Secured by Trust Wallet

Compliance Framework

A transparent regulatory posture for the Treasury Vault

How we analyze regulation, onboard users, protect data, and adapt as rules evolve across jurisdictions.

Note on language: product copy uses capital-protected rather than risk-free. No investment is free of risk. See the Risk Disclosure for the full description of protection scope and limitations.

Jurisdictional analysis

RegionRegimeStatusNotes
European UnionMiCA (Markets in Crypto-Assets), 5AMLD, GDPR, DAC8LiveCASP-aligned disclosures, travel-rule messaging, GDPR data-subject rights, DAC8 reporting readiness.
United KingdomFCA cryptoasset registration, MLR 2017, UK GDPRLiveFinancial promotions rules for retail communications; travel rule per JMLSG guidance.
United StatesFinCEN MSB, state MTLs, OFAC, IRS Form 1099-DAIn reviewOnboarding restricted in states without a money transmitter license. OFAC screening on all counterparties.
SingaporeMAS Payment Services Act, PDPALiveDPT service provider posture; travel rule per MAS Notice PSN02.
UAEVARA (Dubai) / ADGM FSRALiveRulebook-aligned marketing, custody, and risk disclosures.
Sanctioned / high-riskUN, OFAC, EU, UK, HMT listsRestrictedOnboarding and transactions blocked for sanctioned jurisdictions and SDN-listed parties.

AML / KYC tiers

Tier 0 — Browse

View only
  • Email verification
  • Device fingerprint
  • Geo-IP screen

Tier 1 — Standard

Up to $10,000 in vault positions
  • Government-issued ID (passport / national ID / driver license)
  • Selfie with liveness detection
  • Address attestation
  • PEP & sanctions screen (ongoing)

Tier 2 — Enhanced

Up to $250,000
  • Proof of address (utility / bank statement < 90 days)
  • Source-of-funds questionnaire
  • Adverse-media screen

Tier 3 — Institutional / High-balance

Above $250,000
  • Entity formation documents & UBO map
  • Source-of-wealth evidence
  • Enhanced due diligence review by compliance officer
  • Ongoing transaction monitoring with tuned rules

Ongoing controls

Transaction monitoring

Rule-based + behavioral models flag structuring, rapid pass-through, mixer exposure, and sanctioned-address interaction. Alerts triaged within 24h.

Travel Rule

Originator/beneficiary information exchanged with counterparty VASPs via IVMS-101 for transfers above local thresholds.

Blockchain analytics

Every deposit address screened for direct and indirect exposure to illicit sources before credit.

Record retention

KYC records and transaction logs retained per jurisdiction (5–7 years) with tamper-evident storage.

Tax reporting

  • • Annual yield & position statements (CSV, PDF)
  • • US Form 1099-DA style summary where applicable
  • • EU DAC8-formatted export
  • • Cost-basis lots exportable to common tax tools
  • • Users are responsible for filing in their jurisdiction

Data privacy

  • • AES-256 at rest, TLS 1.3 in transit
  • • KYC vault segregated from operational systems
  • • Least-privilege access with full audit trail
  • • DSAR handling within statutory timelines
  • • DPO contact: support@trustwalletledgers.com

Cross-border transactions

Cross-border activity is routed through counterparties that have reciprocal Travel Rule messaging. Transfers exchange IVMS-101 originator/beneficiary data above local thresholds (EU: EUR 1,000; US: USD 3,000; SG: SGD 1,500).

Sanctioned destinations are blocked at the network, address, and counterparty level. Attempted transfers to restricted jurisdictions trigger an escalation to the MLRO and are reported to competent authorities where required.

Audit cadence

Annual
Independent AML program audit
Continuous
SOC 2 Type II
Monthly
Proof-of-reserves attestation
Quarterly
Internal compliance testing

Regulatory change monitoring

  1. 1. Horizon scan. External counsel + RegTech feeds surface proposed rules across covered jurisdictions weekly.
  2. 2. Impact assessment. Compliance officer scores changes for product, disclosure, and operational impact.
  3. 3. Implementation. Cross-functional squad ships policy, product, and disclosure updates before the effective date.
  4. 4. Attestation. Board-level compliance committee reviews adoption evidence quarterly.

FAQ

Contact compliance

For law-enforcement requests, DSARs, or regulatory correspondence, reach the MLRO and DPO teams directly.