Legal/Compliance Statement
Legal

Compliance Statement

StableOps' compliance boundary, non-custodial posture, and operational control commitments.

Last updated: 2026-07-04
Non-custodial boundary
  • StableOps monitors blockchain events and routes operational webhooks. It does not hold customer assets, control private keys, pool funds, settle fiat, or execute payouts.
  • Customers remain the merchant of record or payment operator for their own products and are responsible for wallet governance and user-facing disclosures.
Risk controls
  • The platform supports audit logs, scoped API keys, webhook signing, secret rotation, event idempotency, replay protection, confirmation thresholds, blockchain reorganization detection, tenant isolation, and operational event history.
  • Enterprise deployments can integrate customer-selected KYT, sanctions screening, retention, and export workflows as contractual controls.
Shared responsibility
  • StableOps is responsible for platform availability, infrastructure security, and payment-event processing.
  • Customers are responsible for wallets and private keys, order fulfillment, accounting, and regulatory compliance in the jurisdictions where they operate.
Scope of this statement
  • This page is a product-facing statement of StableOps' compliance posture and the controls available on the platform. It describes how the service is designed to operate, not the obligations of any individual customer.
  • It is not legal advice and not a substitute for customer-specific compliance review. Customers should evaluate their own regulatory, sanctions, tax, and data protection obligations for the jurisdictions in which they operate.
  • Nothing in this statement should be interpreted as certification, regulatory approval, legal opinion, or a representation that use of the platform alone satisfies applicable regulatory requirements.
Sanctions and AML posture
  • StableOps is a non-custodial payment event infrastructure platform and is not a regulated AML or compliance service provider.
  • Sanctions screening, KYT, transaction monitoring, and other risk analysis capabilities are available through the platform, whether provided by StableOps or third-party providers, where supported by plan or enterprise agreement. These are configurable operational controls, not compliance determinations made by StableOps.
  • These capabilities do not replace a customer's legal or regulatory obligations, nor do they determine whether a transaction should ultimately be accepted, rejected, refunded, or reported.
  • Customers operating regulated payment activities remain solely responsible for establishing and maintaining their own KYC, KYT, AML, sanctions compliance, reporting, and other regulatory programs applicable to their jurisdictions.
  • We prohibit use of the platform by or on behalf of sanctioned persons, entities, or jurisdictions, and reserve the right to suspend access where credible evidence of abuse, fraud, security threats, or legal risk arises.
Prohibited businesses and activities
  • The platform may not be used for mixers or tumblers, ransomware, darknet markets, fraud, unlicensed money transmission, or any activity prohibited by the terms of service.
  • Customers in higher-risk categories may be required to provide additional disclosures or contractual controls before production access.
Data residency and infrastructure
  • Event ingestion, confirmations, and webhook delivery run on infrastructure scoped by (organization, environment, chain, address) so tenant data stays isolated.
  • Enterprise deployments can negotiate region, retention, export, and sub-processor terms; default infrastructure regions are documented during onboarding.
Incident response and disclosure
  • We monitor service health with metrics and error reporting, and investigate security or availability incidents through an internal response process.
  • Where an incident materially affects customer data or payment-event processing, we aim to notify affected customers and coordinate remediation per applicable law and contract terms.
  • Operational audit records are retained according to the customer's plan and may be exported where supported.
Compliance contact
  • For compliance, sanctions, or security questions, contact [email protected].
  • Responsible disclosure of suspected vulnerabilities is welcome; please avoid testing that disrupts other tenants or accesses data you are not authorized to view.