> For the complete documentation index, see [llms.txt](https://docs.itradingbot.net/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.itradingbot.net/en/company/aml-policy.md).

# AML Policy

ANTI-MONEY LAUNDERING, COUNTER-TERRORIST FINANCING AND SANCTIONS POLICY OF ITRADINGBOT LIMITED. Version 2.1, 13.09.2026.

### 1. INTRODUCTION

1.1. This Anti-Money Laundering, Counter-Terrorist Financing and Sanctions Policy (the "Policy") sets out how ITradingBot Limited (the "Company") prevents the use of its platform for money laundering, terrorist financing and the evasion of sanctions. The Policy is written to describe what the Company actually does. It is deliberately proportionate to the Company's size (a small remote team led by a sole director) and to the nature of its business, in which the Company never holds customers' assets.

1.2. The Policy has regard to:

● the Anti-Money Laundering and Countering the Financing of Terrorism Act, 2020 of Seychelles and the Regulations made under it;\
● the Prevention of Terrorism Act and the Beneficial Ownership Act, 2020 of Seychelles;\
● sanctions resolutions of the United Nations Security Council as implemented in Seychelles, and the sanctions programmes of the European Union, the United Kingdom and the United States Office of Foreign Assets Control (OFAC);\
● the Financial Action Task Force (FATF) Recommendations, including Recommendation 15 on virtual assets;\
● guidance of the Seychelles Financial Intelligence Unit (FIU) and Financial Services Authority (FSA), to the extent applicable to the Company.

1.3. The Policy was first adopted on 2 September 2024 (as "AML/CFT Guidelines"), amended on 10 September 2026 (Amendment No. 1 — Exchange Account Services) and re-issued in this form by written resolution of the sole director dated 13.09.2026. It is reviewed at least once a year and whenever the Company's business, the applicable law or the requirements of an exchange partner change materially.

### 2. THE COMPANY'S BUSINESS AND WHERE THE RISK IS

2.1. The Company operates a software-as-a-service platform for algorithmic trading (the "Platform"). Customers are natural persons trading their own funds; the Company does not accept legal entities, trustees or persons trading on behalf of others (Terms of Service, Section 2.6), and does not accept politically exposed persons (Section 2.4).

2.2. Customers use the Platform in one of two modes:

● **API Connection Mode** — the Customer connects his or her own account with a third-party exchange (Binance or Bybit) through API keys the Customer creates and controls. The Company never holds, receives or moves the Customer's assets and cannot withdraw them. The exchange has verified the Customer under its own programme. Customer due diligence by the Company in this mode is limited to the registration data described in Section 5.1;\
● **Exchange Account Mode** — the Company provides the Customer with technical access to a trading sub-account ("Exchange Account") opened under the Company's master account with Bybit Technology Limited ("Bybit") under the Bybit Exchange Broker Program. The Customer's assets are held by Bybit. The Company operates no wallets, addresses or private keys of its own; it uses Bybit's API to open sub-accounts and to execute the Customer's transfer and withdrawal instructions. The Company does not manage assets on a discretionary basis.

2.3. Money-laundering and sanctions risk therefore arises almost entirely in Exchange Account Mode, at three points: (a) who the Customer is; (b) where deposits come from; (c) where withdrawals go. The Company controls point (a) itself (Sections 5–7). Points (b) and (c) are controlled by Bybit, which holds the assets, screens deposits and withdrawals and monitors activity under its own compliance programme; the Company's role at those points is to cooperate with Bybit (Section 8).

2.4. The Company does not run its own transaction-monitoring system, blockchain analytics or address screening, and does not set numerical thresholds for enhanced due diligence. This Policy does not claim otherwise.

### 3. GOVERNANCE

3.1. **Responsible person.** The sole director of the Company is the Money Laundering Reporting Officer (MLRO) and Compliance Officer, appointed by written resolution of the sole director dated 13 September 2026. The MLRO is responsible for this Policy, for customer due diligence decisions that are not fully automated, for the registers in Section 10, for cooperation with Bybit and for any report to the FIU.

3.2. **Team.** The Company has no separate compliance department. Team members who handle customer support or the Exchange Account administration tools (the "Team") must know this Policy, must escalate to the MLRO anything that looks unusual (Section 9) and may not tell a Customer that an escalation or a Bybit request has been made where that is prohibited by law.

3.3. **Third-party verification provider.** Identity verification is performed through Didit Identity, Inc. ("Didit" or the "Provider") under Didit's Data Processing Addendum; Didit's verification infrastructure is hosted on AWS servers in the European Union. Verifications performed before the change of provider were performed through Sum and Substance Ltd (Sumsub). The Provider performs document authenticity checks, biometric matching of a selfie/liveness video to the document, an age check from the document, IP-location and device checks, and automated screening of the Customer's name, date of birth and country against sanctions lists (including the United Nations, European Union, United Kingdom and OFAC lists), politically-exposed-person lists and adverse media, as maintained by the Provider. Screening is performed at each verification; the Company has not enabled the Provider's ongoing re-screening of verified Customers and re-screens a Customer only when re-verification occurs under Section 5.5. The Company relies on the Provider for the checks listed above and reviews the Provider's results; it does not perform them manually. In the Provider's console the Company has set the retention period for verification data to 10 years (Section 10.2), keeps the retention of biometric templates after session deletion switched off, and has withdrawn the Provider's permission to use the Company's verification data for training or improving its models (organisation setting disabled on 13 September 2026).

3.4. **Annual review and training.** Once a year the MLRO reviews this Policy, the Restricted Jurisdictions List (Annex A), the Provider's settings and the registers, and records the review. Once a year the MLRO briefs the Team on this Policy and records who attended. No other training programme is claimed.

### 4. RISK-BASED APPROACH

4.1. The Company applies its measures according to risk. The main risk factors it considers are:

● **Customer:** country of issue of the identity document, IP location and device signals at verification, any residence information provided, the results of the Provider's sanctions, politically-exposed-person and adverse-media screening, the Customer's representations on sanctions and politically-exposed-person status, inconsistencies between the data provided and the document;\
● **Product:** Exchange Account Mode carries the risk; API Connection Mode carries little, because the Company never controls assets;\
● **Geography:** the Restricted Jurisdictions List (Annex A), the FATF lists of high-risk and monitored jurisdictions, and jurisdictions restricted by Bybit;\
● **Behaviour:** requests from Bybit concerning a Customer, refusals to provide requested information, use of multiple accounts, attempts to use the platform from restricted jurisdictions.

4.2. Customers who are Restricted Persons (Annex A), politically exposed persons or subjects of sanctions are not accepted for Exchange Account Mode. Other Customers are accepted after standard due diligence (Section 5). Enhanced due diligence (Section 6) is applied when a trigger occurs, not on a fixed schedule.

### 5. CUSTOMER DUE DILIGENCE

5.1. **All Customers (both modes).** On registration the Company records the Customer's e-mail address and/or Telegram identifier, the IP address and the acceptance of the Terms of Service. The IP address is used as a risk factor under Section 4.1. The Customer confirms in the Terms that he or she is at least 18, is not a Restricted Person, is not sanctioned and is not a politically exposed person.

5.2. **Before an Exchange Account is provisioned (Exchange Account Mode).** No Exchange Account is opened until the Customer has completed identity verification through the Provider with an "approved" result. Verification comprises:

● a government-issued identity document (passport, national identity card or residence permit), checked for authenticity;\
● a selfie or liveness video matched to the document;\
● date of birth (the Customer must be at least 18), nationality and country of issue of the document and, where the document contains it, residential address;\
● IP-location and device checks. A session initiated from a location in Part A.2 of Annex A is declined automatically, and a document issued by a jurisdiction in Part A.1 of Annex A is not accepted;\
● automated screening against sanctions lists (including the United Nations, European Union, United Kingdom and OFAC lists), politically-exposed-person lists and adverse media, as maintained by the Provider.

5.3. **Automated results and human review.** An "approved" result with no screening hit is accepted automatically. Any "declined" or "needs review" result, and any screening hit, is reviewed by the MLRO or a Team member designated by the MLRO before the Company refuses service; the Customer may contest a refusal and provide further documents. A confirmed sanctions match, a confirmed PEP status or a document from a Restricted Jurisdiction (Annex A) leads to refusal. The Company records the reason for every refusal.

5.4. **What is not done.** The Company does not collect proof of address as a standard step, does not obtain information on the Customer's occupation, expected volume or source of wealth at onboarding, and does not identify beneficial owners, because Customers are natural persons trading their own funds and the Company holds no assets. Such information is collected only under Section 6.

5.5. **Re-verification.** The Company asks a Customer to verify again when the identity document has expired and the Customer requests a withdrawal or a new Exchange Account, when the MLRO has reason to doubt the earlier verification, when access to authentication factors has been lost and the Customer asks for access to be restored, or when Bybit requires it.

### 6. ENHANCED DUE DILIGENCE

6.1. Enhanced due diligence is applied where:

● Bybit requests information or documents concerning a Customer, a deposit, a withdrawal or an Exchange Account;\
● the Provider's screening returns a politically-exposed-person, sanctions or adverse-media hit that is not clearly a false positive, or the Company otherwise becomes aware, from Bybit, from a public source or from the Customer, that the Customer may be a politically exposed person, a subject of sanctions or the subject of adverse information;\
● the Customer's document, any residence information and IP location are inconsistent with each other in a way that suggests a Restricted Jurisdiction;\
● a Team member escalates a Customer under Section 9 and the MLRO decides that the concern is substantiated.

6.2. Enhanced due diligence consists of collecting from the Customer, as relevant, an explanation and documents on the source of the funds deposited (for example exchange or bank statements, sale contracts, payslips), proof of residence, and any other information Bybit has asked for, and of the MLRO's documented decision to continue, restrict or end the relationship. The Company transmits the material to Bybit where Bybit requires it.

6.3. Until enhanced due diligence is completed the Company may keep the Exchange Account in withdrawal-only mode or, where Bybit has imposed a restriction, leave the restriction in place. The Company does not itself freeze assets; only Bybit can do so.

### 7. SANCTIONS AND RESTRICTED JURISDICTIONS

7.1. The Company does not provide Exchange Account Mode to, and ends the relationship with, any person who is a subject of United Nations, European Union, United Kingdom or OFAC sanctions, and does not provide the Platform to Restricted Persons as defined in Section 2.2 of the Terms of Service and Annex A of this Policy. The Company applies the restriction through the Provider's document-country and IP-location rules (Annex A, Parts A.1 and A.2) and sanctions screening (Section 5.2), through the Customer's representations in the Terms of Service, and through review of any residence information the Customer provides.

7.2. Where a sanctions match is confirmed after an Exchange Account has been opened, the MLRO suspends the Customer's access, informs Bybit by e-mail within one business day, follows Bybit's instructions on the assets, records the case in the incident register and, where required by Seychelles law, reports to the FIU. The Customer is not informed of a sanctions-related report where that is prohibited.

7.3. Annex A is maintained by the MLRO. Changes apply to Exchange Account Mode immediately and are published on this page.

### 8. COOPERATION WITH BYBIT

8.1. Under the Broker Agreement between the Company and Bybit, the Company is responsible for verifying its Customers (Sections 5–7) and for cooperating with Bybit; Bybit screens deposits and withdrawals, monitors activity on sub-accounts and may freeze funds or a sub-account.

8.2. When Bybit contacts the Company about a Customer, a deposit, a withdrawal or an Exchange Account, the MLRO: records the request; informs the Customer where legally permitted and asks for the information or documents required; transmits them to Bybit; records the outcome (release, continued restriction or closure); and, where Bybit requires it, stops the Customer's access to the Exchange Account. Compliance communications with Bybit are sent only by the MLRO or the director, by e-mail, and are retained with the Customer's records.

8.3. The Company does not initiate transfers or withdrawals from an Exchange Account except on the Customer's instruction, on Bybit's or a competent authority's binding requirement, or in the single case of Section 17.2 of the Terms of Service. Every transfer and withdrawal executed with the Company's master API access is recorded together with the identity of the instructing Customer.

### 9. ESCALATION, SUSPICION AND REPORTING

9.1. Any Team member who notices something unusual — for example a Customer asking to withdraw to an address that does not belong to him or her, several Customers sharing documents or devices, a Customer refusing to answer Bybit's questions, or any indication of use of the Platform by a third party — reports it to the MLRO by internal message the same day. The MLRO records the escalation in the suspicion register with the date, the facts and the decision taken.

9.2. Where, after review, the MLRO knows or suspects that funds on an Exchange Account are the proceeds of crime or connected with terrorist financing, the MLRO files a report with the Seychelles Financial Intelligence Unit where the Company is required to do so under the Anti-Money Laundering and Countering the Financing of Terrorism Act, 2020, and may file a report voluntarily in other cases. The MLRO also informs Bybit, which holds the assets. Reports and the underlying analysis are kept in the suspicion register. Nobody may inform the Customer that a report has been made or is being considered.

9.3. The Company has not to date filed a report with the FIU and does not represent that it has an established relationship with the FIU.

### 10. RECORDS

10.1. The Company keeps, for at least seven (7) years after the end of the business relationship or the date of the last transaction, whichever is later:

● the identity-verification result and the data and document images returned by the Provider, and the Company's review decision;\
● the link between each Exchange Account (sub-account identifier) and the verified Customer;\
● the Customer's deposit, transfer and withdrawal requests as recorded by the Platform, with the authentication used and the result;\
● correspondence with Bybit under Section 8;\
● the registers: incident register, suspicion register, complaints register, and the annual review and training records under Section 3.4.

10.2. Records are stored on the Company's servers and with the Provider under the safeguards described in the Privacy Policy and are made available to competent authorities where the law requires. The Provider's retention period for verification data is configured at 10 years from the verification, the shortest setting available that covers the seven-year period in Section 10.1; biometric templates are deleted by the Provider together with the verification session and are not retained separately.

### 11. REFUSAL, SUSPENSION AND TERMINATION

11.1. The Company refuses to open an Exchange Account, or suspends or closes an existing one, where verification cannot be completed, where the Customer is a Restricted Person, a politically exposed person or a subject of sanctions, where the Customer refuses to provide information requested under Section 6, or where Bybit requires it.

11.2. On suspension or termination the Exchange Account is kept in withdrawal-only mode for at least thirty (30) days in accordance with Section 1A.8 of the Terms of Service, unless applicable law, a competent authority or a restriction imposed by Bybit prevents withdrawals, in which case the assets remain with Bybit pending resolution. The Company never appropriates a Customer's assets.

### 12. CONFLICTS OF INTEREST AND CONFIDENTIALITY

12.1. The MLRO's decisions under this Policy are taken in the interest of compliance, not of revenue. Where a decision concerns a Customer with whom a Team member has a personal relationship, that Team member takes no part in it.

12.2. Information obtained under this Policy is used only for the purposes of this Policy and the Privacy Policy and is disclosed only to the Provider, to Bybit under Section 8, to the Company's professional advisers and to competent authorities.

### ANNEX A — RESTRICTED JURISDICTIONS LIST

This list is incorporated by reference into Section 2.2 of the Terms of Service and is the single list used by the Company for all Services. Parts A.1 and A.2 are enforced automatically by the Provider in the Company's verification workflow; Part A.3 is enforced through the Customer's representations and review.

**A.1 Identity documents not accepted (verification declined):** Abkhazia; Canada; Cuba; Democratic Republic of Congo; the so-called "Donetsk People's Republic" and "Luhansk People's Republic"; Iran; Iraq; Kosovo; Malaysia; Myanmar; Netherlands; Democratic People's Republic of Korea; Somaliland; Sovereign Military Order of Malta; Sudan; South Sudan; Syria; Transnistria; United States of America (including its territories); Zimbabwe.

**A.2 Verification sessions from these locations declined (IP location):** every jurisdiction in Part A.1, and in addition mainland China, Hong Kong, Singapore and Uzbekistan. Documents of these four countries are accepted where the Customer is located elsewhere; the restriction follows Bybit's rules on the location of users.

**A.3 Restricted Persons by representation and review:** (a) residents of any jurisdiction in Part A.1, and persons located in any jurisdiction in Part A.2 while using Exchange Account Services, whatever identity document they hold; (b) nationals of the United States of America, Iran and the Democratic People's Republic of Korea regardless of residence; (c) persons resident in the territories of Ukraine temporarily occupied by the Russian Federation, including the Autonomous Republic of Crimea, the city of Sevastopol and the occupied parts of the Donetsk, Luhansk, Kherson and Zaporizhzhia regions — the Provider cannot identify these territories automatically, so the Company identifies them from the place of issue or the address in the document and from information provided by the Customer, and refers such cases to review; (d) persons subject to sanctions (Section 7).

**A.4** In addition, for Exchange Account Mode, persons resident in or nationals of any jurisdiction that Bybit does not serve under its own terms are not accepted.

Last updated: 13.09.2026.

### ANNEX B — REGISTERS KEPT BY THE MLRO

Incident register (security incidents, Bybit freezes and requests, sanctions matches); suspicion register (escalations under Section 9 and any FIU reports); complaints register (complaints under Section 23.2 of the Terms of Service); annual review and training record.
