Osprey
Active / FlagshipCore Monitoring Engine · Apache 2.0 Open Source
High-throughput real-time transaction screening and vigilance engine.
Osprey is the core vigilance engine of opensource.finance. Built in Go as a standalone single binary, Osprey intercepts and evaluates transactions against Google Common Expression Language (CEL) rules in about a millisecond, with zero JVM or Kubernetes overhead.
Measured 2026-09-29 on v0.1.0: Apple M3 Pro laptop, community tier (SQLite), the 12 FATF starter rules, k6 for 30 s. Run docs/LOAD_TESTING.md for numbers on your hardware.
12 FATF-inspired starter rules
Based on public FATF guidance for AML/CFT detection. Each rule is a CEL expression with a weight; weights combine into the transaction's risk score. Load them with scripts/seed-starter-kit.sh, then tune them.
| Rule | Detects | Weight |
|---|---|---|
| Structuring | Amounts just below the $10K reporting threshold (smurfing) | 0.6 |
| High Value | Transactions above $10K | 0.3 |
| Very High Value | Transactions above $50K (enhanced due diligence) | 0.5 |
| Round Amount | Suspiciously round amounts, e.g. exactly $5,000.00 | 0.2 |
| Account Drain | Balance emptied to zero (account takeover) | 0.8 |
| Partial Drain | More than 90% balance reduction in one transaction | 0.5 |
| Same Party | Sender and receiver are the same entity (layering) | 1.0 |
| High Velocity | More than 5 transactions in a time window | 0.6 |
| Extreme Velocity | More than 10 transactions in a time window | 0.8 |
| High Risk Type | CASH_OUT or TRANSFER transaction types | 0.2 |
| Cash Intensive | Cash-based transactions | 0.3 |
| Micro Transaction | Amounts under $10 (card testing, credential probing) | 0.3 |
Overview & Engineering Philosophy
Traditional anti-money laundering and transaction monitoring systems are complex, multi-service monoliths that require dedicated infrastructure teams and hundreds of thousands of dollars in SaaS licensing.
Osprey strips away enterprise bloat to deliver pure, mathematically sound evaluation performance. It evaluates incoming transactions in real time before settlement, returning an alert or no-alert decision with a risk score and the reasons behind it.
Equipped with out-of-the-box FATF typologies (structuring, smurfing, velocity bursts, and sanction screening), Osprey protects fintechs, payment switches, and crypto on-ramps without compromising user privacy.
Architecture Specifications
Memory-safe, non-Turing-complete logic preventing infinite loops and injection vulnerabilities while executing in microseconds.
Embeds zero-configuration SQLite for lightweight edges, or connects to PostgreSQL with row-level tenant isolation for enterprise deployments.
Transactions arrive as JSON over REST today. ISO 20022 (pacs.008, pacs.002, pain.013), gRPC and GraphQL adapters are on the roadmap.
Every evaluation decision is recorded with rule version hashes, evaluation microsecond timestamps, and variable snapshots.
# Pull and run Osprey locally on port 8080
docker run -d --name osprey -p 8080:8080 \
-e OSPREY_ADMIN_TOKEN=change-me \
ghcr.io/opensource-finance/osprey:latest
# Verify health status
curl http://localhost:8080/health
# Evaluate a transaction (load the 12 FATF starter rules first: docs/STARTER_KIT.md)
curl -X POST http://localhost:8080/evaluate \
-H "Content-Type: application/json" \
-H "X-Tenant-ID: default" \
-d '{
"id": "tx-9921",
"type": "TRANSFER",
"debtor": { "id": "user-a", "accountId": "acct-a" },
"creditor": { "id": "merchant-b", "accountId": "acct-b" },
"amount": { "value": 9500, "currency": "USD" },
"timestamp": "2026-09-29T10:00:00Z"
}'Interactive CEL Rule Sandbox
Select a rule to preview its compiled Common Expression Language AST syntax:
Detects intentional smurfing just beneath mandatory reporting limits.
txn.amount >= 9000.0 && txn.amount < 10000.0Other Projects in OpenSource Finance
View All →Osprey Narrator
Fine-tuned domain model for SAR narrative generation & CEL rule synthesis.
Osprey Studio
Visual rule authoring IDE and transaction simulation workbench.
Osprey Cases
Streamlined analyst investigation and regulatory filing workbench.
Universal Financial Adapters
Planned converters for ISO 20022, JSON, gRPC, and GraphQL rails.