This is a courtesy translation. The Portuguese version is the authoritative text and prevails in the event of any divergence.
No XIP user moves funds in Brazilian reais (BRL) without first having their identity verified and their verification record enabled. This prohibition is enforced by the system itself, on the server, on every operation — it does not depend on manual checking or on the application's configuration.
Purpose and scope
This policy establishes the guidelines, controls and internal procedures adopted by XIP to prevent and curb the use of its platform for money laundering, terrorist financing and the financing of the proliferation of weapons of mass destruction (AML/CFT and proliferation financing).
It applies to:
- all of XIP's partners, officers, employees, interns and service providers, with no exception by hierarchical level;
- all operations intermediated by the platform, particularly those converting between Brazilian reais and crypto-assets;
- all relationships with users, partners, suppliers and service providers.
Compliance with this policy is a condition of the relationship with XIP. Failure to comply subjects the offender to the applicable disciplinary and contractual measures, without prejudice to the civil and criminal liability provided for by law.
Reference legal framework
| Instrument | Subject matter |
|---|---|
| Law No. 9,613/1998 | Defines the crime of money laundering and establishes the duties of customer identification, record maintenance and reporting of operations. |
| Law No. 13,260/2016 | Governs terrorism and its financing. |
| Law No. 13,810/2019 | Provides for compliance with sanctions imposed by United Nations Security Council resolutions, including the immediate freezing of assets. |
| Law No. 14,478/2022 | Establishes guidelines for the provision of virtual asset services and for the legal entities that carry them out. |
| Law No. 12,846/2013 | Administrative and civil liability of legal entities for acts against the public administration. |
| Law No. 13,709/2018 (LGPD, Brazil's General Data Protection Law) | Delimits the processing of personal data, including in the performance of the obligations under this policy. |
| Recommendations of the FATF (Financial Action Task Force) | International AML/CFT standards, notably Recommendation 15 (new technologies and virtual asset service providers) and Recommendation 16 (transmission of originator and beneficiary information). |
Operating model and division of responsibilities
A correct understanding of XIP's operating model is essential in order to situate the controls described in this policy.
What XIP is
XIP is a technology provider that offers: (i) a non-custodial crypto-asset wallet, in which the private keys are generated and remain on the user's device; and (ii) an interface that allows the user to contract operations converting between Brazilian reais and crypto-assets.
It follows that XIP:
- does not hold custody of users' crypto-assets and has no technical capability to move, block or freeze them;
- does not maintain payment accounts or balances in Brazilian reais on behalf of users;
- does not perform the financial settlement of operations in Brazilian reais.
The role of the contracted provider
The settlement of operations in Brazilian reais and the verification of users' identity are carried out by an institution authorized to operate and subject to the competent regulation and supervision, engaged by XIP and referred to in this policy as the contracted provider. The following are the responsibility of the contracted provider, in its capacity as a regulated institution:
- the analysis of identification documents and the decision on identity verification;
- the safekeeping of identification documents for the statutory periods;
- the screening against restrictive and sanctions lists and the identification of politically exposed persons (PEPs);
- the monitoring of settled operations and the analysis of alerts;
- the reporting of suspicious transactions and other reports to the competent authorities;
- compliance with asset freezing and blocking orders.
This division is formalized in a contract that establishes compliance, confidentiality, information security and cooperation obligations, and secures XIP's right to require evidence of the provider's compliance with its regulatory duties.
XIP's own duties
Outsourcing the execution does not transfer XIP's responsibility for the integrity of its platform. The following are its own duties, performed directly and described throughout this policy:
- to collect the required identification data and documents and transmit them intact to the contracted provider;
- to technically prevent any operation by a user whose verification record is not verified and enabled;
- to keep complete, intact and auditable records of verification records, operations and events;
- not to create, offer or tolerate any mechanism that circumvents, weakens or conceals the contracted provider's controls;
- to forward to the contracted provider and to the authorities, as applicable, any indications of irregularity that come to its knowledge;
- to respond to requests from competent authorities in a timely manner;
- to select and periodically reassess the contracted provider as to its integrity and regulatory compliance.
The legal regime for virtual asset service providers in Brazil is being consolidated on the basis of Law No. 14,478/2022 and the regulations of the Central Bank of Brazil. XIP monitors this development and will adapt its compliance structure — including authorization, direct reporting and its own reporting obligations — to the extent and within the timeframes in which such duties become applicable to it.
Governance and responsibilities
| Body | Responsibilities |
|---|---|
| Management | Approve this policy and its revisions; provide sufficient human and technological resources; ensure the independence of the compliance function; be ultimately accountable for the effectiveness of the program. |
| Compliance and AML/CFT Officer Raphael Mirante — Diretor de Compliance |
Lead the implementation and maintenance of this policy; assess risks; analyze indications of irregularity and decide on referral; interact with the contracted provider and with authorities; conduct training; report to management. |
| Data Protection Officer (DPO) | Ensure that the controls under this policy are performed in compliance with the LGPD, particularly with respect to the minimization and the purpose of the processing. |
| Technology | Implement and maintain the technical controls described in this policy; ensure the integrity and availability of the records; not deploy any functionality that circumvents the eligibility controls. |
| Customer service and support | Recognize and escalate indications of irregularity; not instruct users to structure operations or to circumvent verification record requirements. |
| All personnel | Know this policy, report suspicions through the internal channels and observe the duty of confidentiality regarding the reports made. |
The Compliance and AML/CFT Officer has direct access to management and the authority to order the suspension of verification records and the halting of operations, without requiring approval from commercial functions.
Risk-based approach
Controls are calibrated according to the risk identified, so that situations of greater exposure receive proportionally more intensive due diligence.
Risk factors considered
| Dimension | Factors |
|---|---|
| User | Consistency of the verification record data; classification as a politically exposed person; presence on restrictive and sanctions lists; history of refusal in a previous verification; indications of acting on behalf of a third party. |
| Operation | Amount and frequency; inconsistency with the declared profile; structuring into amounts close to thresholds; atypical sequence of inbound and outbound operations within a short interval. |
| Channel | Exclusively digital and non-face-to-face, which raises the risk of identity fraud and reinforces the requirement of document verification with liveness proof. |
| Product | Conversion between Brazilian reais and crypto-assets, with settlement in an asset transferable to addresses outside the platform — a risk inherent to virtual assets. |
| Counterparty and destination | Wallet addresses associated with illicit activity, with asset mixing services or with high-risk jurisdictions. |
| Geography | Indications of a connection with jurisdictions under sanctions, with strategic AML/CFT deficiencies or under FATF monitoring. |
Classification and effect
| Category | Profile | Treatment |
|---|---|---|
| Low | Consistent and verified verification record, operations consistent with the declared profile | Standard due diligence and routine monitoring. |
| Medium | Minor discrepancies in the verification record or operations that depart from the historical pattern | Review of the verification record, request for clarification and observation for a defined period. |
| High | Politically exposed person, indication of acting through a third party, persistent atypical operating pattern or connection with a high-risk jurisdiction | Mandatory enhanced due diligence (EDD), approval at a higher level and a shortened periodic review interval. |
| Unacceptable | Presence on a restrictive or sanctions list, refusal to provide essential information or well-founded suspicion of illegality | Refusal or termination of the relationship and immediate referral to the contracted provider and to the authorities, as applicable. |
The internal risk assessment of the business is reviewed at least annually and whenever there is a material change in product, channel, technology, provider or regulatory framework.
User identification and qualification
Anonymous relationships are not permitted. Every user who intends to carry out operations in Brazilian reais is identified and has their identity verified before being enabled.
The required data and documents, the verification flow, the verification record states and the enhanced due diligence criteria are detailed in the KYC and EDD Policy and Procedures, which forms an integral part of this policy for all purposes.
In summary, the following are required: full name, CPF (the Brazilian individual taxpayer registration number), a confirmed e-mail address, a telephone number, an official photo identification document (RG identity card or CNH driver's license) and a facial image for liveness proof, whose function is to link the natural person to the document presented and to mitigate the risk of identity fraud in the non-face-to-face channel.
Prohibition on operating without an enabled verification record
This is the central control of the program and the most consequential in practice.
The system conditions every inbound (on-ramp) or outbound (off-ramp) operation in Brazilian reais on the cumulative verification of two conditions in the user's verification record:
Identity verification approved
The verification record must be in the approved state, resulting from the analysis conducted by the contracted provider. Verification records that are pending, under analysis or refused do not satisfy this condition.
Active verification record
The verification record must be in the active state. Suspended or blocked verification records do not satisfy this condition, even if identity verification was previously approved.
Characteristics of this control:
- it is enforced on the server, in the service layer, before any call to the contracted provider or generation of a quote;
- it is identical for inbound and outbound operations, with no exception by amount, by channel, by account age or by commercial decision;
- it is not circumventable by the application: even if the interface is modified or requests are crafted manually, the refusal occurs on the server;
- the suspension or blocking of the verification record has immediate effect on new operations, with no need for additional intervention.
The technical evidence of this block is documented in Evidence of KYC Records.
Screening of restrictive and sanctions lists and politically exposed persons
Screening against restrictive and sanctions lists and the classification of politically exposed persons are performed by the contracted provider, as part of the identity verification process that precedes the enabling of the verification record, and are contractually required by XIP. They comprise, at a minimum:
- sanctions lists arising from United Nations Security Council resolutions, compliance with which is mandatory in national territory under Law No. 13,810/2019;
- international sanctions lists applicable to the operation;
- national restriction and disqualification lists;
- classification as a politically exposed person, and their representatives, family members and close associates.
The result of the screening is determinative for eligibility: the verification record is not approved where there is a confirmed match on a restrictive or sanctions list. XIP receives and records the decision and the reason for refusal, and the block described in the previous section prevents any operation.
Where a match on a United Nations Security Council sanctions list is identified, the immediate asset freezing regime provided for in Law No. 13,810/2019 applies, executed by the contracted provider with respect to the assets under its custody. XIP immediately suspends the verification record on the platform and provides such cooperation as is required of it. It is noted that, owing to the non-custodial model, XIP does not hold the technical power to freeze crypto-assets held in the user's wallet.
Classification as a politically exposed person does not preclude the relationship, but automatically classifies it as high risk, subjecting it to enhanced due diligence and approval at a higher level.
Transaction monitoring
The monitoring of the operations settled in Brazilian reais, with the generation and analysis of alerts, is performed by the contracted provider, which holds the complete view of the financial flow and the corresponding regulatory competence, and is contractually required by XIP.
Within its own scope, XIP maintains the following controls, which underpin the monitoring and allow any operation to be reconstructed:
- an intact and complete record of every contracted operation, with the user's identification, amounts, asset, destination address, status and timestamps;
- an audit trail of the notifications received from the contracted provider, with the date of receipt, the date of processing and any processing error, preserved even when processing fails;
- unique identifiers per operation and uniqueness constraints in the database, which make it impossible to record the same operation twice or to dissociate it from the user;
- traffic limiting by origin and by account on the quote and operation endpoints, which restricts abusive automation;
- a mandatory and immutable link between each operation and the user's account, with a constraint that prevents the deletion of the user without preserving their financial records.
Indications of irregularity identified by any means — including by customer service, by the analysis of records or by a third-party report — are forwarded to the Compliance and AML/CFT Officer, who analyzes and documents them and decides on referral to the contracted provider and to the competent authorities.
Situations requiring analysis
The following are non-exhaustive examples of situations that give rise to analysis by the Compliance Officer:
- structuring of operations into amounts just below thresholds, with the apparent purpose of avoiding controls;
- a sequence of inbound and outbound operations within a short interval, with no apparent economic purpose;
- operations inconsistent with the financial capacity or the activity declared by the user;
- repeated verification attempts with third-party documents or with signs of tampering;
- multiple verification records associated with the same device, source address or means of contact;
- unjustified resistance to providing requested information or documentation;
- a destination wallet address associated with illicit activity or with an asset mixing service;
- a claim of acting on behalf of a third party without an instrument legitimizing it.
Recordkeeping and traceability
Every verification record, operation and relevant event is recorded in a relational database with integrity controls. The records make it possible to answer, for any operation, who transacted, when, how much, in which asset, to which destination and with what result.
| Record | Content | Integrity safeguard |
|---|---|---|
| User verification record | Name, CPF, wallet address, identifier with the contracted provider, verification state, verification record state, reason for refusal and date of analysis | One verification record per user and per provider; mandatory link to the account. |
| Operation | Type, amount in Brazilian reais, crypto-asset quantity, asset, destination address, status, order and quote identifiers, timestamps | Unique internal identifier; uniqueness of the order per provider; prohibition on cascade deletion. |
| Event received from the provider | Event identifier, type, external reference, linked operation, date of receipt, date of processing, processing error | Uniqueness by provider and event identifier, which prevents reprocessing; retention of the event even in the case of failure. |
| Raw response from the provider | Full copy of the response received, in structured format, for each verification record and operation | Preserves the provider's version of the recorded fact, allowing independent reconciliation. |
Notifications received from the contracted provider are accepted only after verification of an HMAC-SHA256 cryptographic signature over the raw message body. Notifications without a valid signature are rejected, and the system admits no bypass mode that would accept an unsigned message. This control prevents the insertion of false financial events by a third party.
Reporting to authorities
The reporting of suspicious transactions and the other regulatory reports relating to settled operations are the responsibility of the contracted provider, an authorized institution subject to those duties.
XIP, in turn:
- forwards to the contracted provider, in a timely manner and in writing, every indication of irregularity that comes to its knowledge, together with the supporting documentation;
- reports directly to the competent authorities where the law imposes that duty on it or where the facts require immediate action;
- responds to requests from competent authorities, providing the records requested within the limits and in the form of the request;
- preserves the records relating to reports and requests for a period not shorter than the statutory one, even if longer than the ordinary retention period.
Any person associated with XIP is prohibited from informing the user, or any third party, of the existence of a suspicious transaction report or of an authority's request that imposes confidentiality. Breach of this duty constitutes a serious violation, subject to immediate disciplinary measures, in addition to the applicable legal sanctions.
Refusal, suspension and termination of the relationship
XIP refuses to commence, or orders the termination of, the relationship, and the contracted provider suspends or blocks the verification record, in the following scenarios:
| Scenario | Measure |
|---|---|
| Confirmed match on a restrictive or sanctions list | Refusal or immediate termination; reporting to the authorities; compliance with the asset freezing regime. |
| Impossibility of verifying identity or of completing the required due diligence | Refusal of eligibility; no operation in Brazilian reais is permitted. |
| Presentation of a false, tampered or third-party document | Refusal and termination; retention of the records; reporting to the authorities. |
| Unjustified refusal to provide essential information or documentation | Suspension of the verification record and, if the refusal persists, termination. |
| Well-founded suspicion of use of the platform for illicit activity | Immediate suspension; analysis by the Compliance Officer; referral and possible termination. |
| Indication of acting on behalf of an undeclared third party | Suspension until documented clarification; termination if not clarified. |
| Order of a competent authority | Compliance with the terms and within the timeframe of the order. |
Termination of the relationship does not entail deletion of the records: these are retained for the statutory periods, as set out in the following section, and remain available to competent authorities.
As a consequence of the non-custodial model, termination of the relationship does not affect the user's access to the crypto-assets in their own wallet, which remain under their exclusive control.
Record retention
The records of user identification and of operations are retained for a minimum of 5 (five) years counted, respectively, from the termination of the relationship and from the conclusion of each operation, a period extendable by order of a competent authority.
During the retention period, the records are kept unaltered as to their original content and readily retrievable. The database controls prevent the deletion of financial records linked to closed accounts.
The safekeeping of identification documents — document images and facial image — is the responsibility of the contracted provider, which holds them. As described in the Data Protection and Privacy Policy, XIP does not store such images: they are transmitted in memory and forwarded to the provider, without persistence.
Training and compliance culture
- Onboarding: every person joining XIP receives training on this policy before accessing systems that process user or operation data, and formally acknowledges it.
- Annual refresher: periodic training on money laundering typologies applicable to virtual assets, red flags, reporting duties and the duty of confidentiality.
- Targeted training: specific content for the customer service and technology functions, whose day-to-day decisions directly affect the effectiveness of the controls.
- Records: training sessions are recorded, identifying participants, content and date, and the record is retained for evidentiary purposes.
- Extraordinary update: carried out whenever there is a material change to this policy, to the regulatory framework or to the operating model.
Effectiveness assessment
The effectiveness of the program is assessed at least annually, by means of:
- re-examination of the internal risk assessment;
- testing of the technical controls, verifying that the prohibition on operating without an enabled verification record remains intact and non-circumventable;
- verification of the completeness, integrity and retrievability of the retained records;
- review of the compliance and integrity of the contracted provider, requiring evidence of its compliance with its regulatory duties;
- analysis of the incidents, referrals and requests from authorities in the period;
- verification of the execution of the training plan.
The assessment is documented in a report submitted to management, identifying deficiencies, corrective measures, responsible persons and deadlines. Follow-up on the measures is the responsibility of the Compliance and AML/CFT Officer.
Whistleblowing channel
Suspicions of non-compliance with this policy, of irregularity or of unlawful conduct may be reported to compliance@xip.cash, including anonymously.
XIP ensures:
- confidential treatment of the report and of the identity of the reporter, where identified;
- an absolute prohibition on retaliation against anyone who reports in good faith, even if the suspicion is not confirmed;
- analysis of every report received by the Compliance and AML/CFT Officer, with a record of the investigation and of the conclusion.
Absolute prohibitions
The following are prohibited, without exception and regardless of hierarchical authorization:
- commencing or maintaining an anonymous relationship, under a fictitious name or under an unverified identity;
- enabling operations in Brazilian reais for a user whose verification record is not approved and active;
- deploying, offering or tolerating any mechanism that circumvents, disables or conceals the eligibility and verification controls;
- instructing a user to structure operations, to omit information or to present third-party documentation;
- accepting an operation on behalf of an undeclared and undocumented third party;
- informing a user or a third party of a suspicious transaction report or of a request subject to confidentiality;
- altering, deleting or concealing a verification record, an operation record or an event record;
- maintaining a relationship with a person listed on a United Nations sanctions list.
Effective date and review
This policy takes effect on the date indicated in the header and remains in force for an indefinite term. It is reviewed at least annually, and on an extraordinary basis whenever there is:
- a change in the applicable legislation or regulation;
- a material change in product, channel, technology or operating model;
- a replacement of, or material change in, the contracted provider;
- identification of a deficiency in the effectiveness assessment;
- a recommendation from a competent authority or from an audit.
The version in force is always the one published on this page. Previous versions are archived internally for historical evidentiary purposes.
Version history
| Version | Date | Changes |
|---|---|---|
| 1.0 | July 29, 2026 | Initial publication. |