1.Introduction & Scope
Lumiria LLC (“securepayAPI,” “we,” “us”) is committed to preventing the use of its payment services for money laundering, terrorist financing, sanctions evasion, fraud, and other financial crime. This Anti-Money Laundering & Sanctions Policy (the “Policy”) summarises the compliance framework we maintain and the obligations that apply to every Merchant, Representative, beneficial owner, and user of the Services.
This Policy forms part of, and should be read together with, your Terms of Service, our Acceptable Use Policy, our Restricted Businesses list, and our Privacy Policy. Because we operate through regulated banking partners and the card networks, our program is also designed to satisfy their requirements.
2.Legal & Regulatory Framework
We design our program to comply with applicable anti-money-laundering (“AML”) and counter-terrorist-financing (“CFT”) laws and the rules of our partners, including, as applicable:
- the U.S. Bank Secrecy Act (BSA), as amended by the USA PATRIOT Act and the Anti-Money Laundering Act of 2020;
- regulations and guidance issued by the Financial Crimes Enforcement Network (FinCEN);
- economic and trade sanctions administered by the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC), and applicable United Nations, European Union, and United Kingdom sanctions regimes;
- the operating rules of the card networks (Visa, Mastercard, American Express, Discover, JCB, UnionPay) and the AML/KYC requirements of our sponsoring banks and acquiring partners;
- the recommendations of the Financial Action Task Force (FATF) on which much national AML legislation is based;
- other applicable financial-crime, sanctions, and recordkeeping laws of the jurisdictions in which we and our Merchants operate.
3.Our AML/CFT Program
We maintain a written, risk-based AML/CFT program reasonably designed to detect and prevent financial crime. Its core pillars are:
- Designated compliance function — a responsible officer (and supporting team) accountable for the program, with the authority and resources to carry it out;
- Internal policies, procedures & controls — documented, risk-based controls governing onboarding, screening, monitoring, escalation, and reporting;
- Customer due diligence — identity, business, and beneficial-ownership verification at onboarding and on an ongoing basis (Sections 4–5);
- Sanctions & watchlist screening — screening of customers and relevant parties against sanctions, PEP, and adverse-media lists (Section 6);
- Ongoing monitoring — automated and manual surveillance of transactions and behaviour to detect anomalies (Section 7);
- Reporting & escalation — investigation of alerts and, where warranted, filing of suspicious-activity reports with the relevant authorities (Section 8);
- Training & independent testing — staff training and periodic independent review of the program (Section 12);
- Recordkeeping — retention of due-diligence and transaction records for the periods required by law (Section 11).
4.Customer Due Diligence (KYC & KYB)
Before activating an account, and on a periodic and event-driven basis afterwards, we verify who our customers are and understand the nature of their business. We will not accept a customer who cannot or will not provide the information we require. Depending on the Merchant's legal form, jurisdiction, and risk, we collect and verify:
- Know Your Customer (KYC) — the identity of the individual representatives, beneficial owners, and control persons, including name, date of birth, and a government-issued identity document, verified through our identity-verification provider (Sumsub), which may include document authentication and a liveness/selfie check;
- Know Your Business (KYB) — the legal entity type, registered legal name, business registration number, tax identification number (e.g. EIN/VAT), registered address, website, and a description of the products or services sold;
- Beneficial ownership — the identity of natural persons who ultimately own or control 25% or more of the entity (and, for higher-risk relationships, a lower threshold of 10%), and of persons with significant responsibility to manage or direct it;
- Supporting documentation — registration certificates, tax documents, ownership declarations, bank statements, proof of address, and similar records appropriate to the entity type;
- Source & purpose — sufficient information to understand the intended purpose of the account and the expected nature and volume of activity.
We may re-verify this information at any time, and we may request updated documents when an account's activity, ownership, or risk profile changes. Verification decisions are made by our compliance team; submission of documents does not by itself guarantee approval.
5.Enhanced Due Diligence & High-Risk Customers
Where a customer, transaction, or relationship presents a higher risk of money laundering or terrorist financing, we apply Enhanced Due Diligence (“EDD”) — additional measures that may include:
- obtaining and verifying additional identity, ownership, and source-of-funds or source-of-wealth information;
- seeking senior-management approval to establish or continue the relationship;
- applying more frequent reviews and closer transaction monitoring;
- imposing processing limits, reserves, or other risk-mitigating conditions.
Higher-risk indicators include, without limitation: politically exposed persons (PEPs) and their close associates; complex or opaque ownership structures; customers or counterparties connected to high-risk or sanctioned jurisdictions; cash-intensive or otherwise higher-risk business models; and patterns inconsistent with the stated business.
6.Sanctions, PEP & Watchlist Screening
We screen customers, their beneficial owners and representatives, and, where appropriate, related parties and transactions against applicable sanctions lists (including OFAC, UN, EU, and UK lists), politically exposed person (PEP) lists, and adverse-media and watchlist sources, at onboarding and on an ongoing basis as those lists are updated.
- We do not establish or maintain relationships with individuals or entities that are subject to applicable sanctions, or that are owned 50% or more, directly or indirectly, by one or more blocked persons (the OFAC 50 Percent Rule).
- We do not facilitate transactions that are prohibited by, or designed to evade, applicable sanctions, and we restrict access from comprehensively sanctioned or embargoed jurisdictions.
- A confirmed sanctions match may result in immediate suspension of the account, the freezing or blocking of funds where required by law, and reporting to, or escalation to, the relevant authority or responsible financial institution.
Geographic and sanctions-related restrictions are described further in our Restricted Businesses list.
7.Ongoing Monitoring & Transaction Surveillance
We monitor activity across the platform on a risk-based basis to identify behaviour that may indicate money laundering, terrorist financing, fraud, or other prohibited use. This includes automated systems — including rules-based controls and machine-learning models — together with human review, used to detect risk indicators, fraud metrics, and anomalous patterns, and to verify, where relevant, the origin of funds.
- monitoring for unusual volumes, velocities, structuring, layering, or transactions inconsistent with a Merchant's expected profile;
- monitoring for indicators of card testing, unauthorised use of payment credentials, or transaction laundering (processing a third party's sales through your account);
- generating and investigating alerts, and escalating to compliance for review and, where warranted, reporting.
To support monitoring and investigations, we may request additional information or documentation at any time, and we may hold, delay, or decline transactions while a review is in progress.
8.Suspicious Activity Reporting
We maintain a reporting-responsibility framework that allocates, between us and our regulated financial partners, who is responsible for filing reports with the authorities. Where we are directly subject to suspicious-activity reporting rules for a given activity, we will file a Suspicious Activity Report (SAR) within the required timelines. Where a sponsoring bank, acquirer, processor, or other responsible financial institution owns the filing obligation, we document our analysis and promptly escalate the matter, with the supporting evidence, to that institution. We may also make voluntary referrals to law enforcement where appropriate and lawful, and we will take any further action required by law.
9.Risk Appetite & Prohibited Activities
We maintain a risk appetite that defines the customers and activities we are unwilling to support. We will not knowingly establish or maintain a relationship that we are unable to bring within our compliance and risk controls. We prohibit, among other things:
- money laundering, terrorist or proliferation financing, and any attempt to disguise the origin, ownership, or destination of funds;
- transactions involving sanctioned persons, entities, or jurisdictions, or any attempt to evade sanctions;
- processing on behalf of an undisclosed third party, aggregating or factoring others' transactions, or transaction laundering;
- use of the Services in connection with the prohibited or restricted activities set out in our Restricted Businesses list;
- providing false, manipulated, or incomplete identity, business, ownership, or source-of-funds information.
10.Merchant Obligations
To use the Services, you must:
- provide accurate, complete, and current information about your business, representatives, and beneficial owners at onboarding and on an ongoing basis, and promptly notify us of material changes (including changes in ownership, control, sales channels, products, or volumes);
- respond promptly and in good faith to our requests for KYC, KYB, source-of-funds, beneficial-ownership, licensing, or other due-diligence documentation;
- maintain your own appropriate, risk-based compliance controls where you are subject to AML, sanctions, or related obligations;
- not use the Services to facilitate money laundering, terrorist financing, sanctions evasion, fraud, or any activity prohibited by this Policy, the Terms, or applicable law;
- cooperate with our banking partners, the card networks, auditors, regulators, and law-enforcement agencies in connection with any matter involving your account, and preserve relevant records.
11.Recordkeeping & Retention
We retain customer due-diligence records (including identity and business-verification documents and, where applicable, biometric identifiers), transaction records, screening results, and investigation files for the periods required by applicable law and our banking partners — typically at least five (5) years following the end of the customer relationship or the date of the relevant transaction, and longer where a law, regulator, or legal hold requires it. Retention of personal data is described in our Privacy Policy.
12.Governance, Training & Independent Testing
Senior management is responsible for fostering a culture of compliance and for providing the compliance function with sufficient authority and resources. We provide AML, sanctions, and fraud-awareness training to relevant personnel appropriate to their roles, and we subject the program to periodic independent testing or review to assess its design and effectiveness and to drive remediation where gaps are identified.
13.Enforcement & Consequences
If we determine, in our reasonable discretion, that you have violated this Policy or that continuing a relationship would present unacceptable financial-crime risk, we may take any one or more of the following actions, with or without prior notice depending on the severity and legal constraints of the matter:
- request clarification, remediation, or additional information;
- apply processing limits, reserves, or enhanced monitoring;
- hold, delay, decline, freeze, or reverse transactions or settlement funds;
- suspend or terminate your account in accordance with the Terms;
- block or remit funds where required by law, court order, or banking-partner instruction;
- report or escalate the conduct to our banking partners and the card networks, and — directly or through the responsible financial institution — to regulators (such as FinCEN or OFAC) or law-enforcement agencies, as legally required.
Failure to enforce any provision of this Policy is not a waiver of our right to enforce it later.
14.Updates to this Policy
We may update this Policy from time to time to reflect changes in law, regulation, network or banking-partner requirements, or our practices. Material changes will be communicated through the dashboard or by email where appropriate. The “Last updated” date at the top of this page reflects the most recent version.
15.Contact
For questions about this Policy or our compliance program, contact:
Lumiria LLC d/b/a securepayAPI
1451 Richardson Rd. Ste. 109 #127, Apex, NC 27523, USA
Compliance: compliance@securepayapi.com
Legal: legal@securepayapi.com
Phone: +1 844 680 0679