AML/KYC Policy
Last updated: July 17, 2026
This Anti-Money-Laundering and Know-Your-Customer Policy (the “AML/KYC Policy”) explains how VEIL (“VEIL”, “we”, “us”, or “our”) and the independent providers it works with address money-laundering, terrorist-financing, sanctions, and fraud risk. It forms part of, and is incorporated into, our Terms of Use and should be read together with our Privacy Policy. By using the Services, you accept this AML/KYC Policy.
1. Our Role and Approach
VEIL is a privacy-focused, non-custodial aggregator. We do not take custody of funds and we do not execute transactions ourselves; we route Orders to independent third-party providers who do. As a result, the primary anti-money-laundering (AML) and know-your-customer (KYC) checks on any transaction are performed by the executing provider under its own regulatory obligations. VEIL takes a risk-based approach: we screen for obvious risk, surface each provider’s privacy and compliance posture, and cooperate with lawful requests, while collecting as little personal data as possible.
2. Provider Privacy and Compliance Tiers
Providers differ in how strictly they apply AML controls. To help you make an informed choice before you transact, the Services indicate each provider’s privacy and compliance posture, for example:
- High — providers that generally do not request identity verification for standard transactions and are expected to refund promptly if a transaction cannot proceed.
- Standard — providers that may request verification in specific, risk-based circumstances.
- Strict AML — providers that apply stronger controls and are more likely to request KYC or hold funds pending checks, including where a transaction is deemed higher risk.
These indications are informational and based on each provider’s stated practices and observed behavior; they are not a guarantee of how a provider will act in any given case.
3. Transaction Screening and Address Risk
Transactions may be screened against sanctions lists and analyzed for on-chain risk. Addresses and funds associated with elevated risk — for example those linked to sanctioned parties, theft, fraud, scams, ransomware, darknet markets, or mixing/tumbling services used to obscure illicit origin — may be refused, delayed, or escalated for additional checks. Addresses identified as sanctioned (for example on OFAC lists) may be automatically refused.
Do not send funds from mixers, gambling services, or with high AML risk to a transaction. Doing so significantly increases the chance that the executing provider freezes or holds the funds and requires verification before releasing them.
4. Prohibited Persons, Sources and Jurisdictions
You represent and warrant that the funds you transact are lawfully obtained and are not the proceeds of, or intended for, any unlawful activity, and that you are not acting for a sanctioned person. You may not use the Services if you or the funds involved are: subject to sanctions administered by the United Nations, the European Union, the United Kingdom, or the United States Office of Foreign Assets Control (OFAC); located in a comprehensively sanctioned or prohibited jurisdiction; or otherwise barred by applicable law. We may block, refuse, or restrict access on this basis without notice.
5. When a Transaction Is Flagged
Because VEIL is non-custodial, VEIL itself does not freeze funds. If a provider’s AML system or its liquidity partner flags an incoming deposit, the provider may hold, delay, or refund the transaction, or require identity verification or evidence of source of funds before releasing it. Whether, when, and how funds are released or returned in such cases is determined by the provider under its own policies and legal obligations, not by VEIL. Where a provider alleges that a user or the funds are subject to sanctions, the user may be required to demonstrate that they are not a sanctioned person before any payout.
6. Identity Verification (KYC) and Enhanced Due Diligence
The core swap service is designed to work without identity verification. However, KYC or enhanced due diligence may be required by a provider in specific circumstances, including:
- when a transaction is flagged as higher risk or a provider’s AML system is triggered;
- for crypto-to-fiat buy and sell, where regulated payment processors, banks, and on/off-ramps require identity verification;
- for prepaid card issuance and top-up, where the card issuer or program manager requires it; and
- where required by applicable law, sanctions screening, or a lawful request.
Verification may include confirming your identity, the source of funds, or the purpose of a transaction. This information is collected and controlled by the relevant provider under its own privacy policy; VEIL does not carry out KYC for standard swaps and may have no access to such documents.
7. Refunds of Held or Failed Transactions
Where a transaction cannot be completed, a refund may be issued by the provider, typically to the refund address you supply or to the originating address, under the provider’s own policies, timelines, and fees, with network fees deducted. Some providers do not support refund memos or tags; if your refund address requires one (for example, an address at a custodial exchange), a refund may not be credited automatically and you may need to contact that platform’s support. Providing a valid, self-custodied refund address is your responsibility. See the Refunds section of our Terms of Use for more.
8. Record-Keeping and Data
Consistent with our data-minimization approach, we keep only the limited data described in our Privacy Policy and retain it only for as long as necessary to operate the Services, support recent transactions, maintain security, and meet legal obligations. Any data we hold is disclosed outside of executing your transaction only on an individual basis where required by law or valid legal process, and is never sold. Providers keep their own records under their own obligations.
9. Reporting and Cooperation with Authorities
We may investigate suspected abuse and may restrict, suspend, or refuse service where we reasonably believe a transaction is connected to unlawful activity or sanctioned parties. We respond to duly issued, lawful requests from competent authorities and cooperate with law enforcement as required, while limiting disclosure to what is legally necessary. Providers may independently be required to file reports with their own regulators.
10. Your Responsibilities
You are responsible for ensuring that your use of the Services is lawful where you are located, that your funds are lawfully sourced, that you are not a sanctioned person and are not acting for one, and that you provide accurate destination and refund details. You agree not to use the Services to launder funds, finance terrorism, evade sanctions or taxes, or process the proceeds of crime, and you accept that providers may require verification before releasing funds.
11. Consequences of Non-Compliance
Failure to comply with this AML/KYC Policy may result in a transaction being refused, delayed, held, or refunded by a provider, in access to the Services being restricted or terminated, and, where required by law, in information being reported to the relevant authorities. VEIL does not control provider compliance decisions and is not liable for them.
12. Changes to This Policy
We may update this AML/KYC Policy from time to time. Changes become effective when posted on this page, and the “Last updated” date will be revised accordingly. Your continued use of the Services after any change constitutes acceptance of the revised Policy.
13. Contact
If you have any questions about this AML/KYC Policy, contact us at support@veil.exchange. For confidential matters you may encrypt your message with our PGP key, available in the site footer.