Regul8Regul8
AssessCompareLearn

Compliance Report

📅Data last reviewed April 2026
New Compliance Check

Regul8 — Compliance Report

July 2, 2026

Activities: Exchange / Trading Platform · Crypto Custody / Wallet · Onramp / Offramp (fiat ↔ crypto) — Jurisdictions: European Union · USA · Singapore · UAE / Dubai

regul8app.vercel.app · General information only, not legal advice.

💰Tax treatment

Tax summary per jurisdiction (shared across all activities). General information, not tax advice.

🇪🇺European Union

No EU-wide crypto tax — set per Member State. DAC8 (in force Jan 2026) imposes pan-EU CASP reporting of user holdings to tax authorities; OECD CARF aligned.

🇺🇸USA

Property treatment (IRS Notice 2014-21). Short-term (< 1 yr): ordinary income up to 37%. Long-term: 0/15/20%. NFT collectibles: up to 28%. Form 1099-DA mandatory from 2026.

🇸🇬Singapore

NO capital-gains tax. Trading as business: 17% corporate income tax. GST exempt on payment tokens (since 2020). Personal income only if classified as business income.

🇦🇪UAE / Dubai

NO personal income tax on crypto for individuals. Companies: 9% corporate tax on profits > AED 375K (since June 2023). VAT exempt on crypto transfers (Nov 2024).

Exchange / Trading Platform

Field
🇪🇺European Union
🇺🇸USA
🇸🇬Singapore
🇦🇪UAE / Dubai
Applicable Regime
The legal text that grounds it all — scope & territorial reach
📜MiCA↗
📜CLARITY Act· SEC/CFTC split↗
📜MAS· PSA↗
Risk Level
How critical non-compliance is for your activity
HighHighMediumMedium
OUTPUTS — What you must do
Licences Required
The concrete authorizations you must obtain
  • 🪪CASP
  • Passport across all EU-27 Member States once granted (Art. 65)
  • 🪪MSB
  • Money Transmitter Licence (per state, ~48 states)
  • 🪪BitLicense
  • CFTC registration for 'digital commodity' exchanges (CLARITY Act, 2025)
  • 🪪MPI
  • 🪪SPI
  • 🪪VASP
  • VARA tech audit
Key Obligations
Daily compliance duties (KYC, AML, Travel Rule…) — Custodial badge at the top of each cell
🔐 Custodial
  • • KYC/KYB per AMLD6 + EU AML Package 2024
  • • AML/CFT program
  • • MiCA whitepaper for non-listed tokens (already-traded exemption Art. 4(2) for XRP/BTC/ETH)
  • • Capital min. €125K (CASP exchange tier — Art. 67)
  • • FATF Travel Rule >€1K (TFR Reg. 2023/1113)
  • • Market abuse rules (MiCA Art. 80+)
  • • Governance & fit-and-proper (Art. 68)
  • • Environmental impact disclosure (Art. 66)
🔐 Custodial
  • • KYC/AML/BSA compliance
  • • SAR filings
  • • OFAC sanctions screening
  • • Travel Rule >$3K
  • • State-by-state bonding requirements
  • • CLARITY Act: trade-venue classification (SEC vs CFTC) per asset based on 'mature blockchain' test
🔐 Custodial
  • • KYC/AML MAS guidelines
  • • Tech Risk Management
  • • Annual audits
  • • Travel Rule
  • • User protection measures
🔐 Custodial
  • • KYC/AML
  • • Capital requirements
  • • Local director
  • • Asset segregation
  • • Cyber-security framework
CONTEXT — When, how much, with whom
Estimated Timeline
How long to obtain the licence + go live
6–18 months (depends on chosen NCA — LT fastest, IE/LU/MT slower)18–36 months6–12 months6–12 months
Estimated Cost
Licence fees + capital + ongoing costs
€50K–€500K (varies by hub: LT cheapest, IE/LU more expensive)$200K–$1M+SGD 50K–150K$50K–$150K
Regulator
The body that supervises and issues the licence
🏛️ESMA🏛️NCA🏛️FinCEN🏛️NYDFS🏛️CFTC🏛️SEC🏛️MAS🏛️VARA
Alternative Jurisdictions
Other jurisdictions to consider for the same activity
→ Pick a Member-State juri (FR / IE / LU / LT / MT) for actual licensing — passporting via the cheapest hub (typically Lithuania) is standard
→ Outside EU: UK FCA, Switzerland FINMA, Liechtenstein TVTG (with EEA passport)
→ Wyoming LLC (crypto-friendly)
→ EU MiCA as primary market
→ Liechtenstein TVTG
→ Dubai VARA
→ Hong Kong SFC VASP
→ EU MiCA
→ ADGM FSRA (Abu Dhabi)
→ Singapore MAS
→ EU MiCA passport
IMPLEMENTATION — How, with who
🔐 Custody
Regulated custodians operating in the jurisdiction (top 3)
🔐Ripple Custody🧱Fireblocks🛡️BitGo+ 3 more →
🧱Fireblocks⚓Anchorage Digital🛡️BitGo+ 1 more →
No regulated custodian known hereNo regulated custodian known here
💸 Payment
Payment / on-off-ramp providers covering the jurisdiction (top 3)
Not a payment-rail activityNot a payment-rail activityNot a payment-rail activityNot a payment-rail activity
🛡️ KYC / AML
KYC/AML vendors serving the jurisdiction (top 3)
✅Sumsub👤Onfido (Entrust)🛂Jumio+ 10 more →
✅Sumsub👤Onfido (Entrust)🛂Jumio+ 10 more →
✅Sumsub🛂Jumio🌐Trulioo+ 6 more →
✅Sumsub🌍World-Check (LSEG)📨Notabene
🔑 Wallet infra
Wallet-infrastructure vendors (embedded wallet / DKG-MPC) serving the jurisdiction (top 3)
🔑Web3Auth✨Magic🔐Privy (Stripe)+ 3 more →
🔑Web3Auth✨Magic🔐Privy (Stripe)+ 3 more →
🔑Web3Auth✨Magic🔐Privy (Stripe)+ 3 more →
🔑Web3Auth✨Magic🔐Privy (Stripe)+ 2 more →
🇪🇺European Union
📅 Reporting frequency

Quarterly prudential + transaction reports to home-state NCA · Annual audited accounts · Monthly AML filings · Immediate incident reports · MiCA Art. 80 conflicts-of-interest report annually.

📢 Marketing rules

Mandatory risk warnings on all communications (MiCA Art. 66). No yield / return promises. Whitepaper and complaint channels must be clearly displayed. Non-misleading requirement strictly enforced. Influencer disclosures required.

🌍 Client eligibility

Single passported CASP serves all EU-27 residents. Enhanced due diligence for PEPs and FATF grey/black-list countries. No retail restriction but suitability test required for complex products. Must geo-block non-EU jurisdictions without reverse-solicitation chain.

🇺🇸USA
📅 Reporting frequency

SAR filings on suspicious activity (immediate, <30 days) · CTR on cash >$10K · FinCEN Form 107 annually · NYDFS quarterly reports (BitLicense) · State-by-state transaction reports · CLARITY Act quarterly + annual disclosures for investment contract digital assets.

📢 Marketing rules

SEC-era: any marketing projecting returns risks reclassifying the token as a security (Howey). No unregistered investment promotions. NYDFS requires prior approval of consumer-facing advertising. FINRA rules apply to broker-dealer communications. State Blue Sky restrictions on targeted marketing per state.

🌍 Client eligibility

Must serve only states where MTL is held (geo-fence others). Full OFAC screening — block Cuba, Iran, North Korea, Syria, Crimea, Russia, Belarus. Accredited-investor gating for security tokens (Reg D 506(c)). KYC-verified US residency mandatory. No service to sanctioned or PEP list addresses.

🇪🇺
XRPLSpecific Note

XRPL has a native DEX (order book built into the protocol). A front-end DApp accessing it for EU users still needs CASP if it routes orders or controls funds — independent of which NCA issues the licence.

🇺🇸
XRPLSpecific Note

XRPL DEX front-end: SEC may treat as unregistered exchange if trading securities-token pairs. Under CLARITY Act 2025, XRP (secondary sales, SEC v. Ripple July 2023) likely qualifies as 'digital commodity' — CFTC jurisdiction. Other XRPL tokens require case-by-case mature-blockchain analysis.

Crypto Custody / Wallet

Field
🇪🇺European Union
🇺🇸USA
🇸🇬Singapore
🇦🇪UAE / Dubai
Applicable Regime
The legal text that grounds it all — scope & territorial reach
📜MiCA· custody and administration of crypto-assets on behalf of clients↗
•State trust charter•SEC qualified custodian rule📜CLARITY Act custody provisions· 2025↗
📜MAS· PSA↗
Risk Level
How critical non-compliance is for your activity
HighHighMediumMedium
OUTPUTS — What you must do
Licences Required
The concrete authorizations you must obtain
  • 🪪CASP
  • Passport across all EU-27 once granted
  • 🪪SPDI
  • 🪪MSB
  • SEC qualified custodian status for institutional clients
  • CLARITY Act: CFTC-registered 'digital commodity custodian' for CFTC-jurisdiction assets
  • 🪪MPI🪪SPI
  • Custodial services authorization
  • VARA VA custody licence
Key Obligations
Daily compliance duties (KYC, AML, Travel Rule…) — Custodial badge at the top of each cell
🔐 Grey zone
  • • Strict client-asset segregation (Art. 75(7))
  • • Client agreement specifying rights + liabilities (Art. 75(2))
  • • Liability for loss of clients' crypto-assets (Art. 75(8))
  • • ICT risk + cybersecurity (DORA, applicable from Jan 2025)
  • • Insurance / capital coverage proportional to assets under custody
  • • Quarterly reporting to home NCA
  • • ICT third-party risk management
🔐 Custodial
  • • BSA/AML compliance
  • • SAR filings
  • • OFAC screening
  • • SOC 2 Type II audit
  • • Cold storage requirements (institutional clients)
  • • Insurance (crime + cyber policy)
  • • CLARITY Act: segregation of customer digital commodities + prohibition on rehypothecation absent consent
  • • GENIUS Act: special rules apply when custodying qualifying stablecoins
🔐 Custodial
  • • Safeguarding of customer assets
  • • Tech Risk Management
  • • AML/KYC
  • • Segregation of assets
  • • Annual audit
🔐 Custodial
  • • Asset segregation
  • • Cold storage majority
  • • KYC/AML
  • • Insurance requirements
  • • Tech audit
CONTEXT — When, how much, with whom
Estimated Timeline
How long to obtain the licence + go live
9–18 months12–24 months6–12 months6–12 months
Estimated Cost
Licence fees + capital + ongoing costs
€150K–€700K (capital + insurance + ICT)$300K–$1M+SGD 75K–200K$75K–$200K
Regulator
The body that supervises and issues the licence
🏛️ESMA🏛️NCA🏛️FinCEN🏛️CFTC🏛️SEC🏛️OCC🏛️MAS🏛️VARA
Alternative Jurisdictions
Other jurisdictions to consider for the same activity
→ Pick a Member-State juri (FR / IE / LU / LT) for actual licensing
→ Outside EU: Switzerland FINMA DLT custody, Liechtenstein TVTG TT Service Provider (faster, EEA passport)
→ Bermuda DABA
→ Wyoming SPDI charter (faster path)
→ EU MiCA CASP
→ Liechtenstein TVTG
→ Dubai VARA custody
→ Hong Kong SFC
→ EU MiCA
→ Liechtenstein TVTG
→ ADGM FSRA
→ Singapore MAS
→ Liechtenstein TVTG
IMPLEMENTATION — How, with who
🔐 Custody
Regulated custodians operating in the jurisdiction (top 3)
🔐Ripple Custody🧱Fireblocks🛡️BitGo+ 3 more →
🧱Fireblocks⚓Anchorage Digital🛡️BitGo+ 1 more →
No regulated custodian known hereNo regulated custodian known here
💸 Payment
Payment / on-off-ramp providers covering the jurisdiction (top 3)
Not a payment-rail activityNot a payment-rail activityNot a payment-rail activityNot a payment-rail activity
🛡️ KYC / AML
KYC/AML vendors serving the jurisdiction (top 3)
✅Sumsub👤Onfido (Entrust)🛂Jumio+ 10 more →
✅Sumsub👤Onfido (Entrust)🛂Jumio+ 10 more →
✅Sumsub🛂Jumio🌐Trulioo+ 6 more →
✅Sumsub🌍World-Check (LSEG)📨Notabene
🔑 Wallet infra
Wallet-infrastructure vendors (embedded wallet / DKG-MPC) serving the jurisdiction (top 3)
No end-user wallet for this activity (B2B / institutional)No end-user wallet for this activity (B2B / institutional)No end-user wallet for this activity (B2B / institutional)No end-user wallet for this activity (B2B / institutional)
🇪🇺European Union
📅 Reporting frequency

Quarterly prudential reports + custody-specific filings to home NCA · Annual audited accounts · ICT/DORA incident reports immediate · Monthly AML · Annual conflict-of-interest review.

📢 Marketing rules

Must disclose custody model + liability scope + insurance coverage (MiCA Art. 75(2)+(8)). No misleading 'cold-storage 100%' or 'fully insured' unless verifiable. Risk warnings mandatory.

🌍 Client eligibility

Passport across all EU-27 once granted. Custody for retail and professional clients allowed. Enhanced due diligence for PEPs / FATF high-risk countries. No suitability test for plain custody, but onboarding KYC mandatory.

🇺🇸USA
📅 Reporting frequency

Annual SOC 2 Type II audit · Quarterly call reports (if trust charter) · SAR immediate / CTR over $10K · Monthly AML filings · CLARITY Act: quarterly customer-asset segregation statements · Insurance claim notifications real-time.

📢 Marketing rules

SEC / NYDFS: 'qualified custodian' claim only if you meet SEC definition. No rehypothecation implied. Insurance limits must be clearly disclosed. GENIUS Act custody of qualifying stablecoins requires separate advertising treatment. Institutional-only marketing for non-retail offerings.

🌍 Client eligibility

US persons in states where trust charter is recognized. Institutional clients only for SEC qualified-custodian offering (unless state-registered for retail). Full OFAC block — Cuba, Iran, DPRK, Syria, Russia, Belarus, sanctioned entities. Enhanced KYC on beneficial ownership >25%.

🇪🇺
XRPLSpecific Note

On XRPL: SignerList majority + Single Key + IOU gateway models = custodial under MiCA Art. 75. Multi-sig SignerList (minority service participation) + non-custodial wallets = outside Art. 75 scope. MPC/TSS = grey zone (Art. 75 likely applies if service can sign alone).

🔐 Custody context

MiCA Art. 75 captures any service that 'safekeeps or controls' crypto-assets on behalf of a client. The 'control' criterion is decisive on XRPL: holding the master key, being able to sign alone, or controlling an issuing gateway = custodial. SignerList minority + Escrow + Payment Channels = no Art. 75 trigger.

🇺🇸
XRPLSpecific Note

XRPL custody: SEC qualified custodian rules apply for securities-like XRPL tokens; CLARITY Act (2025) shifts 'digital commodity' custody under CFTC (applies to XRP per SEC v. Ripple secondary-sales holding). MPC/TSS (Fireblocks, Silence Labs) widely used for institutional XRPL custody. SignerList multisig provides native on-chain alternative.

Onramp / Offramp (fiat ↔ crypto)

Field
🇪🇺European Union
🇺🇸USA
🇸🇬Singapore
🇦🇪UAE / Dubai
Applicable Regime
The legal text that grounds it all — scope & territorial reach
📜MiCA↗
•MAS Payment Services Act· DPT + Cross-border Money Transfer classes↗
•CBUAE Stored Value Facility· fiat rails
Risk Level
How critical non-compliance is for your activity
HighHighMediumMedium
OUTPUTS — What you must do
Licences Required
The concrete authorizations you must obtain
  • 🪪CASP
  • 🪪EMI
  • Bank partnership for SEPA settlement
  • 🪪MSB
  • State money transmitter licence in every state of operation (~48)
  • 🪪BitLicense
  • Surety bonds per state ($50K–$7M each)
  • 🪪MPI
  • 🪪SPI
  • Cross-Border Money Transfer sub-class if fiat leg crosses border
  • 🪪VASP
  • CBUAE Stored Value Facility licence (if AED float held)
  • AED banking partnership
Key Obligations
Daily compliance duties (KYC, AML, Travel Rule…) — Custodial badge at the top of each cell
🔐 Custodial
  • • Strict KYC (AMLD6) + sanctions screening (EU + UN + OFAC)
  • • Travel Rule >€1K (TFR Reg. 2023/1113)
  • • Customer fund segregation (PSD2 Art. 10)
  • • MiCA Art. 66 marketing rules for the crypto leg
  • • Source-of-funds checks for high-value transfers
🔐 Custodial
  • • BSA/AML
  • • OFAC sanctions screening
  • • SAR / CTR filings
  • • Travel Rule ≥ $3K
  • • Segregated customer accounts
  • • Annual state audits
🔐 Custodial
  • • KYC/AML per MAS AML/CFT Notice
  • • Safeguarding of customer funds (trust account)
  • • Tech Risk Management Notice (TRM)
  • • Capital requirement (SGD 250K for MPI)
🔐 Custodial
  • • KYC/AML per CBUAE + VARA rulebooks
  • • Travel Rule
  • • Capital requirements (AED 1.5M+ for VARA)
  • • Quarterly transaction reporting
CONTEXT — When, how much, with whom
Estimated Timeline
How long to obtain the licence + go live
12–24 months (dual licence stack)24–48 months (MTL patchwork)9–15 months9–18 months
Estimated Cost
Licence fees + capital + ongoing costs
€500K–€1.5M (capital + IT/compliance)$500K–$2M+ (legal + bonds)SGD 200K–600K$200K–$600K
Regulator
The body that supervises and issues the licence
🏛️ESMA🏛️NCA🏛️FinCEN🏛️NYDFS🏛️MAS🏛️VARA
Alternative Jurisdictions
Other jurisdictions to consider for the same activity
→ Pick a Member-State juri (FR / IE / LU / LT) for actual licensing — passporting standard
→ Outside EU: UAE VARA, Singapore MAS MPI
→ Partner with licensed MSB/bank
→ EU MiCA via Ireland or Germany
→ Hong Kong SFC
→ UAE VARA
→ DIFC DFSA (common-law alternative)
→ ADGM FSRA
IMPLEMENTATION — How, with who
🔐 Custody
Regulated custodians operating in the jurisdiction (top 3)
No regulated custodian required for this activityNo regulated custodian required for this activityNo regulated custodian required for this activityNo regulated custodian required for this activity
💸 Payment
Payment / on-off-ramp providers covering the jurisdiction (top 3)
🌙MoonPay🛤️Ramp Network🔁Transak+ 10 more →
🌙MoonPay🛤️Ramp Network🔁Transak+ 8 more →
🌙MoonPay📊Bitstamp🪙Coinbase+ 4 more →
📨Notabene✅Sumsub (Travel Rule + KYC)
🛡️ KYC / AML
KYC/AML vendors serving the jurisdiction (top 3)
✅Sumsub👤Onfido (Entrust)🛂Jumio+ 10 more →
✅Sumsub👤Onfido (Entrust)🛂Jumio+ 10 more →
✅Sumsub🛂Jumio🌐Trulioo+ 6 more →
✅Sumsub🌍World-Check (LSEG)📨Notabene
🔑 Wallet infra
Wallet-infrastructure vendors (embedded wallet / DKG-MPC) serving the jurisdiction (top 3)
🔑Web3Auth✨Magic🔐Privy (Stripe)+ 3 more →
🔑Web3Auth✨Magic🔐Privy (Stripe)+ 3 more →
🔑Web3Auth✨Magic🔐Privy (Stripe)+ 3 more →
🔑Web3Auth✨Magic🔐Privy (Stripe)+ 2 more →
🇪🇺
XRPLSpecific Note

XRPL ODL (On-Demand Liquidity) uses XRP as a bridge currency for fiat-to-fiat corridors. Operators of ODL flows in the EU need CASP + payment-institution authorisations + bank partnerships per corridor.

🇺🇸
XRPLSpecific Note

US onramp for XRP is operational post-2023 SEC settlement (XRP not a security on secondary sales). Uphold, Bitstamp, Kraken provide the licensed rail. XRPL IOUs still ambiguous under federal law.

🇸🇬
XRPLSpecific Note

Singapore treats XRP as a Digital Payment Token under PSA. MAS-licensed gateways (Independent Reserve, Coinhako) offer XRP onramp. XRPL IOUs may require additional classification.

🇦🇪
XRPLSpecific Note

VARA-licensed XRPL onramp feasible — XRP is an approved VA in Dubai. AED stablecoin pilots (by M2, Rain) use XRPL for settlement.

🛠 ZOOM ON IMPLEMENTATION — How you can do this

Providers, vendors and partners that can run your compliance stack in the selected jurisdictions. Filtered by activity (custody, payment, AML/KYC) and jurisdictional coverage.

XRPLCustody Implementation Matrix

🤝 Custody partners for your jurisdictions

You selected custody as an activity. Here are XRPL-supporting institutional providers who operate in (or passport into) your selected jurisdictions. Click any card to open their site.

🔐
Ripple Custody🇨🇭🇪🇺🇫🇷
ripple.com/solutions/custody

Model: Metaco (Swiss bank-grade tech) + Palisade (France-licensed MPC WaaS)

XRPL support: XRPL-native — deepest integration (signer lists, Regular Key, trust lines)

🧱
Fireblocks🇮🇱🇺🇸🇪🇺
www.fireblocks.com

Model: MPC custody for exchanges, banks, fintechs. ~2 000 institutional clients.

XRPL support: XRPL supported since 2021, XRP + issued tokens + trust lines.

⚓
Anchorage Digital🇺🇸
www.anchorage.com

Model: Federally chartered crypto bank (OCC National Trust, 2021). HSM + cold storage.

XRPL support: XRP supported for qualified custody + staking workflows (where applicable).

🛡️
BitGo🇺🇸🇪🇺
www.bitgo.com

Model: Multi-sig + MPC custody. SD state trust (South Dakota) + NY trust. Settlement provider.

XRPL support: XRP supported in multi-sig cold wallet + institutional qualified custody.

♉
Taurus🇨🇭🇪🇺
www.taurushq.com

Model: Swiss bank-grade custody (FINMA DLT framework). Used by Deutsche Bank, State Street.

XRPL support: XRPL supported for tokenised assets + RWAs via T-PROTECT platform.

🚪
GateHub🇪🇺
gatehub.net

Model: XRPL-native retail/SME wallet and custody since 2014. Slovenia VASP.

XRPL support: Reference implementation of the XRPL IOU / Trust Line stablecoin model.

🔑
Dfns🇪🇺🇫🇷🇺🇸
www.dfns.co

Model: Developer-first wallet-as-a-service, MPC-TSS key management via API.

XRPL support: XRPL supported as one of 30+ chains. SOC2 Type II + France registered.

Public information — not a recommendation. Verify current licences and XRPL support with each provider before integration.

🤝 Payment & on/off-ramp partners for your jurisdictions

You selected an on/off-ramp or cross-border payment activity. Here are providers operating in (or passporting into) your jurisdictions, grouped by type. Travel Rule providers (FATF R.16) surface for both scenarios — VASP-to-VASP compliance messaging applies whenever value moves across borders.

🌙
MoonPay🇺🇸🇪🇺🇬🇧🇸🇬🇦🇺
www.moonpay.com/business
🔁On/off-ramp

Model: Mainstream fiat on/off-ramp — cards, SEPA, Apple/Google Pay. 160+ currencies, 30M+ users. Used by OpenSea, Bitcoin.com, Trust Wallet.

XRPL angle: XRP supported as an on-ramp asset; widely embedded in XRPL wallet UX.

🛤️
Ramp Network🇬🇧🇪🇺🇺🇸
ramp.network/business
🔁On/off-ramp

Model: Embeddable on/off-ramp widget — strong in Europe (UK FCA reg., EU MiCA-ready). 80+ countries, low fees on bank transfer.

XRPL angle: XRP supported. RLUSD on-ramping under exploration with Ripple ecosystem.

🔁
Transak🇬🇧🇪🇺🇺🇸🇮🇳
transak.com
🔁On/off-ramp

Model: Global on/off-ramp SDK for dApps and wallets. 160+ countries, 75+ payment methods, 170+ tokens.

XRPL angle: XRP and selected XRPL-native tokens supported in the widget.

💳
Stripe (Crypto onramp + Bridge stablecoins)🇺🇸🇪🇺🇬🇧
stripe.com/crypto
🔁On/off-ramp

Model: Hosted fiat → USDC onramp. Acquired Bridge ($1.1B, Oct 2024) for stablecoin payment APIs. Card → stablecoin in one flow.

XRPL angle: No XRPL-native integration today; stablecoin pipes (USDC, USDB) are EVM-anchored. Worth watching post-Bridge.

🚪
GateHub🇱🇹🇪🇺🇬🇧
gatehub.net
🔁On/off-ramp

Model: XRPL-native gateway since 2014 — issues IOUs against fiat reserves via XRPL Trust Lines. Retail on/off-ramp for XRP, RLUSD and select XRPL tokens. EMI Lithuania.

XRPL angle: XRPL-NATIVE — flagship example of the IOU / Trust Line gateway model. Long-time partner of Ripple ecosystem.

⬆️
Uphold🇺🇸🇬🇧🇪🇺🇧🇷
uphold.com
🔁On/off-ramp

Model: Multi-asset retail platform — fiat, crypto, metals, equities in one wallet. XRPL-native gateway since 2015 (one of the original Ripple ecosystem partners). NYDFS BitLicense + UK FCA + EU MiCA-ready.

XRPL angle: XRPL-NATIVE gateway — IOU model for fiat issuance. Long-time Ripple partner; XRP available since launch.

📊
Bitstamp🇱🇺🇪🇺🇺🇸🇬🇧🇸🇬
www.bitstamp.net
🔁On/off-ramp

Model: Long-running European exchange (founded 2011) — XRP listed since 2014. Acquired by Robinhood in 2024. Strong EU regulatory posture (Luxembourg CSSF) + NYDFS BitLicense + UK FCA + Singapore MAS.

XRPL angle: XRP-listed since 2014 — one of the earliest CEX integrations. Provides retail buy/sell + institutional OTC for XRP.

🪙
Coinbase🇺🇸🇮🇪🇪🇺🇬🇧🇩🇪🇸🇬
www.coinbase.com
🔁On/off-ramp

Model: Largest US-listed crypto exchange (NASDAQ: COIN). Relisted XRP in July 2023 (post-Ripple ruling) and again under CLARITY Act 2025. FinCEN MSB + ~48 state MTLs + NY BitLicense + Ireland CASP (EU passport) + Singapore MPI.

XRPL angle: XRP available for buy/sell since the 2023 relisting. No XRPL-native integration beyond the listing; standard CEX custody for XRP.

🐙
Kraken🇺🇸🇮🇪🇪🇺🇬🇧🇦🇺🇯🇵
www.kraken.com
🔁On/off-ramp

Model: Top-5 global crypto exchange — XRP listed since 2014. US: FinCEN MSB + ~40 state MTLs + Wyoming SPDI trust charter. EU: CASP via Ireland. UK FCA + Australia AUSTRAC + Japan FSA registration.

XRPL angle: XRP listed since 2014, one of the highest-volume XRP venues globally. Retail buy/sell + futures (CFTC-regulated) + institutional OTC.

💜
Revolut🇪🇺🇱🇹🇬🇧🇺🇸🇸🇬🇦🇺🇯🇵
www.revolut.com
🔁On/off-ramp

Model: Mobile-first neobank with 50M+ users. Full EU credit-institution licence (Revolut Bank Lithuania, passportable to all 27 EU states) + UK FCA EMI licence. Crypto buy/sell embedded in the banking app since 2017; XRP supported (with brief 2020-2023 US pause during SEC v. Ripple).

XRPL angle: XRP buy/sell available in EU + UK. Standard custodial model (Revolut holds keys) — no XRPL-native rails. Useful as a fiat → XRP retail funnel.

💳
Wirex🇬🇧🇪🇺🇱🇹🇸🇬🇯🇵
wirexapp.com
🔁On/off-ramp

Model: EMI-licensed crypto card + multi-currency wallet (UK FCA + EU EMI via Lithuania). 6M+ users. Spend crypto via Visa/Mastercard at point-of-sale with auto-conversion. XRP supported.

XRPL angle: XRP supported in the multi-currency wallet — primary use is fiat-XRP-fiat conversion at retail point of sale via the card.

📨
Notabene🇺🇸🇪🇺🇬🇧🇸🇬🇦🇪
notabene.id
📨Travel Rule

Model: Leading Travel Rule messaging network for VASPs (FATF R.16). Pre-transaction sanctions screening + counterparty verification. 1 200+ VASPs.

XRPL angle: Chain-agnostic — works for XRPL VASPs that need MiCA / Travel Rule compliance from day one.

✅
Sumsub (Travel Rule + KYC)🇪🇺🇬🇧🇺🇸🇸🇬🇦🇪
sumsub.com/travel-rule
📨Travel Rule

Model: Travel Rule + KYC + AML monitoring under one roof. Strong in EU + emerging markets, MiCA-aligned. ~5 000 clients.

XRPL angle: Chain-agnostic. Used by XRPL VASPs needing onboarding KYC + Travel Rule in a single SDK.

Public information — not a recommendation. Verify current local licences and XRPL/RLUSD support with each provider before integration.

🛡️ AML / KYC vendors for your jurisdictions

A regulated activity typically needs KYC at onboarding, sanctions / PEP screening, transaction monitoring, and Travel Rule messaging. Here are the established providers that operate in (or passport into) your jurisdictions, grouped by function. Sumsub covers identity + Travel Rule in a single SDK; Chainalysis / Elliptic / TRM have native XRPL coverage.

✅
Sumsub🇪🇺🇬🇧🇺🇸🇸🇬🇦🇪
sumsub.com
🪪KYC / IDV🛡️Sanctions / PEP📨Travel Rule

Model: KYC + KYB + AML monitoring + Travel Rule under one roof. Strong in EU + emerging markets, MiCA-aligned. ~5,000 clients including major crypto exchanges.

Crypto coverage: Chain-agnostic. Used by XRPL VASPs needing onboarding KYC + Travel Rule + monitoring in a single SDK.

👤
Onfido (Entrust)🇬🇧🇪🇺🇺🇸
onfido.com
🪪KYC / IDV

Model: IDV + biometric verification + ongoing monitoring. Acquired by Entrust (2024). Strong in UK / EU / US fintech and crypto markets — Coinbase Europe, Revolut historic clients.

🛂
Jumio🇺🇸🇪🇺🇬🇧🇸🇬
www.jumio.com
🪪KYC / IDV

Model: AI-powered IDV — document verification + biometric liveness + ongoing monitoring. Used by major exchanges (Bitstamp, Bitpanda, Bitso) and banks. SOC2 + ISO 27001.

🎭
Persona🇺🇸🇪🇺🇬🇧
withpersona.com
🪪KYC / IDV

Model: No-code IDV platform with high configurability. Used by US-first fintech / crypto firms — Block (Cash App), Brex, Robinhood. Strong KYB + business-verification module.

🆔
Veriff🇪🇺🇬🇧🇺🇸
www.veriff.com
🪪KYC / IDV

Model: IDV across 230+ countries, 11K+ document types. Estonian-base + EU MiCA-aligned. Used by Bolt, Wise, Kraken, Bitstamp.

🌐
Trulioo🇨🇦🇺🇸🇪🇺🇬🇧🇸🇬
www.trulioo.com
🪪KYC / IDV🛡️Sanctions / PEP

Model: GlobalGateway — KYC + KYB across 195 countries via 450+ data sources. Strong in B2B verification (UBO, business registry checks). Canadian-base, served by major banks + crypto firms.

🛡️
ComplyAdvantage🇬🇧🇺🇸🇪🇺🇸🇬
complyadvantage.com
🛡️Sanctions / PEP

Model: AI-powered sanctions / PEP / adverse-media screening + ongoing monitoring. Strong in fintech and crypto — Coinbase, Gemini, BitGo, Klarna among clients. Real-time data updates.

🌍
World-Check (LSEG)🇬🇧🇺🇸🇪🇺🇸🇬🇦🇪
www.lseg.com/en/risk-intelligence/world-check
🛡️Sanctions / PEP

Model: Refinitiv's World-Check (now part of LSEG) — the gold-standard sanctions / PEP / heightened-risk database. Curated by 400+ analysts; used by Tier-1 banks worldwide.

📚
LexisNexis Risk Solutions🇺🇸🇬🇧🇪🇺
risk.lexisnexis.com
🛡️Sanctions / PEP

Model: Bridger Insight XG sanctions screening + Accuity payment screening. Strong in regulated banking + crypto on-ramp. US-base with global reach.

🔗
Chainalysis🇺🇸🇬🇧🇪🇺🇸🇬🇦🇺
www.chainalysis.com
⛓️Chain analytics

Model: Industry-standard crypto transaction monitoring + investigations + sanctions screening. Used by US Treasury / IRS / FBI + most regulated exchanges. Reactor (investigations) + KYT (Know Your Transaction) products.

Crypto coverage: Native XRPL coverage — XRPL transactions + IOU flows + AMM tracked. Reactor supports XRPL investigations. RLUSD coverage from launch.

🌀
Elliptic🇬🇧🇺🇸🇪🇺🇸🇬
www.elliptic.co
⛓️Chain analytics

Model: Crypto-native AML platform — Holistic (cross-chain monitoring) + Lens (entity intelligence). UK-base, MiCA-aligned. Strong in EU + UK regulated markets. Coinbase, Revolut, Binance among clients.

Crypto coverage: XRPL covered. Cross-chain heuristics for stablecoin tracing (USDC, USDT, RLUSD).

🔭
TRM Labs🇺🇸🇬🇧🇪🇺🇸🇬
www.trmlabs.com
⛓️Chain analytics

Model: Real-time blockchain intelligence + sanctions screening + investigations. Used by US Secret Service, FBI, OFAC + major crypto exchanges. Strong in compliance automation for institutional flows.

Crypto coverage: XRPL native coverage. RLUSD tracking from issuance.

📨
Notabene🇺🇸🇪🇺🇬🇧🇸🇬🇦🇪
notabene.id
📨Travel Rule🛡️Sanctions / PEP

Model: Leading Travel Rule messaging network for VASPs (FATF R.16). Pre-transaction sanctions screening + counterparty verification. 1,200+ VASPs onboarded. Founded by post-FATF Travel Rule architects.

Crypto coverage: Chain-agnostic — works for XRPL VASPs that need MiCA / Travel Rule compliance from day one.

Public information — not a recommendation. Verify current certifications (SOC2, ISO 27001) and jurisdictional coverage with each vendor before integration.

🔑 Wallet infrastructure for your jurisdictions

Embedded-wallet infrastructure vendors (DKG-MPC + social login) serving the markets in your selected jurisdictions. Distinct from institutional custodians — these vendors provide non-custodial / grey-zone wallets for consumer UX ("no seed phrase"). Click any card to open the vendor site.

🔑
Web3AuthNon-custodial🇺🇸🇪🇺🇫🇷🇩🇪🇪🇸🇵🇱+30
web3auth.io

Focus: DKG-MPC + social login (Google, Apple, X, Discord, email). 25M+ users, 1,500+ apps. Series B, multi-chain. "No seed phrase" consumer UX leader.

XRPL support: Supports Ed25519 + secp256k1 (XRPL curves) via Custom Auth Network. No native XRPL adapter yet but technically integrable. Worth watching as XRPL consumer apps grow.

✨
MagicGrey zone🇺🇸🇪🇺🇫🇷🇩🇪🇪🇸🇵🇱+16
magic.link

Focus: Delegated keys via HSM. Email / SMS / social login. SOC 2 Type II + ISO 27001. Strong on regulated fintech use cases.

XRPL support: EVM + Solana + Flow native. No XRPL support today. Their delegated-key model would map to a SignerList multisig if added.

🔐
Privy (Stripe)Non-custodial🇺🇸🇪🇺🇫🇷🇩🇪🇪🇸🇵🇱+13
www.privy.io

Focus: Embedded wallets + MPC + progressive auth. Acquired by Stripe (Mar 2025) — now powering Stripe Crypto on/off-ramp + Bridge stablecoins UX layer.

XRPL support: EVM + Solana focus today. Post-Stripe acquisition, XRPL support possible if Bridge stablecoin rails route via XRPL.

⚡
DynamicNon-custodial🇺🇸🇪🇺🇫🇷🇩🇪🇪🇸🇵🇱+11
www.dynamic.xyz

Focus: Wallet onboarding orchestrator + KYC + multi-wallet support. Connects 350+ wallets including hardware + embedded + ENS / DID.

XRPL support: Multi-wallet aggregator — supports Xaman, Crossmark, GemWallet for XRPL since 2024. Best fit for XRPL consumer apps wanting plug-and-play wallet UX.

⚛️
Particle NetworkNon-custodial🇺🇸🇪🇺🇫🇷🇩🇪🇪🇸🇵🇱+18
particle.network

Focus: Modular Account Abstraction wallet + MPC + chain abstraction. ERC-4337 native + gasless transactions. Strong APAC presence.

XRPL support: EVM-first (Account Abstraction is EVM-specific). No XRPL native support — XRPL has its own AA-equivalents (Hooks on Xahau, Regular Key).

🔱
TriaGrey zone🇺🇸🇪🇺🇫🇷🇩🇪🇸🇬🇭🇰+8
tria.so

Focus: Chain-abstraction wallet + name service (.tria handles). Cross-chain transfers without bridging. Asia-Pacific focus.

XRPL support: EVM + Solana + Cosmos. No XRPL native today but their chain-abstraction model could absorb XRPL via custom plug-in.

Public information — not a recommendation. Verify current XRPL coverage and custody model with each vendor before integration.

🏛️ Official portals by jurisdiction

Regulators, public registers and law texts to verify directly at the source. Opens in a new tab.

🇪🇺European Union
  • RegulatorESMA — MiCA portal ↗
  • Public registerESMA — Public CASP register ↗
  • Law textEUR-Lex — MiCA Regulation 2023/1114 ↗
🇺🇸USA
  • Public registerFinCEN — MSB registration lookup ↗
  • Public registerNMLS — State MTL register ↗
  • RegulatorNYDFS — Virtual currency businesses (BitLicense) ↗
  • Public registerOCC — Trust bank charters ↗
  • GuidanceSEC — Crypto Assets ↗
  • TaxIRS — Digital assets tax guidance ↗
🇸🇬Singapore
  • Law textMAS — Payment Services Act ↗
  • Public registerMAS — Financial institutions directory ↗
🇦🇪UAE / Dubai
  • RegulatorVARA — Dubai Virtual Asset Regulatory Authority ↗
  • Public registerVARA — Public licensee register ↗
  • RegulatorADGM FSRA — Virtual asset framework ↗

📚 Official sources

Links to the laws and official guidance referenced in this report.

  • ↪
    MiCA — Regulation (EU) 2023/1114· European Parliament
  • ↪
    MiCA Articles 59-75 (CASP)· ESMA / National NCAs
  • ↪
    Payment Services Directive (EU) 2015/2366· European Commission
  • ↪
    GENIUS Act (2025) — Stablecoin federal framework· US Congress / OCC
  • ↪
    Digital Asset Market Clarity Act (2025)· US Congress
  • ↪
    SEC v. Ripple Labs — Summary Judgment (July 2023)· SDNY (US District Court)
  • ↪
    FinCEN — MSB registration (31 CFR 1022)· FinCEN (US Treasury)
  • ↪
    FinCEN MSB Registration· FinCEN
  • ↪
    Bank Secrecy Act — 31 USC 5311· FinCEN
  • ↪
    State Money Transmitter Licences (CSBS NMLS)· State regulators
  • ↪
    NYDFS 23 NYCRR Part 200 (BitLicense)· NYDFS
  • ↪
    OFAC Sanctions Compliance for Virtual Currency· OFAC (US Treasury)
  • ↪
    FATF Recommendations (2023 update)· FATF
  • ↪
    FATF Recommendation 16 — Travel Rule for VASPs· FATF
  • ↪
    VARA Virtual Assets Regulations· VARA (Dubai)
  • ↪
    MAS Payment Services Act (PSA)· Monetary Authority of Singapore
  • ↪
    SFC VASP / VATP Licensing Regime· SFC (Hong Kong)
  • ↪
    FCA Cryptoasset Registration Guide· FCA (UK)
  • ↪
    FINMA Guidance on ICOs and DLT· FINMA (Switzerland)
  • ↪
    Liechtenstein TVTG (Token Act) 2020· FMA Liechtenstein

AI Compliance Audit

Personalised roadmap, risk analysis and recommendations — auto-generated

Regul8 provides general information for educational purposes only. This is not legal advice. Information may not be up to date. Always consult a qualified lawyer specializing in digital asset law for advice specific to your situation.

Regul8 © 2026
💬

Ask anything

💬

Ask anything about crypto regulation

Term lookups and common questions are answered instantly (glossary + FAQ). Other questions go to the contextual AI.

General information only. For your specific situation, consult a qualified lawyer.