change a decision you already recorded on a hit. A resolved hit is no longer a dead end — its assignee can reopen the decision, with the existing rationale carried over to amend (the reasoning has to actually change to be accepted). If the alert was already closed, you're asked whether its disposition still stands. The same revision is available through Comply AI.
  • Step through alerts without going back to the list. An alert opened from a list now has previous/next controls in its header, the way profiles and blockchain addresses already did.
  • Hide the fields a profile never filled in. A switch drops every empty field across a profile's information tab (including sections left with nothing to show); the choice is remembered in your browser and applies while editing.
  • Show a hidden field to the whole group in one click. The warning marker on a field that's hidden by the group but holds data is now a button that names the field and group and asks to confirm, instead of sending you to settings.
  • Profiles open the way you left them — a collapsed overview stays collapsed on the next profile you open (following a link to a section still expands it).
  • See which role you're signed in with. The sidebar user card and menu now show your role in the current organization, and update when you switch organizations.

What's improved

  • Redesigned watchlist hit card. The side-by-side comparison of your customer against the listed party now leads the card at full width, with the vendor's details, narrative, and citations below; the card shows every identifier the record carries (all passports and listing numbers, not just the first) and links out to the vendor's own record.

What's fixed

  • The audit log on an alert opens again (it had shown "Something went wrong"); the notification-subscription screens name their events and categories again; ⌘/Ctrl-click and "Open in new tab" work on an alert's Related cards; the profile and blockchain-address action menus match the rest of the app and are readable in dark mode; plus assorted section and menu polish.
  • Signing in still works when rate-limiting is briefly unavailable — sign-in, session renewal, password reset, and public intake forms no longer fail if the rate-limit service is momentarily unreachable.

7 August 2026 — Explained matches, durable source citations, and a leaner vendor lineup

What's new

  • Match explanations on screening hits. A hit now shows why its score is what it is — the exact listed term that matched (flagged when it's an alias/AKA rather than the primary name) and a field-by-field verdict (name, date of birth, country, gender: matched or not) — so an ambiguous score can be adjudicated at a glance. Works retroactively for already-stored World-Check hits.
  • Additional details on hits. The vendor's full narrative on a listed party — biography, identification details, reports, and per-regime sanction notes — is captured with each hit and shown as structured, collapsible sections, instead of something to look up in the provider's own console.
  • Durable source citations. Every source cited by a hit is resolved and self-hosted: each link shows its status — Live, Wayback (a date-matched web-archive snapshot), Archived copy only, or Unavailable — and "View source" opens a self-contained, sandboxed copy that works even when the original site is gone (files like PDFs and spreadsheets are offered as a download). A live page that has drifted from what was cited is flagged.

What's changed

  • A leaner screening vendor lineup. Castellum, OpenSanctions, and Hypernative have been retired: watchlist screening now runs exclusively through World-Check, and blockchain-address screening through Chainalysis and TRM. Organizations on a retired vendor were moved over automatically, and historical results, hits, alerts, and resolutions are unaffected — only running new screenings against those vendors is gone.

What's improved

  • Attachment filtering, rebuilt. The attachments panel now filters by source and document type through two dropdowns (each option showing how many attachments it would leave, and options that would leave none hidden), plus a search box across attachment names, filenames, and notes — replacing the row of chips that grew with every document type. Attachment cards are calmer, with badges and the type picker sized to the panel.
  • A stronger Comply AI. The assistant moved to Anthropic's latest Sonnet model, better at multi-step research across your data, at no change in cost. Asking for your riskiest wallets or most recently changed profiles now works (previously it could only sort by name or creation date).
  • Scheduled screening failures are visible. When a scheduled watchlist screening can't complete, the profile's schedule now records what went wrong and when, clearing automatically on the next successful run.

What's fixed

  • Document category names read properly again ("Screening & Monitoring Reports" no longer collapses to "Screening Monitoring Reports"); the attachment type list stays inside the panel; related parties load in a single request and show the profile's whole related network; navigating away from a still-loading page no longer shows an error; member pickers list every member (not just the first 25) and say so when a list fails to load; blockchain-address pages no longer flash "No data available" before results arrive; and a fully reviewed request for information now shows as Closed instead of staying Responded.

21 July 2026 — Attachment provenance and blockchain-address screening detail

What's new

  • See where every attachment came from. Each attachment now shows how it reached the platform — uploaded by your team, submitted through an intake form, or provided in an RFI response — along with who uploaded it and when.
  • Redesigned attachments panel. Attachment cards are more compact and scannable; document type and review status are edited inline (status shown as a colored badge, with a confirmation before a change takes effect); attachments can be filtered by source and by type; and the type list now covers screening-report and corporate-document types that previously had to be filed as "Other".
  • Far more detail on a screened blockchain address. The address page now surfaces an Address Metrics section (incoming/outgoing attributed-exposure USD, first/last-active, transfers in/out), a plain-language risk reason, and address-type / VASP classification chips with tooltips. Sanctions-list attribution appears as badges on sanctions rows and associations (e.g. OFAC SDN, UK OFSI); a match whose list can't be identified is called out as a distinct "Review required" state rather than shown as clean. A new Counterparties table lists the named entities an address transacted with, most material first, with per-direction USD and their own sanctions badges. All of this is mirrored in the PDF screening report and the screening-comparison view (including a counterparty diff between two screenings).
  • Counterparty categories drill down. Each Counterparty Exposure category row now expands to reveal the named counterparties in it, with sanctions badges and sent/received amounts, on both desktop and mobile.
  • Open any row in a new browser tab. Hold ⌘/Ctrl (or middle-click) on a row in any list — profiles, related parties, addresses, alerts, intake forms, groups, compliance-health results — or on a profile's tabs, to open it in a new tab without losing your place.

What's improved

  • Longer notes. Notes now accept up to 50,000 characters, so long compliance narratives no longer need to be split across several notes.
  • Tidier tables. Status and type badges within a column now share a single width, so columns line up cleanly.
  • Where an address's identity lives. The address-type and VASP chips moved into the Address Identification section (the risk reason stays with Risk Analysis), so identity and risk are cleanly separated on screen, in the comparison view, and in the PDF.

What's fixed

  • Periodic code security audit completed.

16 July 2026 — Open a submission from the forms page

What's new

  • View a submission without leaving the forms page. On an intake form's Submissions tab, click any submission to open the original form exactly as the submitter saw it, with their answers and consents filled in — the same read-only view already used on a profile's page.

15 July 2026 — Guided bulk-import wizard

What's new

  • Import from a CSV in guided steps. Import profiles or blockchain addresses from a CSV: pick the group, download a template that matches its fields, upload, then review your data in an editable spreadsheet. Each column maps from its own header, flagged cells are highlighted (red for errors, amber for warnings) with the reason on hover, and the row number turns red so a bad row stands out. Fix cells inline and re-run the checks without re-uploading, and open a reference of every accepted field and value from the sheet.

13 July 2026 — Mobile support and dark mode

What's new

  • Full mobile support. Every page, table, form, and modal adapts to small screens, with a bottom navigation bar, full-screen dialogs, and readable text sizes throughout — across the dashboard, profiles, addresses, alerts, settings, notifications, the AI chat, intake forms and their builder, and the public intake/RFI forms your clients fill in on their phones. Buttons are easier to tap, and typing no longer triggers unwanted zoom on iPhones.
  • Dark mode. A dark theme spans every authenticated screen, toggleable from the sidebar (or the mobile menu). It's driven by centralized theme tokens, so surfaces, text, borders, and the lime brand accent stay consistent everywhere. (The intake-form survey styling keeps its own theme.)

10 July 2026 — Phone-photo uploads and consistent labels

What's new

  • Phone-photo uploads just work. The attachment and RFI file pickers now accept HEIC/HEIF, TIFF, WebP, BMP, and AVIF alongside PDF/PNG/JPEG, so iPhone photos upload without conversion (the platform transcodes them to a viewable image), even when the browser reports no file type.

What's improved

  • Country and choice labels resolve consistently. Gender, ID type, custom dropdowns, and country fields now render their readable name from a shared catalog everywhere they appear — in read mode, in the PDF report, and in the watchlist side panel — instead of depending on a label travelling next to each value.
  • Full custom-field types and conditional logic in forms. The form renderer now supports the complete custom-field type set and the current show/hide condition rules across profile, RFI, and intake-form surfaces.

9 July 2026 — Custom RFI questions, follow-ups, and reminders

What's new

  • Custom questions on an RFI. The compose modal gains a Custom Questions builder — type free-text questions (up to 25, add/remove/reorder) that go out alongside the fields and documents you request. An RFI can be question-only. The public form renders them as a required "Additional Questions" section, and answers come back in the response-review drawer with each question as the heading; accepting one records the answer on the audit trail without writing anything to the profile.
  • Follow-up RFIs. A responded RFI gets a Send follow-up action that reopens the compose modal in follow-up mode; the new RFI is linked to the original and carries a "Follow-up" badge. Follow-ups are typically question-only.
  • RFI reminders. The profile's Requests-for-Information drawer now has a Send reminder action on live RFIs, a reminder count and last-reminded timestamp, and a View reminder email preview. Each RFI row also lists exactly what was requested — the fields and documents — as chips.

What's improved

  • Forms can ask a question in plain language. A field now carries a separate recipient-facing question and helper text, distinct from the internal audit label — so a field whose audit noun reads awkwardly ("U.S. citizen") can ask it properly ("Are you a U.S. citizen?") on the form without changing what staff and the audit trail see.

What's fixed

  • Faithful RFI email preview. The sent-email preview now renders the email exactly as delivered, instead of clipping content, and references the actual "Provide Information" button.
  • RFI checkbox alignment. A checkbox for a long, wrapping question label now sits flush with the first line instead of centering against the whole block.

8 July 2026 — Retry when a query fails

What's new

  • Inline retry instead of empty sections. List tables, profile and alert detail views, blockchain-address lookups, intake/RFI drawers and summaries, and the settings group/risk-engine panels now show an inline error state with a Retry button when a request fails, instead of rendering an empty or stale section.
  • Guards against losing edits. Closing or navigating away from an edited role or account form now prompts before discarding changes.

What's improved

  • Faster and steadier. Several screens load faster, and modal dialogs now share consistent focus, dismissal, and scroll behavior.

What's fixed

  • A crash in a banner outside the main app no longer takes down the whole app shell, and profile-screening schedule-expiry timers no longer leak across schedule updates.

6 July 2026 — Screening configuration shows correctly again

What's fixed

  • Organization settings no longer show empty screening config. The Screening Configuration card could show empty created/updated dates and "Not configured" for services that were in fact configured, depending on which screen loaded first. It now always reflects the real configuration.

5 July 2026 — Intake header band renders reliably

What's fixed

  • Header band no longer paints white intermittently. A timing- and stylesheet-order issue could leave an intake form's header band white until a refresh — hiding a logo with light elements. The band and its description color now render reliably on every load.

4 July 2026 — Email theming controls

What's new

  • Email header-band, footer, and button-text colors. The intake-form Email editor's Colors section gains Header Band (a band behind the logo), Footer, and Button Text pickers, alongside Background / Card / Accent. Unset, they render exactly as before; set a brand color (e.g. navy) so a logo with light elements reads on it, and button text stays legible on any accent.

What's removed

  • Organization brand-logo upload. Org settings no longer upload or show a "Brand Logo" — the email header logo is now configured per form instead.

What's fixed

  • The intake header band no longer flashes white before the theme applies.

What's new

  • Content and field blocks. Add display-only content blocks (rich HTML/text) and generic fields (short/long text, checkbox, choice, number, date, email) that are recorded on the submission only — never written to the profile — for waivers, signatures, acknowledgements, and extra consents. A page can be marked a consent page, so its required checkboxes act as the consent acknowledgements.
  • Editable landing group in Settings. The editor's Settings tab shows the form's default group and lets you reassign it; changing any submission-level default (group, profile type, or blockchain) opens a confirmation dialog explaining the effect first.

What's improved

  • Intake forms for everyone. Intake forms and publishing are now available to every organization — the feature flags and their gating were removed.
  • Editor polish. Field types read as human labels (Short text, Single choice, …), the Question Settings panel is wider, and conditions stack in cleaner cards.
  • Readable legal and consent text. Consent, legal, and privacy blocks render with document-like styling — sensible heading sizes, paragraph spacing, and indented lists — and authored numbered lists render as legal-document enumerations with hanging indents.
  • Optional/clearable defaults. A wallet section's blockchain falls back to the form's default, and the default profile type and blockchain can be cleared so the form asks the respondent instead.

What's fixed

  • Phone fields no longer crash the profile page. Validating a phone field could replace the whole profile view with "Something went wrong"; it now validates normally.
  • Readable header description on a colored band, and the read-only submission view now renders markdown/HTML labels (e.g. a consent acknowledgement) instead of raw tags.

2 July 2026 — Text-field options and per-page preview

What's new

  • Short or long text, per question. Free-text questions have a Multi-line toggle in the editor — turn it off for a single-line input, on for a text box — available on every free-text field.
  • Preview a single page. Each page in the builder has a Preview this page button that opens the preview jumped straight to that page, with a Back to builder link.
  • Require a repeated section. Repeated sections (e.g. Beneficial Owners) now have a Required toggle — when on, the submitter must add at least one entry before continuing.

What's improved

  • Longer consent text. The consent acknowledgement editor now accepts long legal notices (up to 100,000 characters).

What's fixed

  • On dark form themes, multi-line text boxes and the date-picker icon stay legible; page/section titles containing & render correctly; and returning from a page preview opens the builder at the first page.

What's new

  • Custom form links. An intake form's link can be given a readable custom address (e.g. celo-tip-intake) from Settings, copyable in one click, with a live preview of the URL.
  • Choose which groups a form offers. Uncheck any group (e.g. internal or operational ones) to hide it from applicants.
  • Default profile type and blockchain. Choose the default profile type and blockchain when creating any intake form, and change them later from Settings.

What's improved

  • Dark and custom form themes. Intake forms render correctly on any color palette — descriptions, inputs, and borders adapt instead of staying light and unreadable.
  • Faster page loads, especially the profile and blockchain-address detail pages, and a smoother form builder.
  • Cleaner test-submission result — what a submission would create is shown as tidy, sectioned cards (profile, related parties, wallets, attachments).
  • Page-specific browser tab titles. The browser tab now shows the page you're on instead of a single static title, so bookmarks are meaningful and multiple open tabs are easy to tell apart.

What's fixed

  • Condition guardrails in the builder. The profile-type and group selectors can't be hidden, made conditional, or marked optional; a condition can only reference an earlier question; and removing a question clears any condition that referenced it.

30 June 2026 — Test an intake form before publishing

What's new

  • Test this form. A "Test this form" action opens a form exactly as a respondent sees it and, on submit, shows a report of what a real submission would create — profile, fields, related parties, wallets/addresses — without saving anything. It runs against your current draft, so you can test at any point while building.
  • Send test email. Send the real invitation email to your own inbox to check the template and delivery.

What's improved

  • Optional group for address forms, since address forms create standalone addresses, and the form's header actions are grouped under a single Actions menu.

What's fixed

  • Faithful rich text on public forms. Titles, descriptions, and consent text render their formatting and special characters (e.g. &) instead of raw HTML, and a wide header logo is centered and height-capped.
  • In the builder, the profile-type and group selector cards show their question instead of the raw field key.

28 June 2026 — Intake form condition builder

What's new

  • Visual condition builder. Add show/require rules to questions and pages from a visual builder — pick the source question, operator, and values — plus an "Applies to" control to target individual vs. business respondents or specific groups. An "Add Identification Page" shortcut sets up the profile-type and group questions, and the field picker groups fields by branch.

25 June 2026 — Blockchain-address attachments

What's new

  • Attachments on a blockchain address. A blockchain address now has its own Attachments section, just like profiles — upload supporting documents (PDFs or images), classify each by type (Screening Report, Transaction Record, Ownership Verification, or Other), and keep per-attachment notes, each gated by your role's permissions.

What's improved

  • Shared attachments component. Profile and address attachments now run on one shared component, so they look and behave identically and improve together. (A role granted attachment access without attachment-note access will now see note actions disabled.)

24 June 2026 — Comply AI on intake forms, and an optional address group

What's new

  • Comply AI on intake-form pages. The Comply AI assistant is now available on intake-form pages — both a form's detail page and the form editor — so you can ask about a form while building or reviewing it, the same way you already can on profiles, alerts, and blockchain addresses.

What's fixed

  • Choosing a group is optional. You can save a blockchain address without a group, matching the rest of the platform, and clear a previously assigned group back to none from the address Overview.

16 June 2026 — Blockchain-address groups, and "Profile Groups" becomes "Groups"

What's new

  • Addresses belong to a group. Blockchain addresses now belong to a governing Group, the same way profiles do. When you add an address on its own you choose its group (auto-selected when your org has only one), and that group drives the address's risk thresholds and screening schedule; addresses created within a profile inherit that profile's group. The group shows as an editable, linked row in the address Overview and follows the usual edit-and-save and rationale rules.
  • Deep links switch organization for you. Opening a link or bookmark to a profile, blockchain address, alert, intake form, or group that lives in a different organization now switches your active organization automatically to open it, instead of failing to load.

What's improved

  • "Profile Groups" is now simply "Groups." The feature is renamed across the app — every "Profile Group" label, and the settings section, now reads "Groups," and its settings page moved from /settings/profile-groups to /settings/groups (old links redirect automatically). Now that both profiles and blockchain addresses belong to one, the shorter name fits what the feature actually governs.

What to watch

  • For API and AI-tool users, this is a breaking rename. The same change renames the API and MCP surface: the .../profile-groups/ endpoint becomes .../groups/; fields rename (profile_groupgroup, profile_group_namegroup_name, profile_groups_urlgroups_url); the ?profile_group__in= / analytics ?profile_group= filters become ?group__in= / ?group=; profile_screening_min_score becomes screening_min_score; the profile_group.* permissions become group.*; and the MCP tools profile_group_* become group_*. Anything hard-coding the old paths, fields, permissions, or tool names must update. (The intake-form survey key ca_profile_group is intentionally unchanged.)

12 June 2026 — Dropdowns open in front of dialogs

What's fixed

  • Selection dropdowns always appear in front. The risk-threshold editor and the risk-engine group and blockchain-address dialogs previously opened their dropdowns behind the dialog, leaving options invisible and unclickable. They now always open in front.

11 June 2026 — Branded error pages, and long notes no longer vanish

What's new

  • Branded error pages. When a page can't be found or something goes wrong — a missing profile or address, a broken link, or a server error — you now see a clear, branded in-app screen (including a dedicated "not found" page for a record that doesn't exist) instead of a blank or raw browser error.

What's fixed

  • Pasting a long note no longer saves an empty one. The character counter now always reflects the editor; when the text exceeds the limit it turns red and disables save until trimmed. The limit was doubled to 10,000 characters so longer compliance notes fit.

9 June 2026 — Live change highlights and custom profile fields

What's new

  • Live change highlights. When a teammate, an AI assistant, or an automated screening updates a profile or address, the exact fields, sections, tabs, badges, and rows that changed briefly flash so you can see what moved. Highlights are scoped to the record you're viewing and never flash your own edits.
  • Custom profile fields. Custom fields configured for your organization now appear in a profile's Primary Party Information alongside the standard fields — shown in read mode, editable inline, and captured automatically from matching intake-form questions.
  • Submission confirmation page. After submitting any intake form (public or invitation-only), the submitter sees a branded "received securely" confirmation instead of the form quietly resetting.

What's fixed

  • Blockchain picker shows networks again — the "Select blockchain" dropdown opens in front of the dialog and table filter panel, so the list of networks is visible when adding an address, in profile creation, and when filtering the address table.

4 June 2026 — Stay signed in, notification types, and alert rationale

What's new

  • New notification types. The notification center now recognizes alert-closed notifications, intake-form profile-onboarding notifications, and split private/public intake-invitation events.

What's improved

  • Alert assignment rationale. Assigning an alert to another reviewer now captures a short rationale, delivered with their notification and shared with the take-over flow. Self-assignment is unchanged.
  • Live refresh after profile edits. Editing a profile automatically refreshes its screening status and compliance health, without a manual reload.
  • Streamlined profile Actions menu — the redundant "Edit Profile" and "Screening hits" shortcuts (which just jumped to views already on the page) were removed.

What's fixed

  • Stay signed in. The app now refreshes an expired session in the background instead of signing you out after a few minutes of normal use.
  • KYC document links open the file from an alert's side panel, instead of an internal API page.
  • Duplicate wallet address flagged inline on the address field with a clear message, rather than only as a passing error.

30 May 2026 — Request for Information, redesigned

What's new

  • Redesigned RFI workflow. "Send RFI" and "View RFIs" live on the profile Actions menu, gated by dedicated RFI permissions. The request form is schema-driven, and a history drawer shows every RFI sent for a profile along with what was requested.
  • Response review and adjudication. When a client responds, a review banner appears on the profile; reviewers see each submitted answer next to its current value and accept or reject it item by item — nothing changes on the profile until they do.
  • Email preview. The send modal can preview the exact email before it goes out, and the history drawer can reopen the email that was already sent.

What's fixed

  • Periodic code security audit completed.

28 May 2026 — Redesigned alerts workflow

What's new

  • Alert detail page. Each alert opens to a dedicated detail page sized for the decision: watchlist alerts get a hit-by-hit comparison panel; blockchain-address alerts get a risk-change breakdown with new exposures highlighted. A side panel collects the alert's audit trail, decision form, and related alerts, and the lifecycle actions — Claim, Assign, Unassign, Close (with disposition), Escalate (with recipient + reason) — are grouped on the alert header.
  • Profile Alerts tab. The profile page has a new Alerts tab listing every alert linked to the profile, plus a banner summarizing open alerts for related parties (UBOs, controllers, officers) so an EDD reviewer can pivot laterally without leaving the profile.

What's improved

  • Alerts list with inline filtering. The alerts list surfaces risk tier, sanctions/PEP/adverse-media flags, and watchlist source name as filterable columns.
  • Take-over requires a rationale. Taking over an alert assigned to another analyst now requires a written justification, recorded on the audit log.

26 May 2026 — Reliable loads and quicker tab counters

A smaller follow-up: a fix so a freshly published release is always picked up on the next visit, plus faster tab counters on profile pages.

What's new

  • Notes and attachments counts up front. Profile pages now show how many notes and attachments are attached on the tab labels without first downloading the full lists, so the counters appear immediately.

What's fixed

  • No more blank pages after a release. After a new release goes out, opening a deep link such as /login or a specific profile page used to occasionally serve a stale, blank screen for a few minutes. The latest release is now picked up immediately on the next visit.
  • Profile status changes from the overview save correctly. Editing the Review Status or Relationship Status from the profile overview now persists — previously the success message appeared but the value silently reverted on refresh.

22 May 2026 — Cross-profile analysis via your AI assistant

A major expansion of what your AI assistant — Comply AI in-app, or any external tool like Claude or ChatGPT connected via MCP — can do across your organization's records, plus a couple of UI-visible improvements to profile creation and archiving.

The capabilities listed under What you can ask your AI assistant are not buttons in the app. They become available when you talk to Comply AI in-app, or to any MCP-connected AI tool such as Claude Desktop or ChatGPT. See the MCP integration guide.

What you can ask your AI assistant

  • Bulk profile review at a glance. Ask your AI assistant to pull a full table of profiles in your organization — with wallet, watchlist, adverse-media, and RFI data joined inline — in a single request. Reviewing hundreds of profiles is dramatically faster than reconciling four separate views by hand.
  • Stuck-RFI detection. Ask your AI assistant to flag profiles that are currently in RFI Sent status but have no RFI actually dispatched since they entered that status — catching the case where status was flipped manually without ever sending the request.
  • Duplicate detection. Ask your AI assistant to surface profiles that share a phone number, an email domain, or a bio URL (with normalization), grouping them as clusters that may indicate coordinated registrations or proxy accounts.
  • Identity-signal detection. Ask your AI assistant to flag credential anomalies — an email handle that looks like a phone number, a generic English first-name handle on a company domain, a handle that appears in another profile's name — as leads to investigate, each with a low / medium / high confidence indicator.
  • Bulk actions at scale. Through your AI assistant, move up to 100 profiles to a new review status in a single step (the system walks each profile through the legal path of the status workflow), or add the same note to up to 500 profiles at once.
  • Tag operations. Your AI assistant can now add, remove, or replace tags on profiles — strip every existing tag and install a new set, or remove a specific subset, in one call.
  • Analytics drill-down. When you ask your AI assistant for an analytics summary, it can now break results down by profile group or risk level in the same answer.

What's new in the app

  • Provision a profile in one step. A profile can be fully set up at the moment you create it — schedule, screening configuration, tags, and rationale included — with no follow-up edit required.
  • Archive from any status. A profile can now be archived from any review status, instead of needing to be walked through intermediate transitions first.

What's improved

  • Unified screening results. Watchlist, sanctions, and PEP results from every screening provider now look the same on screen, so a hit from one provider reads the same as a hit from another.
  • Faster cold loads. The first page you open after a period of inactivity now loads noticeably faster.
  • Faster analytics dashboards. Organization analytics now load faster, especially when several teammates are viewing the same dashboard at the same time.
  • Polished notification emails. Notification emails refreshed for clarity, and admins can now configure many notification events in a single step instead of one at a time.

What's fixed

  • No more false Profile Approved notifications during bulk updates. If a bulk status change ran into a problem mid-way and rolled back, you could still receive notifications for the intermediate steps that didn't actually stick. Notifications now only fire after the change has fully completed.
  • Invalid status transitions are blocked everywhere. A few less-common ways of updating a profile (through an API key or an AI tool) could previously skip the validation that prevents illegal status changes (for example, jumping straight from Pending Review to Approved without a review). Those paths now apply the same validation as the web app.
  • Faster loading on profiles with many notes. Notes lists on profiles with hundreds of notes now load quickly, instead of trying to fetch the full set at once.
  • Threshold-update notifications no longer slow down on large organizations. When a risk threshold changes in an organization with many members, sending out the resulting notifications is now noticeably faster.

15 May 2026 — Live updates everywhere

Profiles, alerts, blockchain addresses, notes, and tags now refresh in place whenever something changes — without a page reload.

What's new

  • Live updates across the app. Edits land instantly across every connected session: when a teammate makes a change in another tab, when an MCP client (Claude Desktop, Comply AI, etc.) updates a record, when an automated screening completes, or when an external integration posts an update, the affected views re-fetch the moment the change lands.
  • No unnecessary re-fetches on your own edits. Your own tab does not refresh again on changes you just made — only changes from other people, AI tools, or integrations trigger a refresh in your view.
  • Rationale enforcement everywhere. Audit-rationale requirements are now applied the same way regardless of channel — the web app, AI tools, and external integrations all run the same check. The rule also applies to Review Status and Relationship Status transitions, not only field edits.

What's improved

  • Audit log attributes API-key activity to the right person. Changes made through a per-user API key now record the key's owner as the actor in audit logs, instead of attributing them to the system. Audit dashboards filtering for system-actor entries to find API-key activity may need to be reviewed.

14 May 2026 — Comply AI assistant and external AI tools

The launch of the in-app AI assistant, a way to connect outside AI tools, and a major sign-in refresh.

What's new

  • Comply AI assistant. Ask compliance questions in plain language — "which high-risk profiles do we have?", "show me open alerts assigned to me", "summarize this entity's blockchain exposure" — and get answers drawn from real CryptoComply records, never guessed. Responses stream back in real time, with each step the assistant takes (the tools it called, the records it consulted) shown inline in a collapsible track so analysts can audit the reasoning, not just the answer.
  • Conversations saved per user. Conversations are saved per user per organization, automatically titled, and searchable. Return to any past session from the sidebar, rename it, or pick up where you left off.
  • Edit and regenerate. Any previous message in a conversation can be edited; the assistant regenerates its response from that point without starting a new conversation.
  • Cancel in-progress responses. A cancel button appears while the assistant is generating, so a long response can be interrupted at any time.
  • Feedback on every answer. Thumbs-up and thumbs-down on individual responses help improve answer quality.
  • Markdown formatting. Assistant responses render full markdown — headers, lists, bold, code blocks, and tables — instead of plain text.
  • Connect external AI tools. Tools like Claude Desktop, Claude Code, claude.ai, ChatGPT, and Goose can now connect securely to CryptoComply over the internet. Each tool signs in as a real user through the browser, inherits that user's permissions and organization memberships, and operates on real records.
  • Write actions require explicit confirmation. When an external AI tool tries to update a profile, add a note, resolve an alert, or change anything else, the action is shown for review before it touches the database. Approval is required every time; AI tools cannot silently mutate data.
  • Profile, alert, address, RFI, screening, and tag operations from AI tools. External AI clients can browse, filter, view, and update profiles (with status, screening progress, and risk history available), browse and resolve alerts, manage blockchain addresses (with full exposure breakdowns), create RFIs, trigger screenings, and create or assign tags.
  • Notification subscription audit. Org admins can see from Settings → Notifications who in their organization receives each notification type and through which channels, in two views: by event (every notification with the subscribers who will receive it) and by user (any member's full notification matrix at a glance).

What's improved

  • Sign-in screen shows the active account. The sign-in screen now displays the logged-in user's email prominently, with a Not you? Switch user link to sign in as a different account without leaving the flow.

What's fixed

  • Google sign-in restored. Sign-in with Google was being hidden by a default template; the button now works correctly on both the login and authorization pages.

Heads up

  • /dashboard prefix dropped. Web addresses no longer carry the /dashboard prefix — old bookmarks continue to work via automatic redirect.
  • Previous chat assistant replaced. The earlier AI chat (which routed messages through an external workflow service) has been retired in favor of the new in-app assistant. Existing conversations were migrated automatically — no user action required.
  • Some personal notifications no longer configurable. Alert assigned to you and the bulk-invitation completion notice no longer appear in notification settings — they always fire to the targeted user.

19 April 2026 — Tags across profiles and addresses, redesigned tables

A unified tagging system across profiles and blockchain addresses, plus a refreshed table experience with multi-column sort and column drag.

What's new

  • Tags page in Settings. A new Tags page at Settings → Tags lets administrators create and manage tags for both blockchain addresses and profiles from one place, with separate tabs for each entity type. Tags can be named, color-coded from an 8-color palette (gray, red, orange, amber, green, blue, slate, purple), and described. Platform-global tags are visible but cannot be edited or deleted.
  • Tag profiles. Profiles can now be tagged the same way blockchain addresses can — tags are assigned from the profile overview panel, and tag pills appear directly in the profiles list. Existing blockchain-address tags default to gray and look exactly as before.
  • Bulk tag assignment. Select multiple profiles in the profiles table and click Assign Tags to apply tags to all of them in one action. The same toolbar button is now available on the blockchain addresses table for consistency.
  • Tags when creating a blockchain address. Tags can be picked or created inline directly from the Add Blockchain Address modal, so the address comes out tagged on creation without a follow-up edit.
  • Search by tag. The blockchain address search now matches against tag names in addition to name, address, blockchain, and linked profile — typing exchange surfaces every address tagged Exchange.
  • Multi-column sort. Click any column header to add it to the sort; a small number next to the arrow (1, 2, 3…) shows sort priority. Clicking the same column again cycles through ascending, descending, and removed.
  • Drag-to-reorder columns. Column titles double as drag handles. The per-column options menu was removed since sorting and reordering are now direct actions on the header.
  • Type badge on profiles. The profile list now shows a Type badge (Individual / Entity) for quick visual scanning.
  • Richer identity fields on individuals. Individual profiles can now capture first name, middle name, last name, phone, bio, Bio URL, SSN, driver's license (number and state), passport (number and expiration date), and alien registration number. Each field can be shown or hidden per Profile Group from Settings → Profile Groups → Visibility.
  • URLs render as clickable links. Bio URL and other URL fields are now clickable in read-only mode; clicking shows a confirmation dialog warning that the user is about to leave CryptoComply before opening the external site in a new tab.

What's improved

  • Redesigned column headers. The sort arrow now sits to the right of the title and only appears on hover or when the column is actively sorted.
  • Smarter horizontal space. Extra column width is now absorbed by the main content column (e.g. Name) instead of being spread across every column. The selection-checkbox column takes less width.
  • Highlighted selected rows. Selected rows now show a subtle accent color so it is easy to see which rows are checked at a glance.
  • Independent sidebar scrolling. The sidebar menu now scrolls independently when Settings is expanded with many items, so the user card at the bottom is always visible.
  • Hidden fields with data are flagged. A warning icon now appears next to any profile field that is shown even though the Profile Group config marks it hidden, because the field contains data — the tooltip explains the override.
  • Per-item errors on bulk tag assignment. When a bulk tag assignment partially fails, the error now points to the specific addresses or tags that caused the problem, instead of failing the whole action silently.
  • Clearer errors when deleting a tag in use. Deleting a tag that is still assigned somewhere now tells you how many assignments need to be removed first, instead of erroring out.

What's fixed

  • Consistent profiles-table column widths. Status, Type, Group, and Date columns in the profiles table now use preset widths for consistent layout.

Heads up

  • The new identity fields are hidden by default in existing profile groups. Organizations that want first name, middle name, last name, phone, bio, Bio URL, SSN, driver's license, passport, and alien-registration fields to display must enable each one per profile group from the profile group settings page. Newly created profile groups are unaffected.
  • Changes to the new identity fields require a rationale. The new identity fields are tracked in the audit log and require a rationale on change, matching the treatment of the other tracked identity fields on individual profiles.
  • Tag settings URL simplified. The Tags settings page is now at /settings/tags; the previous /settings/blockchain-address-tags link redirects.

14 April 2026 — Notifications, intake forms, and AI-powered adverse media

A notification center, full intake-form management, AI-powered adverse-media screening, and the first round of screening real-time feedback.

What's new

  • Notification center. An in-app inbox plus email for key events — alerts assigned to you, alerts escalated, profile onboarded / approved / declined / escalated, form submissions received or failed, bulk-invitation sends completed, RFI responses received, and new blockchain addresses. Each user picks the channels per event from Settings → Notification Preferences; org admins can make selected events mandatory from Settings → Notification Events. The bell icon shows unread counts in real time and clicking a notification opens the related record.
  • Intake forms. A new dashboard section to manage open and invitation-only intake forms. View submission stats and response rates, send invitations individually or in bulk (up to 1,000 per request — via paste or CSV), resend invitations to extend expiration, and revoke access. Bulk sends are processed in the background with a summary email when complete. Forms come with full lifecycle tracking on every invitation: Sent, Accessed, Submitted, or Revoked.
  • Intake form settings in-app. Organization administrators can edit form settings directly — name, active toggle, invitation and reminder email subjects, how long invitations stay valid (1 to 365 days), and an optional closing date — without involving CryptoComply staff.
  • Invitation reminders. Send reminder emails in bulk to invitees who have received but not yet submitted via the Send Reminders action. Reminders skip anyone who has already submitted or whose link was revoked. Each invitation tracks how many reminders have been sent and when the last one went out, visible in the invitations table.
  • Adverse-media screening. AI-generated adverse-media reports on the profile page, with collapsible sections for overview, identity, warnings, deep-dive analysis, and cited sources with tiered confidence. The same report is accessible as a modal from the Actions dropdown. Profiles created via intake form submissions are now automatically screened for adverse media — and for watchlist hits — on submission, with no waiting for the next scheduled run.
  • Real-time screening progress. The Profile Screening tab now shows a live indicator during active screenings — a pulsing dot, the current step, and a mini progress bar that updates as the screening proceeds.
  • Clickable hit sources. URLs in the source list for screening hits now render as clickable external links instead of plain text.

What's improved

  • Mandatory notifications for critical events. Time-sensitive events that require immediate attention — alerts escalated and intake-form submission failures — are now mandatory by default at the platform level so they are never missed. Organization admins can still override any event in either direction.
  • Initial screening on profile creation. Newly created profiles now trigger an initial screening immediately when they have a full legal name, instead of waiting for the next update.
  • Long screenings no longer delay emails. Screenings and notifications now run independently, so a long-running screening cannot delay time-sensitive emails like form submission confirmations or alert assignments.
  • "Powered by CryptoComply" footer on public forms. Public intake forms and RFI response forms now include a footer with links to the Privacy Policy and Terms of Service, so external respondents always have clear access to those terms.

What's fixed

  • Edit-note modal shows existing content. Opening the edit-note modal now displays the existing note text instead of an empty editor.
  • Screening hit details render reliably across providers. A field in a screening hit that previously appeared blank for some providers now displays correctly regardless of the provider, so analysts see the same level of detail no matter where the hit came from.
  • Adverse-media warning details render reliably. Warning details on adverse-media reports now display correctly in every case, including when the underlying AI engine returns its sources or match factors in less structured forms.
  • Re-invite after submission. Once a recipient has submitted their response, the form can now send them a new invitation to the same email — the previous duplicate-email check no longer blocks re-invitation after the original was answered.
  • Profile sorting by Type. Sorting the profiles list by Type (individual / entity) now works correctly.
  • Tag list no longer fails to load. A rare condition that could prevent the tag list from loading is resolved.

23 March 2026 — Sequential navigation, screening history, and World-Check

Faster navigation between table results, a full screening-history timeline with comparison, exportable data, and a new screening provider.

What's new

  • Sequential navigation. After opening a profile, blockchain address, or alert from a filtered table, navigate between results using prev / next arrows or the left/right keyboard arrow keys — without returning to the table. A position indicator (e.g. 3 / 47) shows where you are in the list, and a dropdown lets you jump to any item on the current page. The next or previous page loads automatically when reaching the boundary.
  • Data export. Profiles, blockchain addresses, and alerts tables now support exporting data to CSV or JSON. Select specific rows or export all filtered results, choose which fields to include, and pick the output format. Exports run in the background — a notification with an automatic download appears when the file is ready. Up to 10,000 rows at a time.
  • Screening history timeline. Blockchain address pages now display a visual timeline of all past screenings, with total exposure over time and risk-colored segments. Click any point on the chart to view that screening's risk analysis and address identifications. Same-day screenings are grouped with a count badge — click it to pick individual screenings.
  • Side-by-side inquiry comparison. Compare any two screenings to see exactly what changed: risk level changes, exposure deltas per counterparty category with row highlighting, and address-identification differences. Select two points on the timeline with the Compare button, or use Compare with latest on the historical-screening banner for the most common case.
  • Editable blockchain address. The blockchain address field in the overview section is now editable, following the same edit-and-save flow as the name and other fields.
  • World-Check screening. World-Check One (LSEG) is now available as a screening provider for both individuals and entities, including passport-check support. Organizations configure their World-Check credentials from Settings → Organization → Vendor Integrations.

What's improved

  • Server-side blockchain-address export. Blockchain-address export no longer runs in the browser. Larger datasets export reliably without browser performance issues.
  • Consistent row-selection. Checkboxes for row selection are now consistent across profiles, blockchain addresses, and alerts tables.
  • Consistent date formatting. All dates use the same display style throughout tables, PDFs, notes, and alert headers.
  • Inquiry context built in. The blockchain address detail now embeds a summary of the last screening inquiry (risk level, status, type, date) directly, so basic screening info appears without an extra load.
  • Total USD exposure in inquiries. Screening inquiries now include the total USD exposure, giving analysts a quick financial-risk summary without opening the full result.
  • Risk-change inquiry filter. A new changes only filter on screening history lets you view only the screenings that produced a risk change, making it easier to track risk progression.

What's fixed

  • No data badge on blockchain addresses with no screening data. A blockchain address that has not yet been screened now shows a clear No data badge, instead of appearing blank.
  • Address association tags reappear after a screening update. Address association tags that briefly disappeared after a screening update due to a renamed underlying field are now visible again.
  • Wallet screening results load when provider data is incomplete. Wallet screening results now load even when the screening provider's response is missing or incomplete on a particular run.
  • Negative-news alerts send email notifications. Email notifications for negative-news alerts now go out correctly.
  • Profile status changes work on older profiles. Profile status changes no longer break for profiles that were created before earlier product updates.
  • Role permissions always show as a list. A role page that occasionally appeared to show no permissions now always lists them correctly.
  • Faster profile detail pages with many related parties. Profile pages with many related parties now load noticeably faster.

2 March 2026 — Audit trails, compliance dashboards, and the risk engine

A comprehensive audit-log redesign, configurable rationale enforcement, organization-wide compliance dashboards, automated health checks, in-app risk-threshold management, and full configurability of profile groups.

What's new

  • Profile PDF reports. Configurable PDF report generation for profiles, with per-section toggles, a preview before download, and audit-trail limit settings. Available from the profile Actions dropdown.
  • Redesigned audit log. A new audit log table with expandable rows, detailed field-level changes (before / after values), filtering by action or actor, and CSV / JSON export. Available for both profiles and blockchain addresses, with visual diff highlighting and rationale tracking.
  • Rationale enforcement. When updating a profile or blockchain address, users are now required to provide a rationale — a written justification — on fields configured by their organization. Changes without a rationale are rejected with a clear message indicating which fields need justification.
  • Audit Settings page. A new page at Settings → Audit lets compliance teams pick which profile and blockchain-address fields require a rationale when changed, giving control over change-justification policies per entity type.
  • Section-based edit mode. Profile and blockchain-address overview sections now support batch editing — edit multiple fields in a section at once and save them as a group via the section's Edit / Save / Cancel controls.
  • Profile Group redesign. Redesigned Settings → Profile Groups → Details page with tabbed settings: Ongoing Screening (per-risk-level frequencies with colored badges), Sections Visibility (toggle visibility of entire sections and individual fields per Individual / Entity), Exposure Risk Thresholds (interactive range sliders with cascade logic), and Address Identification Risks (override default risk levels per category). Screening-frequency tooltips on profile and blockchain-address pages now indicate whether the frequency was set manually or inherited from the profile group.
  • Organization dashboard. A new dashboard with two tabs giving an organization-wide view of compliance operations: Overview — snapshot metrics including total profiles, open alerts, review-pipeline distribution, alerts-per-month chart with the organization creation marker, and stale-profile detection — and Analytics — period-based breakdowns for profiles, blockchain addresses, alerts, exposure categories, and review activity with configurable date range and active-only filtering.
  • Compliance Health. A new diagnostic page at Settings → Compliance Health runs 8 automated checks across profiles, blockchain addresses, and configuration to surface compliance gaps. Each check shows severity (critical, high, medium, low), affected item count, and a suggested action. Filterable by severity and category.
  • Organization Settings page. A new page at Settings → Organization to manage organization profile, API keys, and vendor integrations: update organization name and logo (with image cropping), create / edit / enable / disable external API keys for screening vendors (Chainalysis, TRM, OpenSanctions), see usage analytics per key, assign API keys to active vendor integrations, and view active wallet and watchlist screening services.
  • Risk Engine Settings. A centralized page at Settings → Risk Engine to view and manage exposure-risk thresholds across three scopes: Organization (set organization-wide defaults), Profile Groups (override per group), and Blockchain Addresses (override per address). Interactive slider editor with drag-to-adjust breakpoints. Import and export thresholds in JSON or CSV.
  • Quick threshold view on addresses. A threshold-settings icon on blockchain-address exposure tables opens a slide-out panel showing the active risk thresholds for that address.

What's improved

  • Refreshed profile overview. Profile overview sections (Primary Party, PEP, Business Regulatory, Expected Transaction Activity) now use Edit / Save / Cancel controls per section. Blockchain-address overview (name, screening frequency, tags) uses the same section edit mode with batch save.
  • Profile group is a link. The Profile Group badge on the profile overview is now a clickable link to the profile group settings.
  • Real-time risk recalculation. Profile and blockchain-address risk ratings refresh automatically when exposure risk thresholds or screening schedules are updated.
  • Sidebar adapts to your permissions. The Settings section in the sidebar now shows only the items you have access to, based on your role.
  • Flexible logo cropping. The organization logo cropper now supports non-circular crops and configurable output formats.
  • Activity-log readability. Profile and blockchain-address activity logs now show structured entries with actor details and human-readable descriptions, including all historical audit records.

What's fixed

  • Screening results refresh after a threshold change. When you update risk thresholds at any scope (organization, profile group, or blockchain address), recently shown screening results now update on screen without needing a manual refresh.
  • Status updates from the profile overview enforce rationale rules. Changing Review Status or Relationship Status directly from the profile overview now correctly requires a rationale when your organization has configured one, matching the rest of the app.
  • Analytics card labels. Analytics breakdown cards now read Profiles Onboarded, Blockchain Addresses Added, and Alerts Created to match the summary stat cards above them.
  • Activity-log actor display. Activity-log entries from automated actions or external systems now display the actor information correctly, instead of appearing as missing.

Looking for older releases? See the What's New archive — February 2026 and earlier.