The short version
Public agencies do not need a custom chain. They need records that cannot be quietly edited, and a way to follow money when a case goes live.
That is already happening. Land offices, tax authorities, and digital-ID programs use ledgers for titles, budgets, and credentials. Investigators use the same public chains to trace stolen funds, sanctions evasion, and fraud proceeds. Tatum sits in the middle: one Data API, one Security API, and Notifications across 100-plus networks, on SOC 2 Type II and ISO/IEC 27001:2022 infrastructure.
Public-sector teams in North America are already landing on the Data API. Volume on those keys is still a handful of calls. That is how a serious desk starts. This piece is the map from that first lookup to a full investigation stack.
Why agencies are on-chain now
Crypto is no longer a side channel. It is how some fraud rings move value, how some vendors get paid, and how some public programs will eventually issue credentials and titles.
When fraud proceeds hop from a clinic or a contractor to a mixer to a stablecoin wallet, the case file needs chain data the same way it needs bank records. That is already true in the United States and across North America, not only in places that run a digital-ID program.
Builders already felt this on the market-structure side with the CLARITY Act. Agencies feel it as operational work: who owns this address, what did it hold last Tuesday, did it just move, is it flagged?
Public-sector stack
What an agency actually buys
Five government use cases
Switch the cards. Each job maps to a Tatum surface you can put in a procurement packet without inventing a new vendor for every chain.
What Tatum maps to each job
Procurement teams ask for a product list, not a vision deck. This is the mapping.
| Agency job | Tatum product | What you get |
|---|---|---|
| Wallet lookup | Data API / Portfolio | Native, token, and NFT balances in one schema |
| Follow the money | Transaction history | Incoming and outgoing transfers, paginated, chain-normalized |
| Risk screen | Security API | Flag scams, stolen funds, phishing, dark-web labels. Source included |
| Live monitoring | Notifications | Webhook on the next hop. Reorg-aware. No polling loop |
| As-of audit | Historical balances | Balance at a past block or timestamp for court and committee exhibits |
| Node access | RPC Gateway | Failover routing, archive where you need it, SLA-backed uptime |
| Program wallets | Smart Wallets | MPC 2-of-2 for benefit payouts or civic apps. No full key on a ministry laptop |
We do not pretend the Security API replaces Chainalysis or Elliptic on a mega-case. Docs are explicit: for business-critical screening, specialized vendors still matter. What Tatum gives a desk on day one is a fast, multi-chain check (Bitcoin, Ethereum, Litecoin, Solana, Tron) with the intelligence source in the response, plus the rest of the data plane on the same key.
Screen an address before you chase it
This is a real response from Tatum’s malicious-address check. The wallet is a documented trust-trading scam on CryptoScamDB. A clean address returns {"status":"valid"}. Tatum does not store the list of addresses you screen.
Security API
GET /v3/security/address/{address}
From a handful of calls to a full case file
This is the growth path we want for desks that already found us.
Protecting program funds is not a crypto hobby. If a subject’s proceeds sit in USDT or ETH, a North American desk needs the same primitives a bank AML team uses: who holds what, where it moved, whether the counterparty is already flagged, and a webhook if it moves again at 2am.
The first step is usually the same. Look up the wallet. Leave. That is rational. Standing up a node fleet to answer one case is a waste of a year.
The upgrade is four calls, not a six-month RFP.
Grow the desk
Four steps after the first wallet lookup
If you are that desk: talk to us before you rebuild this on three vendors. The same Dashboard key covers Gateway, Data, Security, and Notifications. Get in touch if you need a questionnaire filled, an NDA for the SOC 2 Type II report, or a quieter onboarding than a public signup page.
Real-world public-sector patterns
These are not Tatum case studies. They are the programs investigators and digital-government teams already point to when they explain why a ledger belongs in civic stack design.
| Place | What they put on a ledger | Why it matters for APIs |
|---|---|---|
| Estonia | Citizen data integrity, digital ID, e-taxation inside e-Estonia | Civic apps still need reliable reads, alerts, and audit exports |
| United Arab Emirates | Real estate and land registration on decentralized ledgers | Title history and current owner queries are portfolio problems |
| Georgia and Dubai | Verifiable property and land transactions | Fraud prevention is transfer monitoring plus an immutable log |
| United States | Asset tracing when program fraud hits crypto rails | Start with Data API lookups. Add screening and webhooks as the case grows |
The compliance bar agencies already ask for
Enterprise reviews stall on paperwork, not latency slides. Tatum’s answers are boring on purpose.
- SOC 2 Type II and ISO/IEC 27001:2022. Request the report and certificate through the Drata Trust Center. The SOC 2 pack needs an NDA. The ISO certificate does not.
- Defined incident response. P1 initial response in 2 hours, P2 in 8 hours, P3 in 24 business hours. Business plans get 24/7 prioritized support. Details live in the SLA.
- No address list retained on malicious-address checks. The query hits intelligence sources and returns. That matters for investigative sensitivity.
- Role-based access, key rotation, logged activity on the platform side. Same story we tell banks in enterprise security.
If a questionnaire is sitting in someone’s inbox, send it through sales. Do not paste control language into a public ticket.
How an investigation desk should wire this
A practical week, not a transformation program.
- Create a key in the Dashboard. Restrict it to the unit. Do not share it with a contractor laptop that also runs Discord.
- Pull portfolio and history for the first subject address on the chain you actually care about.
- Screen that address and every counterparty the history returns.
- Open an
ADDRESS_EVENTsubscription to your case webhook. Deduplicate ontxId. Acknowledge 200 quickly and process async. - Store the JSON. Courts like timestamps and hashes more than a slide.
- When the graph gets wide, pipe the same data into Maltego or your existing intel tool. We already documented that path for Bitcoin scam trails.
For civic builders (identity, titles, benefits), invert the stack: Smart Wallets or Gateway for writes, Data API for public lookups, Notifications for ops, Security API on any payout destination.
FAQ
Click a question to open the answer.
No. The Security API is a fast multi-chain screen with sourced labels (including CryptoScamDB and Blockmate). For the heaviest AML and sanctions programs, keep a specialized vendor in the loop. Use Tatum for the data plane, monitoring, and first-pass risk so analysts are not starting from a blank explorer.
Bitcoin, Ethereum, Litecoin, Solana, and Tron today. Portfolio, history, and Gateway coverage is much wider (100-plus networks). Screen on the five, investigate on all of them.
Malicious-address checks are not persisted as your watchlist. You still have platform logs for API usage, which is normal for any vendor. Keep case-sensitive addresses in your own evidence store.
Yes. Use the Drata Trust Center for SOC 2 Type II (NDA) and the ISO 27001 certificate. For a security questionnaire, contact Tatum through the get-in-touch form so it is routed with a signatory and deadline.
Create an ADDRESS_EVENT subscription with your webhook URL. Tatum watches the chain and POSTs when the address moves. Notifications are reorg-aware. You can wait for confirmations before you treat a transfer as final.
No. Identity, land, public finance, and elections are civic build problems. Investigations are the incoming traffic we are seeing from public-sector teams that discovered the Data API on their own. Both groups use the same APIs.
If you want the builder-side version of “make the stack exam-ready,” start with enterprise-grade security and the AI-era attack notes. If you want the civic product version, the APIs above are the same ones wallets and banks already run in production.



