helix

Compliance

What we do (and don't do) to keep Helix safe, compliant, and partnerable.

Our position

Helix is a non-custodial software tool, not a regulated financial institution. We do not hold user funds, do not transmit fiat, and do not provide investment, brokerage, or money services. As a result, we are not in scope of the UK Money Laundering Regulations 2017 (MLR17) for the Helix product itself.

We do, however, take compliance seriously — both because it protects our users and because it is a prerequisite for partnering with regulated EMIs (BVNK and similar), which our B2B offering depends on.

Our stack

Sanctions screening
Chainalysis (planned)
Every claim screens sender + recipient wallet addresses against OFAC SDN, UK OFSI, and EU consolidated lists. Hits are blocked at the API layer and reviewed manually.
Travel Rule (FATF Rec 16)
Notabene (planned)
For transfers ≥ USD 1,000, sender/beneficiary counterparty data is exchanged via Notabene's VASP-to-VASP network before settlement.
KYC / eKYC
Sumsub (planned)
For fiat ramps, users complete Sumsub's eKYC flow (passport + selfie + PoA for high-value) before any fiat leg. Helix never sees the KYC docs.
Fiat EMI partner
BVNK Limited (FCA #901007)
For GBP↔USDC and EUR↔USDC, the regulated partner (BVNK) handles all KYC, sanctions, and Travel Rule obligations. Helix routes users to BVNK's flow.

What we handle vs what our partners handle

ActivityHelixPartner (BVNK / others)
Sanctions screening on wallets✅ Yes (sender + recipient)
Sanctions screening on fiat counterparties✅ Yes
KYC on fiat users✅ Yes
KYC on crypto-only users⚠️ Optional / not required
Travel Rule (crypto-to-crypto, ≥$1k)✅ Planned (Notabene)
Travel Rule (crypto-to-fiat)✅ Yes
Suspicious Activity Reports (SARs)✅ To NCA / OFAC✅ To NCA / OFAC
Refunds / reversals❌ Cannot (blockchain finality)✅ Within their rails
Custody of customer funds❌ Never✅ Only during fiat leg

Prohibited jurisdictions and users

Helix blocks activity involving:

  • Any person, entity, address, or jurisdiction on the OFAC SDN list, the UK OFSI consolidated list, the EU consolidated list, or the UN Security Council list.
  • Residents or nationals of comprehensively sanctioned jurisdictions (currently: North Korea, Iran, Syria, Cuba for US persons, Crimea / DNR / LNR regions).
  • Anyone under 18 years old.
  • Anyone attempting to use the Service on behalf of any of the above.

Travel Rule (FATF Recommendation 16)

Helix adopts the FATF Travel Rule standard. For crypto-to-crypto transfers of less than USD 1,000, no counterparty information is required from users. For crypto-to-crypto transfers of USD 1,000 or more, Helix will (once the Notabene integration is live) require sender and recipient counterparty information to be exchanged via the Notabene VASP network before settlement.

For any transfer that involves a fiat leg, the regulated partner (currently BVNK Limited) applies its own Travel Rule compliance, which meets or exceeds the FATF standard.

Record keeping

We retain claim records (sender wallet, recipient wallet, amount, timestamp, transaction hashes, optional recipient phone, optional note) for a minimum of 7 years, in line with UK financial record retention requirements. These records are made available to UK and international law enforcement on valid legal process.

We do not retain the contents of private communications. We retain only the data you provide when creating or claiming a claim, plus standard server access logs (retained 30 days).

Reporting and disclosure

If we have reason to suspect that the Service is being used for money laundering, terrorism financing, sanctions evasion, fraud, or other criminal activity, we will:

  • File a Suspicious Activity Report (SAR) with the UK National Crime Agency (NCA) via the SARs Online system.
  • Notify OFSI of any sanctions-related concerns.
  • Cooperate with law enforcement on valid legal process (subpoenas, warrants, production orders).
  • Where appropriate, freeze the user's access and any in-flight claims.

We do not tip off users about SARs or law-enforcement inquiries.

Audits and security

We engage independent security auditors to review the ClaimEscrow smart contract before any production deployment to Base mainnet. Audit reports are available on request to qualified counterparties (lawyers, regulators, partners) under NDA.

We run a public bug-bounty program for our smart contracts and core infrastructure. Severity-tiered payouts (up to $50,000 for critical issues). Contact security@helix.money for the disclosure policy.

For partner due diligence

We're happy to provide detailed compliance documentation to qualified partners (regulated EMIs, MSBs, payment service providers, auditors, and law firms) under NDA. Contact compliance@helix.money with your request, and we'll respond within 2 business days.

A standard partner pack includes: company incorporation documents, director KYC, AML/CFT policy, data protection policy, smart contract audit report, insurance certificates, and a sample API integration guide.