AML Policy

Last updated: April 27, 2026

1. Introduction

Inkryptus Investimentos e Corretagem Ltda ("Inkryptus") is committed to preventing the use of its platform for money laundering, terrorism financing, or any other illicit activity. This Anti-Money Laundering and Counter-Terrorism Financing Policy ("AML Policy") describes the measures, procedures, and controls that Inkryptus maintains to detect, prevent, and report suspicious activity.

This policy applies to all users, partners, employees, and contractors who interact with or operate the Inkryptus platform and its products.

2. Regulatory framework

Inkryptus operates on public blockchain infrastructure (BNB Smart Chain). The availability and legality of the platform depend on the laws and regulations applicable in each user's jurisdiction. Inkryptus monitors regulatory developments in the digital asset sector and aligns its compliance practices with applicable requirements, including but not limited to anti-money laundering, counter-terrorism financing, and sanctions obligations.

Users are responsible for ensuring that their use of the platform complies with the laws of their jurisdiction.

3. Know Your Customer (KYC)

3.1 Identity verification

Inkryptus requires identity verification through its KYC process, powered by Veriff. The verification process collects and validates personal identity documents and biometric data to confirm the identity of each user.

3.2 Verification tiers

TierRequirementMonthly withdrawal limit
BronzeAccount created, no KYCUp to US$500
SilverKYC completed and approvedUp to US$500,000

Users who have not completed KYC are subject to restricted withdrawal limits. Enhanced due diligence may be applied to users whose activity patterns, transaction volumes, or risk profile require additional verification.

3.3 When KYC is required

  • Account creation (basic information)
  • Increasing withdrawal limits beyond Bronze tier
  • When flagged by internal risk assessment or transaction monitoring
  • At Inkryptus's discretion based on risk indicators

3.4 KYC data handling

Identity verification data is processed by Veriff as a third-party data processor. Data handling follows the practices described in the Privacy Policy. Inkryptus does not store raw biometric data after verification is complete.

4. Transaction monitoring

4.1 Internal monitoring

Inkryptus maintains internal transaction monitoring systems that analyze user activity for patterns consistent with money laundering, terrorism financing, fraud, or other illicit conduct. Monitored parameters include, but are not limited to:

  • Transaction frequency, volume, and velocity
  • Unusual patterns relative to account history and profile
  • Rapid deposit-withdrawal cycles
  • Transactions inconsistent with stated account purpose
  • Activity patterns associated with known typologies of financial crime

4.2 Risk-based approach

Inkryptus applies a risk-based approach to transaction monitoring. Users and transactions are assigned risk scores based on multiple factors, including verification status, geographic indicators, transaction behavior, and external risk data. Higher-risk accounts and transactions are subject to enhanced scrutiny.

4.3 Alerts and escalation

When monitoring systems detect activity that meets predefined risk thresholds, alerts are generated for manual review by the compliance team. The compliance team evaluates the alert, may request additional information from the user, and determines whether further action is warranted, including account restriction or reporting.

5. Suspicious activity

5.1 Reporting

When Inkryptus identifies activity that it reasonably believes may constitute money laundering, terrorism financing, fraud, or other financial crime, it will report the activity to competent authorities as required by applicable law. Inkryptus does not notify users when a report has been filed, in accordance with legal obligations regarding confidentiality of such reports.

5.2 Account restrictions

Inkryptus may temporarily restrict account functionality (including deposits, withdrawals, and trading) when an account is under review for suspicious activity. Users will be notified of restrictions where legally permissible and will be given the opportunity to provide clarifying information. Restrictions are applied as a protective measure and are lifted once the review is concluded, unless further action is required.

For details on account suspension and termination procedures, see Terms of Use, Section 13.

6. Sanctions compliance

Inkryptus screens users and transactions against applicable sanctions lists, including but not limited to those maintained by relevant international and national authorities. Users identified as sanctioned persons, or users attempting to transact with sanctioned entities, will have their accounts restricted and reported to competent authorities.

7. Record keeping

Inkryptus retains transaction records, KYC documentation, and compliance-related correspondence for a minimum of five (5) years from the date of the transaction or the end of the business relationship, whichever is later. Records are maintained in accordance with the Privacy Policy and applicable data protection regulations.

Records may be retained for longer periods where required by law, regulation, or ongoing legal proceedings.

8. Employee and partner obligations

All Inkryptus employees and contractors with access to user data or platform operations are required to:

  • Complete AML/CFT training upon onboarding and on a periodic basis
  • Report any suspected illicit activity through internal channels
  • Maintain confidentiality regarding compliance investigations and reports

External partners and contractors are required to comply with the Terms of Use and must not promote the platform using misleading, fraudulent, or non-compliant communications.

9. Cooperation with authorities

Inkryptus cooperates with competent authorities in the investigation and prosecution of financial crimes. Upon receipt of a valid legal request, Inkryptus will provide requested information and documentation in accordance with applicable law. Inkryptus may also proactively report suspected criminal activity when it identifies indicators of serious financial crime.

10. Policy updates

This AML Policy is reviewed periodically and updated as necessary to reflect changes in applicable law, regulatory guidance, platform operations, or risk assessment. Material changes will be published on the platform with an updated effective date.

11. Contact

For compliance-related inquiries:

Inkryptus Investimentos e Corretagem Ltda CNPJ: 36.514.802/0001-67 Email: support@inkryptus.com


Ilisasishwa mwisho