CypherGoat logo CypherGoat
Home Exchanges Affiliate TWIM
Swap

Compliance and AML Policy

How CypherGoat assesses and monitors the third-party providers it lists, applies sanctions controls, and cooperates with competent authorities.

Last updated: September 8, 2026

This policy describes the controls CypherGoat operates as a software interface. It should be read together with our Terms of Service and Privacy Policy. Compliance enquiries and legal process should be directed to compliance@cyphergoat.com.
  • 1. Purpose

    CypherGoat is committed to preventing its software from being used to facilitate money laundering, terrorist financing, sanctions evasion or any other criminal activity. This policy sets out the controls we apply, the limits of what a non-custodial interface can control, and how we work with the regulated and unregulated providers we list.

  • 2. Our Role and Regulatory Position

    CypherGoat operates a rate comparison and routing interface. We query third-party exchange providers for live quotes, display them, and pass the user's instruction to the provider the user selects.

    CypherGoat does not exchange fiat currency for digital assets, does not buy or sell digital assets as principal or agent, does not transmit value, and does not hold, pool or control customer assets at any point. We do not open accounts, hold balances, or maintain a customer relationship of the kind that gives rise to customer due diligence obligations.

    Because we never take possession of funds and are not party to the trade, the customer relationship in every transaction is between the user and the executing provider. Customer due diligence, transaction screening and suspicious activity reporting for that trade sit with the provider, which carries out those functions under its own legal and regulatory obligations. We support our partners in meeting those obligations and do not assist any user in circumventing them.

  • 3. Governance and Responsibility

    Responsibility for this policy sits with CypherGoat's designated compliance contact, reachable at compliance@cyphergoat.com. That function owns partner onboarding decisions, partner reviews, sanctions controls, responses to legal process, and the maintenance of this policy.

    This policy is reviewed at least annually, and additionally whenever there is a material change to our partner set, our product, or the legal framework applicable to us.

  • 4. Partner Due Diligence

    Every provider is assessed before it is integrated. Providers reach us through direct commercial approach or through our own market research, and no provider is listed without completing this assessment. We record the outcome of each assessment.

    Onboarding assessment covers:

    • Corporate identity. Legal entity name, jurisdiction of incorporation, registration details, and beneficial ownership where the provider will disclose it.
    • Licensing and registration status. Whether the provider holds a licence or registration in its home jurisdiction, and if so which.
    • Published compliance framework. Whether the provider maintains and publishes an AML policy, a sanctions policy, terms of use and a privacy policy, and whether those documents are coherent and current.
    • Stated verification practices. The circumstances in which the provider requires identity verification, and how it communicates that to users.
    • Sanctions posture. Whether the provider screens addresses and counterparties against applicable sanctions lists, and how it handles a match.
    • Adverse media and reputation. Public reporting, enforcement action, law enforcement seizure history, and unresolved user complaints.
    • Operational track record. Time in operation, liquidity source, settlement reliability, and responsiveness to support escalation.
    • Contact and escalation path. A working channel through which we can raise a compliance or user issue and get a response.

    Providers that will not engage with this assessment, or that decline to identify the operating entity, are not listed.

  • 5. Ongoing Monitoring

    Listing is not permanent. Partners are subject to periodic review and to event-driven review whenever something material comes to our attention.

    Between reviews we monitor settlement failures and delays, unresolved user complaints and support escalations, changes to a provider's published terms or compliance documentation, changes to licensing or corporate status, adverse media, and enforcement or law enforcement action. Patterns of user reports are treated as a monitoring signal in their own right.

  • 6. Suspension and Removal of Partners

    We may suspend or remove a provider from the interface at any time and at our sole discretion. Circumstances that will normally trigger removal include:

    • Credible evidence that the provider is facilitating criminal activity or sanctions evasion.
    • Enforcement action, licence revocation, or a law enforcement seizure affecting the provider.
    • Loss of a licence or registration that the provider previously relied on.
    • A sustained pattern of failed settlements, withheld funds, or unaddressed user complaints.
    • Withdrawal or material weakening of the provider's published compliance framework.
    • Refusal to engage with a compliance enquiry from us.
    • Any conduct that in our judgement makes continued listing inappropriate.

    Suspension takes effect immediately on the interface and does not require notice to the provider.

  • 7. Sanctions

    CypherGoat does not make its service available to persons or entities subject to sanctions administered by the United Nations, the United States Office of Foreign Assets Control (OFAC), or equivalent regimes, nor to users located in comprehensively sanctioned jurisdictions. The applicable restrictions and the current jurisdiction list are set out in our Terms of Service.

    Deposit and destination addresses identified as sanctioned are refused. Where a partner or a competent authority notifies us that a user is subject to sanctions or is circumventing a geographic restriction, we take the steps required to comply and will decline to serve further requests associated with that activity.

  • 8. Prohibited Activity

    CypherGoat has zero tolerance for use of its software for any illegal purpose. The prohibited uses set out in section 4 of our Terms of Service form part of this policy. We reserve the right to investigate suspected breaches, to refuse or block access to the interface, and to report activity to competent authorities where required or permitted.

  • 9. Source of Revenue

    CypherGoat is funded by commission paid by partner providers on completed trades routed through our interface, together with revenue from our commercial API. We do not charge users a fee above the rate quoted by the provider, we do not take a spread on user funds, and we do not receive, hold or route user assets in order to earn revenue.

    Commission is received from the providers listed on the interface. The due diligence and monitoring described in sections 4 to 6 are therefore also the controls we apply to the counterparties from which our revenue originates. Commission from a suspended or removed provider is not accepted for periods after removal.

  • 10. Cooperation with Authorities

    CypherGoat responds to validly issued legal process served through proper channels and cooperates with lawful requests from competent authorities. Requests should be sent to compliance@cyphergoat.com.

    We will state honestly what we do and do not hold. Because we are non-custodial and account-free, the records available to us are limited to the transaction metadata described in our Privacy Policy. Where the information sought sits with an executing provider rather than with us, we will say so and identify the provider.

  • 11. Record Keeping

    We retain partner due diligence and review records, records of partner suspensions and removals, records of compliance enquiries and our responses, and the transaction metadata described in our Privacy Policy. Retention periods for user data are set out in that policy. Compliance records relating to partners are retained for at least five years from the end of the relationship.

  • 12. Limits of This Policy

    We state plainly what a non-custodial interface can and cannot do. CypherGoat cannot screen a transaction it does not hold, cannot freeze funds it never controls, and cannot verify the identity of a user with whom it has no account relationship. Our controls operate at the level of partner selection, sanctions restrictions, prohibited use enforcement and cooperation with authorities. Transaction-level controls sit with the executing provider, and we assess each provider's capacity to apply them as part of the due diligence described above.

Compliance enquiries, partner due diligence requests and legal process: compliance@cyphergoat.com.

CypherGoat

CypherGoat

CypherGoat

About Us Blog Guides Affiliate Program Affiliate Login Transparency Status Merch

Resources

SafeRoute Partnered Exchanges Tor Site Contact Support Developer Portal API Documentation This Week In Monero MCP Server

Legal

Terms of Service Privacy Policy Compliance & AML CypherGoat Shield

Connect With Us

GitHub Twitter Telegram Channel SimpleX Bot

© 2026 CypherGoat. All Rights Reserved.

Proudly open-source onGitHub