Sanctions & Restricted Jurisdictions
Last updated: 2026-06-27 Version: 1.1
This page lists jurisdictions where Swaps is not available, the sanctions lists we screen against, and how we handle sanctions matches. It complements the Terms of Service §3.3-3.4 and the AML Statement.
1. Comprehensively restricted jurisdictions
Swaps does not provide service to users located in, ordinarily resident in, or accessing the Service from:
- Cuba
- Iran
- North Korea (Democratic People's Republic of Korea)
- Syria
- Crimea region (Russian-occupied territory of Ukraine)
- Donetsk People's Republic and Luhansk People's Republic (Russian-occupied territories of Ukraine)
These restrictions reflect EU, UN, UK, and US comprehensive sanctions. The geo-block is enforced at the network layer (Cloudflare WAF). Attempts to bypass the geo-block via VPN, proxy, or other means breach the Terms of Service §3.3 and the Acceptable Use Policy.
2. Additional country-level limitations
In some countries, Swaps is technically accessible but specific Provider services may not be available due to Provider-side restrictions or local-law constraints. We surface this at quote time — if no Provider covers your country/payment-method combination, the Service tells you so rather than offering a non-functional path.
Country-level coverage may change as Provider integrations and local regulations evolve. The current list is reflected dynamically on the country and corridor pages of www.swaps.app.
3. How sanctions enforcement actually works on Swaps
Swaps does not itself perform provider-side KYC/sanctions screening for core wallet-only and comparison flows, and does not itself perform per-person or per-address sanctions screening at this time. Sanctions enforcement on the Service is layered, and each layer has a different actor:
- Network layer — geographic block. Cloudflare WAF blocks traffic from the comprehensively sanctioned jurisdictions in §1. This is enforced before any Swaps backend logic runs.
- Country-level routing layer — Swaps perimeter. Our backend country-routing layer marks sanctioned jurisdictions as Prohibited and blocks the Quote & Redirect flow at the country granularity before the user reaches a Provider.
- Provider KYC layer — per-person screening. The active fiat/payment Providers we route to, as listed in the generated taxonomy, operate their own AML programmes and perform person-level sanctions screening — including against the OpenSanctions consolidated list (UN, EU, UK OFSI, US OFAC SDN, and other national lists) where applicable — as part of their KYC at the time of the user's transaction with them. DEX/protocol integrations are categorized separately and do not make Swaps a custodian or AML-obligated exchange. Sandbox/pending providers, such as Onmeta until runtime proof is complete, and historical/removed providers, such as MoonPay, Onramp.money, and Onramper, are not described as live provider coverage.
Per-address OpenSanctions screening by Swaps itself, in addition to the Provider's screening, is tracked as future work on our compliance backlog and is not currently active. Until that work is shipped, address-level sanctions enforcement on Swaps is, by design, performed by the Provider as part of its own programme, not by Swaps.
This same layered framing applies across all Swaps products, including Payment Links and Payroll. Merchants, Payers, Employers, and payroll Recipients are all subject to sanctions screening. The Provider (Bridge) performs person-level sanctions screening of these parties at KYC, KYB, and transfer time under its own AML programme; Swaps enforces the same perimeter controls described above (the network geo-block in §1 and the country-routing layer) and does not itself perform per-person screening. A sanctions match at the Provider blocks the transfer or payout and may result in account action.
4. What happens when sanctions controls trigger
| Trigger | Layer | Action |
|---|---|---|
| Access from a comprehensively sanctioned jurisdiction (Cuba, Iran, North Korea, Syria, Crimea, DPR, LPR) | Cloudflare WAF (network) | Request blocked at the network edge with a generic compliance response. Most Swaps backend logic is not reached. |
| Quote requested for a country classified as Prohibited in our country-routing layer | Swaps backend perimeter | Quote refused. Generic compliance message displayed: "Service unavailable in your region." |
| Provider's own KYC sanctions screen identifies the user as a sanctions match | Provider KYC | The Provider blocks the transaction under its programme. Swaps does not receive the underlying match data; the Provider may share back a generic outcome. Refund and dispute are governed by the Provider's policies. |
| Suspected attempt to bypass geo-block via VPN, proxy, residential IP, or impossible-geolocation movement | Swaps backend abuse signals | Throttle, IP block, and possible Account suspension under the Acceptable Use Policy §3 and Limits & Enforcement. |
Swaps does not disclose specific match details to users, because doing so can frustrate enforcement and may not be appropriate where the matching layer is the Provider, not Swaps. Where required by law, we share information with the relevant authority.
5. False positives
Sanctions screening can produce false positives — common names match listed persons, name transliterations vary, addresses tagged in third-party feeds may not actually be sanctioned. The recourse depends on which layer flagged you:
- Country-level Swaps block — if you believe your country is incorrectly classified, email legal@swaps.app with a clear statement. We respond within 30 calendar days.
- Provider-level KYC block — the Provider is your counterparty for that flow; raise the false-positive claim through the Provider's own support channel. We will, on request, share with you the information we hold about your interaction so you can pursue the Provider (see Limits & Enforcement §8). Swaps does not require government ID for this Swaps-side review; the Provider may require ID under its own process.
6. Sanctioned crypto-assets and protocols
In addition to person and entity sanctions, certain crypto-mixers and protocols are themselves sanctioned by some jurisdictions (for example, Tornado Cash by US OFAC under SDN designation 2022-08-08). We do not facilitate transactions to or from sanctioned protocols where we have visibility.
Our Search Address Report surfaces exposure to such protocols where the data feeds we use include it. The report is informational — see the Search Address Report Terms.
7. Travel Rule and originator/beneficiary information
The FATF Travel Rule and its EU implementation (TFR — Regulation (EU) 2023/1113) require obligated entities to share originator and beneficiary information for crypto-asset transfers above certain thresholds. Provider obligations sit with the relevant obligated entities. Swaps cooperates with Providers and authorities using available metadata where lawfully required or contractually required, but Swaps does not move funds.
8. Crypto-asset exposure for the user
Some jurisdictions restrict the holding, trading, or use of crypto-assets in ways that go beyond sanctions. These include outright bans, capital controls, currency-export controls, or specific Provider blocks. Examples (non-exhaustive, may change):
- China: domestic crypto trading restrictions; Swaps does not route through Chinese-licensed Providers.
- Algeria, Bangladesh, Bolivia, Egypt, Iraq, Morocco, Nepal, Pakistan, Tunisia: domestic restrictions on crypto-asset trading; Provider coverage may be limited or absent.
- United States: state-by-state variation in money-transmitter licensing requirements affecting Provider availability per state.
These are jurisdictional restrictions the user is responsible for understanding and complying with. Swaps does not provide legal advice on whether your specific transaction is lawful in your country.
9. Updates
This list is maintained at this path and updated when sanctions regimes change. Major changes (new comprehensive jurisdiction added or removed) are reflected within 7 days of the underlying regulatory change. OpenSanctions list updates are continuous.
10. Contact
For any sanctions-related inquiry (user-side false positive, authority request, partner inquiry, list update):
- Email: legal@swaps.app
- Postal: Supa Labs OÜ, Oru tn 2, Tallinn 10127, Estonia
Contact: legal@swaps.app