Compliance
What we actually do about identity, monitoring and data — and what is not in place yet.
How we operate
-
Identity (KYC)
Identity verification is required only for BRL/PIX operations: a PIX deposit needs a valid CPF, and a PIX withdrawal needs T1 verification. Crypto trading, deposits and withdrawals work with a confirmed e-mail and two-factor authentication, capped at US$ 10,000 per day per account.
-
Monitoring (AML)
Withdrawals pass through automated checks before they are sent: a daily cap, a velocity limit of one withdrawal every five minutes and up to US$ 20,000 per hour, and a manual review from the equivalent of US$ 1,000. Watchdogs reconcile hot-wallet balances and ledger liabilities continuously, and a discrepancy pauses payouts.
-
Data protection
Our Privacy Policy states what personal data we collect, why we hold it and how to exercise your rights, following the LGPD and the GDPR. Privacy requests go to privacy@offcode.pro.
-
Regulation
OFFCODE's corporate entity is being structured and the service is not presently operating under a specific financial-services license. We track international regulatory practice and the FATF recommendations for virtual assets, and we say where we stand instead of implying a status we do not hold.
What is not in place yet
We hold no third-party security or compliance certification — no ISO 27001, no SOC 2, no PCI DSS. Proof of Reserves is in development: a snapshot of reserves against liabilities is generated hourly, and publishing it is still being built. We list this here rather than show a badge nobody audited.
Whistleblowing and Ethics Channel
If you spot suspicious activity or irregularities, contact our compliance channel anonymously and securely.
