Technology
How CLOAK reads the chain.
CLOAK is an analysis layer over public Solana data. It fetches what anyone could fetch, normalizes it, and turns it into explainable findings. No private data sets, no guesses presented as facts, no access to your keys.
At a glance
- Data source
- Helius · public data
- Methodology
- cloak-index/1.0
- Index components
- 7
- Graph cap
- 80 nodes
01 — Architecture
Server-side, read-only, bounded.
- A
Your browser
Sends a public address. Keys, signatures and approvals never enter the flow.
- B
CLOAK API
Validates every request with Zod, rejects anything that looks like a secret, applies per-IP rate limits.
- C
Helius
Parsed Events for history, DAS getAssetsByOwner for balances, Wallet API identity for public labels on paid plans.
- D
Analysis engine
Normalizes transactions, maps counterparties, builds Wallet DNA, signals and the CLOAK Index — deterministically.
- E
Intelligence report
Streams back stage by stage. Exportable as PDF or JSON; history stays in your browser.
- Transaction history
- Helius Parsed Events, newest first, paginated 100 at a time and bounded to the configured window (300 by default, hard ceiling 500).
- Balances
- DAS getAssetsByOwner with fungible tokens and native balance. Prices are shown only when the provider publishes one.
- Public labels
- Wallet API batch identity on paid Helius plans. Without it the labeling component is marked not evaluated — never assumed clean.
- API keys
- Held server-side only. The browser talks to CLOAK; it never sees a provider key.
- Validation
- Requests and provider responses are schema-validated with Zod before any analysis runs.
- Caching
- Short-lived in-memory cache with LRU eviction to avoid refetching the same public data.
- Rate limits
- Per-IP token buckets on scans and reads. Transient provider errors are retried with backoff.
02 — Analysis layers
Five layers, one report.
01
Scan
CLOAK Scanner
Fetches a bounded window of public history and current balances for one address, then normalizes every transaction into a stable internal model so live and demo data travel through identical code.
02
Signals
Wallet DNA & Exposure Signals
Builds a behavioral profile — a 24 × 7 activity matrix, cadence, program mix and trading patterns — and derives exposure signals. Each signal carries severity, confidence, the evidence transactions, its limitation and a recommendation.
03
Trace
Trace Map
Draws the relationship graph from observed transfer legs only: who sent to whom, how often and how much. Optional second hop for the strongest relationships, under hard caps.
04
Index
CLOAK Index
Combines seven explainable components into a single 0–100 exposure index. Every point is attributable to a component with a written basis.
05
Recommend
Privacy Mode
Turns findings into educational practices — wallet separation, fresh receiving addresses, funding hygiene — that reduce future linkability. They do not change what is already public.
03 — Methodology · cloak-index/1.0
The CLOAK Index.
An observational exposure index from 0 to 100. Higher means more exposure indicators were observed in the analyzed dataset. It is pure and deterministic: the same inputs always produce the same index.
- Visible holdings15Fungible tokens, NFTs (counted as half) and a non-zero SOL balance readable at the address.Saturates at 10 units15
- Repeated counterparties20Counterparties that share at least 3 transactions with the wallet.Saturates at 6 counterparties20
- Relationship concentration15Share of transfer interactions held by the top three counterparties.Evaluated from 5 interactions15
- Activity rhythm15Share of timestamped activity inside the busiest 4-hour UTC window, scaled against the uniform baseline of 4/24 (≈17%).Evaluated from 10 timestamped tx15
- Program footprint10Distinct programs used, excluding infrastructure programs nearly every transaction touches (System, Token, Compute Budget and similar).Saturates at 10 programs10
- Public trading15Swaps observed in the analyzed window — entries, exits and token choices are public.Saturates at 15 swaps15
- Public labeling10Transactions with publicly labeled counterparties, or a public label on the analyzed address itself.Saturates at 5 tx · needs a label source10
Formula
index = round( Σ (wᵢ × sᵢ) / Σ wᵢ × 100 )
Each component maps one indicator to a strength sᵢ between 0 and 1. The sums run over evaluable components only. A component that cannot be evaluated is excluded and its weight is not counted as zero — missing data never makes a wallet look private.
Insufficient data
- Fewer than 10 successful, timestamped transactions in the analyzed window.
- Less than 60% of total indicator weight could be evaluated.
- In either case the report shows INSUFFICIENT DATA with the reason, instead of a number.
Bands
0–24
low
25–49
moderate
50–74
elevated
75–100
high
What the index is not
Not a privacy certification
A low value means fewer indicators were observed in this window — not that the wallet is private.
Not a security rating
It says nothing about key safety, contract risk or whether funds are secure.
Not identity attribution
It never states or implies who owns an address.
04 — Signal rules
What counts, and what never does.
Dust is ignored
Native transfers below 0.00001 SOL are dropped. They are overwhelmingly address-poisoning spam and would invent relationships the owner never chose.
Venues are not counterparties
Swap and liquidity legs are attributed to the trading venue, not to the wallets on the other side of a pool.
Infrastructure is excluded
Programs nearly every transaction touches (System, Token, Compute Budget, memo) are not counted as behavior.
No fabricated links
Relationships come from observed transfer legs only. CLOAK never infers that two addresses share an owner.
Labels name their source
A label is shown only when the data provider asserts it, and the source is always stated. CLOAK never invents one.
Trace Map limits
- Max nodes
- 80
- Max first-hop nodes
- 40
- Second-hop seeds
- 5
- Nodes per seed
- 6
- Tx read per seed
- 50
- Evidence per edge
- 4
When a cap removes observed relationships, the report marks the graph as truncated.
05 — Limitations
What CLOAK cannot see.
- L.01
Only a bounded window of recent history is analyzed. Older activity can carry exposure the report does not reflect.
- L.02
Off-chain records — exchange accounts, IP addresses, KYC data — are invisible to CLOAK but may be visible to others.
- L.03
Public labels depend on the data provider and plan. Without a label source, the labeling component is not evaluated.
- L.04
Provider parsing can be incomplete for new or unusual programs; such transactions are classified as program or unknown activity.
- L.05
Signals describe observable patterns. They are not proof of identity, intent or ownership.
- L.06
The index is a methodology, not a measurement of truth. It is versioned so changes stay visible.
