Compliance
What we do (and don't do) to keep Helix safe, compliant, and partnerable.
Our position
Helix is a non-custodial software tool, not a regulated financial institution. We do not hold user funds, do not transmit fiat, and do not provide investment, brokerage, or money services. As a result, we are not in scope of the UK Money Laundering Regulations 2017 (MLR17) for the Helix product itself.
We do, however, take compliance seriously — both because it protects our users and because it is a prerequisite for partnering with regulated EMIs (BVNK and similar), which our B2B offering depends on.
Our stack
What we handle vs what our partners handle
| Activity | Helix | Partner (BVNK / others) |
|---|---|---|
| Sanctions screening on wallets | ✅ Yes (sender + recipient) | — |
| Sanctions screening on fiat counterparties | — | ✅ Yes |
| KYC on fiat users | — | ✅ Yes |
| KYC on crypto-only users | ⚠️ Optional / not required | — |
| Travel Rule (crypto-to-crypto, ≥$1k) | ✅ Planned (Notabene) | — |
| Travel Rule (crypto-to-fiat) | — | ✅ Yes |
| Suspicious Activity Reports (SARs) | ✅ To NCA / OFAC | ✅ To NCA / OFAC |
| Refunds / reversals | ❌ Cannot (blockchain finality) | ✅ Within their rails |
| Custody of customer funds | ❌ Never | ✅ Only during fiat leg |
Prohibited jurisdictions and users
Helix blocks activity involving:
- Any person, entity, address, or jurisdiction on the OFAC SDN list, the UK OFSI consolidated list, the EU consolidated list, or the UN Security Council list.
- Residents or nationals of comprehensively sanctioned jurisdictions (currently: North Korea, Iran, Syria, Cuba for US persons, Crimea / DNR / LNR regions).
- Anyone under 18 years old.
- Anyone attempting to use the Service on behalf of any of the above.
Travel Rule (FATF Recommendation 16)
Helix adopts the FATF Travel Rule standard. For crypto-to-crypto transfers of less than USD 1,000, no counterparty information is required from users. For crypto-to-crypto transfers of USD 1,000 or more, Helix will (once the Notabene integration is live) require sender and recipient counterparty information to be exchanged via the Notabene VASP network before settlement.
For any transfer that involves a fiat leg, the regulated partner (currently BVNK Limited) applies its own Travel Rule compliance, which meets or exceeds the FATF standard.
Record keeping
We retain claim records (sender wallet, recipient wallet, amount, timestamp, transaction hashes, optional recipient phone, optional note) for a minimum of 7 years, in line with UK financial record retention requirements. These records are made available to UK and international law enforcement on valid legal process.
We do not retain the contents of private communications. We retain only the data you provide when creating or claiming a claim, plus standard server access logs (retained 30 days).
Reporting and disclosure
If we have reason to suspect that the Service is being used for money laundering, terrorism financing, sanctions evasion, fraud, or other criminal activity, we will:
- File a Suspicious Activity Report (SAR) with the UK National Crime Agency (NCA) via the SARs Online system.
- Notify OFSI of any sanctions-related concerns.
- Cooperate with law enforcement on valid legal process (subpoenas, warrants, production orders).
- Where appropriate, freeze the user's access and any in-flight claims.
We do not tip off users about SARs or law-enforcement inquiries.
Audits and security
We engage independent security auditors to review the ClaimEscrow smart contract before any production deployment to Base mainnet. Audit reports are available on request to qualified counterparties (lawyers, regulators, partners) under NDA.
We run a public bug-bounty program for our smart contracts and core infrastructure. Severity-tiered payouts (up to $50,000 for critical issues). Contact security@helix.money for the disclosure policy.
For partner due diligence
We're happy to provide detailed compliance documentation to qualified partners (regulated EMIs, MSBs, payment service providers, auditors, and law firms) under NDA. Contact compliance@helix.money with your request, and we'll respond within 2 business days.
A standard partner pack includes: company incorporation documents, director KYC, AML/CFT policy, data protection policy, smart contract audit report, insurance certificates, and a sample API integration guide.