Anti-Money Laundering, Sanctions and Prohibited Use Policy

Version 1.0 · Effective 14 September 2026 · Next full review by 14 September 2027

Operator: Recorise Ltd, company number 248397, Seychelles.
This public Policy is supported by internal risk rules, screening procedures and escalation standards that are not published in full because disclosure could facilitate circumvention.

1. Purpose and scope

This Policy describes the risk-based measures used by Recorise Ltd, operating the Netts service (“Netts”, “we”, “us”), to prevent the Services from being used for money laundering, terrorist financing, sanctions evasion, fraud, phishing, ransomware, theft or other unlawful activity.

It applies to Netts websites, APIs, bots, dashboards, TRON Energy and Bandwidth delegation, address activation, blockchain analytics, prepayments, internal service balances, withdrawals, post-paid billing and related services.

2. Nature of the Services and regulatory status

Netts provides blockchain infrastructure, software, APIs and temporary delegation of protocol-level computational resources, including TRON Energy and Bandwidth.

Netts does not request or control a customer’s external-wallet private keys or seed phrases and does not initiate or sign token transfers from a customer’s external wallet. Resource delegation does not give Netts authority to transfer assets held in the receiving wallet.

Recorise Ltd does not represent Netts as a licensed virtual-asset exchange, wallet or custodial service. The Services are network-resource and software/API services. The regulatory characterisation of a particular arrangement may depend on the agreed service model and applicable law.

Netts may accept fiat or supported digital-asset payments. Depending on the service model, a payment may be a prepayment recorded as an off-chain service balance or a post-paid settlement of Services already delivered and invoiced.

3. Customer and payment models

Netts may provide standard self-service access without prior identity verification. Such access remains subject to technical controls, sanctions screening, wallet and transaction monitoring, limits and the right to request additional information.

Corporate, high-volume, post-paid, credit-based, dedicated-SLA or intermediary arrangements may require business verification before activation.

Settlement may be made in fiat currency or supported digital assets. Digital-asset payments may be received to Recorise-controlled blockchain addresses or to corporate accounts maintained in the name of Recorise Ltd with approved third-party digital-asset service providers.

In a post-paid arrangement, the payment settles an invoice for Services already delivered and no prepaid customer balance is maintained for that arrangement.

4. Risk-based approach

Netts applies controls proportionately to risk. Relevant factors may include:

  • customer type and level of identification;
  • business activity and intended use of the Services;
  • countries of establishment, operation or access;
  • ownership and control of a business customer;
  • payment method, payment wallet and transaction history;
  • receiver-address history and blockchain exposure;
  • expected and actual volume;
  • unusual patterns, attempts to circumvent controls or repeated failed requests;
  • internal intelligence and third-party blockchain analytics.

A low-risk rating or a successful automated check does not guarantee that a customer, address or transaction is free from unlawful activity.

5. Customer identification and business verification

Netts does not require the same level of identification from every customer.

Netts may request personal identification, company information, ownership information, proof of authority, proof of wallet control, source-of-funds information, regulatory information or an explanation of a transaction or use case where justified by risk.

Business verification may include legal name and registration details, directors, authorised representatives, beneficial owners, ownership and control structure, business activity, regulatory status, relevant countries, expected volumes and approved payment methods.

Netts may refuse, limit or suspend Services where requested information is not provided, cannot be verified or does not adequately address the identified risk.

6. Screening of digital-asset deposits and withdrawals

Netts applies sanctions, internal-list and blockchain-risk screening to digital-asset deposits and withdrawals under its risk-based controls.

Netts may review the transaction identifier, originating or destination address, asset, network, amount, customer relationship and relevant blockchain exposure. The depth and timing of screening may vary by transaction type, asset, product and risk profile. A payment or withdrawal may be placed on compliance hold while an alert is reviewed.

A technical failure or unavailable screening provider is recorded and handled under the applicable control rules; it is not silently treated as a successful screening result.

7. Receiver-address controls and central deny list

Every resource-delegation request is checked against the central Netts address deny list before fulfilment.

A request involving an address included in the deny list is rejected. The affected request is not forwarded to an internal or external resource provider for fulfilment.

The deny list may include addresses associated with sanctions, token-issuer restrictions, phishing, scams, ransomware, malware, stolen assets, fraud, law-enforcement information, internal abuse findings or other unacceptable risk.

8. Enhanced blockchain screening

Netts uses third-party blockchain analytics, including Elliptic, together with internal intelligence and risk classifications.

Enhanced screening may be applied based on the customer profile, first use of an address, transaction value or volume, unusual behaviour, risk alerts, contractual enterprise requirements, targeted review, random sampling or periodic rescreening.

Not every receiver address receives the same depth of blockchain analysis. External datasets and automated tools may be incomplete and cannot identify every unlawful or high-risk address.

9. Sanctions and token-issuer restrictions

The Services must not be used by, for, on behalf of or for the benefit of a person or entity subject to applicable sanctions or asset-freeze restrictions, or to facilitate sanctions evasion.

Netts may also refuse resource delegation to an address included in a token-issuer blacklist, including an applicable USDT issuer blacklist. A token-issuer blacklist is treated as a separate operational and risk control and is not necessarily a government sanctions list.

10. Prohibited use

The Services must not be used in connection with:

  • money laundering, terrorist financing or sanctions evasion;
  • phishing, address poisoning, impersonation or credential theft;
  • fraud, scams or deceptive schemes;
  • ransomware, malware, extortion or cybercrime;
  • stolen or misappropriated assets;
  • darknet markets or unlawful goods and services;
  • deliberate transaction obfuscation intended to conceal criminal proceeds;
  • attacks on blockchain networks, systems or users;
  • any activity prohibited by applicable law or the Netts Terms of Use.

Attempted, indirect or facilitated use may be treated in the same manner as direct use.

11. Independent intermediaries and channel partners

Netts may provide Services through an independent reseller, channel partner, contractor or other contractual intermediary acting in its own name and for its own account.

Netts applies risk-based due diligence to such an intermediary and may request information concerning a disclosed business end customer, its ownership, regulatory status, intended use, payment arrangements or designated wallet addresses.

The use of an intermediary does not permit any customer, payment or address to avoid Netts sanctions, prohibited-use or risk controls.

12. Actions taken on an alert

Depending on the circumstances, Netts may:

  • reject or cancel a delegation request;
  • place a deposit, service balance, payment, refund or withdrawal on compliance hold;
  • request customer, company, ownership, wallet or transaction information;
  • restrict an account, API key, address, payment method or product;
  • conduct manual or enhanced review;
  • terminate the relationship;
  • preserve records and evidence;
  • make a report or disclosure where required or permitted by law;
  • follow instructions from a competent authority.

Netts will not automatically return value to a prohibited or sanctioned address. Any release, return or other disposition is subject to compliance review and applicable law.

13. Data sharing

To assess the risk associated with a blockchain address, Netts submits that public address, and where relevant a public transaction identifier, to approved blockchain analytics providers, including Elliptic, and receives a risk assessment in return. Netts does not send a customer’s name, contact details, account data or identity documents to such a provider, and the assessment received is processed within Netts systems.

Where an order is fulfilled through an external resource provider, Netts may disclose the public receiver address and the minimum order data necessary to perform the delegation. A rejected deny-list request is not forwarded for fulfilment.

Relevant information may also be disclosed to infrastructure and security providers, professional advisers, auditors, banks, approved digital-asset service providers, insurers or competent authorities where necessary and subject to applicable confidentiality, security and legal requirements.

Netts does not sell customer or receiver-address lists.

14. Public blockchain records and record keeping

Resource delegation and related blockchain transactions may create permanent public records, including transaction identifiers, block data, source addresses, receiver addresses and resource quantities. Netts does not control the public blockchain and cannot alter or erase records maintained by the network.

Blockchain records identify addresses and transactions but do not necessarily identify the natural or legal persons controlling those addresses.

Netts separately retains customer, payment, contractual, screening, risk and operational records under its data-retention standards. Off-chain records may be deleted, anonymised or de-linked when the applicable retention period expires, unless continued retention is required for legal, contractual, security, investigation or claim purposes.

15. Governance, testing and review

Netts assigns responsibility for this Policy and maintains internal controls, testing, audit evidence and staff instructions appropriate to its business and risk profile.

This Policy is reviewed at least annually and after a material change to the Services, customer profile, payment methods, screening technology, sanctions environment or applicable requirements.

16. Contact

Recorise Ltd
Company number: 248397
F2-2A, Oceanic House, Providence Estate, Mahé, Seychelles
Compliance enquiries: [email protected]
Security contact: [email protected]
Website: netts.io