LEGAL · COMPLIANCE
This page describes how latchpay is regulated, who holds the funds, and what stays on your side of the line. Effective March 30, 2026.
latchpay, Inc. was founded in 2024, and we will be direct about what that means: we are partway through a state-by-state money-transmitter licensing program, not at the end of one. Where our license has been granted, we operate under it. Where an application is pending, we operate under sponsor-bank arrangements with regulated banking partners — the movement of funds happens under the partner institution's regulatory authority, subject to their oversight, examination, and program requirements.
Two things are true in every state, on every rail, regardless of which posture applies:
A current licensing matrix — which states are licensed, which are pending, which operate under sponsorship — is part of the due-diligence pack described under Audits & attestations.
We do not name our banking partners on a marketing page; names are available under NDA during diligence. What we will publish is the bar they have to clear. Every institution that holds customer funds or originates payments for latchpay must be:
Partners are reviewed annually against these requirements, and the reconciliation feed is the enforcement mechanism: a partner whose statements we cannot match line-by-line is a partner we are exiting. How that matching works is described on How it works.
latchpay maintains a written BSA/AML program with a designated compliance officer who is accountable for it by name to our board and our banking partners. The program is risk-based, independently reviewed, and boring by design. Its operating parts:
Every recipient is screened against OFAC, EU, and UN sanctions lists before any rail is touched. A payout to an unscreened or matched recipient does not queue, does not retry, and does not fail over — it stops. Screening happens again on list updates, not just at onboarding.
Ongoing monitoring runs against every disbursement: velocity rules, pattern detection across runs, and anomaly flags on recipient, amount, and rail behavior. Alerts route to the compliance team, not to a dashboard nobody reads.
We file suspicious activity reports where required by law and cooperate with our banking partners' own monitoring programs. We do not tell customers when a SAR has been filed; the law prohibits it, and we follow the law.
latchpay screens recipients, monitors transactions, and controls the rails. You remain responsible for the parts of the relationship only you can see:
We maintain SOC 2 Type II and PCI DSS Level 1, both renewed annually by independent assessors, and we commission external penetration tests at least annually. The technical controls behind those attestations are described on Security.
For diligence, write to compliance@latchpay.xyz and we will provide, under NDA:
We answer diligence questionnaires with the documents above rather than with adjectives.
latchpay processes personal data — recipient names, account details, transaction records — under GDPR and CCPA. We act as a processor for the recipient data you submit and as a controller for our own customer records. Retention periods, subprocessors, and data-subject rights are documented in the Privacy Policy; the subprocessor list in the due-diligence pack is the same one the policy references.
When we receive a request for customer data from law enforcement or a regulator, we review it for legal validity, narrow it to what the request actually compels, and produce no more than that. We notify the affected customer before disclosure unless we are legally prohibited from doing so — and where a prohibition expires, we notify afterward. Requests that arrive without legal process are declined and logged.
Request the pack, or start with the sandbox and read the reports while you integrate.