Osprey

Active / Flagship

Core Monitoring Engine · Apache 2.0 Open Source

High-throughput real-time transaction screening and vigilance engine.

Osprey is the core vigilance engine of opensource.finance. Built in Go as a standalone single binary, Osprey intercepts and evaluates transactions against Google Common Expression Language (CEL) rules in about a millisecond, with zero JVM or Kubernetes overhead.

Go 1.26Google CELSQLite / PostgreSQLJSON RESTApache 2.0
Evaluation Latency
~1 ms
Median, single request, 12 rules
Under Load
380 / s
p99 66 ms, 10 concurrent clients
Binary Size
25 MB
33 MB RAM under load
Spin-up Time
< 60s
Single compiled Go binary

Measured 2026-09-29 on v0.1.0: Apple M3 Pro laptop, community tier (SQLite), the 12 FATF starter rules, k6 for 30 s. Run docs/LOAD_TESTING.md for numbers on your hardware.

12 FATF-inspired starter rules

Based on public FATF guidance for AML/CFT detection. Each rule is a CEL expression with a weight; weights combine into the transaction's risk score. Load them with scripts/seed-starter-kit.sh, then tune them.

RuleDetectsWeight
StructuringAmounts just below the $10K reporting threshold (smurfing)0.6
High ValueTransactions above $10K0.3
Very High ValueTransactions above $50K (enhanced due diligence)0.5
Round AmountSuspiciously round amounts, e.g. exactly $5,000.000.2
Account DrainBalance emptied to zero (account takeover)0.8
Partial DrainMore than 90% balance reduction in one transaction0.5
Same PartySender and receiver are the same entity (layering)1.0
High VelocityMore than 5 transactions in a time window0.6
Extreme VelocityMore than 10 transactions in a time window0.8
High Risk TypeCASH_OUT or TRANSFER transaction types0.2
Cash IntensiveCash-based transactions0.3
Micro TransactionAmounts under $10 (card testing, credential probing)0.3

Overview & Engineering Philosophy

Traditional anti-money laundering and transaction monitoring systems are complex, multi-service monoliths that require dedicated infrastructure teams and hundreds of thousands of dollars in SaaS licensing.

Osprey strips away enterprise bloat to deliver pure, mathematically sound evaluation performance. It evaluates incoming transactions in real time before settlement, returning an alert or no-alert decision with a risk score and the reasons behind it.

Equipped with out-of-the-box FATF typologies (structuring, smurfing, velocity bursts, and sanction screening), Osprey protects fintechs, payment switches, and crypto on-ramps without compromising user privacy.

Architecture Specifications

Common Expression Language (CEL)

Memory-safe, non-Turing-complete logic preventing infinite loops and injection vulnerabilities while executing in microseconds.

Dual Storage Engine

Embeds zero-configuration SQLite for lightweight edges, or connects to PostgreSQL with row-level tenant isolation for enterprise deployments.

JSON REST Ingestion

Transactions arrive as JSON over REST today. ISO 20022 (pacs.008, pacs.002, pain.013), gRPC and GraphQL adapters are on the roadmap.

Deterministic Audit Trails

Every evaluation decision is recorded with rule version hashes, evaluation microsecond timestamps, and variable snapshots.

Docker Quickstart (60 Seconds)
# Pull and run Osprey locally on port 8080
docker run -d --name osprey -p 8080:8080 \
  -e OSPREY_ADMIN_TOKEN=change-me \
  ghcr.io/opensource-finance/osprey:latest

# Verify health status
curl http://localhost:8080/health

# Evaluate a transaction (load the 12 FATF starter rules first: docs/STARTER_KIT.md)
curl -X POST http://localhost:8080/evaluate \
  -H "Content-Type: application/json" \
  -H "X-Tenant-ID: default" \
  -d '{
    "id": "tx-9921",
    "type": "TRANSFER",
    "debtor": { "id": "user-a", "accountId": "acct-a" },
    "creditor": { "id": "merchant-b", "accountId": "acct-b" },
    "amount": { "value": 9500, "currency": "USD" },
    "timestamp": "2026-09-29T10:00:00Z"
  }'

Interactive CEL Rule Sandbox

Select a rule to preview its compiled Common Expression Language AST syntax:

Selected Rule Explanation

Detects intentional smurfing just beneath mandatory reporting limits.

CEL Expression
txn.amount >= 9000.0 && txn.amount < 10000.0