AML, CFT, and Sanctions Policy
IMPORTANT: This Policy describes risk-based controls. It does not represent that HedgeCore is a bank, custodian, exchange, money transmitter, money services business, virtual asset service provider, or other regulated financial institution.
Key Disclosures
- HedgeCore is a technology platform. HedgeCore does not itself generate trading signals, select trades, place orders, manage portfolios, provide personalized investment advice, or act as a fiduciary for Users.
- Your Trading Assets remain at Bybit. HedgeCore does not accept, hold, safeguard, transfer, or withdraw those assets. The Platform accepts only a limited API Credential and rejects any credential with withdrawal, transfer, or other prohibited permissions.
- Subscription Fees are paid directly to HedgeCore in supported cryptocurrency as payment for HedgeCore services. HedgeCore does not maintain a User deposit account, wallet balance, prepaid balance, or service-credit balance.
- Users must maintain a Bybit account that satisfies Bybit identity-verification requirements. HedgeCore does not routinely collect identity documents from every User, but may request additional information in response to a documented legal, sanctions, fraud, security, payment, or referral risk.
- HedgeCore may reject, restrict, suspend, block, withhold, or report activity where required by law or reasonably necessary to address sanctions or financial-crime risk.
1. Purpose, Scope, and Status
1.1 Purpose
This Anti-Money Laundering, Counter-Terrorist Financing, Sanctions and Financial Crime Policy (the "Policy") describes the risk-based controls used by HedgeCore Inc. ("HedgeCore", "Company", "we", "us", or "our") to reduce the risk that the HedgeCore platform is used for money laundering, terrorist financing, sanctions evasion, fraud, theft, market abuse, or other unlawful activity.
This Policy applies to Users, referral participants, Strategy Providers, payment and payout activity, personnel, contractors, and other persons who access, support, or interact with the Platform. It should be read with the Terms of Use and Privacy Policy.
1.2 Regulatory Status
HedgeCore maintains this Policy because it is a U.S. company operating technology that involves cryptocurrency payments, exchange API connections, and referral payouts. Maintaining these controls is not an admission that HedgeCore is a covered financial institution, money services business, money transmitter, exchange, custodian, broker, adviser, or virtual asset service provider under any particular law.
Legal classification depends on the facts, the jurisdictions involved, and applicable law. If the Platform, applicable law, or the Company's regulatory status changes, HedgeCore will update its controls and complete any registration, licensing, reporting, customer-due-diligence, or formal AML-program requirements that become applicable.
2. Platform Model and Risk Boundaries
2.1 Technology Platform
HedgeCore provides technical access to a catalogue of automated trading Strategies developed by independent Strategy Providers. A User independently selects a Strategy, creates and funds a Bybit account, submits a limited API Credential, and activates the connection. HedgeCore validates the credential and enables the technical connection, but does not originate, select, modify, or cancel trades and does not manage the User's portfolio.
2.2 No Custody or Transfer of Trading Assets
Trading Assets remain in the User's Bybit account or Connected account. HedgeCore does not accept, hold, safeguard, pool, lend, stake, invest, transfer, or withdraw those assets.
2.3 Direct Subscription Payments
Subscription Fees are paid directly to HedgeCore, or to a payment processor acting for HedgeCore, as payment for HedgeCore's own services.
3. Compliance Principles
- Risk-based and proportionate: controls are tailored to the Platform's actual products, users, counterparties, geographies, payment flows, and technical architecture.
- No routine blanket documentary KYC: HedgeCore uses Bybit account-verification indicators and other available information at onboarding and requests additional documents only where required by law or reasonably justified by a documented risk trigger.
- Data minimization: compliance information is limited to what is reasonably necessary for the relevant review and is handled under the Privacy Policy.
- No circumvention: Users may not evade Bybit restrictions, geographic controls, API-permission validation, sanctions controls, payment controls, or referral rules.
- Escalation and documentation: material alerts are reviewed, decisions are documented, and legally required blocking, rejection, reporting, or cooperation steps are taken.
4. User Onboarding and Eligibility Controls
4.1 Baseline Information
HedgeCore may collect and evaluate information available through the Platform and its integrations, including Account identifiers, email and Telegram information, Bybit UID, account type, KYC status or level, KYC region, API permission scope, IP address, device and session information, subscription-payment wallet, referral-payout wallet, blockchain transaction data, and referral relationships.
4.2 Bybit Verification
A User must maintain a valid Bybit account that has completed the identity-verification level required by Bybit for the relevant products. Verification performed by Bybit is conducted for Bybit's own purposes and is not identity verification performed by HedgeCore. HedgeCore may verify available Bybit account-status and eligibility indicators, but does not routinely obtain the identity documents submitted to Bybit.
4.3 Sanctions and Geographic Eligibility
HedgeCore may screen available User information, IP and geolocation indicators, Bybit KYC region, subscription-payment wallets, referral-payout wallets, Strategy Providers, and other relevant counterparties against sanctions lists, geographic restrictions, and risk indicators applicable to HedgeCore or the relevant activity. HedgeCore may use internal tools or qualified third-party providers for this purpose.
A User must not access the Platform from an excluded or prohibited jurisdiction, use a VPN, proxy, nominee, false address, third-party account, or other method to misrepresent location or eligibility, or cause HedgeCore to deal with a sanctioned or otherwise prohibited person.
4.4 Risk-Triggered Additional Due Diligence
HedgeCore may request additional information where required by law or reasonably necessary to resolve a sanctions, fraud, security, payment, referral, wallet-ownership, tax, or other documented risk concern. Depending on the circumstances, this may include:
- legal name, date of birth, nationality, country of residence, address, and contact information;
- government-issued identification or proof of address;
- evidence that a Bybit account, payment wallet, or payout wallet is owned or lawfully controlled by the User;
- source-of-funds or source-of-wealth information relating to a particular payment or risk event;
- for entities, formation documents, business purpose, directors, authorized representatives, and beneficial ownership information;
- tax forms or information required for Referral Commission reporting or withholding; and
- an explanation of unusual account, payment, referral, or geographic activity.
Failure to provide reasonably requested information may result in rejection, restriction, suspension, non-payment, or termination, subject to applicable law.
5. Monitoring, Review, and Actions
5.1 Scope of Monitoring
HedgeCore monitors Platform, payment, referral, API-validation, security, and eligibility information on a risk basis. HedgeCore does not represent that it performs comprehensive AML monitoring of all Bybit trading or of all activity in a User's exchange account.
5.2 Investigation and Escalation
HedgeCore may investigate an alert using available records, blockchain information, account metadata, technical logs, information requested from the User or Strategy Provider, and information from relevant service providers or public sources. Material matters may be escalated to the person responsible for compliance, senior management, legal counsel, a service provider, Bybit, or a competent authority, as appropriate.
5.3 Available Actions
Subject to applicable law, HedgeCore may:
- reject registration, a Subscription payment, API connection, Strategy activation, or Referral Commission payout;
- request additional information or verification;
- restrict or suspend an Account, Subscription, Strategy connection, or Referral Programme participation;
- disconnect a Strategy or require revocation and replacement of an API Credential;
- withhold, reverse, or cancel a Referral Commission affected by fraud, sanctions, an invalid payment, or breach;
- block or reject property or activity where required by sanctions law;
- preserve records and cooperate with lawful investigations; and
- report activity where legally required or otherwise permitted by applicable law.
HedgeCore may be unable to provide detailed reasons for a compliance action where disclosure is prohibited, could prejudice an investigation, or could undermine security or fraud controls.
6. Sanctions Compliance
HedgeCore is a U.S. person and is required to comply with applicable U.S. economic sanctions. HedgeCore also applies other sanctions and geographic restrictions where they are applicable to the Company, a User, a Strategy Provider, a service provider, or a transaction.
Controls may include sanctions-list screening, ownership and control review, IP and geolocation controls, Bybit KYC-region review, wallet-address screening, blockchain analytics, payment and payout review, risk-based re-screening, and investigation of red flags. The existence or absence of a wallet address on a sanctions list is not the only factor considered.
Where applicable law requires property to be blocked or a transaction to be rejected, HedgeCore will take the required action and make required reports. Blocked property cannot be returned, transferred, or otherwise dealt in unless authorized by the relevant authority or the legal prohibition ceases to apply.
7. Reporting and Cooperation
HedgeCore responds to valid court orders, subpoenas, regulatory requests, sanctions requirements, and other lawful process. HedgeCore may voluntarily provide information to law enforcement or another competent authority where permitted by law and reasonably believed necessary to prevent or address unlawful activity.
This Policy does not state that HedgeCore is subject to a Suspicious Activity Report filing obligation. If a reporting obligation applies to HedgeCore in a particular circumstance, HedgeCore will make the required report and will not disclose a legally protected report where disclosure is prohibited.
8. Records and Privacy
HedgeCore keeps records reasonably necessary to document eligibility checks, API-permission validation, subscription payments, referral payouts, sanctions reviews, investigations, compliance decisions, reports, and interactions with authorities. Retention is based on applicable law, tax and accounting requirements, security needs, dispute and legal-claim periods, and the Company's documented retention schedule.
Where U.S. sanctions recordkeeping rules apply, relevant records may be retained for the period required by those rules, which may be up to ten years. Other compliance records are not automatically subject to a ten-year period. Personal data is handled as described in the Privacy Policy and access is limited to authorized persons with a need to know.
9. Governance and Internal Controls
- Responsibility: HedgeCore designates a responsible person with authority to maintain sanctions and financial-crime controls and escalate material matters.
- Risk assessment: HedgeCore periodically reviews its users, products, payments, payouts, counterparties, geographies, technology, and legal environment and adjusts controls to identified risks.
- Policies and procedures: operational procedures support API validation, sanctions and wallet screening, investigations, escalation, recordkeeping, and incident response.
- Training: personnel whose roles involve payments, payouts, user support, security, or compliance receive proportionate, role-appropriate training.
- Testing and remediation: controls are periodically reviewed or tested in a manner proportionate to the Company's size and risk profile, and identified weaknesses are remediated.
10. User Responsibilities and Prohibited Conduct
A User must provide accurate information, use only accounts and wallets owned or lawfully controlled by the User, maintain a verified and eligible Bybit account, submit only a compliant trading-only API Credential, respond to lawful and reasonable compliance requests, and use the Platform only for lawful purposes.
Users must not use or attempt to use the Platform for money laundering, terrorist financing, sanctions evasion, fraud, theft, market manipulation, wash trading, spoofing, pump-and-dump activity, insider trading, tax evasion, unauthorized management of third-party assets, referral abuse, or any other unlawful activity.
11. Changes to This Policy
HedgeCore may update this Policy to reflect changes in the Platform, risk profile, law, sanctions programmes, regulatory guidance, or operational controls. Material changes will be communicated through the Platform, email, or another reasonable method before they take effect, unless earlier action is required for legal, sanctions, fraud-prevention, security, or technical reasons.
Contact
HedgeCore Inc.
Registered address: 8 The Green, Ste D, Dover, Delaware 19901, USA
Legal, privacy, and compliance enquiries: admin@hedgecore.ai