Legal · Platform documentation

AML / Compliance Policy

CIB INCEPTIONLast updated 11 April 2026

This AML / Compliance Policy describes the approach of CIB INCEPTION to preventing money laundering, terrorist financing, sanctions evasion, fraud, abuse of platform infrastructure, and other unlawful or bad-faith use of platform services (collectively, the “Services”).

By using the Services, the user confirms that they have read this AML / Compliance Policy and understand that access to certain functions, products, and transactions may depend on compliance, AML, sanctions, fraud, and security checks.

1Purpose of This Policy

The purpose of this Policy is to protect the Services, users, partners, and infrastructure against:

  • money laundering;
  • terrorist financing;
  • sanctions evasion;
  • fraud;
  • use of nominees and concealed beneficial owners;
  • multi-accounting;
  • abuse of reward, referral, and staking mechanisms;
  • use of unlawfully obtained assets;
  • other unlawful, abusive, or high-risk conduct.

2Risk-Based Approach

The Services apply a risk-based approach.

The scope of review, availability of functions, permitted limits, transaction processing speed, and level of monitoring may depend, among other things, on:

  • the user’s jurisdiction;
  • the type of product or transaction;
  • the nature and volume of transactions;
  • source of funds;
  • origin of Digital Assets;
  • wallet activity history;
  • transaction patterns;
  • use of related accounts;
  • sanctions and reputational risk;
  • internal risk indicators;
  • other factors the Services consider relevant.

3What Checks May Be Applied

As part of AML / Compliance controls, the following may be applied:

  • user identification;
  • KYC / KYB checks;
  • proof of residential or registered address;
  • source of funds checks;
  • source of wealth checks;
  • sanctions screening;
  • PEP screening;
  • adverse media checks;
  • blockchain analytics;
  • wallet risk scoring;
  • transaction monitoring;
  • behavioral monitoring;
  • fraud detection;
  • enhanced due diligence;
  • manual review;
  • ongoing monitoring after onboarding.

The Services may determine the scope and sequence of such checks at their sole discretion.

4What Documents and Information May Be Requested

The Services may at any time request from the user:

  • identity documents;
  • proof of address;
  • selfie / liveness verification;
  • company documents, where a corporate account is used;
  • information about the beneficial owner;
  • information about source of funds;
  • information about source of wealth;
  • information about the origin of Digital Assets;
  • explanation of the economic purpose of transactions;
  • information about counterparties;
  • proof of control over a wallet or account;
  • any other documents and explanations reasonably necessary for AML, sanctions, fraud prevention, security, or compliance purposes.

Failure to provide such information may result in restriction, suspension, or termination of service.

5Sanctions and Restricted Jurisdictions

Users are prohibited from using the Services:

  • in violation of sanctions regimes;
  • on behalf of sanctioned persons;
  • to circumvent geographic, legal, or compliance restrictions;
  • to conceal jurisdiction, residency, beneficial ownership, or control.

The Services may restrict or terminate access to functions, accounts, or products if:

  • the user is located in a restricted jurisdiction;
  • the user acts on behalf of a sanctioned person;
  • a transaction is associated with sanctions risk;
  • there are indications of sanctions evasion or circumvention of restrictions.

6Blockchain Monitoring and Wallet Screening

Because part of the Services involves Digital Assets, the Services may use blockchain analytics and wallet screening tools.

As part of such procedures, the following may be analyzed:

  • origin of assets;
  • links between addresses and illicit activity;
  • interaction with mixers or obfuscation tools;
  • connections to darknet activity, scam schemes, ransomware, stolen funds, or sanctioned entities;
  • transaction chains and associated wallets;
  • suspicious patterns and abnormal behavior;
  • connections between multiple accounts, addresses, and devices.

The Services may use the results of such analysis as grounds for review, restriction, freezing, or refusal of service.

7Prohibited Conduct

The user is prohibited from using the Services for:

  • money laundering;
  • terrorist financing;
  • sanctions evasion;
  • concealment of source of funds;
  • concealment of the beneficial owner;
  • use of nominees;
  • use of stolen, hacked, illicitly obtained, or fraud-related assets;
  • providing false or misleading information;
  • use of another person’s documents or accounts;
  • creation of fake, nominee, technical, duplicate, or related accounts;
  • artificial splitting of transactions to bypass limits or checks;
  • coordinated actions designed to circumvent AML / compliance controls;
  • any other unlawful, fraudulent, abusive, or bad-faith activity.

8Anti-Abuse and Fraud Against the Platform

The Services treat as a violation any actions aimed at obtaining an improper benefit from the platform infrastructure, including:

  • multi-accounting;
  • creation of fake or related accounts;
  • use of third-party accounts to place one’s own funds;
  • allocation of personal funds through friends, relatives, employees, agents, nominees, or other stand-ins;
  • artificial generation of referral profit;
  • artificial extraction of staking income;
  • circular transfers among related accounts;
  • concealment of related ownership structures or coordination;
  • exploitation of calculation errors, delays, bugs, vulnerabilities, or infrastructure features;
  • attempts to obtain rewards, bonuses, referral income, or staking yield in a manner contrary to the economic logic of the product;
  • any other actions or omissions aimed at causing the Platform, the Services, providers, partners, or other users material, financial, operational, reputational, technical, or other harm, or creating a substantial risk of such harm.

9Measures That May Be Taken

Where the Services identify or reasonably suspect a violation of this Policy, they may, without prior notice:

  • request additional documents and explanations;
  • restrict access to certain functions;
  • reject a transaction;
  • delay execution of a transaction;
  • suspend the accrual of rewards, bonuses, or Yield;
  • block an account in whole or in part;
  • freeze Digital Assets during the review period;
  • suspend or prohibit withdrawals;
  • cancel improperly accrued Yield;
  • cancel rewards, bonuses, referral income, and other benefits;
  • recalculate balances, accruals, and transaction results;
  • refuse further service;
  • share data with providers, partners, and competent authorities where lawful grounds exist.

The user agrees that any improperly obtained rewards, bonuses, Yield, referral income, or other economic benefits shall not be regarded as lawfully acquired and may be cancelled unilaterally.

10Enhanced Due Diligence

The Services may apply enhanced due diligence where a transaction, account, user, or counterparty is associated with elevated risk.

Grounds for enhanced due diligence may include, among other things:

  • large or unusual transactions;
  • complex or non-transparent transaction patterns;
  • use of high-risk jurisdictions;
  • high transaction frequency;
  • links to high-risk wallets;
  • elevated sanctions, fraud, or reputational risk;
  • signs of nominee use or related accounts;
  • inconsistent information or documents;
  • other factors the Services consider material.

11Ongoing Monitoring

User review is not limited to the onboarding stage.

The Services may conduct ongoing monitoring throughout the entire period of use of the platform, including:

  • repeated KYC / AML checks;
  • repeated sanctions screening;
  • analysis of new transactions and wallet activity;
  • updates to the user’s risk profile;
  • repeated requests for documents or explanations;
  • review of limits, statuses, and availability of functions.

12Refusal of Service and Termination of Access

The Services may refuse account opening, access to a product, execution of a transaction, or continuation of service without disclosing detailed internal reasons where necessary for:

  • compliance with law;
  • AML / CFT purposes;
  • sanctions control;
  • fraud prevention;
  • anti-abuse protection;
  • security purposes;
  • protection of users, partners, and infrastructure;
  • reduction of legal, regulatory, operational, or reputational risks.

13No Obligation to Disclose Internal Criteria

The Services are not required to disclose to the user:

  • internal AML / fraud thresholds;
  • risk scoring logic;
  • monitoring scenarios;
  • automated detection criteria;
  • internal alerts;
  • full results of internal investigations;
  • the grounds and technical details of suspicions, where disclosure could prejudice security, compliance, or legitimate interests of the Services.

14Storage and Sharing of Compliance Data

Data obtained as part of AML / Compliance procedures may be stored, used, analyzed, and shared to the extent necessary for:

  • compliance with legal requirements;
  • carrying out checks;
  • preventing unlawful activity;
  • investigating incidents;
  • protecting the rights and legitimate interests of the Services;
  • responding to requests from regulators, courts, and competent authorities.

15Interaction with Providers and Authorities

Where lawful grounds or reasonable necessity exist, the Services may interact with:

  • AML / KYC / KYT providers;
  • blockchain analytics providers;
  • payment and card partners;
  • banking partners;
  • custodial providers;
  • exchange and liquidity providers;
  • legal and audit advisers;
  • law enforcement, judicial, regulatory, and other competent authorities.

16Changes to This AML / Compliance Policy

This AML / Compliance Policy may be amended at any time. The updated version becomes effective upon publication unless stated otherwise.

Continued use of the Services after the changes take effect means that the user has reviewed the updated version and accepts it to the extent applicable.

CIB INCEPTION · AML / Compliance Policy · Last updated 11 April 2026