CLOAK Terminal is live
Skip to content

Technology

How CLOAK reads the chain.

CLOAK is an analysis layer over public Solana data. It fetches what anyone could fetch, normalizes it, and turns it into explainable findings. No private data sets, no guesses presented as facts, no access to your keys.

At a glance

Data source
Helius · public data
Methodology
cloak-index/1.0
Index components
7
Graph cap
80 nodes

01 — Architecture

Server-side, read-only, bounded.

  1. A

    Your browser

    Sends a public address. Keys, signatures and approvals never enter the flow.

  2. B

    CLOAK API

    Validates every request with Zod, rejects anything that looks like a secret, applies per-IP rate limits.

  3. C

    Helius

    Parsed Events for history, DAS getAssetsByOwner for balances, Wallet API identity for public labels on paid plans.

  4. D

    Analysis engine

    Normalizes transactions, maps counterparties, builds Wallet DNA, signals and the CLOAK Index — deterministically.

  5. E

    Intelligence report

    Streams back stage by stage. Exportable as PDF or JSON; history stays in your browser.

Transaction history
Helius Parsed Events, newest first, paginated 100 at a time and bounded to the configured window (300 by default, hard ceiling 500).
Balances
DAS getAssetsByOwner with fungible tokens and native balance. Prices are shown only when the provider publishes one.
Public labels
Wallet API batch identity on paid Helius plans. Without it the labeling component is marked not evaluated — never assumed clean.
API keys
Held server-side only. The browser talks to CLOAK; it never sees a provider key.
Validation
Requests and provider responses are schema-validated with Zod before any analysis runs.
Caching
Short-lived in-memory cache with LRU eviction to avoid refetching the same public data.
Rate limits
Per-IP token buckets on scans and reads. Transient provider errors are retried with backoff.

02 — Analysis layers

Five layers, one report.

  1. 01

    Scan

    CLOAK Scanner

    Fetches a bounded window of public history and current balances for one address, then normalizes every transaction into a stable internal model so live and demo data travel through identical code.

  2. 02

    Signals

    Wallet DNA & Exposure Signals

    Builds a behavioral profile — a 24 × 7 activity matrix, cadence, program mix and trading patterns — and derives exposure signals. Each signal carries severity, confidence, the evidence transactions, its limitation and a recommendation.

  3. 03

    Trace

    Trace Map

    Draws the relationship graph from observed transfer legs only: who sent to whom, how often and how much. Optional second hop for the strongest relationships, under hard caps.

  4. 04

    Index

    CLOAK Index

    Combines seven explainable components into a single 0–100 exposure index. Every point is attributable to a component with a written basis.

  5. 05

    Recommend

    Privacy Mode

    Turns findings into educational practices — wallet separation, fresh receiving addresses, funding hygiene — that reduce future linkability. They do not change what is already public.

03 — Methodology · cloak-index/1.0

The CLOAK Index.

An observational exposure index from 0 to 100. Higher means more exposure indicators were observed in the analyzed dataset. It is pure and deterministic: the same inputs always produce the same index.

  • Visible holdings15Fungible tokens, NFTs (counted as half) and a non-zero SOL balance readable at the address.Saturates at 10 units
  • Repeated counterparties20Counterparties that share at least 3 transactions with the wallet.Saturates at 6 counterparties
  • Relationship concentration15Share of transfer interactions held by the top three counterparties.Evaluated from 5 interactions
  • Activity rhythm15Share of timestamped activity inside the busiest 4-hour UTC window, scaled against the uniform baseline of 4/24 (≈17%).Evaluated from 10 timestamped tx
  • Program footprint10Distinct programs used, excluding infrastructure programs nearly every transaction touches (System, Token, Compute Budget and similar).Saturates at 10 programs
  • Public trading15Swaps observed in the analyzed window — entries, exits and token choices are public.Saturates at 15 swaps
  • Public labeling10Transactions with publicly labeled counterparties, or a public label on the analyzed address itself.Saturates at 5 tx · needs a label source
Total weight100

Formula

index = round( Σ (wᵢ × sᵢ) / Σ wᵢ × 100 )

Each component maps one indicator to a strength sᵢ between 0 and 1. The sums run over evaluable components only. A component that cannot be evaluated is excluded and its weight is not counted as zero — missing data never makes a wallet look private.

Insufficient data

  • Fewer than 10 successful, timestamped transactions in the analyzed window.
  • Less than 60% of total indicator weight could be evaluated.
  • In either case the report shows INSUFFICIENT DATA with the reason, instead of a number.

Bands

  1. 0–24

    low

  2. 25–49

    moderate

  3. 50–74

    elevated

  4. 75–100

    high

What the index is not

  • Not a privacy certification

    A low value means fewer indicators were observed in this window — not that the wallet is private.

  • Not a security rating

    It says nothing about key safety, contract risk or whether funds are secure.

  • Not identity attribution

    It never states or implies who owns an address.

04 — Signal rules

What counts, and what never does.

  • Dust is ignored

    Native transfers below 0.00001 SOL are dropped. They are overwhelmingly address-poisoning spam and would invent relationships the owner never chose.

  • Venues are not counterparties

    Swap and liquidity legs are attributed to the trading venue, not to the wallets on the other side of a pool.

  • Infrastructure is excluded

    Programs nearly every transaction touches (System, Token, Compute Budget, memo) are not counted as behavior.

  • No fabricated links

    Relationships come from observed transfer legs only. CLOAK never infers that two addresses share an owner.

  • Labels name their source

    A label is shown only when the data provider asserts it, and the source is always stated. CLOAK never invents one.

Trace Map limits

Max nodes
80
Max first-hop nodes
40
Second-hop seeds
5
Nodes per seed
6
Tx read per seed
50
Evidence per edge
4

When a cap removes observed relationships, the report marks the graph as truncated.

05 — Limitations

What CLOAK cannot see.

  • L.01

    Only a bounded window of recent history is analyzed. Older activity can carry exposure the report does not reflect.

  • L.02

    Off-chain records — exchange accounts, IP addresses, KYC data — are invisible to CLOAK but may be visible to others.

  • L.03

    Public labels depend on the data provider and plan. Without a label source, the labeling component is not evaluated.

  • L.04

    Provider parsing can be incomplete for new or unusual programs; such transactions are classified as program or unknown activity.

  • L.05

    Signals describe observable patterns. They are not proof of identity, intent or ownership.

  • L.06

    The index is a methodology, not a measurement of truth. It is versioned so changes stay visible.

Methodology cloak-index/1.0Data · Helius

Read the method. Then read your wallet.