Bring Your Own Screening Check adds a manual review step to your transaction screening. If you also have automatic Anti-Money Laundering (AML) screening (Chainalysis or Elliptic) or Travel Rule enabled, it slots between them: after AML screening completes and before Travel Rule processing begins. It does not require either one, though; you can use it on its own, without AML or Travel Rule enabled at all.
This feature is currently in Early Access mode. Contact your Customer Success manager to join.
How it works
Bring Your Own Screening Check works as a standalone step, or alongside your other screening checks. When other checks are enabled, they run in this order:
- Automatic AML, if enabled. Chainalysis or Elliptic screens the transaction as usual.
- Bring Your Own Screening Check. If enabled and active, transactions matching a SCREEN rule pause here for your verdict. What you base that verdict on is up to you: a manual compliance review, your own internal risk logic, or a call out to any screening provider, including one Fireblocks does not natively support. Fireblocks does not need to know which; it only needs your Accept or Reject. Transactions matching a PASS rule skip straight to the next step.
- Travel Rule, if enabled. Compliance data is exchanged with the counterparty Virtual Asset Service Provider (VASP).
This applies to both incoming and outgoing transactions. A transaction held for review enters a Pending state and waits for your verdict; if none arrives before your configured timeout, Fireblocks automatically rejects the transaction, and this cannot be reversed.
Setting it up
Before you begin, contact your Customer Success manager to enable Bring Your Own Screening Check for your workspace.
- Set your timeouts. How long Fireblocks waits for your verdict before automatically rejecting a transaction. Incoming and outgoing have separate timeouts: incoming ranges from 10 seconds to 7 days (default 1 hour); outgoing ranges from 10 seconds up to your JWT lifetime minus 30 minutes (default 1 hour). Set one or both via the API. Leave enough margin for your team or system to respond reliably, since a timeout auto-rejection cannot be reversed.
- Configure your pre-screening rules. These decide which transactions get held for your verdict (SCREEN) and which skip straight through (PASS). Rules are evaluated in order, and the first match wins. This is not self-service: open a support ticket with the rules you want, based on fields like source or destination type, address, asset, amount, and direction.
- Test in the sandbox, including how your integration handles a transaction that times out, before activating in production.
- Activate, via the API, once your timeouts and rules are set. Transactions are not held for review until the feature is both enabled for your workspace and activated. To pause reviewing transactions without losing your configuration, deactivate instead: every transaction bypasses the review step while deactivated, and your timeouts and rules stay saved for whenever you reactivate.
Submitting verdicts
Submit Accept or Reject for a transaction via the API, using an idempotency key so a retry cannot submit the same verdict twice.
You can also submit a verdict before the transaction reaches the review step, for example while automatic AML screening is still running. Fireblocks stores it and applies it automatically once the transaction arrives at the waiting phase.
Checking a verdict's status returns one of:
| Status | What it means |
|---|---|
| Pre-accepted | Submitted before the transaction reached the review step; will apply automatically once it does |
| Pending | Waiting for your verdict |
| Received | Verdict received and being applied |
| Completed | Verdict applied; the transaction continues |
A repeated submission for a transaction that already has a verdict, or one that has already moved past the review step, returns a conflict rather than overwriting anything. Do not retry in that case; the outcome is already final.
Limitations
Pre-screening rules are not self-service; you configure them through a support ticket, not directly through the API.
Developer portal
See Bring your own screening check for the API reference, including request and response formats and error handling.