CRYPTO TRAVEL RULE COMPLIANCE
Audit-Ready Travel Rule, Built On Verified Identity
Verify the customer, vet the counterparty VASP against a 12,000+ entity directory, and transmit FATF Recommendation 16 data, on the identity and AML platform your team already runs.
Book A Demo
Trusted By Leading Digital Asset Businesses Worldwide
WHY SHUFTI FOR TRAVEL RULE
Verify the Customer, Vet the VASP, Transmit the Data
Fewer Stalled Transfers, Less Manual Work
Most Travel Rule failures happen because the receiving VASP was never identified in time, not because the message itself was wrong. The 12,000+ entity directory keeps delivery close to 100% when the VASP is named, and grows automatically with every new counterparty you reach.
Reduce Vendor Complexity
Route through a direct VASP-to-VASP protocol, TRP, CODE and Binance GTR from a single API call, all on the IVMS 101 data standard. The platform identifies the counterparty and selects the protocol automatically. No separate memberships, no protocol management, and no second vendor for identity.
Pre - Transmission Risk Scoring
Every counterparty VASP is scored from 1 to 100 before any data is transmitted, enriched with KYB status and MiCA authorisation. Compliance teams set their own thresholds to proceed, hold for review, or escalate. Customer data never reaches a flagged VASP unless your team approves it.
Flexible Verification For Unhosted Wallets
Regulators demand different levels of wallet ownership proof. Four methods run in one platform: Satoshi Test for on-chain proof, Signature Proof for cryptographic confirmation, Visual Proof for manual review, and Self Declared for lower-risk cases. Each generates a unique 24-hour link, audit-logged against the transaction.
The Compliance Workflow
From First Message to Audit-Ready Evidence
From Initiation to Audit Trail
Every transfer captures the complete FATF Recommendation 16 field set for both parties, with counterparty VASP details auto-populated from the directory. Your team enters less data by hand, and nothing goes out incomplete.
Confirm that every Travel Rule message reached the counterparty VASP and was acknowledged, with delivery status tracked end to end so no transfer is left unaccounted for.
Run the required checks before value moves and keep monitoring after settlement, so screening, thresholds, and evidence stay aligned across the full lifecycle of the transfer.
Sanctions, MiCA Status, and Full Audit Trail
Every counterparty VASP is screened against OFAC, EU and UN sanctions lists at onboarding, and access is revoked within a week if a VASP is sanctioned afterwards. You are never left transacting with a counterparty your last screening missed.
MiCA authorisation status is tracked for every VASP in the directory, and transfers to a non-compliant CASP are flagged automatically before they go out. Your team catches an authorisation gap before a regulator does.
Originator data, beneficiary data, the protocol used, screening result, risk score and delivery status all sit in one downloadable report per transaction. When a regulator asks for evidence, it is one export, not a reconstruction.
Every Jurisdiction Threshold in One Workflow
MiCA, FinCEN, the FCA and every other threshold you operate under run at the same time, with overrides available for specific high-risk counterparties. One rule set covers every market instead of one configuration per jurisdiction.
Every rule resolves to proceed, hold or escalate, and anything high-risk routes straight to manual review. Your compliance team sets the policy once, and the platform applies it on every transfer.
Offer the Travel Rule under your own brand with full API parity to the hosted platform. Your end customers see your product, not a third-party compliance vendor.
Prove Wallet Ownership. Four Methods
The customer returns a specific micro-transaction from the declared wallet, and ownership is confirmed the moment the exact amount comes back. It is on-chain proof, not a self-reported claim.
The customer signs a challenge message with the wallet's private key, proving control cryptographically without moving any funds. Technical users get the fastest, most rigorous method available.
A screenshot of the wallet interface covers manual review, and a signed attestation covers lower-risk jurisdictions where the other methods are impractical. Both are audit-logged against the transaction like every other method.
Regulatory Readiness
Compliance Coverage Built For Regulated Markets

IVMS101
ActiveGlobal Travel Rule Data Format, Native To Every Shufti Message.

MiCA & TFR
Threshold EUR: 0Zero Threshold For Every Transfer Processed By An EU CASP.

Direct
ActiveDirect VASP-To-VASP Messaging Across The Connected Network.

VARA
No Fixed ThresholdFATF-Aligned Workflows For All VARA-Licensed VASPs.

TRP
ActiveCross-Platform Interoperability With TRP-Connected Institutions.

FCA
Threshold GBP: 1,000UK Money Laundering Regulations For FCA-Registered CASPs.

Code VASP
ActiveIntegration For Cross-Network Message Routing.

FinCEN
Threshold USD: 3,000Bank Secrecy Act Obligations For US Virtual Currency Businesses.

Binance GTR
ActiveCoverage Of The Binance Global Travel Rule Network.

FATF Recommendation 16
40+ CountriesBaseline Standard Adopted Across MAS, FINTRAC, AUSTRAC, FINMA, FSA & SFC.
Independently Audited. Globally Certified
Audits and Certifications That Back Every Trust Claim

iBeta PAD Level 3
Liveness detection adversarially tested at PAD Level 3. Certified at 0% APCER, the highest tier available.

PCI DSS
Assessed by an independent QSA across all 12 control domains. AoC available for your auditor.

ISO 27001
Annually audited and certified for information security management. Certificate publicly verifiable through the issuing certification body.

QG-GDPR
Data processing, retention, and transfer controls independently audited against GDPR requirements.

Cyber Essentials Plus
UK government-backed scheme certifying controls against the most common cyber threats. Assessed and certified by an approved certification body.

DHS RIVR
Ranked among top performers in the U.S. Department of Homeland Security's RIVR 2025 evaluation for identity validation accuracy and security thresholds.
Single API, Seamless Integration
Build fully customisable verification flows with seamless backend integration.
- Gain full control by customising verification flows end-to-end.
- Integrate seamlessly with your backend for quick implementation.
- Design flexible verification journeys tailored to your users.
Launch a native verification experience in your mobile app within minutes.
- Launch native verification within minutes on iOS or Android.
- Use ready-made UI with camera, capture, and real-time feedback.
- Customise flows to fit seamlessly into your mobile app.
With KYC Journey Builder, create personalised verification journeys without writing a single line of code.
- Customise your journey effortlessly with drag-and-drop functionality.
- Instantly see how your verification flow looks for your users.
- Easily connect with Hosted Verification for a consistent, branded experience.
Run Shufti within your own identical-capability infrastructure for maximum data control and privacy.
- Keep all sensitive information in-house to meet strict governance and data residency requirements.
- Keep sensitive information fully private and secure in-house.
- Deploy in highly regulated sectors without compromising compliance.
Industry-Specific Solutions
Built For Your Business
Banking Rails You Already Run
Banks adding digital-asset custody inherit the same Travel Rule duty as a traditional wire, with a supervisor who expects the same audit trail. Add compliance as a layer over your existing infrastructure via REST API, without a parallel system for one asset class.
Don’t just take our word for it, hear from our customers
The Confidence Our Clients Share
The future of digital identity is defined by trust, interoperability, and regulatory alignment, so our partnership with Shufti reinforces DevCode Identity’s commitment to supporting our global customers with the most secure, best-in-class, compliant identity verification solutions available today.
Combining our Conversion Driven Compliance Orchestration Platform with Shufti’s global KYC and IDV capabilities allows our customers not only to navigate complex regulatory demands but also to maintain a seamless customer onboarding experience with the highest achievable conversion rates.
We’re proud to continue our partnership with Shufti as we expand into new jurisdictions.
Shufti’s verification technology not only strengthens our compliance framework but also ensures our players enjoy a smooth, secure onboarding experience.
We aim to offer our clients and their traders the very best tools with which to do their jobs, we’re excited to be able to work with Shufti.
They’re a leading company, and we’re looking forward to offering their solutions to our clients through our CRM.
The relationship with Shufti was born out of frustration with an existing provider, so we started our discussion with Shufti.
The response time was excellent, from the start of speaking to sales to getting up and running with the demo.
Everything You Need To Know In One Place
Frequently Asked Questions
The Travel Rule is a FATF Recommendation 16 requirement that obligates Virtual Asset Service Providers to transmit originator and beneficiary information with every crypto transfer above a jurisdiction-specific threshold. MiCA enforces this at EUR 0 (zero threshold), FinCEN at USD 3,000, and the FCA at GBP 1,000. Shufti supports all thresholds in one configurable workflow.
A directory of 12,000+ entities, including exchanges, PSPs, banks, custodians and OTC desks, resolves the receiving VASP. Delivery is close to 100% when the VASP is named, and about 50% auto-resolved from wallet and blockchain analytics when it is not.
IVMS 101 is the shared data standard for every message. Routing runs across a direct VASP-to-VASP protocol, TRP, CODE and Binance GTR from a single API call, and the platform selects the correct protocol automatically. TRISA is not used.
Shufti offers four wallet verification methods: Satoshi Test, Signature Proof, Visual Proof, and Self Declared. Each generates a unique 24-hour link. All evidence is audit-logged.
Yes. The EU Transfer of Funds Regulation applies to every crypto transfer regardless of amount, and zero-threshold is enforced natively. MiCA authorisation status is tracked per VASP.
Yes. The rule engine lets compliance teams set jurisdiction thresholds, VASP-specific overrides, and automated proceed, hold or escalate actions, with EUR 0, USD 3,000 and GBP 1,000 running at the same time.
Every VASP receives a 1-100 risk score enriched with KYB data, MiCA compliance indicators, and severity labels. Risk assessment happens before data transmission. High-risk counterparties trigger configurable escalation.
Post-transaction transmits data after transfer processing. Pre-transaction gates the withdrawal until confirmed by the receiving VASP. Both can run side by side on the same platform.
API integration typically takes 2 to 5 business days. SDK integration takes 1 to 3 business days. Sandbox access is provisioned within 24 hours. These timelines reflect actual enterprise deployment experience, not estimates. A dedicated integration support team is available throughout the process.
A RESTful API with JSON and webhooks, plus a sandbox for testing. Existing Shufti clients add the Travel Rule to the same API key. New clients go live within days.
Yes, the Travel Rule deploys alongside AML Screening, Transaction Monitoring and identity verification on one platform, with one audit trail and one API.
Yes. White-label deployment gives you full API parity under your own brand. Counterparty and transfer records stay in your branded environment, and your customers never see a third party.
No. For counterparties outside directly integrated networks, a compliant send-and-document approach records the transmitted data as your compliance evidence. Clients who are already TRUST members can keep that membership independently.
This is the sunrise problem, and it is common since not every VASP has live messaging yet. Incoming transfers without data can be released under policy, backfilled from the customer, or escalated as a formal claim, and every action is logged as audit evidence.
Not if you already use Shufti. The Travel Rule activates on your existing API key and contract, alongside AML Screening and identity verification, so there is no second vendor, no second audit trail, and no separate procurement cycle.
MiCA Is Live. Supervisors Are Inspecting
See how a 12,000+ entity directory, multi-protocol routing on IVMS 101, and identity-verified originators deliver audit-ready compliance from a single API.