FieldTypeDescription
dataoptionalAmlEvidenceResponse | null—
check_idrequireduuid—
audit_idrequireduuid—
productrequired"investigation"—
subjectrequiredAmlProductSubjectResponse—
typerequiredSubjectType—
valuerequiredstring—
networkrequiredAmlNetwork—
assetrequiredAmlAsset—
generated_atrequireddate-time—
lookback_daysrequiredinteger—
linked_identitiesrequiredAmlEvidenceIdentityResponse[]—
addressrequiredstring—
kindrequiredstring—
node_activityoptionalAmlEvidenceNodeActivityResponse[]Observed transaction-flow denominator for graph nodes. Values are deduplicated from the immutable screening trace and are not wallet balances.
addressrequiredstring—
observed_inflowrequiredstring—
observed_outflowrequiredstring—
observed_amountrequiredstringLargest observed inbound or outbound value in the immutable screening window. This is not the current on-chain balance.
screened_transaction_transfersoptionalAmlEvidenceSubjectTransferResponse[]Economic transfers that belong to the screened transaction subject. Empty when the screened subject is an address.
sourcerequiredstring—
destinationrequiredstring—
transactionrequiredstring—
networkrequiredAmlNetwork—
assetrequiredAmlAsset—
amountrequiredstring—
timestampoptionaldate-time | null—
channelrequiredstring—
rolerequiredstring—
initiatoroptionalstring | null—
observed_address_transfersoptionalAmlEvidenceSubjectTransferResponse[]Observed economic transfers touching the screened address or its linked identities, deduplicated from the immutable analysis trace. These are activity records, not confirmed risk exposure or full wallet history.
sourcerequiredstring—
destinationrequiredstring—
transactionrequiredstring—
networkrequiredAmlNetwork—
assetrequiredAmlAsset—
amountrequiredstring—
timestampoptionaldate-time | null—
channelrequiredstring—
rolerequiredstring—
initiatoroptionalstring | null—
pathsrequiredAmlEvidencePathResponse[]—
categoryrequiredRiskCategory—
risk_addressrequiredstring—
entity_namerequiredstring | nullPresent only when the analyst key also has the aml:entity:read downstream-disclosure scope.
directionrequiredExposureDirection—
confirmed_hopsrequiredinteger—
amountrequiredstring | null—
amount_basisrequiredstring—
stepsrequiredAmlEvidenceTransferResponse[]—
sourcerequiredstring—
destinationrequiredstring—
transactionrequiredstring—
networkrequiredAmlNetwork—
assetrequiredAmlAsset—
amountrequiredstring—
depthrequiredinteger—
timestamprequireddate-time—
directionrequiredExposureDirection—
channelrequiredstring—
rolerequiredstring—
initiatoroptionalstring | null—
participant_roleoptionalstring | null—
matched_amountoptionalstring | null—
matched_transfersoptionalAmlEvidenceSubjectTransferResponse[]—
sourcerequiredstring—
destinationrequiredstring—
transactionrequiredstring—
networkrequiredAmlNetwork—
assetrequiredAmlAsset—
amountrequiredstring—
timestampoptionaldate-time | null—
channelrequiredstring—
rolerequiredstring—
initiatoroptionalstring | null—
contextual_signalsrequiredAmlEvidenceContextResponse[]—
categoryrequiredRiskCategory—
directionrequiredExposureDirection—
countrequiredinteger—
warningrequiredstring—
coveragerequiredAmlCoverageItemResponse[]—
categoryrequiredRiskCategory—
statusrequiredstring—
directionsoptionalExposureDirection[]—
lookback_daysrequiredinteger—
analyst_notesrequiredstring[]—
policy_versionrequiredstring—
dataset_revisionrequiredstring—
export_tokenrequiredstring—
export_endpointrequiredstring—
export_expires_atrequireddate-time—
assessmentoptionalAmlProductResultResponse | nullImmutable screening result associated with this evidence export.
productrequiredAmlProduct—
subjectrequiredAmlProductSubjectResponse—
typerequiredSubjectType—
valuerequiredstring—
networkrequiredAmlNetwork—
assetrequiredAmlAsset—
risk_scoreoptionalinteger | nullSafio decision-support risk points backed by confirmed evidence. Null when the available coverage cannot support a defensible numeric result. This value is not a probability of criminal activity.
risk_levelrequiredRiskLevel—
decisionrequiredstring—
triggered_rulesrequiredstring[]—
categoriesrequiredAmlCategoryAssessmentResponse[]—
categoryrequiredRiskCategory—
assessment_statusrequiredstring—
exposure_typerequiredstring—
min_confirmed_hopsoptionalinteger | null—
path_statusrequiredstring—
exposure_amount_usdoptionalstring | nullDocumented USDT exposure amount or path-capacity upper bound. Null for non-USDT assets and when exposure is not attributable to an amount.
exposure_shareoptionalnumber | null—
directionsoptionalExposureDirection[]—
context_signal_countoptionalinteger—
warningoptionalstring | null—
coveragerequiredAmlCoverageItemResponse[]—
categoryrequiredRiskCategory—
statusrequiredstring—
directionsoptionalExposureDirection[]—
lookback_daysrequiredinteger—
coverage_statusrequiredstring—
lookback_daysrequiredinteger—
route_summariesoptionalAmlRouteSummaryResponse[] | nullAggregated confirmed routes available to Enhanced and Investigation.
categoryrequiredRiskCategory—
directionrequiredExposureDirection—
confirmed_hopsrequiredinteger—
exposure_typerequiredstring—
exposure_amount_usdoptionalstring | null—
exposure_shareoptionalnumber | null—
first_observed_atoptionaldate-time | null—
last_observed_atoptionaldate-time | null—
entity_nameoptionalstring | nullPresent only when the API key permits downstream entity disclosure.
evidence_availableoptionalboolean—
policy_versionrequiredstring—
dataset_revisionrequiredstring—
billingrequiredBillingChargeResponse—
enabledrequiredboolean—
amountrequiredstring—
currencyrequiredstring—
balance_afterrequiredstring | null—
waivedoptionalbooleanTrue when a reserved AML charge was automatically returned because the purchased result was not delivered with contractually sufficient coverage.
warningsrequiredstring[]—
activity_summaryoptionalAmlActivitySummaryResponse | nullSource-neutral amounts and dates from the immutable subject activity. Transaction amounts exclude fees and are not an attributed illicit amount. Address directional totals remain protected.
transaction_amountoptionalstring | nullGross sum of observed value-transfer events; internal hops may count the same value more than once.
value_transfer_countoptionalinteger | null—
first_transfer_atoptionaldate-time | null—
last_transfer_atoptionaldate-time | null—
timestamp_statusoptionalstring—
assessment_summaryoptionalstring[]Deterministic explanation of confirmed findings and coverage; not an analyst opinion.
customer_riskoptionalCustomerRiskResultResponse | nullResult calculated with the customer's published model. Safio's proprietary score remains in risk_score and is evaluated independently.
model_idrequireduuid—
model_namerequiredstring—
model_versionrequiredinteger—
scoreoptionalinteger | null—
risk_levelrequiredRiskLevel—
decisionrequiredstring—
triggered_rulesrequiredstring[]—
erroroptionalErrorBody | null—
coderequiredstring—
messagerequiredstring—
statusoptionalinteger | null—
extraoptionalobject | null—