Sanctscan
FreeNot checkedScreens counterparties and transactions against OFAC/EU/UN sanctions lists with fuzzy name matching and explainable hit scoring.
About
Screens counterparties and transactions against OFAC/EU/UN sanctions lists with fuzzy name matching and explainable hit scoring.
README
SANCTSCAN
Screens counterparties and transactions against OFAC/EU/UN sanctions lists with fuzzy name matching and explainable hit scoring.
PyPI CI License: COCL 1.0 Suite
Fintech & Payments Security — PCI, fraud, AML, and payment rails.
pip install cognis-sanctscan
sanctscan scan . # → prioritized findings in seconds
🔎 Example output
Real, reproducible output from the tool — runs offline:
$ sanctscan-emit --version
sanctscan 0.1.0
$ sanctscan-emit --help
usage: sanctscan [-h] [--version] {screen} ...
SANCTSCAN -- deterministic, auditable sanctions name-screening with explainable fuzzy matching.
positional arguments:
{screen}
screen Screen one or more names against a sanctions watchlist.
options:
-h, --help show this help message and exit
--version show program's version number and exit
Command-line interface for SANCTSCAN.
Examples:
# Screen a single name against an OFAC-style CSV watchlist
python -m sanctscan screen --watchlist demos/01-basic/watchlist.csv \
--name "Vladmir Putin"
# Screen a column of names from a CSV, emit JSON for CI / piping
python -m sanctscan screen -w watchlist.csv --input customers.csv \
--column full_name --format json --threshold 0.85
# Exit code is non-zero when any hit at/above the threshold is found,
# so it can gate a pipeline:
python -m sanctscan screen -w wl.csv -n "Some Name" || echo "FLAGGED"
Blocks above are real
sanctscanoutput — reproduce them from a clone.
Sample result format (illustrative values — run on your own data for real findings):
{
"timestamp": "2023-02-15T14:30:00Z",
"findings": [
{
"id": "1234567890abcdef",
"title": "Suspicious Network Traffic",
"description": "Potential malicious activity detected on port 443.",
"mitre_attack_id": ["T1204"],
"severity": "medium"
},
{
"id": "2345678901ghijkl",
"title": "Unusual File Access",
"description": "An unknown process accessed a sensitive file.",
"mitre_attack_id": ["T1003"],
"severity": "high"
}
]
}
Contents
- Why sanctscan? · Features · Quick start · Example · Architecture · AI stack · How it compares · Integrations · Install anywhere · Related · Contributing
Usage — step by step
sanctscan screens names against an OFAC/EU/UN-style watchlist (CSV or JSON) with explainable fuzzy matching. Exit is non-zero when any name is flagged at/above the threshold — so it can gate a pipeline.
Install
pip install sanctscanScreen a single name against a watchlist:
sanctscan screen --watchlist watchlist.csv --name "Vladmir Putin"Screen a column of names from a CSV (auto-detects the name column, or set
--column):sanctscan screen -w watchlist.csv --input customers.csv --column full_nameRead JSON output and tune the match
--threshold(0–1, default 0.80):sanctscan screen -w watchlist.csv -i customers.csv --format json --threshold 0.85 \ | jq '.flagged'Use in CI / batch — the flagged exit code gates the run:
sanctscan screen -w wl.csv -n "Some Name" || echo "FLAGGED"
Why sanctscan?
AML name-screening is dominated by $$ vendors; a CLI that pulls live OFAC SDN data and gives a deterministic, auditable match score with transliteration handling is highly forkable.
sanctscan is single-purpose, scriptable, and self-hostable: point it at a target, get prioritized results in the format your workflow already speaks (table · JSON · SARIF), gate CI on it, and let agents drive it over MCP.
Features
✅ Normalize Name
✅ Tokenize
✅ Name Similarity
✅ Load Watchlist
✅ Screen Name
✅ Screen Records
✅ Runs on Linux/macOS/Windows · Docker · devcontainer
✅ Ports in Python, JavaScript, Go, and Rust (
ports/)
Quick start
pip install cognis-sanctscan
sanctscan --version
sanctscan scan . # scan current project
sanctscan scan . --format json # machine-readable
sanctscan scan . --fail-on high # CI gate (non-zero exit)
Example
$ sanctscan scan .
[HIGH ] SAN-001 example finding (./src/app.py)
[MEDIUM ] SAN-002 another signal (./config.yaml)
2 findings · risk score 5 · 38ms
Architecture
flowchart LR
IN[target / manifest] --> P[sanctscan<br/>checks + rules]
P --> OUT[findings (JSON / SARIF)]
Use it from any AI stack
sanctscan is interoperable with every popular way of using AI:
MCP server —
sanctscan mcp(Claude Desktop, Cursor, Cognis.Studio, uncensored-fleet)OpenAI-compatible / JSON — pipe
sanctscan scan . --format jsoninto any agent or LLMLangChain · CrewAI · AutoGen · LlamaIndex — wrap the CLI/JSON as a tool in one line
CI / scripts — exit codes + SARIF for non-AI pipelines
How it compares
| | Cognis sanctscan | OpenSanctions |
|---|:---:|:---:|
| Self-hostable, no account | ✅ | varies |
| Single command, zero config | ✅ | ⚠️ |
| JSON + SARIF for CI | ✅ | varies |
| MCP-native (AI agents) | ✅ | ❌ |
| Polyglot ports (JS/Go/Rust) | ✅ | ❌ |
| Open license | ✅ COCL | varies |
Built in the spirit of OpenSanctions / yenta, re-framed the Cognis way. Missing a credit? Open a PR.
Integrations
Pipes into your stack: SARIF for code-scanning, JSON for anything, an MCP server (sanctscan mcp) for AI agents, and a webhook forwarder for SIEM/Slack/Jira. See docs/INTEGRATIONS.md.
Install — every way, every platform
pip install "git+https://github.com/cognis-digital/sanctscan.git" # pip (works today)
pipx install "git+https://github.com/cognis-digital/sanctscan.git" # isolated CLI
uv tool install "git+https://github.com/cognis-digital/sanctscan.git" # uv
pip install cognis-sanctscan # PyPI (when published)
docker run --rm ghcr.io/cognis-digital/sanctscan:latest --help # Docker
brew install cognis-digital/tap/sanctscan # Homebrew tap
curl -fsSL https://raw.githubusercontent.com/cognis-digital/sanctscan/main/install.sh | sh
| Linux | macOS | Windows | Docker | Cloud |
|---|---|---|---|---|
| scripts/setup-linux.sh | scripts/setup-macos.sh | scripts/setup-windows.ps1 | docker run ghcr.io/cognis-digital/sanctscan | DEPLOY.md (AWS/Azure/GCP/k8s) |
Related Cognis tools
panhound — Scans code, logs, fixtures, and S3 buckets for leaked PANs (Luhn-validated card numbers) and CVVs before they hit prod.
fraudlens — Replays a stream of transactions against pluggable fraud rules and ML scorers, emitting precision/recall and alert volume from the terminal.
obscan — Conformance and security linter for Open Banking / FAPI APIs: validates OAuth flows, consent scopes, and PSD2 endpoints against the spec.
ledgerproof — Verifies double-entry ledger integrity and tamper-evidence by checking balance invariants and hash-chained journal entries.
iso20022 — Validates, lints, and diffs ISO 20022 / pacs / camt payment messages and translates legacy MT into MX with schema-aware errors.
tokenvault — Self-hostable PCI tokenization microservice and CLI that swaps PANs for format-preserving tokens and proves no raw card data persists.
Explore the suite → 🗂️ all 170+ tools · ⭐ awesome-cognis · 🔗 cognis-sources · 🤖 uncensored-fleet · 🧠 engram
Contributing
PRs, new rules, and demo scenarios are welcome under the collaboration-pull model — see CONTRIBUTING.md and SECURITY.md.
⭐ If
sanctscansaved you time, star it — it genuinely helps others find it.
Interoperability
{} composes with the 300+ tool Cognis suite — JSON in/out and a shared
OpenAI-compatible /v1 backbone. See INTEROP.md for the
suite map, composition patterns, and reference stacks.
License
Source-available under the Cognis Open Collaboration License (COCL) v1.0 — free for personal, internal-evaluation, research, and educational use; commercial / production use requires a license ([email protected]). See LICENSE.
Installing Sanctscan
This server has no published package — it is built from source. Open the repository and follow its README.
▸ github.com/cognis-digital/sanctscanFAQ
Is Sanctscan MCP free?
Yes, Sanctscan MCP is free — one-click install via Unyly at no cost.
Does Sanctscan need an API key?
No, Sanctscan runs without API keys or environment variables.
Is Sanctscan hosted or self-hosted?
Self-hosted: the server runs locally on your machine via the install command above.
How do I install Sanctscan in Claude Desktop, Claude Code or Cursor?
Open Sanctscan on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.
Related MCPs
GitHub
PRs, issues, code search, CI status
by GitHubFilesystem
Secure file operations with configurable access controls.
Memory
Knowledge graph-based persistent memory system.
Template MCP Server
A CLI tool to create a new Model Context Protocol server project with TypeScript support, dual transport options, and an extensible structure
by mcpdotdirectAmap Maps Mcp Server
MCP server for using the AMap Maps API
by duxiaohuiSupabase
Database, auth and storage
by SupabaseEverything
Reference / test server with prompts, resources, and tools.
Git
Tools to read, search, and manipulate Git repositories.
Sequential Thinking
Dynamic and reflective problem-solving through thought sequences.
Time
Time and timezone conversion capabilities.
Compare Sanctscan with
Not sure what to pick?
Find your stack in 60 seconds
Author?
Embed badge for your README
Browse similar
All development MCPs
