Crypto & DeFi Verification
No crypto exchange, broker or protocol uses Solidus. There is no pilot and no named counterparty on this page.
Nothing here is legal advice.
Why this is the vertical we care about
Because the check genuinely repeats. A regulated crypto-asset business identifies a customer at onboarding and again on refresh: the repetition is a regulatory obligation, not a product choice.
That is the pattern the portability argument needs, and it is why we point at this vertical rather than at a market where a person is verified once and never again. On total cost of ownership the crossover is a function of how often the check repeats, and here it repeats by law.
That is the whole of the argument's strength. What follows is the rest of the picture.
The disqualifier for a Turkish crypto-asset service provider
Türkiye's remote-identification rules for licensed providers require a match against the national population registry, alongside a real-time recorded session.
We do not perform that match. A search of our codebase for any national-registry integration returns nothing, re-run 2026-07-31; the national identifier appears only as a checksum read off a document. A checksum is not a registry match.
So a Turkish crypto-asset service provider cannot satisfy its identification rule with our pipeline alone. MASAK · TCKN
The gaps for an EU crypto-asset service provider
MiCA, the FATF Travel Rule, IVMS 101, sanctions screening, PEP handling and transaction monitoring
are all not-built, and a code check confirms there is no Travel Rule implementation anywhere.
IVMS 101 · Travel Rule
We are one input to a compliance programme, not a compliance programme.
DeFi, where the question is different
A protocol with no legal entity generally has no customer due-diligence obligation to discharge: there is nobody for a regulator to place the duty on. Where an obligation exists it usually sits with an interface operator, a fiat on-ramp or a custodial service, and it sits with them, not with us.
We are not going to sell "compliant DeFi." Where a front-end operator does carry a duty, we can supply the identity-proofing input; we cannot make a permissionless protocol compliant, and anyone claiming to is selling something that does not exist.
What we would actually provide
Document authentication, liveness and face match, producing a credential the person keeps and can present again, with disclosure limited at presentation. the mechanics
And the boundary that never moves: an obligated business remains fully liable for its own compliance whether or not it uses us. Whether a supervisor treats third-party verification as satisfying a duty is unsettled. reliance
What would have to be true before an exchange could adopt this
- A national-registry match, where the jurisdiction requires one.
- An external security audit.
- Screening and monitoring, or an explicit division of responsibility with whoever provides them.
- A relying party willing to be first. The count today is zero.