Governance

Compliance & client onboarding

Forensic findings are only useful if they survive scrutiny. This page describes the internal standards Bitaps applies when taking on a matter, verifying who we are acting for, and cooperating with exchanges, counsel and authorities. It describes our own procedures and is not a statement of licensing, certification or regulatory approval.

Last updated 24 August 2026

01Client verification

Before we act on your behalf with a third party — filing a freeze request, contacting an exchange, executing a bridge reclaim — we confirm who you are and that you have authority over the affected wallets or accounts. Depending on the matter that can involve:

  • a government-issued identity document, or company registry details for a corporate client;
  • proof of control of the affected wallet, such as a signed message or a verifiable transaction;
  • a written authorisation letting us correspond with custodians and authorities for you;
  • the police, insurer or exchange reference number where a report has already been filed.

Verification steps appear as requirements on the relevant stage of your case file.

02Matters we decline

We will not take on, and will withdraw from, work where:

  • the purpose appears to be laundering, concealing or reclaiming proceeds of crime;
  • the client cannot demonstrate a legitimate interest in the assets or addresses concerned;
  • the request is surveillance of a private individual without a lawful basis;
  • a party involved appears on applicable sanctions lists;
  • the intended use of our findings is intimidation, extortion or vigilante action.

03Counterparty screening

During tracing we compare addresses against attribution, exchange and sanctioned-entity datasets. Screening results are indicative intelligence, not legal determinations: an address labelled as belonging to a service may be a deposit address, a shared wallet or misattributed. We state confidence levels in our reports and distinguish observed facts from inference.

04Conflicts of interest

We check new matters against existing engagements before accepting them. Where we identify a conflict — for example two clients with competing claims to the same recovered assets — we disclose it and either decline the second matter or proceed only with informed written consent and strict information barriers.

05Evidence handling

  • On-chain state is snapshotted at intake so later movement does not erase the original picture.
  • Every material step is timestamped and attributed to the analyst who performed it.
  • Reports separate raw data, method and conclusion so a third party can retrace our steps.
  • Original client uploads are preserved unaltered alongside any derived exhibits.

06Working with law enforcement and exchanges

We prepare packages in the format investigators and compliance teams actually use, and we respond to lawful requests from competent authorities. We do not hand over your case file to a third party on request alone: disclosures are made where you authorise them or where the law compels us, and we tell you when that happens unless we are legally barred from doing so.

07Recovered assets

We do not take custody of client assets. Recovered funds are released by the custodian, court or bridge endpoint to a destination address you nominate and confirm, and each recovery is reconciled against the original loss in writing.

08Raising a concern

If you believe an engagement, analyst or finding falls short of these standards, write to support@bitaps.co or to Bitaps, Marken 6, Himmelev, 4000 Roskilde, Denmark. Concerns are reviewed independently of the analyst involved and answered in writing.

Questions about this document?

Write to support@bitaps.co or contact us at Marken 6, Himmelev, 4000 Roskilde, Denmark.

See also our legal & policy centre.