Legal

AML Policy

Last updated: 2026-05-13 · v0.1 — pending legal review. This Anti-Money Laundering (AML) Policy sets out the principles, procedures, and controls Halfin ("Halfin", "we", "us", "our") applies to prevent the use of its Services for money laundering, terrorism financing, sanctions evasion, fraud, and other financial crime. It forms an integral part of the Terms of Use and is binding on all Merchants and authorized personnel.

01

Commitment and standards

Halfin is committed to compliance with AML, counter-terrorism financing (CTF), and sanctions regulations applicable to its operations. We align our procedures with the recommendations of the Financial Action Task Force (FATF), with the sanctions regimes of the United States Office of Foreign Assets Control (OFAC), the United Nations Security Council, the European Union, and the United Kingdom, and with other applicable international standards.

We adopt a risk-based approach, applying controls proportionate to the risk profile of each Merchant, transaction, and counterparty.

02

Scope of application

This Policy applies to:

  • All Merchants onboarded to the Services and their beneficial owners, directors, and authorized personnel.
  • All transactions processed through the Services.
  • All Halfin personnel, contractors, and third-party providers handling Merchant data or transactions.
03

Customer due diligence (KYB)

Before establishing a business relationship, every prospective Merchant undergoes Know Your Business (KYB) verification. KYB includes, at minimum:

  • Verification of legal entity registration, including company name, registration number, and registered office.
  • Identification of directors, ultimate beneficial owners (typically holding 25% or more, or otherwise exercising control), and authorized signatories.
  • Verification of identity and address for each director and beneficial owner, using government-issued identification and proof of address.
  • Documentation of business model, including products and services offered, target verticals, and expected transaction profile (volume, frequency, geography, counterparties).
  • Documentation of source of funds and, where relevant, source of wealth.
  • Documentation of regulatory or licensing status, where applicable to the Merchant's activities.
  • Screening against international sanctions, PEP, and adverse media databases.
04

KYB approval

No Merchant is granted live access to the Services until KYB has been completed to Halfin's satisfaction and written approval has been issued by the compliance team.

05

Enhanced due diligence

Enhanced Due Diligence (EDD) applies to Merchants and transactions presenting higher money laundering or terrorism financing risk, including but not limited to:

  • Merchants operating in high-risk verticals (where permitted, including iGaming and similar).
  • Merchants with complex ownership structures, including trusts, nominee arrangements, or layered holding companies.
  • Merchants connected to politically exposed persons (PEPs) or their close associates.
  • Merchants located in or transacting with higher-risk jurisdictions.
  • Transactions exhibiting patterns inconsistent with the declared business profile.
  • Large transactions, unusually structured transactions, or transactions involving privacy-enhancing techniques.
06

EDD measures

EDD may include additional documentation requests, source-of-funds verification, on-call or video verification of beneficial owners, on-site review where appropriate, and senior compliance approval before continuing the relationship.

07

Ongoing monitoring

Halfin conducts ongoing transaction monitoring designed to detect activity inconsistent with declared business purpose or indicative of money laundering, terrorism financing, sanctions evasion, fraud, or other financial crime. Monitoring includes automated rule-based screening, behavioral analytics, and human review of flagged activity.

Halfin conducts periodic reviews of Merchant profiles, frequency depending on risk classification.

Merchants must promptly notify Halfin of any material change to:

  • Legal entity structure.
  • Beneficial ownership.
  • Business model, products, or target geographies.
  • Regulatory or licensing status.
  • Authorized personnel.
08

Sanctions screening

Halfin screens Merchants, beneficial owners, authorized personnel, and counterparty wallet addresses (where technically feasible) against:

  • OFAC Specially Designated Nationals (SDN) and related lists.
  • United Nations Security Council Consolidated List.
  • European Union consolidated financial sanctions list.
  • HM Treasury (United Kingdom) financial sanctions list.
  • Other sanctions lists as applicable.
09

Sanctions screening — enforcement

Screening is performed at onboarding and on an ongoing basis. Matches result in immediate restriction of access pending review and, where confirmed, termination of the relationship and reporting to appropriate authorities.

Halfin does not provide Services to any person or entity subject to comprehensive sanctions or located in jurisdictions listed in the Restricted Countries policy.

10

Wallet address screening

Where technically feasible and consistent with our non-custodial architecture, Halfin screens cryptocurrency wallet addresses involved in transactions against blockchain analytics indicators of illicit activity, including but not limited to:

  • Direct or indirect exposure to sanctioned addresses.
  • Connection to known darknet markets, mixers, or fraud schemes.
  • Exposure to ransomware payments.
  • Other high-risk attribution.
11

Wallet screening outcomes

Transactions involving high-risk addresses may be flagged, delayed, or rejected pending review.

12

Suspicious activity reporting

Halfin reports suspicious activity to financial intelligence units, law enforcement, and other competent authorities in accordance with applicable law.

Halfin is not obligated to disclose to a Merchant whether a report has been filed about activity involving that Merchant. "Tipping off" a Merchant about a filed report is prohibited where applicable law requires confidentiality.

13

Recordkeeping

Halfin retains KYB documentation, transaction records, monitoring outputs, and related records for at least five (5) years following the end of the business relationship or completion of the transaction, or longer where required by applicable law.

14

Restricted countries and activities

Halfin does not establish business relationships with, or provide Services to, persons or entities located in, incorporated in, or ordinarily resident in jurisdictions listed in the Restricted Countries policy.

Halfin does not provide Services for, and prohibits use of the Services in connection with, any activity listed in the Restricted Activities policy.

Both policies form an integral part of these AML controls and are updated based on changes in applicable law, official advisories, and internal risk assessment.

15

Cooperation with authorities

Halfin cooperates with lawful requests from regulators, law enforcement, financial intelligence units, courts, and other competent authorities. Such cooperation may include disclosure of personal data and transaction records, subject to applicable legal protections.

16

Training

Halfin personnel involved in AML-related functions receive periodic training on this Policy, applicable regulations, and emerging risks. Training is recorded and reviewed.

17

Governance

Halfin has appointed a compliance function responsible for the development, maintenance, and oversight of this Policy. The compliance function operates independently of commercial functions and has direct reporting access to senior management.

The Policy is reviewed at least annually and updated to reflect changes in applicable law, sanctions, regulatory expectations, and Halfin's risk profile.

18

Merchant obligations

Merchants must:

  • Provide accurate, complete, and current KYB and ongoing compliance information.
  • Maintain their own AML controls consistent with the requirements of their jurisdiction and business.
  • Not use the Services in connection with money laundering, terrorism financing, sanctions evasion, fraud, or any other activity listed in the Restricted Activities policy.
  • Cooperate with reasonable requests for information and documentation.
  • Notify Halfin promptly of any change in their compliance status or relevant regulatory developments.
  • Comply with all applicable laws in the jurisdictions in which they operate.
19

Consequences of non-compliance

Failure to comply may result in suspension or termination of access, reporting to authorities, and other measures consistent with applicable law.

20

Updates to this Policy

Halfin may update this Policy from time to time. Material changes will be notified through the Website, by email, or through the dashboard. Continued use of the Services after changes take effect constitutes acceptance.

21

Contact

Compliance inquiries: [email protected]

related

Keep reading across the cluster.

Terms of UseThe master agreement governing use of the halfin Services.Privacy PolicyWhat personal data we collect, how we use it, and your rights.Restricted ActivitiesActivities we do not provide Services for.Restricted CountriesJurisdictions where we do not provide Services.halfin FAQ — how crypto payments work end to endHow halfin invoicing, checkout, deposit addresses, payouts, conversion, and webhooks work. Browse every question or read the cross-cutting answers.Security and controls at halfinHow halfin protects the money path: HMAC-signed webhooks, scoped API keys, payout approvals with an audit trail, and reorg-aware crediting.Legal centerThe halfin legal center: Terms of Use, Privacy Policy, AML Policy, Cookie Policy and more. All documents are version v0.1 and pending full legal review.Refund PolicyWorking draft of how refunds work in our non-custodial model.Are crypto payments final?Yes — a confirmed on-chain transfer is irreversible and there are no chargebacks. Finality is a property of the chain, which is what makes reconciliation clean.Can I build while onboarding is pending?Yes — build against a sandbox key first. The sandbox is the same API as production with test data, and your full integration is verified before going live.How does halfin attribute operator actions?Each action a person takes in the dashboard is recorded against them, so after the fact you can answer who released a withdrawal or issued an API key.What happens during onboarding review?Onboarding review is the business-verification step before a live key moves real funds. What it establishes, why it scales to your business, and where it is settled.