Compliance Framework
How we analyze regulation, onboard users, protect data, and adapt as rules evolve across jurisdictions.
| Region | Regime | Status | Notes |
|---|---|---|---|
| European Union | MiCA (Markets in Crypto-Assets), 5AMLD, GDPR, DAC8 | Live | CASP-aligned disclosures, travel-rule messaging, GDPR data-subject rights, DAC8 reporting readiness. |
| United Kingdom | FCA cryptoasset registration, MLR 2017, UK GDPR | Live | Financial promotions rules for retail communications; travel rule per JMLSG guidance. |
| United States | FinCEN MSB, state MTLs, OFAC, IRS Form 1099-DA | In review | Onboarding restricted in states without a money transmitter license. OFAC screening on all counterparties. |
| Singapore | MAS Payment Services Act, PDPA | Live | DPT service provider posture; travel rule per MAS Notice PSN02. |
| UAE | VARA (Dubai) / ADGM FSRA | Live | Rulebook-aligned marketing, custody, and risk disclosures. |
| Sanctioned / high-risk | UN, OFAC, EU, UK, HMT lists | Restricted | Onboarding and transactions blocked for sanctioned jurisdictions and SDN-listed parties. |
Rule-based + behavioral models flag structuring, rapid pass-through, mixer exposure, and sanctioned-address interaction. Alerts triaged within 24h.
Originator/beneficiary information exchanged with counterparty VASPs via IVMS-101 for transfers above local thresholds.
Every deposit address screened for direct and indirect exposure to illicit sources before credit.
KYC records and transaction logs retained per jurisdiction (5–7 years) with tamper-evident storage.
Cross-border activity is routed through counterparties that have reciprocal Travel Rule messaging. Transfers exchange IVMS-101 originator/beneficiary data above local thresholds (EU: EUR 1,000; US: USD 3,000; SG: SGD 1,500).
Sanctioned destinations are blocked at the network, address, and counterparty level. Attempted transfers to restricted jurisdictions trigger an escalation to the MLRO and are reported to competent authorities where required.
For law-enforcement requests, DSARs, or regulatory correspondence, reach the MLRO and DPO teams directly.