Infinihash operates compliance, identity and settlement infrastructure for regulated institutions. This page is the honest, current state of our security, compliance, and data posture across KYC, KYT and Rails. We flag what is live, what is in progress, what is on the roadmap, and what we have decided not to do at all. No aspirational certifications.
Status reflects current reality. Where a framework is in progress or planning, we say so. We do not claim certifications we have not earned.
SOC 2 program in progress — no report issued yet. Pre-attestation security questionnaires available on request.
Scoping ISMS, control mapping, and gap assessment. No fixed certification date.
Cookie consent banner is now live estate-wide. Remaining gaps before we claim alignment: (1) ✓ Published — Data Subject Request workflow is now publicly documented, (2) ✓ Published — Records of Processing Activities summary is now public, (3) Privacy Policy is self-authored v1 and not yet counsel-reviewed, (4) no Data Processing Agreement is available for signature yet — a template written against the actual data flows described on this page is drafted and with counsel; we are not offering one until it can be executed, and we do not claim standard contractual clauses we have not put in place. Remediation tracked under internal #1820.
Privacy notice published and a consumer rights inbox is monitored. Cookie consent layer is now live. Remaining gaps: ✓ documented DSR workflow, ✓ public RoPA, counsel-reviewed Privacy Policy. Tracked under internal #1820.
KYC + KYT products operational. SAR / FinCEN JSON export shipped. Built for regulated DAS and OTC counterparties.
OFAC SDN cryptocurrency addresses screened on every KYT request. UN and EU consolidated lists tracked in roadmap.
Note: GDPR and CCPA do not offer formal certifications. The status above reflects the readiness of our documented controls, not an attestation. Until every gap listed above is closed, we describe ourselves as "in progress" rather than "aligned."
Our customers operate in regulated corners of finance and crypto. The platform was designed around their controls, audit trails, and reporting workflows. Named customer references and case studies are in progress.
Counterparty KYT screening, wallet attribution, and SAR-ready transaction monitoring for digital-asset strategies.
Continuous monitoring of corporate wallets, OFAC screening on inbound flows, and treasury-level KYC for vendors and payees.
Investigative KYT support, on-chain provenance reports, and chain-of-custody exports for regulatory and litigation matters.
Pre-trade counterparty KYC, address screening on every settlement, and FinCEN-JSON SAR export to satisfy BSA obligations.
KYT screens against an ingestion pipeline of sanctions, stablecoin freezes, and curated threat intelligence. Counts shown are deduplicated addresses currently in the active label set.
| Source | Category | Addresses | Acceptance Tier |
|---|---|---|---|
| OFAC SDN (US Treasury) | Sanctions | 656 | T1 . 100% accept |
| Stablecoin issuer freezes (USDT, USDC, etc.) | On-chain enforcement | 7,463 | T3 . accept |
| ScamSniffer phishing & drainer set | Threat intel | 2,530 | T4 . evaluated |
| Aggregate active label set | All accepted sources | 10,000+ | Growing toward 260k |
KYC handles document OCR, MRZ extraction, structured field capture, and — since 2026 — an in-house liveness challenge with face match against the document portrait. This page previously described liveness as roadmap; that was stale, and the correction is below.
Rails takes a USD invoice, collects it by ACH, and settles it as stablecoin to a wallet the tenant controls. Everything below describes behaviour that is implemented and enforced in code, not intent. Where a capability is missing we name it rather than calling it roadmap.
409 escrow_hold_unsupported. The rail forwards funds to the destination in one transfer, so an escrow funded through it would report as held while the money had already left. We refuse at the door rather than show a balance that is not there.409 refund_unsupported. No settlement adapter implements a refund leg, so dispute rules that would auto-refund route to human review instead of recording a refund no rail performed.Foundational controls. Where a control is partial or vendor-default, we say so explicitly.
We collect the data we need to run identity verification, transaction monitoring, and billing. We do not sell personal data.
Standing legal pages:
No Data Processing Agreement is available for signature yet. A template written against the data flows described on this page — including the Rails subprocessors below — is drafted and under counsel review. We would rather say that than answer a DPA request with nothing. Email [email protected] to be told when it is executable.
This list reflects current production subprocessors across KYC, KYT and Rails. Each entry says what that vendor actually receives, not just what it is for. Material changes are announced via email to enterprise customers ahead of go-live.
For vulnerabilities, incident reports, abuse, or compliance and privacy requests.