Policies, procedures and evidence describing how XIP handles personal data, prevents money laundering and the financing of terrorism, and verifies the identity of its users. Published for consultation by users, partners and authorities.
Categories of data processed, purposes and legal bases, sharing, retention periods, security measures and the data subject request channel.
POL-02Operating model, governance, risk-based approach, screening, monitoring, transaction records, reporting to authorities and record retention.
POL-03Required data and documents, verification flow, record states, transaction eligibility, EDD triggers, re-profiling and refusal.
EVD-01Table schemas, masked illustrative records, audit trail, evidence of the transaction block, and the masking rules applied.
DES-01Layer architecture, endpoints, application screens, pipeline security controls and a video walkthrough of the onboarding process.