Legal

Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF) Policy

A public summary of Cyrafa LLC's U.S. financial-crime compliance framework

Legal entityCyrafa LLC, a Montana domestic limited liability company
Federal statusFinCEN-registered Money Services Business (MSB), Registration No. 31000307129357
Registered activitiesMoney transmission and dealing in foreign exchange, as stated in Cyrafa's FinCEN registration record
Version3.0 | Effective upon publication | Last updated 11 August 2026

1. Introduction to the Policy and Objectives

Cyrafa LLC (“Cyrafa,” “we,” “us,” or “our”) is organized in Montana and registered with the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) as an MSB. FinCEN registration is a federal registration under the Bank Secrecy Act (BSA). It is not a bank charter, deposit-insurance status, state money-transmitter license, recommendation, certification, approval, or endorsement by FinCEN.

The Montana Division of Banking and Financial Institutions states that Montana does not regulate money transmitters as such, while noting that other Montana licenses may apply depending on the activities performed. Cyrafa therefore evaluates each service under applicable federal law and the laws of the states and countries involved. Services are offered only where Cyrafa or the relevant regulated service provider is legally permitted to provide them.

This Policy explains the high-level principles governing Cyrafa’s AML/CFT, KYC/KYB, sanctions, transaction-monitoring, reporting, training, recordkeeping, risk-assessment, and independent-review controls. Its objectives are to prevent Cyrafa’s services from being used for money laundering, terrorist or proliferation financing, sanctions evasion, fraud, or other unlawful activity; identify, assess, and mitigate customer, product, geographic, transaction, counterparty, delivery-channel, partner, and digital-asset risks; comply with applicable BSA, FinCEN, OFAC, and other legal requirements; and establish clear responsibility for escalation, investigation, reporting, recordkeeping, training, and review.

This Policy applies to Cyrafa’s applicable business-account, payment, foreign-exchange, SWIFT/IBAN, payout, treasury, crypto-to-fiat, digital-asset, and related services as made available. It applies to customers, prospective customers, beneficial owners, controllers, directors, authorized users, payers, payees, merchants, counterparties, relevant personnel, agents, contractors, vendors, and service providers connected with a relationship or transaction.

This is a public summary. Cyrafa maintains separate confidential internal policies, risk assessments, procedures, systems, alert logic, investigation methods, thresholds, and reporting protocols. Nothing in this Policy requires Cyrafa to disclose confidential controls or creates a right to receive or continue receiving a service.

2. Definitions of Money Laundering and Terrorism Financing

Money laundering means conducting, attempting, or assisting a transaction involving property derived from unlawful activity to promote unlawful activity or to conceal or disguise the nature, location, source, ownership, or control of the property. It may involve placing illicit funds into the financial system, moving or converting them through transactions, and integrating them into apparently legitimate activity.

Terrorism financing means directly or indirectly providing, collecting, moving, storing, or using funds, property, financial services, or other value with the knowledge or intention that they will support a terrorist act, terrorist, or terrorist organization. Unlike money laundering, terrorism financing may involve funds obtained from lawful or unlawful sources.

These definitions include attempts, participation, facilitation, conspiracy, and assistance where covered by applicable law.

3. Governance

Cyrafa maintains a risk-based AML/CFT program reasonably designed for its size, services, customers, transaction activity, delivery channels, counterparties, geographic exposure, digital assets, networks, and third-party relationships. Consistent with the BSA rules applicable to MSBs, the program includes written policies, procedures, and internal controls; a designated AML Compliance Officer responsible for day-to-day administration; ongoing, role-appropriate training for relevant personnel; and independent review at a frequency and scope proportionate to risk.

Senior Management provides oversight, supports the compliance function, approves the risk-based framework, provides appropriate authority and resources, and receives material compliance information.

The AML Compliance Officer administers the program, implements and monitors controls, coordinates training and review, maintains required records, investigates escalations, and ensures required regulatory reporting.

Relevant personnel must follow applicable controls, complete assigned training, protect confidential information, and promptly escalate suspicious or prohibited activity.

Cyrafa may use banks, payment institutions, custodians, exchanges, liquidity providers, compliance vendors, technology providers, or other parties to support a service. Cyrafa applies risk-based due diligence and oversight proportionate to their role and risk. Outsourcing does not eliminate obligations that remain applicable to Cyrafa, and a partner may impose its own separate compliance requirements.

4. Prevention Procedures

4.1 Customer and business due diligence: Before activating a relationship or regulated feature, and throughout the relationship where appropriate, Cyrafa obtains and verifies information proportionate to the customer and risk. For a business, this may include legal and trading names; formation, registry, tax, address, contact, and active-status information; constitutional documents and licenses or authorizations relevant to the business; identity and authority of directors, managers, account administrators, signatories, and other authorized persons; direct and indirect ownership, beneficial owners, controllers, and the ownership and control structure; business model, products and services, customer types, counterparties, websites, expected volumes, transaction purpose, countries, currencies, and payment or settlement flows; and bank accounts, wallet addresses or wallet control, source of funds, source of wealth, and supporting commercial documents where warranted by risk.

For an individual associated with a customer or transaction, Cyrafa may collect and verify name, date of birth, residential address, nationality, government-issued identification, contact details, occupation, authority, and other information permitted by law. Verification may use documents, reliable databases, liveness or biometric checks, device and network information, and other reasonable methods. Cyrafa may require certified, translated, notarized, or updated records and may consult registries, banks, professional advisers, counterparties, or other reliable sources where lawful and appropriate.

Cyrafa does not permit anonymous or fictitious relationships, and no relationship is approved until required due diligence and compliance decisions are complete.

4.2 Risk rating and enhanced due diligence: Customer risk is assessed using relevant factors rather than a single data point. Higher-risk relationships or transactions may require additional identity or ownership verification, deeper review of business purpose and counterparties, source-of-funds or source-of-wealth evidence, licenses, contracts, invoices, bank or financial statements, wallet history, transaction rationale, additional approval, enhanced monitoring, or more frequent review.

PEP status, association with a higher-risk jurisdiction, or adverse information does not by itself establish wrongdoing. These indicators are assessed in context. Cyrafa may nevertheless decline or restrict activity where information is incomplete, false, contradictory, unverifiable, unlawful, inconsistent with the stated purpose, or outside its risk appetite.

4.3 Sanctions, digital-assets, and prohibited use: Cyrafa maintains risk-based controls designed to comply with sanctions administered by the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC). Depending on the service and risk, screening may cover customers, beneficial owners, controllers, authorized persons, counterparties, payment parties, transaction data, and wallet addresses at onboarding, during transactions, when information changes, and through periodic or event-driven re-screening.

Where digital assets are involved, preventive controls may include validation of supported assets, networks, transaction hashes, wallet ownership or control, originator and beneficiary information, blockchain analytics, transaction tracing, direct or indirect exposure review, and assessment of chain, token, bridge, exchange, hosted or self-hosted wallet, and counterparty risk.

Cyrafa does not knowingly permit its services to be used for money laundering, terrorist or proliferation financing, sanctions evasion, structuring, fraud, scams, identity theft, corruption, bribery, tax crime, or concealment of beneficial ownership; false identities, forged or altered documents, impersonation, unauthorized access, or misleading transaction information; ransomware, malware, stolen assets, darknet markets, trafficking, child sexual-abuse material, illegal weapons or narcotics, or other serious criminal activity; unlicensed or unlawfully offered financial, investment, gambling, money-service, virtual-asset, or payment activity; or attempts to circumvent onboarding, screening, monitoring, approvals, geographic restrictions, recordkeeping, or regulatory reporting.

Additional restrictions may appear in Cyrafa’s Terms of Service, Acceptable Use rules, partner agreements, or risk appetite. An activity not listed here is not automatically permitted.

5. List of Applicable Laws, Regulations and International Standards

Cyrafa’s framework is principally informed by the following, as applicable to its actual services, customers, locations, and transactions.

United States federal law and regulation: the Bank Secrecy Act, 31 U.S.C. § 5311 et seq.; FinCEN regulations in 31 C.F.R. Chapter X, including Parts 1010 and 1022; applicable provisions of the USA PATRIOT Act and the Anti-Money Laundering Act of 2020, together with implementing rules in effect; federal money-laundering laws, including 18 U.S.C. §§ 1956 and 1957; applicable terrorism-financing and material-support laws, including 18 U.S.C. §§ 2339A-2339C; sanctions laws and regulations administered by OFAC, including applicable regulations in 31 C.F.R. Chapter V; and applicable FinCEN guidance and advisories concerning money transmission and convertible virtual currency.

Montana, other jurisdictions, and international standards: applicable Montana entity, commercial, consumer, privacy, and activity-specific laws; licensing and legal requirements of other U.S. states or countries where a service, customer, transaction, or regulated partner creates such obligations; and the Financial Action Task Force (FATF) Recommendations and relevant risk-based guidance.

FATF materials are international standards, not independently binding legislation on Cyrafa. They are considered where relevant and apply legally only to the extent implemented through applicable law, regulation, contractual obligation, or partner requirement.

6. Obligations

Cyrafa’s obligations: maintain and renew its FinCEN MSB registration and maintain required agent information where applicable; maintain an effective written AML/CFT program appropriate to its risks; perform risk-based KYC/KYB, screening, monitoring, escalation, and due diligence; maintain required customer, transaction, funds-transfer, reporting, and supporting records; file SARs, CTRs, OFAC reports, and other reports when legal conditions are met; respond to lawful requests from regulators, courts, and law-enforcement authorities; and apply appropriate due diligence and oversight to agents, foreign counterparties, regulated partners, and service providers.

Customer obligations: Customers and connected persons must provide complete, accurate, current, and non-misleading information; respond to reasonable compliance requests; use only authorized accounts, wallets, and payment methods; and notify Cyrafa of material changes to ownership, control, business activity, licenses, location, expected activity, or authorized users.

Failure to cooperate, unexplained inconsistency, suspected unlawful activity, or risk outside Cyrafa’s appetite may result in delayed onboarding, rejection of a transaction, restriction or suspension, return of funds where lawful and operationally possible, termination, reporting, or other action permitted or required by law. Cyrafa may apply controls more stringent than the minimum legal requirement.

7. Compliance and Reporting

Compliance concerns are escalated to the AML Compliance Officer or an authorized delegate. Material matters may be reported to Senior Management, subject to SAR confidentiality and other legal restrictions. Cyrafa documents material alerts, investigations, decisions, approvals, and filings in accordance with internal procedures.

An automated alert, blockchain label, risk score, or screening result informs review but does not by itself establish wrongdoing or determine the outcome. Cyrafa assesses available facts, customer profile, transaction purpose, proximity, value, frequency, recency, patterns, counterparties, and reliable mitigating information.

Cyrafa may share information with financial institutions, regulated partners, service providers, or authorities when permitted or required by law and subject to appropriate safeguards. Reporting or cooperation by a service provider does not eliminate any obligation that remains applicable to Cyrafa.

8. Commitment

Cyrafa is committed to maintaining an effective, risk-based AML/CFT and sanctions framework. Senior Management supports the independence and authority of the compliance function and provides resources proportionate to Cyrafa’s size, services, risk profile, and legal obligations.

Cyrafa does not knowingly permit retaliation against personnel who make a good-faith internal compliance report. Commercial considerations must not override a legal reporting, blocking, rejection, or escalation requirement.

9. Transaction Monitoring

Cyrafa monitors activity through automated and manual, real-time and retrospective controls proportionate to the service and risk. Monitoring may consider transaction size, frequency, velocity, structuring, rapid movement, pass-through activity, unusual conversion, multiple accounts or wallets, device or location anomalies, beneficiary changes, payment narratives, source and destination, customer profile, counterparties, chargebacks, and deviations from expected activity.

Transactions may be subject to maker-checker approval, compliance review, additional authentication, or information requests before release. For digital-asset activity, Cyrafa may use blockchain analytics to assess wallet ownership or control, sanctions exposure, fraud, stolen funds, scams, ransomware, darknet markets, mixers or tumblers, high-risk services, and other illicit-finance indicators.

During review, Cyrafa may request information; delay, decline, cancel where possible, restrict, hold, or prevent a transaction; limit account functionality; conduct a lookback; return funds where lawful and operationally possible; or terminate a relationship. Cyrafa does not guarantee completion within a particular time while compliance checks are pending.

10. Reporting of Suspicious Activity

Personnel must promptly escalate activity that they know, suspect, or have reason to suspect may involve unlawful proceeds, evasion of BSA requirements, structuring, fraud, sanctions evasion, terrorist financing, lack of apparent lawful purpose, or activity inconsistent with the customer’s known profile.

The AML Compliance Officer or authorized delegate assesses the available information, documents the decision, and determines whether a Suspicious Activity Report (SAR) or other action is required. Cyrafa files required SARs with FinCEN within the legally prescribed period and may file voluntarily where permitted and appropriate.

The absence of a SAR filing does not prevent Cyrafa from restricting or terminating activity based on law, partner requirements, contractual rights, or risk appetite.

11. Confidentiality of Information

Customer, compliance, investigation, and reporting information is restricted to persons with an authorized business or legal need to know and is protected through appropriate access, security, retention, and disposal controls. Cyrafa may use qualified vendors to verify identity, screen parties, monitor transactions, analyze blockchains, store records, or support investigations, subject to appropriate safeguards and applicable law.

SARs and information that would reveal whether a SAR has been filed or considered are confidential. Cyrafa will not notify a person involved in the activity of a SAR decision except where disclosure is permitted by law. Cyrafa may also withhold specific reasons for a compliance action where disclosure is prohibited or could compromise security, an investigation, or regulatory reporting.

12. External Reporting

Where applicable, Cyrafa reports to the competent authority, including through SARs and Currency Transaction Reports (CTRs) filed with FinCEN; OFAC blocking, rejection, annual blocked-property, or other required sanctions reports; responses to lawful subpoenas, court orders, regulatory requests, law-enforcement inquiries, or information-sharing requests; and other reports required by applicable federal, state, or foreign law.

External filings are made only by authorized personnel and within applicable deadlines. Regulatory reporting does not require Cyrafa to disclose the filing or its contents to a customer or counterparty. Cyrafa may use lawful information-sharing mechanisms where applicable and subject to their requirements.

13. Record Keeping

Cyrafa maintains records required by applicable law, which may include customer and beneficial-ownership information, verification documents, authorization records, risk assessments, account and wallet information, transaction and funds-transfer records, screening results, alerts, investigations, decisions, approvals, regulatory filings and supporting material, sanctions reports, training records, independent-review documentation, and remediation evidence.

BSA records are generally retained for at least five years where the relevant rule applies. Specified OFAC records are retained for ten years. Records may be retained longer where required by another law, contract, legal process, investigation, litigation hold, or preservation obligation.

Records must be accurate, retrievable, protected from unauthorized alteration or disclosure, and made available to competent authorities where lawfully required. Information is handled in accordance with applicable law and Cyrafa’s Privacy Policy.

14. AML and CTF Training

Relevant personnel receive initial and ongoing AML/CFT and sanctions training appropriate to their responsibilities and Cyrafa’s risk profile. Training may address KYC/KYB, beneficial ownership, suspicious-activity indicators, structuring, sanctions, digital-asset risks, escalation, SAR confidentiality, recordkeeping, fraud, and changes in law, guidance, services, or threats.

Training completion and relevant materials are documented. Additional or remedial training may be assigned following control changes, incidents, review findings, or identified knowledge gaps.

15. Risk Assessment

Cyrafa assesses inherent and residual risk across customers, beneficial owners, business activities, products and services, transaction types, volumes, delivery channels, geographies, counterparties, digital assets and networks, agents, regulated partners, and service providers.

Risk assessments consider both expected and actual activity and are updated when Cyrafa introduces a material product or corridor, changes a process or provider, identifies a control weakness, experiences an incident, or encounters a material legal or threat change.

No single factor automatically determines risk. Higher risk does not necessarily establish wrongdoing, but it may require enhanced due diligence, approval, monitoring, restrictions, or rejection.

16. Compliance Effectiveness Review Plan

Cyrafa arranges independent review of its AML/CFT program at a scope and frequency commensurate with its risks. The reviewer may be a qualified internal or external person but must not be the person responsible for day-to-day administration of the program.

The review may assess governance, risk assessment, KYC/KYB, sanctions controls, transaction monitoring, SAR and CTR processes, funds-transfer records, digital-asset controls, training, agent or third-party oversight, recordkeeping, prior remediation, and whether the program is implemented effectively.

Review findings are documented and reported to appropriate management. Remediation actions are assigned to responsible owners, tracked against target dates, and validated where appropriate. Additional review may be conducted following a material incident, legal change, new product, significant control weakness, or major change in Cyrafa’s risk profile.

Cyrafa reviews this public Policy periodically and updates it when appropriate to reflect changes in law, guidance, services, partners, or risk. Material operational controls may be updated without prior public notice where necessary to protect customers, comply with law, or manage risk.

17. Contact

Questions about this Policy or good-faith concerns regarding possible misuse of Cyrafa’s services may be sent to [email protected]. Do not send identity documents, private keys, seed phrases, passwords, or other sensitive information unless Cyrafa specifically requests it through an approved secure channel.

Public policy notice: This document provides general information about Cyrafa’s compliance approach and is not legal, tax, financial, or regulatory advice to any customer or third party.