Compliance
How Onyx Bridge Pay Inc. is regulated, how client money is protected, how we govern the platform, and what we require of the partners who build on it. Written to be read by clients, partners and their auditors.
- Effective
- 25 August 2026
- Version
- Draft 1.0 — pre-launch
- Applies to
- Clients, partners, auditors
Our regulatory status
Onyx Bridge Pay Inc. is incorporated in Ontario, Canada and operates as an MSB / PSP operating in a neobank (EMI) model. We provide accounts, domestic and international transfers, currency exchange, fiat-to-stablecoin conversion and card programmes, both directly and through White Label partners.
We are in a pre-launch phase. Registrations, partner arrangements and product availability are being finalised in sequence, and we publish the current position rather than claiming permissions we do not yet hold.
Registrations and permissions
Scroll the table sideways to see all columns
| Framework | Role | Status |
|---|---|---|
| PCMLTFA / FINTRAC | Money services business, subject to AML, reporting and record-keeping duties | Registration numbers published in the client dashboard and available on request |
| Retail Payment Activities Act | Payment service provider performing retail payment activities | Registration and operational risk requirements addressed as part of launch readiness |
| Provincial money transmission rules | Currency exchange and money transmission where provincially regulated | Assessed and addressed per province of operation |
| Card scheme programmes | Card issuing through licensed issuing partners and BIN sponsors | Delivered under partner licences and scheme rules |
| EU / EEA distribution | Services to EEA clients and partners | Delivered with licensed local partners; GDPR applies in full |
| GDPR Article 27 | EU and UK representative appointed for data protection | Contactable at eu-representative@onyxbridgepay.com |
We do not overstate our status. If you need written confirmation of a specific permission, or evidence for your own onboarding file, request it from compliance@onyxbridgepay.com and we will provide what we can substantiate.
Safeguarding of client funds
Protecting client money is the control we treat as non-negotiable. Funds you send us, and funds received for you, are client funds and remain yours.
- Client funds are held in designated safeguarding accounts at regulated credit institutions, segregated from our own corporate money.
- We never lend client funds, invest them for our own account, use them as working capital, or pledge them as security.
- Balances are reconciled daily between our ledger and the safeguarding accounts, with breaks investigated and escalated under a documented procedure.
- Safeguarding partners are selected on financial strength and regulatory standing, reviewed periodically, and diversified to limit concentration risk.
- In the event of our insolvency, safeguarded client funds are intended to be distinguishable from our estate and returned to clients ahead of general creditors, subject to applicable insolvency law.
Safeguarding protects your funds from our failure. It is not deposit insurance and does not protect against the failure of a bank holding the safeguarding account, or against losses you cause yourself, for example by authorising a payment to a fraudster.
Governance and oversight
The board of directors is accountable for the control environment. It approves the risk appetite, the policy framework and the annual compliance plan, and receives regular reporting on regulatory obligations, incidents, complaints, audit findings and remediation.
Named individuals hold accountability for AML and sanctions, data protection, information security, operational resilience and complaints, each with direct escalation to the board. Compliance and risk operate independently of commercial targets, and compliance decisions cannot be overridden by revenue considerations.
We maintain a policy register with defined owners, review dates and version history. Every policy is reviewed at least annually and on material regulatory change.
Policy framework
The following policies govern how we operate. Summaries are available to clients and partners; full documents are shared with regulators, auditors and partners under confidentiality.
- AML and counter-terrorist financing policy, including the enterprise risk assessment.
- Sanctions and financial-crime screening policy.
- Fraud prevention and scam response policy.
- Privacy and data protection policy, with records of processing and DPIA procedure.
- Information security policy, including access control, cryptography and secure development standards.
- Operational resilience, business continuity and disaster recovery policy.
- Outsourcing and third-party risk management policy.
- Complaints handling policy.
- Conflicts of interest, anti-bribery and corruption policy.
- Whistleblowing and speak-up policy.
- Client onboarding, offboarding and appetite policy.
- Product governance and change management policy.
Data protection and GDPR
We are subject to the EU and UK GDPR for clients in those territories, to PIPEDA in Canada, and to Quebec Law 25 for Quebec residents. Our privacy policy sets out the detail; the operational controls behind it are summarised here.
- A data protection officer with defined independence, resources and direct board access.
- An appointed EU and UK representative under GDPR Article 27.
- A record of processing activities maintained under Article 30, covering purposes, categories, recipients, transfers and retention.
- Data protection impact assessments before high-risk processing, including biometric verification, automated screening and new profiling models.
- Privacy by design and by default in product development, with data minimisation and defined retention built into each feature.
- Article 28 data processing agreements with every processor, and due diligence before engagement.
- Transfer impact assessments and Standard Contractual Clauses, plus the UK Addendum, for transfers not covered by an adequacy decision.
- A documented data subject rights procedure with a one-month response target and identity verification safeguards.
- A personal data breach procedure with 72-hour supervisory authority notification and high-risk notification to individuals.
- Annual staff privacy training and a register of privacy incidents and near misses.
Information security
Our security programme is aligned to ISO/IEC 27001 and, for card data, to the applicable PCI DSS scope, with card credentials handled by certified issuing and processing partners so that sensitive authentication data does not enter our environment unnecessarily.
- Encryption of data in transit and at rest, with managed key rotation and separation of duties for key access.
- Least-privilege and role-based access control, mandatory multi-factor authentication for staff, and periodic access recertification.
- Network segmentation, hardened baseline configurations and centralised secrets management.
- Secure software development lifecycle with peer code review, dependency scanning and pre-release security testing.
- Independent penetration testing at least annually and after significant change, with tracked remediation.
- Continuous logging, alerting and monitoring, with tamper-evident audit trails.
- Vulnerability management with severity-based remediation deadlines.
- Strong customer authentication for client logins and sensitive actions, with step-up authentication on risk signals.
- A coordinated vulnerability disclosure route for researchers.
Report a suspected vulnerability or security incident to security@onyxbridgepay.com. We acknowledge reports promptly and do not pursue good-faith researchers who follow our disclosure guidance.
Operational resilience
We identify our important business services, set impact tolerances for disruption, and test whether we can stay within them under severe but plausible scenarios.
- Business continuity and disaster recovery plans with defined recovery time and recovery point objectives per service.
- Redundant infrastructure across availability zones, with automated failover and regularly restored backups.
- Incident management with severity classification, defined escalation, client communication templates and post-incident review.
- Scenario testing covering the failure of a critical third party, a cyber attack, data corruption and loss of key personnel.
- Notification of material operational incidents to regulators and affected clients within the timeframes that apply to us.
- Exit and substitution plans for critical suppliers so that a single vendor cannot become an unmanaged dependency.
Outsourcing and third-party risk
We rely on banking partners, card issuers and processors, verification and screening vendors, blockchain analytics providers and cloud infrastructure. Outsourcing a function never outsources our accountability for it.
- Risk-based due diligence before engagement, covering financial stability, regulatory standing, security posture, data protection and concentration risk.
- Written contracts with defined service levels, audit and information rights, sub-outsourcing controls, data protection terms and termination assistance.
- A register of all outsourcing and critical third-party arrangements, classified by criticality.
- Ongoing performance and control monitoring, with periodic reassessment and evidence collection such as assurance reports.
- Documented exit strategies for critical arrangements, including data return and migration paths.
White Label partner compliance
Partners launch under their own brand on our regulated infrastructure. Because their activity sits inside our regulatory perimeter, partner compliance is a condition of access rather than a recommendation.
Before launch
- Corporate due diligence on ownership, control, directors and beneficial owners, plus sanctions and adverse media screening.
- Assessment of the partner’s licensing position in every market it intends to serve.
- Review of the proposed target market, customer segments, products and geographies against our risk appetite.
- Assessment of the partner’s own AML, fraud, complaints, data protection and security controls.
- A signed partner agreement, data processing agreement and agreed control matrix allocating each obligation.
While live
- Mandatory platform controls that the partner cannot disable, weaken or bypass.
- Ongoing monitoring of partner portfolio quality, alert outcomes, complaint volumes and incident history.
- Periodic control reviews and the right to audit on reasonable notice, extending to the partner’s relevant suppliers.
- Defined escalation channels and cooperation obligations for regulatory and law-enforcement requests.
- Marketing review so that regulatory status, pricing and product limitations are described accurately.
- Graduated remedies: remediation plans, restriction of onboarding, suspension of processing and, ultimately, termination with an orderly client migration.
Client protection and fair treatment
- Pre-contract disclosure of fees, exchange margins and execution timelines, with the total cost shown before you confirm a transaction.
- Plain-language terms, with at least two months notice of changes that are not to your advantage.
- Strong customer authentication and transaction alerts to reduce unauthorised use.
- Clear refund rights for unauthorised or incorrectly executed payments, and scheme dispute support for card transactions.
- Fraud and scam warnings surfaced at the point of payment, with a documented response procedure when a client reports a scam.
- Additional care for clients in vulnerable circumstances, including flexible verification routes and escalation to trained staff.
- Accessibility considered in our interfaces, and support available through more than one channel.
Complaints handling
Tell us when we get something wrong. Write to complaints@onyxbridgepay.com, use the in-app support channel, or send a letter to our registered office. Please include your account reference, what happened and the outcome you are looking for.
- 01We acknowledge your complaint within five business days and give you a reference and a named contact.
- 02We investigate independently of the team or person the complaint concerns.
- 03We aim to send a final response within 15 business days, and in exceptional cases within a maximum of 35 business days, explaining the delay and the expected date.
- 04Our final response explains our conclusion, the reasons for it, any redress offered, and how to escalate if you disagree.
- 05If you remain dissatisfied you may refer the matter to the competent supervisory authority or alternative dispute resolution body for your jurisdiction, whose details we provide with the final response.
We record every complaint, analyse root causes and report themes to the board, so that recurring problems are fixed rather than merely compensated.
Audit and assurance
- An independent effectiveness review of the AML programme at least every two years, as required of Canadian reporting entities.
- A risk-based internal audit plan approved by the board, covering compliance, security, operations and finance.
- External financial audit in line with our statutory obligations.
- Independent penetration testing and, where relevant, third-party assurance reporting on our control environment.
- A single findings register: every issue has an owner, a severity, a deadline and evidence of closure, tracked to the board.
Partners and prospective clients conducting their own due diligence can request our current assurance pack, including policy summaries, control descriptions and the most recent independent review outcome, under a confidentiality agreement.
Raising a concern
Staff, clients, partners and suppliers can raise a concern about financial crime, misconduct, data misuse or a control failure confidentially, and anonymously if preferred. Reports go directly to the compliance function and, for serious matters, to the board.
We prohibit retaliation of any kind against a person who raises a concern in good faith, and treat retaliation as a disciplinary matter in its own right.
Compliance contacts
- Compliance team
- compliance@onyxbridgepay.com
- AML and financial crime
- aml@onyxbridgepay.com
- Data protection officer
- dpo@onyxbridgepay.com
- EU / UK representative
- eu-representative@onyxbridgepay.com
- Security and vulnerability reports
- security@onyxbridgepay.com
- Complaints
- complaints@onyxbridgepay.com
- Partner due diligence requests
- partners@onyxbridgepay.com
- Registered office
- Onyx Bridge Pay Inc., 100 King Street West, Suite 5700, Toronto, Ontario M5X 1C7, Canada