Product · Chitin
Chitin
Reduces AML alert fatigue by suppressing low-confidence false positives, without touching the volume or clarity of genuine risk alerts.
The problem
Transaction-monitoring systems flag a large number of events that analysts must review. In practice, most of those alerts are false positives. Teams spend their time clearing noise; genuine risk is easier to miss when it sits in the same queue.
That is a documented operations problem, not a new discovery. Adding another detector on top of the same rules usually adds more alerts. The useful job is to take alerts a legacy system already produced and decide which ones do not need a person.
How it works
Calibrated suppression
- Score every alert. Each incoming alert receives a confidence score: how likely it is to be a false positive under the current, known operating regime.
- Lock the threshold on a calibration split. The suppress / review cutoff is set on held-out calibration data only. The evaluation split is not used to tune that threshold.
- Suppress likely false positives only. Alerts below the cutoff leave the analyst queue. Alerts that look like genuine risk stay in the queue at the same volume and with the same payload the source system already produced. Chitin does not rewrite or dilute those cases.
Chitin is an add-on in front of an existing monitoring stack, not a replacement detector. Thresholds stay frozen from the calibration split before any evaluation score is computed.
Scope
What this does — and what it does not
Current scope is alert-volume reduction: suppress low-confidence false positives when conditions look like the regime the system was calibrated on. That is the shipped product.
It is not a detector for novel or adversarial laundering patterns, and it is not dual-regime detection. Finding illicit activity the models have never seen — including after a structural break in how laundering looks — is a separate, ongoing research area. It is not a Chitin feature.
We state that here because a buyer should know the boundary before a demo, not after an incident.
Validation
Elliptic, under a chronological split
Elliptic
Public AML benchmark · held-out chronological evaluation · suppression of likely false positives
Chitin was evaluated on the Elliptic Bitcoin transaction dataset, using a chronological train / evaluate split so later time steps are not used to set thresholds. The claim under test is alert-volume reduction on that benchmark, not detection of unseen typologies after a regime break.
Tricombinator uses the same evaluation discipline — held-out splits, frozen thresholds, pre-registered claims — on the coding product (Sentinel Router) and in quantitative trading. Those are separate products. The public coding repo does not include Chitin.
Evaluate
Request a compliance review
For AML engineering, compliance, and accelerator or partner reviewers. Say whether you want a demo against your alert stream, a walkthrough of the eval protocol, or both.