AML Statement

Last updated: 2026-06-27 Version: 1.1

This statement explains Swaps' position on anti-money-laundering (AML), counter-financing-of-terrorism (CFT), and know-your-customer (KYC) obligations. It complements the Terms of Service §1.4 and the Sanctions policy.


1. Who performs KYC

Providers perform KYC, not Swaps. When you choose an offer on Swaps and click through, you are redirected to a Provider that is independently licensed and supervised under its own jurisdiction's law. The Provider performs identity verification, source-of-funds checks where applicable, ongoing monitoring, and transaction-execution KYC.

Swaps does not collect government-issued identity documents, biometric data, selfies, or proof of address. Swaps does not perform Swaps-side KYC for wallet-only self-custody or core comparison flows because Swaps does not custody funds, does not safeguard or control signing material, and does not itself execute transactions or transfers in its own name. Where a Swaps product uses provider-side regulated rails — including Payment Links, Pay Invoice, Payroll, or fiat buy/sell — the relevant Provider performs the verification, screening, and execution required for that service under its own authorisations and AML programme; Swaps does not hold, move, or settle those funds.

2. Why Swaps is not the provider of regulated money movement

Under EU AML law (Directive (EU) 2015/849 as amended by 2018/843 and the new AML Regulation 2024/1624), AML-obligated entities are:

  • credit and financial institutions;
  • crypto-asset service providers (CASPs) as defined by MiCA — that is, persons providing custody, exchange, transfer, advice, or order-execution services in relation to crypto-assets;
  • certain other professional service providers (lawyers, accountants, real-estate agents, etc. — not us);
  • providers of trust and company services (not us).

Under the current model, Swaps does not itself perform these activities in its own name. Swaps:

  • Does not custody crypto-assets or fiat for users.
  • Does not safeguard private keys, seed phrases, passkey secrets, session keys, or other means of access.
  • Does not execute exchanges or transfers of crypto-assets in its own name.
  • Does not advise on specific crypto-assets.
  • Does not match orders or operate an order book.
  • Does not provide trust or company services.

Core comparison and routing is an information-society service under Directive 2000/31/EC. The Wallet Service is non-custodial wallet software. Provider-executed flows are carried out by the relevant Provider in its own name.

This position is documented in the Terms of Service §1 and is supported by the architecture of the codebase: no custody table, no fund-flow ledger, encrypted-handoff redirect_init to the Provider, no order-matching engine.

3. What Swaps does do (perimeter controls)

Even where Swaps is not the Provider performing regulated execution, it operates perimeter controls to reduce the risk of being misused:

ControlWhat it does
Sanctions perimeter (country level)Network-layer geo-block of comprehensively sanctioned jurisdictions (Cloudflare WAF) plus country-level Prohibited enforcement in our routing layer. Per-person and per-address sanctions screening is performed by the licensed Providers we route to as part of their KYC programmes (typically against the OpenSanctions consolidated list aggregating UN, EU, UK OFSI, US OFAC SDN, and other national lists). Swaps itself does not currently perform per-address sanctions screening; this is tracked as future work on our compliance backlog. See the Sanctions policy.
Geo-block at the network layerCloudflare WAF blocks traffic from sanctioned jurisdictions (Cuba, Iran, North Korea, Syria, Russian-occupied Crimea / DPR / LPR).
Multi-account & abuse detectionWe detect attempts to multi-account, scrape, or run automated transactions, and we block them. Patterns suggesting structuring or layering for AML purposes are referred for review.
Provider selectionWe only integrate with Providers that themselves operate AML programmes — KYC, transaction monitoring, suspicious-activity reporting in their own jurisdiction. We do not list unlicensed or unregulated counterparties.
Cooperation with authoritiesWe respond to lawful requests from competent authorities for transaction metadata and Wallet metadata we hold within the limits of GDPR and our retention windows. Where we observe activity consistent with sanctions evasion or financial crime, we may proactively share available information with the relevant Provider and, where appropriate, authorities.

4. Travel Rule

The FATF Travel Rule (and its EU implementation in TFR — Regulation (EU) 2023/1113) applies to transfers of crypto-assets between obligated entities. Swaps does not itself transfer, custody, or execute crypto-asset transfers in its own name. For provider-executed products such as Payment Links, Pay Invoice, Payroll, or fiat buy/sell, the regulated Provider performs the execution and any required Travel Rule process under its own authorisations. For direct Wallet use, Swaps provides non-custodial wallet software and does not control the transfer or the means of access.

Where the Provider is required to collect or share Travel Rule information (originator name, address, account number, beneficiary name, account number), the Provider collects that information in its own flow. Swaps assists with available metadata where legally required or contractually required by the Provider, but does not itself hold funds or control settlement.

5. MiCA / CASP regulatory status

Under MiCA (Regulation (EU) 2023/1114), an entity becomes a CASP if it provides one or more crypto-asset services in its own name and for a fee. Based on the current non-custodial software, comparison, routing, and provider-executed model, Swaps is intended to operate outside custody, exchange, transfer, payment-account, e-money, and order-execution services by Swaps itself.

If Swaps' business model changes — for example, if Swaps begins holding user funds, safeguarding or controlling means of access, operating payment accounts or e-money balances, executing transactions in its own name, or providing crypto-asset advice — then CASP authorisation or another regulatory authorisation would be evaluated before launch of that activity.

6. Cooperation with Providers

Each Provider has its own AML and Travel Rule obligations. Where we share metadata with a Provider as part of the encrypted handoff (redirect_init), we share only what the Provider needs to initiate the transaction (pair, amount, destination address, optional email reference). The Provider then collects whatever AML/Travel Rule data its programme requires from the user, directly.

7. Provider-executed and wallet product flows

Some Swaps products result in value moving between parties. In every case, Swaps remains a technical and commercial interface: it never receives, holds, transmits, or takes custody of funds, and it is never a destination for funds.

  • Payment Links — the merchant's customer pushes payment, and the regulated Provider (Bridge) creates and settles the transfer directly to the merchant's settlement destination. See the Payment Link Terms.
  • Pay Invoice — the payer funds a provider-side payment instruction for a supported bank invoice; Bridge/provider-side rails settle the recipient where the corridor is enabled. See the Terms of Service and the product flow shown before payment.
  • Payroll — the employer instructs payouts, and the regulated Provider (Bridge) executes and settles the transfers to recipients. See the Payroll Terms.
  • Wallet Service — direct on-Tempo Wallet use is non-custodial wallet software. Swaps may display balances, prepare transaction data, submit user-authorized signed transactions, and show status, but cannot unilaterally move, freeze, recover, or settle Wallet funds. See the Wallet Service Terms.

In provider-executed flows the Provider performs customer due diligence (KYC/KYB), transaction screening, and execution under its own authorisations and AML programme. Swaps' role is to maintain its own AML programme and to assist the Provider as required under the Bridge Developer Agreement, including supporting KYC/KYB processes, monitoring for and reporting suspicious activity, and never holding funds. Swaps does not itself perform provider-side KYC and does not custody or settle the funds.

8. Contact

For AML-related inquiries, sanctions-related inquiries, or lawful information requests from authorities:

  • Email: legal@swaps.app
  • Postal: Supa Labs OÜ, Oru tn 2, Tallinn 10127, Estonia.

We respond to lawful information requests within 30 calendar days, or sooner where the law requires.


Contact: legal@swaps.app

Related Pages