us

216.73.217.98

CRYPTO TRAVEL RULE COMPLIANCE

Audit-Ready Travel Rule, Built On Verified Identity

Verify the customer, vet the counterparty VASP against a 12,000+ entity directory, and transmit FATF Recommendation 16 data, on the identity and AML platform your team already runs.

Book A Demo
Four-step Travel Rule flow: customer verified, counterparty VASP vetted against directory, FATF Recommendation 16 data transmitted, and an audit-ready compliant transfer record
Trusted By Digital Asset Businesses

Trusted By Leading Digital Asset Businesses Worldwide

12k+
Entities
4
Protocols, One API
85+
Jurisdictions Covered
4
Wallet Verification Methods
Trusted By Leading Digital Enterprises Worldwide
Hero Cashew GemOne Banxy Bitget IronFX Penn National Gaming Rakuten Noteris Witzeal

WHY SHUFTI FOR TRAVEL RULE

Verify the Customer, Vet the VASP, Transmit the Data

Fewer Stalled Transfers, Less Manual Work

Most Travel Rule failures happen because the receiving VASP was never identified in time, not because the message itself was wrong. The 12,000+ entity directory keeps delivery close to 100% when the VASP is named, and grows automatically with every new counterparty you reach.

Book A Demo
Delivery-when-named panel: 12,000+ entity directory and ~100% delivery rate that grows with every counterparty.

Reduce Vendor Complexity

Route through a direct VASP-to-VASP protocol, TRP, CODE and Binance GTR from a single API call, all on the IVMS 101 data standard. The platform identifies the counterparty and selects the protocol automatically. No separate memberships, no protocol management, and no second vendor for identity.

Book A Demo
Four protocols unified — VASP-to-VASP, TRP, CODE, Binance GTR — collapsing into a single API call on the IVMS 101 data standard.

Pre - Transmission Risk Scoring

Every counterparty VASP is scored from 1 to 100 before any data is transmitted, enriched with KYB status and MiCA authorisation. Compliance teams set their own thresholds to proceed, hold for review, or escalate. Customer data never reaches a flagged VASP unless your team approves it.

Book A Demo
1–100 risk score enriched with KYB status and MiCA authorisation, with Proceed, Hold for Review, and Escalate compliance thresholds.

Flexible Verification For Unhosted Wallets

Regulators demand different levels of wallet ownership proof. Four methods run in one platform: Satoshi Test for on-chain proof, Signature Proof for cryptographic confirmation, Visual Proof for manual review, and Self Declared for lower-risk cases. Each generates a unique 24-hour link, audit-logged against the transaction.

Book A Demo
Four wallet-ownership proof methods — Satoshi Test, Signature Proof, Visual Proof, Self Declared — each with a 24-hour link and audit log.

The Compliance Workflow

From First Message to Audit-Ready Evidence

Travel Rule transfer with originator, beneficiary and evidence chain

From Initiation to Audit Trail

Every transfer captures the complete FATF Recommendation 16 field set for both parties, with counterparty VASP details auto-populated from the directory. Your team enters less data by hand, and nothing goes out incomplete.

Confirm that every Travel Rule message reached the counterparty VASP and was acknowledged, with delivery status tracked end to end so no transfer is left unaccounted for.

Run the required checks before value moves and keep monitoring after settlement, so screening, thresholds, and evidence stay aligned across the full lifecycle of the transfer.

Sanctions screening against OFAC, EU and UN lists

Sanctions, MiCA Status, and Full Audit Trail

Every counterparty VASP is screened against OFAC, EU and UN sanctions lists at onboarding, and access is revoked within a week if a VASP is sanctioned afterwards. You are never left transacting with a counterparty your last screening missed.

MiCA authorisation status is tracked for every VASP in the directory, and transfers to a non-compliant CASP are flagged automatically before they go out. Your team catches an authorisation gap before a regulator does.

Originator data, beneficiary data, the protocol used, screening result, risk score and delivery status all sit in one downloadable report per transaction. When a regulator asks for evidence, it is one export, not a reconstruction.

Jurisdiction thresholds for MiCA, VARA, FCA, FinCEN and FATF R16

Every Jurisdiction Threshold in One Workflow

MiCA, FinCEN, the FCA and every other threshold you operate under run at the same time, with overrides available for specific high-risk counterparties. One rule set covers every market instead of one configuration per jurisdiction.

Every rule resolves to proceed, hold or escalate, and anything high-risk routes straight to manual review. Your compliance team sets the policy once, and the platform applies it on every transfer.

Offer the Travel Rule under your own brand with full API parity to the hosted platform. Your end customers see your product, not a third-party compliance vendor.

Satoshi Test confirming wallet ownership by returned micro-transaction

Prove Wallet Ownership. Four Methods

The customer returns a specific micro-transaction from the declared wallet, and ownership is confirmed the moment the exact amount comes back. It is on-chain proof, not a self-reported claim.

The customer signs a challenge message with the wallet's private key, proving control cryptographically without moving any funds. Technical users get the fastest, most rigorous method available.

A screenshot of the wallet interface covers manual review, and a signed attestation covers lower-risk jurisdictions where the other methods are impractical. Both are audit-logged against the transaction like every other method.

Regulatory Readiness

Compliance Coverage Built For Regulated Markets

IVMS101

Active

Global Travel Rule Data Format, Native To Every Shufti Message.

MiCA & TFR

Threshold EUR: 0

Zero Threshold For Every Transfer Processed By An EU CASP.

Direct

Active

Direct VASP-To-VASP Messaging Across The Connected Network.

VARA

No Fixed Threshold

FATF-Aligned Workflows For All VARA-Licensed VASPs.

TRP

Active

Cross-Platform Interoperability With TRP-Connected Institutions.

FCA

Threshold GBP: 1,000

UK Money Laundering Regulations For FCA-Registered CASPs.

Code VASP

Active

Integration For Cross-Network Message Routing.

FinCEN

Threshold USD: 3,000

Bank Secrecy Act Obligations For US Virtual Currency Businesses.

Binance GTR

Active

Coverage Of The Binance Global Travel Rule Network.

FATF Recommendation 16

40+ Countries

Baseline Standard Adopted Across MAS, FINTRAC, AUSTRAC, FINMA, FSA & SFC.

Independently Audited. Globally Certified

Audits and Certifications That Back Every Trust Claim

iBeta PAD Level 3

Liveness detection adversarially tested at PAD Level 3. Certified at 0% APCER, the highest tier available.

PCI DSS

Assessed by an independent QSA across all 12 control domains. AoC available for your auditor.

ISO 27001

Annually audited and certified for information security management. Certificate publicly verifiable through the issuing certification body.

QG-GDPR

Data processing, retention, and transfer controls independently audited against GDPR requirements.

Cyber Essentials Plus

UK government-backed scheme certifying controls against the most common cyber threats. Assessed and certified by an approved certification body.

DHS RIVR

Ranked among top performers in the U.S. Department of Homeland Security's RIVR 2025 evaluation for identity validation accuracy and security thresholds.

Built for Compliance: Go live in minutes with our flexible API and lightweight SDKs

Single API, Seamless Integration

Build fully customisable verification flows with seamless backend integration.

  • Gain full control by customising verification flows end-to-end.
  • Integrate seamlessly with your backend for quick implementation.
  • Design flexible verification journeys tailored to your users.
Explore API Docs
RESTful API img

Launch a native verification experience in your mobile app within minutes.

  • Launch native verification within minutes on iOS or Android.
  • Use ready-made UI with camera, capture, and real-time feedback.
  • Customise flows to fit seamlessly into your mobile app.
Explore SDKs Docs
Lightweight SDK image

With KYC Journey Builder, create personalised verification journeys without writing a single line of code.

  • Customise your journey effortlessly with drag-and-drop functionality.
  • Instantly see how your verification flow looks for your users.
  • Easily connect with Hosted Verification for a consistent, branded experience.
Explore More
On-Premise Deployment image

Run Shufti within your own identical-capability infrastructure for maximum data control and privacy.

  • Keep all sensitive information in-house to meet strict governance and data residency requirements.
  • Keep sensitive information fully private and secure in-house.
  • Deploy in highly regulated sectors without compromising compliance.
Contact Sales
On-Premise Deployment image

Industry-Specific Solutions

Built For Your Business

Banking Rails You Already Run

Banks adding digital-asset custody inherit the same Travel Rule duty as a traditional wire, with a supervisor who expects the same audit trail. Add compliance as a layer over your existing infrastructure via REST API, without a parallel system for one asset class.

ICICI Bank Canada Safwa Islamic Bank Al Rajhi Bank
Industry-specific Travel Rule compliance

Don’t just take our word for it, hear from our customers

The Confidence Our Clients Share

The future of digital identity is defined by trust, interoperability, and regulatory alignment, so our partnership with Shufti reinforces DevCode Identity’s commitment to supporting our global customers with the most secure, best-in-class, compliant identity verification solutions available today.

Combining our Conversion Driven Compliance Orchestration Platform with Shufti’s global KYC and IDV capabilities allows our customers not only to navigate complex regulatory demands but also to maintain a seamless customer onboarding experience with the highest achievable conversion rates.

Mark Knighton
Chief Global Development Officer -
Global Alliances, DevCode

Everything You Need To Know In One Place

Frequently Asked Questions

The Travel Rule is a FATF Recommendation 16 requirement that obligates Virtual Asset Service Providers to transmit originator and beneficiary information with every crypto transfer above a jurisdiction-specific threshold. MiCA enforces this at EUR 0 (zero threshold), FinCEN at USD 3,000, and the FCA at GBP 1,000. Shufti supports all thresholds in one configurable workflow.

A directory of 12,000+ entities, including exchanges, PSPs, banks, custodians and OTC desks, resolves the receiving VASP. Delivery is close to 100% when the VASP is named, and about 50% auto-resolved from wallet and blockchain analytics when it is not.

IVMS 101 is the shared data standard for every message. Routing runs across a direct VASP-to-VASP protocol, TRP, CODE and Binance GTR from a single API call, and the platform selects the correct protocol automatically. TRISA is not used.

Shufti offers four wallet verification methods: Satoshi Test, Signature Proof, Visual Proof, and Self Declared. Each generates a unique 24-hour link. All evidence is audit-logged.

Yes. The EU Transfer of Funds Regulation applies to every crypto transfer regardless of amount, and zero-threshold is enforced natively. MiCA authorisation status is tracked per VASP.

Yes. The rule engine lets compliance teams set jurisdiction thresholds, VASP-specific overrides, and automated proceed, hold or escalate actions, with EUR 0, USD 3,000 and GBP 1,000 running at the same time.

Every VASP receives a 1-100 risk score enriched with KYB data, MiCA compliance indicators, and severity labels. Risk assessment happens before data transmission. High-risk counterparties trigger configurable escalation.

Post-transaction transmits data after transfer processing. Pre-transaction gates the withdrawal until confirmed by the receiving VASP. Both can run side by side on the same platform.

API integration typically takes 2 to 5 business days. SDK integration takes 1 to 3 business days. Sandbox access is provisioned within 24 hours. These timelines reflect actual enterprise deployment experience, not estimates. A dedicated integration support team is available throughout the process.

A RESTful API with JSON and webhooks, plus a sandbox for testing. Existing Shufti clients add the Travel Rule to the same API key. New clients go live within days.

Yes, the Travel Rule deploys alongside AML Screening, Transaction Monitoring and identity verification on one platform, with one audit trail and one API.

Yes. White-label deployment gives you full API parity under your own brand. Counterparty and transfer records stay in your branded environment, and your customers never see a third party.

No. For counterparties outside directly integrated networks, a compliant send-and-document approach records the transmitted data as your compliance evidence. Clients who are already TRUST members can keep that membership independently.

This is the sunrise problem, and it is common since not every VASP has live messaging yet. Incoming transfers without data can be released under policy, backfilled from the customer, or escalated as a formal claim, and every action is logged as audit evidence.

Not if you already use Shufti. The Travel Rule activates on your existing API key and contract, alongside AML Screening and identity verification, so there is no second vendor, no second audit trail, and no separate procurement cycle.

MiCA Is Live. Supervisors Are Inspecting

See how a 12,000+ entity directory, multi-protocol routing on IVMS 101, and identity-verified originators deliver audit-ready compliance from a single API.