A crypto exchange that deploys AI support without a compliance and security checklist is not saving money. It is widening its attack surface and handing a regulator a reason to look closer.
AI customer support for a crypto exchange is the use of large language model agents to handle account, trading, and asset-movement tickets across chat, email, voice, and messaging, while honoring KYC, AML, sanctions, and consumer-protection obligations and producing an audit trail. The hard part is not answering "where is my deposit." It is doing so without enabling a withdrawal to a sanctioned wallet, walking a victim through a scam-driven transfer, or leaking identity documents. This article is a requirements checklist, not a vendor ranking. It lists the must-haves, defines what good looks like for each, and shows how a few representative vendors (Lorikeet, Sierra, Fin by Intercom, Decagon) map to them.
Crypto support tickets are irreversible-money tickets. A wrong withdrawal approval or a missed sanctions flag has no chargeback path, unlike a card dispute.
Social engineering and scam-driven self-transfers are now a primary loss vector, so the AI must detect coached victims, not just answer questions.
Regulators increasingly expect a replayable record of every automated decision. Audit logging is a requirement, not a nice-to-have.
Compliance-sensitive actions (KYC unlocks, withdrawal releases, account freezes) need a deterministic human escalation path that the AI cannot skip.
SOC 2, data residency, and PII handling are procurement gates. Failing one removes a vendor from the shortlist regardless of resolution rate.
Last updated: June 2026
Crypto exchange support sits in a different risk class than e-commerce or SaaS. The customer asking "why is my withdrawal pending" might be a legitimate user, a money launderer testing controls, or a fraud victim being coached by a stranger on a messaging app. The AI agent has to triage all three from the same opening message, and the cost of getting it wrong is an irreversible asset movement, a sanctions breach, or an enforcement action. Most AI support vendors will quote you a deflection rate. A crypto compliance officer will ask whether the agent can prove what it did, refuse what it should refuse, and escalate what a human must own. The checklist below is built around those questions.
How to use this checklist
Each requirement has three parts: the requirement itself, "what good looks like" so you can score a vendor objectively, and a short note on how the four representative vendors map. The vendor mapping is illustrative of the market, not exhaustive, and is based on publicly described capabilities as of mid-2026. Always verify current posture under NDA, because scope and certifications drift. Treat any requirement marked as a procurement gate (KYC, AML escalation, mandatory human escalation, audit logging, SOC 2) as pass or fail rather than a score. A vendor that cannot meet a gate does not belong on a crypto exchange shortlist, no matter how strong it is elsewhere.
Lorikeet is an AI customer support platform built for complex, regulated businesses including fintechs, financial services, and trading platforms. It builds AI concierges that resolve issues end-to-end across chat, email, voice (sub-1-second latency), SMS, and WhatsApp, pairs natural-language workflows with deterministic structured workflows, and runs a defence-in-depth model: pre-launch adversarial simulations, inbound message checks, outbound guardrails, and 100% automated post-facto QA through its Coach agent. That posture is the reason it appears as the reference point in each requirement below. It is fair to note the trade-off: Lorikeet is deliberately scoped to complex regulated use cases, so a tiny exchange wanting a five-minute self-serve FAQ widget will find it heavier than a lightweight chatbot.
The Crypto Exchange AI Support Requirements Checklist
1. KYC and identity verification handling
Requirement: The agent must handle KYC and identity-verification tickets (document re-uploads, verification status, tier upgrades, account-recovery identity checks) without ever revealing how to bypass a control or accepting identity decisions it is not authorized to make.
What good looks like: The agent can read verification status from the KYC provider, explain exactly what a customer needs to submit, and trigger a re-review, but the actual identity decision (approve, reject, escalate to enhanced due diligence) stays with the system of record or a human reviewer. It never coaches a customer on what to write to pass a check, never confirms whether a specific document "would work," and treats repeated failed attempts as a possible fraud signal rather than a support friction problem.
Vendor mapping: Lorikeet handles KYC flows as structured workflows with scoped, least-privilege tools, so the agent can advance a re-verification while the approval decision stays gated and logged. Decagon and Sierra can be configured to take similar actions through custom tooling on enterprise deployments. Fin by Intercom is strongest when KYC status lives in the connected helpdesk or CRM and the action set is read-and-guide rather than deep multi-system orchestration.
2. AML and sanctions-aware escalation
Requirement: The agent must recognize AML and sanctions risk signals and route them to the correct human or system, and it must never take an action that could constitute facilitating a prohibited transaction.
What good looks like: When a ticket touches a flagged address, a sanctioned jurisdiction, a structuring pattern, or a request to move funds in a way that evades a hold, the agent stops the self-serve path and escalates to the compliance queue with the context attached. It does not explain to a customer how a hold works in enough detail to help them route around it, and it does not lift or bypass an AML hold under any phrasing. The escalation is deterministic, meaning it fires on the rule, not on the model's mood.
Vendor mapping: Lorikeet supports this through deterministic structured workflows plus guardrails, so a sanctions or AML condition can hard-route to a human regardless of how the customer phrases the request, and the decision is captured for audit. Sierra and Decagon can encode escalation logic on enterprise builds. Fin by Intercom can route on detected intents and keywords, with depth depending on the connected systems and the rules configured.
3. Transaction and withdrawal handling
Requirement: The agent must handle deposit, withdrawal, and transfer tickets with explicit limits on what it can release or change, because these actions move irreversible assets.
What good looks like: The agent can explain why a withdrawal is pending (new-device hold, address whitelist delay, risk review), check status, and update a customer, but releasing a held withdrawal, raising a limit, or whitelisting a new address sits behind a threshold and an approval step. Dollar-value or risk-tier thresholds block autonomous action above a configured line. The agent treats urgency and pressure ("release it now, I am about to miss a trade") as a reason for more scrutiny, not less.
Vendor mapping: Lorikeet supports threshold blocks and approval gates inside workflows, with the agent able to take low-risk actions and hand off high-value ones, and every action recorded. Decagon and Sierra can implement value-gated actions on custom enterprise deployments. Fin by Intercom typically reads status and guides the customer, leaning on the underlying helpdesk and any connected actions for execution.
4. Scam and social-engineering detection
Requirement: The agent must detect when a customer is likely being coached by a scammer into self-transferring funds, and intervene rather than helpfully complete the transfer.
What good looks like: The agent recognizes the patterns of authorized push payment fraud and pig-butchering scripts: a customer in a hurry to send to a new external wallet, references to a "support agent" or "investment advisor" who told them to move funds, or to a "recovery" or "verification" deposit. Instead of speeding the transfer along, it slows down, surfaces a scam warning, and routes to a human or a fraud-intervention flow. This is the requirement most chat-only deflection bots fail, because their objective function is to resolve and close, which is exactly the wrong instinct here.
Vendor mapping: Lorikeet can encode scam-pattern detection as guardrails and escalation rules, and its pre-launch adversarial simulations let a team red-team these exact scripts before go-live rather than discover the gap in production. Sierra and Decagon can build intervention flows on enterprise deployments. Fin by Intercom can flag risky intents, with intervention depth set by the rules and connected tooling.
5. Mandatory human escalation paths
Requirement: Certain actions must never be fully automated. The agent must have deterministic, non-bypassable escalation for the categories your risk team defines.
What good looks like: Account freezes, suspected fraud, sanctions matches, large-value disputes, vulnerable-customer signals, and any "I want a human" request route to a person on a path the model cannot talk its way out of. The escalation is rule-based, not discretionary, so it triggers identically whether the customer is polite or hostile. The handoff carries full context so the human is not starting cold. Escalations are tracked and, ideally, not billed in a way that punishes the exchange for doing the safe thing.
Vendor mapping: Lorikeet treats escalation as deterministic workflow logic, does not charge for escalations under its per-resolution model, and lets the customer define what counts as a resolution, which removes the incentive to suppress handoffs. Sierra's outcome-only pricing means escalations are not billed either, though the model can bias a vendor toward easy, fully resolvable tickets. Decagon supports configured escalation on enterprise builds. Fin by Intercom routes to human teams natively through the Intercom inbox.
6. Audit logging and replayability
Requirement: Every automated decision must produce a complete, timestamped, replayable record of the reasoning and every tool call, retained for the period your regulators require.
What good looks like: For any ticket from months ago, you can replay what the agent saw, what it decided, which tools it called with which inputs, and why it escalated or acted. This is the artifact a compliance team uses in an examination and the one a chat transcript cannot replace. The standard is the full chain, not a sampled log and not a summary.
Vendor mapping: Lorikeet logs tool calls and reasoning steps and layers 100% automated post-facto QA through its Coach agent, which reviews every ticket rather than a sample, supporting both pre-go-live sign-off and after-the-fact examination. Decagon and Sierra provide enterprise logging and analytics; verify replay depth against your specific examination needs. Fin by Intercom provides conversation and resolution records within the Intercom platform; confirm the depth of tool-call-level detail for regulated use.
7. SOC 2, data residency, and infrastructure security
Requirement: The vendor must hold SOC 2 (Type II), support the data residency your jurisdictions require, and pass your security review, including no-train guarantees on underlying model providers.
What good looks like: A current SOC 2 Type II report available under NDA, documented data residency options (for example US, AU, UK) that match where your users and regulators sit, contractual no-train agreements with the model providers so customer data is not used to train third-party models, and a clean history of passing security reviews from demanding institutions. This is a procurement gate. A miss here ends the conversation.
Vendor mapping: Lorikeet holds SOC 2, offers data residency across US, AU, and UK, maintains contractual no-train agreements with its model providers, and reports passing security reviews including major financial institutions. Sierra, Decagon, and Fin by Intercom each maintain enterprise security postures including SOC 2; confirm the current report, residency options, and model-provider terms directly, since these vary and change.
8. PII handling and redaction
Requirement: The agent must minimize, redact, and protect personally identifiable information and sensitive financial data throughout the interaction and in storage.
What good looks like: Identity documents, wallet addresses, government IDs, and financial details are redacted where they are not needed, access is role-based, and the agent never echoes sensitive data back into a channel where it does not belong or surfaces one customer's data to another. Redaction happens before data reaches places it should not be retained. The agent declines requests that would expose PII even when the requester is persuasive.
Vendor mapping: Lorikeet provides PII redaction and role-based access control as part of its regulated-grade posture. Decagon, Sierra, and Fin by Intercom offer PII handling controls appropriate to enterprise CX; confirm redaction defaults and configurability against your data classification.
9. Pre-launch adversarial simulation
Requirement: Before the agent touches a real customer, you must be able to test its behavior against adversarial and edge-case scenarios and read a pass or fail report.
What good looks like: You can run a suite of simulated tickets, including the dangerous ones (a scammer-coached withdrawal, a sanctions-adjacent request, a social-engineering attempt to unlock an account), before go-live, and your compliance team can review the results. Guardrails are proven against these scripts in advance, not discovered to be missing in production. The test suite is rerunnable after every change so a workflow edit cannot silently reopen a hole.
Vendor mapping: Lorikeet builds this in: pre-launch adversarial simulations and red-teaming are a core part of its defence-in-depth model, and simulations can be rerun as a regression suite. Sierra and Decagon offer testing and sandbox capabilities on enterprise deployments; confirm whether adversarial scenario simulation is first-class. Fin by Intercom offers preview and testing tooling within its platform; confirm the depth of adversarial scenario coverage for regulated workflows.
Requirement-by-vendor coverage at a glance
The table below summarizes how the four representative vendors map to the nine requirements. "Native" means the capability is a first-class, built-in part of the platform's regulated posture. "Configurable" means it can be built on enterprise deployments with custom tooling. "Depends on connected systems" means the capability leans on the underlying helpdesk, CRM, or actions you wire in. Verify all entries under NDA against current product before procurement.
1. KYC and identity verification handling · Lorikeet: Native (structured workflows, gated decisions) · Sierra: Configurable · Fin by Intercom: Depends on connected systems · Decagon: Configurable
2. AML and sanctions-aware escalation · Lorikeet: Native (deterministic routing + guardrails) · Sierra: Configurable · Fin by Intercom: Depends on connected systems · Decagon: Configurable
3. Transaction and withdrawal handling · Lorikeet: Native (threshold blocks + approval gates) · Sierra: Configurable · Fin by Intercom: Depends on connected systems · Decagon: Configurable
4. Scam and social-engineering detection · Lorikeet: Native (guardrails + adversarial simulation) · Sierra: Configurable · Fin by Intercom: Depends on connected systems · Decagon: Configurable
5. Mandatory human escalation paths · Lorikeet: Native (deterministic, escalations not charged) · Sierra: Native (escalations not billed under outcome pricing) · Fin by Intercom: Native (routes to Intercom inbox) · Decagon: Configurable
6. Audit logging and replayability · Lorikeet: Native (tool-call + reasoning logs, 100% QA via Coach) · Sierra: Enterprise logging (verify replay depth) · Fin by Intercom: Platform records (verify tool-call depth) · Decagon: Enterprise logging (verify replay depth)
7. SOC 2, data residency, infrastructure security · Lorikeet: Native (SOC 2, US/AU/UK residency, no-train terms) · Sierra: SOC 2 (confirm residency) · Fin by Intercom: SOC 2 (confirm residency) · Decagon: SOC 2 (confirm residency)
8. PII handling and redaction · Lorikeet: Native (redaction + RBAC) · Sierra: Enterprise controls · Fin by Intercom: Enterprise controls · Decagon: Enterprise controls
9. Pre-launch adversarial simulation · Lorikeet: Native (simulations + rerunnable regression suite) · Sierra: Sandbox/testing (confirm adversarial depth) · Fin by Intercom: Preview/testing (confirm adversarial depth) · Decagon: Sandbox/testing (confirm adversarial depth)
The pattern: the requirements that separate a crypto-grade agent from a chatbot are determinism, provability, and the willingness to refuse. See how Lorikeet handles regulated, end-to-end resolution.
How to run procurement against this checklist
A demo is designed to look good. Procurement for a crypto exchange should be designed to make a demo break. Use the checklist as a scoring rubric, mark the five gates (KYC, AML escalation, mandatory human escalation, audit logging, SOC 2) as pass or fail, and weight the rest to your risk profile. Then put each shortlisted vendor through the same hard scenarios in their own environment.
Questions that make a demo break
Show me the full audit trail for an automated decision your agent made last week, including every tool call and the reasoning between them.
Run a simulated ticket where a customer is being coached by a scammer into a withdrawal, and show me what the agent does.
Show me the agent refusing to lift a withdrawal hold under pressure, and walk me through the guardrail that enforces it.
What happens when a sanctions-adjacent request comes in worded as an innocent question? Show the deterministic escalation firing.
Can my compliance team run your adversarial test suite before go-live and read the pass or fail report?
How is an escalation priced, and does your pricing create any incentive to avoid escalating?
What is your data residency, and can I see the SOC 2 Type II report and the no-train terms with your model providers under NDA?
Scoring approach
Score each requirement on a simple three-point scale (meets, partially meets, does not meet) using the "what good looks like" definitions as the bar. Any "does not meet" on a gate eliminates the vendor. For the non-gate requirements, weight scam detection and transaction handling heavily, because those are where a miss turns into an irreversible loss. Validate the top one or two vendors with a sandbox run on your own hardest tickets before signing, and require the adversarial simulation results in writing.
Lorikeet's take
Most AI support vendors optimize for resolution rate. For a crypto exchange, resolution rate is the wrong headline metric, because the cheapest way to raise it is to attempt everything and quietly mishandle the dangerous edge cases. The number that matters is whether the agent refuses, escalates, and logs correctly on the tickets where a mistake is irreversible. That is why the requirements that anchor this checklist are determinism, provable guardrails, mandatory escalation, and a complete audit trail.
Lorikeet is built around that posture: deterministic structured workflows combined with natural-language workflows, defence in depth from pre-launch simulation through inbound checks and outbound guardrails to 100% automated QA, and a pricing model that does not charge for escalations or let the vendor define what counts as a resolution. If your toughest stakeholder is your compliance officer and your worst-case ticket is an irreversible asset movement, that is the bar to hold every vendor to. See how Lorikeet handles end-to-end resolution.
Key Takeaways
Crypto support is irreversible-money support, so the requirements that matter are about refusing, escalating, and logging, not raw deflection rate.
Treat KYC handling, AML and sanctions escalation, mandatory human escalation, audit logging, and SOC 2 as pass-or-fail procurement gates.
Scam and social-engineering detection is the requirement most chat-only bots fail, because their instinct is to complete the transfer rather than slow it down.
Pre-launch adversarial simulation lets your compliance team prove guardrails before go-live instead of discovering gaps in production.
Score vendors with the "what good looks like" definitions, validate the top choice on your own hardest tickets, and verify SOC 2, residency, and no-train terms under NDA.
Conclusion
Deploying AI support on a crypto exchange is not a question of whether the technology can answer questions. It can. The question is whether it can be trusted with irreversible money under adversarial conditions, and whether you can prove to a regulator that it behaved correctly. The nine requirements above are the difference between an agent that supports your obligations and a chatbot that quietly widens your risk. Run every vendor against the same checklist, mark the gates honestly, and make them break their own demo before you sign.
If you are evaluating AI support for a crypto exchange, book a Lorikeet demo and bring your hardest, most adversarial tickets. We will run them against your guardrails before you commit.









