SubScript Logo
SubScript
Sign InGet Started
Back to Home
Institutional Trust & Transparency

Compliance & Regulatory Portal

Last Updated: September 4th, 2026 · Mainnet Compliance Standard 2.4

Sanctions Compliant

OFAC SDN, UK HMT & EU consolidated list screening automated via continuous risk surveillance.

Consumer First

100% compliant with FTC Click-to-Cancel rules and California SB-313 auto-renewal statutes.

Non-Custodial

Decentralized smart contract routing with immutable receipt hashes and autonomous settlement.

Regulatory Classification

1. Protocol Architecture & Software Non-Custodial Status

SubScript is an open-source decentralized smart contract protocol and transaction routing system built natively on Circle's Arc Network. Transactions settle in Circle USDC.

Software Protocol Classification: Under FinCEN guidance (FIN-2019-G001), the U.S. Bank Secrecy Act (BSA), the European Union Markets in Crypto-Assets Regulation (MiCA), and the UK Financial Services and Markets Act (FSMA), SubScript functions as an unhosted software protocol and infrastructure developer.
Non-Custodial Settlement: For external Web3 wallets (MetaMask, Rabby, Phantom, OKX, etc.), SubScript never holds, receives, custodies, or transmits user assets. Funds flow directly between the subscriber and the merchant via autonomous smart contracts (SubScriptRouter, SubScriptVault, SubScriptPSA).
Embedded MPC Accounts: For users onboarding via email, embedded multi-party computation accounts are provisioned through Circle's licensed, SOC2-certified developer-controlled wallet infrastructure. SubScript never possesses monolithic private keys.
Not a Depository or Broker-Dealer: SubScript is not a bank, depository institution, money services business (MSB), fiat currency transmitter, digital asset exchange, or investment advisor. Balances held in wallets or vaults are not bank deposits and are not insured by FDIC, SIPC, or European deposit guarantee schemes.
AML & CFT Framework

2. Anti-Money Laundering & Counter-Terrorist Financing Policy

SubScript enforces a comprehensive, risk-based AML/CFT framework designed to prevent the protocol and hosted interfaces from being utilized for illicit financial flows.

Zero Tolerance Policy: SubScript prohibits any transaction, subscription, or merchant activity associated with terrorist financing, narcotics trafficking, human exploitation, sanctions evasion, or cyber extortion.
Continuous Transaction Monitoring: Our automated risk engine continuously analyzes platform payment flows for velocity anomalies, payment structuring, rapid-fire subscriptions across disposable addresses, and abnormal transaction amounts.
Risk Alerts Engine: Identified anomalies generate immutable records in our `risk_alerts` security table, flagging subjects for compliance review, enhanced diligence, sponsorship suspension, or administrative blacklisting.
Sanctions Enforcement

3. Global Sanctions Screening & Geographic Geofencing

SubScript strictly complies with economic sanctions programs administered by the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC), the United Nations Security Council, the European Union, and the United Kingdom HM Treasury.

Automated Address Screening: All inbound merchant registrations, large volume flows, and account interactions are cross-referenced against OFAC Specially Designated Nationals (SDN) lists and global sanctions screening databases via our `compliance_screenings` engine.
Comprehensive Geographic Geofencing: SubScript utilizes IP-based geographic routing controls to block access, hosted checkout pages, and developer APIs from comprehensively sanctioned nations and territories: Cuba, Iran, North Korea, Syria, and the Crimea, Donetsk, and Luhansk regions of Ukraine.
Immediate Asset Freezing / Blocking: If an address is identified on a recognized sanctions list, SubScript's hosted gateway immediately terminates interface access, revokes API keys, and reports relevant findings to regulatory authorities where required by law.
Merchant Integrity

4. Prohibited & Restricted Businesses Policy

To maintain platform integrity and protect consumers, SubScript prohibits merchants from utilizing our checkout infrastructure for high-risk or unlawful categories.

Weapons & Explosives: Sale of firearms, ammunition, military ordnance, explosives, or hazardous biological materials;
Exploitative & Illegal Content: Child sexual abuse material (CSAM), non-consensual imagery, prostitution, or human trafficking;
Cybersecurity Exploits: Distribution of malware, ransomware, stolen data credentials, phishing templates, or DDoS-for-hire services;
Financial Fraud & Deception: Ponzi schemes, unauthorized pyramid selling, high-yield investment programs (HYIP), or advance-fee scams;
Anonymizing & Mixing Services: Cryptocurrency privacy tumblers, obfuscation protocols, or unhosted money-pooling smart contracts intended to conceal source of funds;
Deceptive Billing Traps: Negative option billing, disguised autorenewals, forced bundled charges, or merchants who fail to provide prominent cancellation mechanisms;
Controlled Substances: Unlicensed sale of prescription drugs, regulated pharmaceuticals, or prohibited narcotics.
Identity Verification

5. Tiered Customer Due Diligence (KYC) & Merchant Verification (KYB)

SubScript employs a multi-tiered verification structure to balance permissionless Web3 developer innovation with rigorous institutional compliance.

Tier 0 (Standard Developer / Subscriber): Permissionless access to standard subscription routing, testnet sandbox development, and baseline monthly transaction volumes with standard rate limiting;
Tier 1 (Verified Merchant Badge): Requires completion of business verification (KYB) through our licensed identity partner portal. Confirms business incorporation, legal representative identity, and domain ownership. Unlocks the public Verified Merchant Badge on hosted checkout pages;
Tier 2 (Enterprise & Custom Limits): Requires enhanced due diligence (EDD), source-of-wealth attestation, and custom risk assessment. Unlocks customized sponsorship quotas, elevated API rate multipliers, and dedicated fiat on-ramp settlement rails;
Data Protection in KYC: SubScript does not store raw identity documents, passport scans, or biometric selfies on our servers. All identity evidence is captured directly by our SOC2 Type II-certified identity partner.
Consumer Protection

6. Consumer Protection & FTC Click-to-Cancel Compliance

SubScript is engineered to solve the historical problems of recurring subscription abuse, hidden charges, and deliberate cancellation friction.

FTC 'Click-to-Cancel' Rule Compliance: Cancelling a recurring subscription on SubScript requires no more clicks or effort than signing up. Subscribers can cancel directly from their dashboard with a single confirmation.
Immediate Smart Contract Revocation: Cancelling immediately revokes the underlying on-chain spend allowance. Neither the merchant nor automated protocol keepers can charge the subscriber once cancelled.
California Automatic Renewal Law (SB-313 / AB-390): Clear and conspicuous disclosure of renewal terms, billing frequencies, and amounts is presented on every hosted checkout page prior to purchase.
Advance Renewal Notifications: SubScript's automated notification engine dispatches advance reminder emails before upcoming subscription renewals to ensure complete consumer transparency.
Tax Compliance

7. Tax Compliance & Merchant of Record (MoR) Boundaries

Clear legal and operational division of indirect tax calculation, reporting, and statutory remittance.

Merchant as Sole Seller: The merchant is the sole seller and legal Merchant of Record for all goods and services sold via SubScript checkout pages and payment links.
Indirect Taxes (Sales Tax, VAT, GST): Merchants are strictly responsible for determining, calculating, collecting, reporting, and remitting all indirect taxes (including U.S. State Sales Tax, EU Value-Added Tax, UK VAT, and GST) to the competent tax authorities in jurisdictions where their customers are situated.
Digital Asset Reporting (IRS Form 1099-DA & DAC8): As an unhosted software protocol, SubScript does not provide tax advice or issue individualized tax forms unless explicitly required under applicable broker regulations.
Law Enforcement

8. Law Enforcement & Subpoena Processing Guidelines

SubScript cooperates with domestic and international law enforcement agencies conducting bona fide criminal investigations.

Official Request Submission: All legal process, formal subpoenas, court orders, and government inquiries must be submitted directly to our legal desk at compliance@subscriptonarc.com with official agency credentials and case identifiers.
Immutable Blockchain Records vs. Off-Chain Metadata: Law enforcement agencies are reminded that SubScript cannot alter, freeze, or delete transactions on public blockchain networks (Arc Network, Ethereum, Solana). All on-chain transfers are permanently recorded on the public distributed ledger.
Off-Chain Disclosures: SubScript will disclose available off-chain account metadata (linked email addresses, IP-derived geography, verification case status, and timestamp logs) only in response to valid, legally enforceable court orders, search warrants, or binding statutory directives.

Regulatory & Law Enforcement Inquiries

Dedicated confidential channels for regulators and authorized agencies.

SubScript strictly respects legal process and cooperates with valid regulatory inquiries. Subpoenas, court orders, and law enforcement requests must be sent from verified agency domains to our compliance team.

Email Compliance Deskcompliance@subscriptonarc.com · PGP Available Upon Request
© 2026 SubScript Protocol. All rights reserved.
Terms of ServicePrivacy PolicyRefund PolicyFulfillment PolicyComplianceSupport