Last reviewed: 22 August 2026
Safewire is a non-custodial payments platform. We never hold customer or merchant funds — every movement of money is signed by the person or business that owns it. What we do hold is the obligation to know who is transacting, to keep a complete record of it, and to pass the required information alongside the payment.
This page sets out the regimes we build to and what each one requires. It is a description of the rules, not legal advice.
A floor, plus the rules where you live
Safewire applies one baseline standard to everybody, then adds the rules of the customer's own jurisdiction on top. Where two rules cover the same thing, the stricter one applies.
| Layer | Who it covers |
|---|---|
| Baseline | Every payer and every merchant on the platform, everywhere |
| Regional overlay | Customers resident in a jurisdiction with its own regime |
The baseline is the Canadian standard. It is the most prescriptive of the regimes we operate under, so holding everyone to it means no customer is ever held to less than their own country requires.
Canada — the baseline
Proceeds of Crime (Money Laundering) and Terrorist Financing Act and Regulations (PCMLTFA / PCMLTFR). Supervised by FINTRAC. Amounts in Canadian dollars.
CAD 1,000 — per payment
- Identity verification of the payer, using a prescribed method.PCMLTFR s.95(1)(d); methods at s.105
- Transfer record — name, address, date of birth, occupation, amount and date.PCMLTFR s.36(g)
- Travel rule — payer and payee details travel with the payment.PCMLTFR s.124.1
CAD 10,000 — totalled across a 24-hour period, per person
- Large Virtual Currency Transaction Report to FINTRAC.
- Large Cash Transaction Report where cash is taken at a merchant counter.
CAD 100,000 — per payment
- Politically exposed person determination for the payer.PCMLTFR s.120
Any amount — sanctions and ministerial directives
- Ministerial directives covering North Korea, Iran and Russia require verification, record-keeping and reporting at any amount.PCMLTFA Part 1.1
- Sanctions screening against SEMA, the Justice for Victims of Corrupt Foreign Officials Act, the Criminal Code listings, and the United Nations, OFAC, EU and UK OFSI lists.
Screening runs before a payment is assembled. A match is a refusal, not a verification step — there is no tier of identity that clears it.
United Kingdom
Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (SI 2017/692, as amended). Applies on top of the baseline to customers resident in the UK.
£800 — per transfer
The UK sets its threshold in sterling rather than adopting the FATF figure.
- Customer due diligence on the occasional transaction.reg 27(7E)
- Travel rule for cryptoasset transfers.reg 64C
European Economic Area
Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets. Applies on top of the baseline to customers resident in the EEA.
Every transfer — no minimum
- Travel rule — payer and payee details accompany every crypto-asset transfer, regardless of amount.Article 14; recital 30
Everywhere else
FATF Recommendation 15 and its Interpretive Note. The international baseline, applied to customers resident anywhere not covered above.
USD 1,000 — per transfer
- Occasional transaction due diligence and travel-rule information.INR.15 ¶6(b), ¶7(b)
Sint Maarten
Records covering residents of Sint Maarten are retained for ten years.
How a payment is assessed
Every payment is measured against the rules before it is assembled, in five steps. All five are written to the record, so the decision can be replayed later exactly as it was made.
- Price it. The amount is converted to the currency each applicable regime is written in, using an independent market rate. The rate and the moment it was taken are kept on the record.
- Find the lines it reaches. The payment is compared to every threshold that applies to this customer — per-payment, and cumulative across the relevant window.
- Work out the assurance required. The highest requirement wins, whether it comes from a statutory threshold or from Safewire's own activity-based policy.
- Read the assurance held. The customer's verification status is read from our servers. A device is never asked to assert its own standing.
- Allow or refuse. If the customer holds what the payment requires, it proceeds. If not, it is refused before anything is signed — nothing moves, and there is nothing to reverse.
A refused payment tells the customer plainly what would let them complete it.
The record
Every assessment produces one entry, written once and never edited: the amount and the rate it was priced at, the regime and the thresholds reached, the cumulative totals, what the payment required, what the customer held, the screening result, and the outcome. That entry is what an examiner reads.
Regulatory citations were last reviewed against the source texts on 22 August 2026. This page describes the requirements Safewire builds to. It is not legal advice, and it is not a representation about any individual transaction.