All systems operational · 99.99% uptime

LEGAL · COMPLIANCE

Moving money is a regulated activity. Good.

This page describes how latchpay is regulated, who holds the funds, and what stays on your side of the line. Effective March 30, 2026.

How latchpay is regulated

latchpay, Inc. was founded in 2024, and we will be direct about what that means: we are partway through a state-by-state money-transmitter licensing program, not at the end of one. Where our license has been granted, we operate under it. Where an application is pending, we operate under sponsor-bank arrangements with regulated banking partners — the movement of funds happens under the partner institution's regulatory authority, subject to their oversight, examination, and program requirements.

Two things are true in every state, on every rail, regardless of which posture applies:

  • Customer funds are held 1:1 in segregated, bankruptcy-remote accounts at regulated banking partners. They are never commingled with operating funds and never lent. The float is not a business model.
  • Every payout passes through the same screening, policy, and ledger controls. Licensing posture changes who supervises the transmission; it does not change how the money is handled.

A current licensing matrix — which states are licensed, which are pending, which operate under sponsorship — is part of the due-diligence pack described under Audits & attestations.

Our banking partners

We do not name our banking partners on a marketing page; names are available under NDA during diligence. What we will publish is the bar they have to clear. Every institution that holds customer funds or originates payments for latchpay must be:

  • A regulated, chartered institution subject to federal or national banking supervision in its jurisdiction.
  • Willing to hold customer funds in segregated FBO (for-benefit-of) accounts, titled so that the funds are identifiably our customers' and bankruptcy-remote from latchpay.
  • Able to provide daily statement feeds in machine-readable form, so our ledger reconciles against the bank's records every day — not against our own database's opinion of itself.

Partners are reviewed annually against these requirements, and the reconciliation feed is the enforcement mechanism: a partner whose statements we cannot match line-by-line is a partner we are exiting. How that matching works is described on How it works.

Financial crimes program

latchpay maintains a written BSA/AML program with a designated compliance officer who is accountable for it by name to our board and our banking partners. The program is risk-based, independently reviewed, and boring by design. Its operating parts:

Sanctions screening

Every recipient is screened against OFAC, EU, and UN sanctions lists before any rail is touched. A payout to an unscreened or matched recipient does not queue, does not retry, and does not fail over — it stops. Screening happens again on list updates, not just at onboarding.

Transaction monitoring

Ongoing monitoring runs against every disbursement: velocity rules, pattern detection across runs, and anomaly flags on recipient, amount, and rail behavior. Alerts route to the compliance team, not to a dashboard nobody reads.

Reporting

We file suspicious activity reports where required by law and cooperate with our banking partners' own monitoring programs. We do not tell customers when a SAR has been filed; the law prohibits it, and we follow the law.

Platform obligations

latchpay screens recipients, monitors transactions, and controls the rails. You remain responsible for the parts of the relationship only you can see:

  • KYC of your own users. You know your sellers, creators, vendors, or contractors. We screen the recipients you send us; we do not onboard your users for you.
  • Lawful purpose. Payouts you post must arise from lawful activity on your platform. Our monitoring is a control, not a permission slip.
  • Accurate recipient data. Names, account details, and jurisdictions you submit must be correct. Screening a wrong name protects nobody.
A cleared payout is not legal advice. Our screening passing a recipient means our lists did not match; it does not mean the underlying transaction is lawful, and it does not transfer your compliance obligations to us. The allocation of responsibility is spelled out in the Terms of Service.

Audits & attestations

We maintain SOC 2 Type II and PCI DSS Level 1, both renewed annually by independent assessors, and we commission external penetration tests at least annually. The technical controls behind those attestations are described on Security.

For diligence, write to compliance@latchpay.xyz and we will provide, under NDA:

  • The current SOC 2 Type II report
  • The state licensing matrix, including pending applications
  • Summaries of the BSA/AML and sanctions programs
  • The subprocessor list
  • Certificates of insurance

We answer diligence questionnaires with the documents above rather than with adjectives.

Data protection

latchpay processes personal data — recipient names, account details, transaction records — under GDPR and CCPA. We act as a processor for the recipient data you submit and as a controller for our own customer records. Retention periods, subprocessors, and data-subject rights are documented in the Privacy Policy; the subprocessor list in the due-diligence pack is the same one the policy references.

Law-enforcement & regulator requests

When we receive a request for customer data from law enforcement or a regulator, we review it for legal validity, narrow it to what the request actually compels, and produce no more than that. We notify the affected customer before disclosure unless we are legally prohibited from doing so — and where a prohibition expires, we notify afterward. Requests that arrive without legal process are declined and logged.

Diligence teams are welcome here.

Request the pack, or start with the sandbox and read the reports while you integrate.