Which name matcher suffices, at which threshold, measured on your own alert history.
Nothing of yours goes up: the lists come down, your alerts stay on your machine.
It also screens a list of counterparties (companies, vessels, IMO numbers) against five public
sanctions lists, on your machine: see npm run cribler below.
Name screening (sanctions, PEP, internal lists) raises alerts; most of them are false, and
nobody can say why the threshold sits at 85 rather than 90 except "that is the vendor's
setting". This tool measures it: several matchers, from exact to phonetic to a local
embedding model, are run over the alerts your analysts already dispositioned, and each
matcher × threshold cell is read for recall on confirmed matches, false-alert rate and
alerts per thousand screenings, with its count and its interval, or not at all.
It is the second tool of the Cascade suite. The first, cascade-routing,
measures which extraction tier suffices per field. Same method, same seal, same key.
Node 24 or newer, on macOS, Linux or Windows: the whole test suite runs on all three at every push to main, on GitHub's runners (.github/workflows/tests.yml). Nobody has yet run the tool on a client's Windows machine, and this page does not claim it.
Nothing, except two explicit downloads: npm run listes -- --fetch pulls the five public lists
named above, and npm run poids -- --fetch pulls the embed tier's weights. Every other command
runs with the network cut:
CASCADE_OFFLINE=1 is honoured by the one module allowed to touch it, and a test reads every
source so that no second one appears (src/frontiere.test.ts).
What is measured, assumed, synthetic
Every rate in a report carries its n and its 95 % Wilson interval. Analyst minutes per
alert and analyst cost are assumed and declared. Perturbed variants of list entries are
synthetic, measured apart, and never merged into a measured recall. Below five confirmed
matches, no recall is quoted, and the report states why.
For a procurement or compliance review: what the tool talks to, and when, running on a machine without network, a pre-filled vendor security questionnaire, and a pilot annex of outsourcing clauses, a draft for counsel.
Records are sealed (npm run sceller) with the same content hash as cascade-routing, and
reports are verified against the same public key, cle-publique.pem,
with npm run verify.
426 tests across 54 files, counted from the sources rather than typed here.
The same public licence as cascade-routing: non-commercial use without limit of time, a
thirty-day evaluation on your own records for organisations, a commercial licence for
production. See LICENSE and LICENCES.md.