AML/KYC Statement

Effective: 7/30/2026 · Updated: 7/30/2026 · v2.0

1. Our Position

1.1. The operator of the EIDEX Platform (the “Company”) maintains a zero-tolerance approach to money laundering, terrorist financing, the financing of the proliferation of weapons of mass destruction and the circumvention of sanctions regimes. The operator's details are set out in section 1 of the User Agreement.

1.2. The Company operates an internal AML/CFT (Anti-Money Laundering / Countering the Financing of Terrorism) programme developed having regard to the Recommendations of FATF (the Financial Action Task Force) and the applicable law of the Republic of Seychelles.

1.3. This Statement is a public summary of our approach. The detailed internal AML/CFT programme, including procedures, thresholds and risk matrices, is approved by the Company's management and is provided to counterparties, auditors and competent authorities upon reasoned request. Certain parameters of the programme are not published, as their disclosure would reduce the effectiveness of the controls.

2. Organisation of the Compliance Function

2.1. The Company has appointed an officer responsible for the AML/CFT programme (MLRO — Money Laundering Reporting Officer). The MLRO is empowered to suspend transactions, initiate reviews and file reports with the competent authorities, and reports directly to the Company's management. The MLRO's contact details are provided to counterparties and competent authorities upon reasoned request.

2.2. The AML/CFT programme is approved by the Company's management, is version-controlled and is reviewed at least once every 12 months, and additionally on an ad hoc basis where there is a material change in the applicable law, sanctions regimes, the product range or the risk profile.

2.3. Employees whose duties relate to the acceptance and servicing of users, transaction monitoring or the handling of alerts undergo AML/CFT training upon appointment and thereafter on a regular basis.

2.4. Where individual functions (identity verification, blockchain analytics, screening against sanctions lists) are performed by external providers, responsibility for compliance with the requirements remains with the Company. Providers are selected on the basis of due diligence and their performance is monitored.

3. User Verification (KYC)

3.1. To access account functionality (trading, internal transfers, withdrawals, P2P transactions) users complete mandatory identity verification (KYC — Know Your Customer). Verification is mandatory before trading and withdrawals are carried out, and not only at the withdrawal stage.

3.2. Verification is carried out through an independent licensed identity provider (Sumsub) and includes checking the authenticity of the identity document, a biometric presence check (liveness), matching the document data against the data entered by the user, and screening against the lists specified in section 4.

3.3. The Platform applies verification tiers; the range of available transactions and daily limits depend on the tier attained. The current tiers and limits are displayed in the verification section of the user's personal account.

3.4. Instant exchange transactions are screened at transaction level (blockchain analytics, section 6); the Company is entitled to require KYC to be completed at any time where risk checks are triggered.

3.5. The Company is entitled to request re-verification (re-KYC) upon expiry of an identity document, a change in the user's data, a material change in the nature of transactions, or following a periodic review of the risk profile.

3.6. Minors (persons under 18 years of age) and persons connected with Prohibited or Restricted Jurisdictions (section 3 of the User Agreement) are not serviced. The use of VPNs, proxies and other means of concealing actual location in order to circumvent these restrictions is prohibited.

3.7. The Company does not open or service anonymous accounts or accounts in fictitious names. Transactions for the benefit of, and from, third parties (third-party deposits and payments) are prohibited.

4. Sanctions, PEP and Adverse Media Screening

4.1. Upon registration and thereafter on an ongoing basis, users and persons connected with them are screened against sanctions and restrictive measures lists, including:

  • OFAC (the Office of Foreign Assets Control of the U.S. Department of the Treasury), including the SDN list;
  • the consolidated sanctions list of the United Nations Security Council;
  • the consolidated sanctions list of the European Union;
  • the United Kingdom sanctions list (UK HM Treasury / OFSI).

4.2. In addition, screening is carried out for status as a politically exposed person (PEP), their relatives and close associates, as well as checks for adverse information in public sources (adverse media).

4.3. Screening is performed both at initial verification and by way of periodic re-screening: when sanctions lists are updated, previously verified users are screened again.

4.4. A match against sanctions lists constitutes grounds for the immediate blocking of transactions. PEP status does not automatically entail refusal of service, but places the user in a higher-risk category with mandatory enhanced due diligence (section 5) and a decision by an authorised officer.

5. Risk-Based Approach

5.1. Each user is assigned a risk level. The assessment takes into account: jurisdiction and residence, screening results (section 4), the stated purposes of using the Platform, the nature and volume of transactions, the risk profile of the blockchain addresses and counterparties used, and behavioural indicators.

5.2. The risk level determines the depth of due diligence, the frequency of profile review and the limits applied. The risk profile is reviewed periodically and upon the occurrence of trigger events.

5.3. For higher-risk users, enhanced due diligence (EDD) is applied, which may include: requesting information and documents on the source of funds and source of wealth, clarifying the purposes of transactions, confirming employment or activity, and approval of the relationship by an authorised officer.

5.4. The Company is entitled to refuse to establish or continue a relationship where the risk cannot be reduced to an acceptable level or where the user refuses to provide the information requested.

6. Transaction Monitoring and Blockchain Analytics

6.1. Cryptocurrency transactions undergo automated screening of the origin of funds (blockchain analytics, KYT — Know Your Transaction) on every deposit, exchange and withdrawal.

6.2. The Platform monitors for indicators of suspicious activity, including: links to darknet marketplaces, mixers and anonymisation services, stolen funds and the proceeds of hacks, fraudulent schemes, sanctioned addresses and addresses with a high risk score, as well as structuring of transactions (splitting amounts), inconsistency of transactions with the declared profile, and indicators that an account is being used by a third party.

6.3. The triggering of a monitoring rule generates an internal case (alert), which is reviewed by the responsible officer. Following the review a decision is taken: no risk identified, request for further information, application of EDD, suspension of transactions, termination of the relationship and/or filing of a report with the competent authority.

6.4. The Company documents the course of case reviews and the decisions taken.

7. Travel Rule

7.1. The Company recognises the applicability of FATF Recommendation 16 (the Travel Rule) to transfers of virtual assets and, as the corresponding requirements come into force in its jurisdiction of registration, implements the exchange of originator and beneficiary information with other virtual asset service providers (VASPs).

7.2. Transfers to service providers that do not support the required exchange of information, as well as transfers for which the necessary information cannot be obtained or verified, may be restricted or subjected to enhanced due diligence.

8. Freezing and Return of Funds During an AML Check

8.1. Every exchange transaction undergoes an automated AML check of the origin of the incoming funds before they are credited and the transaction is executed.

8.2. Where an AML check is triggered (links to sanctioned addresses, mixers, darknet marketplaces, stolen or other high-risk funds), the Company is entitled to suspend execution and freeze the incoming crypto-assets until the check is completed.

8.3. As part of the check, the Company is entitled to request information on the origin of the funds and/or completion of identity verification (KYC).

8.4. If the funds do not pass the AML check and the risk cannot be eliminated, the frozen crypto-assets are returned to the sender's address (the address from which they were received), less the network fee. Returns to any address other than the sender's address are not made.

8.5. Funds established to be linked to unlawful activity or to sanctions restrictions are not returned and may be blocked, with notification of the competent authorities in accordance with the applicable law.

9. Suspicious Activity Reporting and Cooperation with Authorities

9.1. The Company files suspicious activity/transaction reports (SAR/STR) with the authorised body in accordance with the applicable law and complies with lawful requests from competent authorities.

9.2. The Company does not notify the user of the fact that such a report has been filed where such notification is prohibited by the applicable law (the prohibition on “tipping-off”).

9.3. The Company does not establish or maintain correspondent relationships with shell banks.

10. Record Retention and Data Protection

10.1. The Company retains records of user verification, risk assessment, transactions and reviewed cases for at least 7 (seven) years from the termination of the business relationship or the carrying out of an occasional transaction — or longer where required by the applicable law or a lawful request from a competent authority.

10.2. Personal data is processed to the extent necessary to comply with AML/CFT requirements, applying organisational and technical protection measures. The processing arrangements, the categories of recipients and the user's rights are described in the Privacy Policy.

10.3. Information is disclosed to third parties only to the extent necessary to comply with the applicable law, lawful requests from competent authorities or the requirements of the Company's counterparties that facilitate the execution of transactions.

11. Questions

For questions relating to this Statement, please contact the Platform's support service or the e-mail address specified in the User Agreement.