Trust / Compliance model

Who owns what in the regulated stack.

OVAAL is the technology and orchestration layer. The partner's own licence owns the regulated relationship with the end-user. Authorised providers execute the regulated service. This page makes that split explicit and shows how compliance workflows are configured on top of it.

Responsibility matrix.

The same split applies to every integration: the customer holds the regulated relationship, OVAAL provides the technology and orchestration, and authorised providers execute regulated services. We agree it in writing before the first integration call.

ActivityCustomer (you)OVAALAuthorised provider
Regulatory permissionsPrimary for your business modelTechnology role unless expressly authorisedPrimary for the outsourced regulated service
KYC / KYB policyPolicy ownerWorkflow orchestrationVerification where contracted
AML, sanctions & Travel RuleProgramme owner under your licenceIntegration and routing of the workflowScreening and messaging where contracted
Safeguarding / custodyDepends on modelNo, unless expressly authorisedPrimary where applicable
Routing configurationOversight and commercial choicesRules engineExecution eligibility
Settlement & reconciliationReview and finance opsPlatform record and workflowSource confirmations
Support & complaintsPrimaryTechnical escalationService-specific escalation

The DPA and MSA turn this matrix into contractual terms. Unless expressly stated, OVAAL is not a bank, payment institution, electronic-money institution or crypto-asset service provider.

Configurable compliance workflows.

OVAAL orchestrates the compliance steps; your team operates them under your own authorisation, and authorised providers run the checks. Integrations are configurable per market and per partner.

WorkflowWhat OVAAL orchestratesExecuted by
Identity (KYC / KYB)Onboarding flow, status, re-checks and routingIdentity-verification providers
AML & transaction monitoringScreening triggers, case routing and audit trailAML screening vendors
Sanctions & wallet screeningPre-transaction checks and policy gatingSanctions and wallet-screening vendors
Travel RuleMessage exchange and counterparty handlingTravel Rule providers
Settlement railsRouting across eligible rails and reconciliationAuthorised providers and regulated rails partners

This page covers who owns what. For how the orchestration is built and configured, see the risk & compliance module. We list the categories here. The specific providers we integrate with (and your options per market) are disclosed in the gated compliance pack, where contractually allowed.

Partner compliance pack.

Available to qualified partners, on request before signing, and in full on signed paperwork:

  1. Data Processing Agreement (DPA) template. GDPR Art. 28 and EU Transfer of Funds Regulation aware.
  2. Sub-processor list. Current and intended, with change-notice terms.
  3. Named provider options. The specific identity, AML, sanctions, Travel Rule and rails providers we integrate, per market, where contractually allowed.
  4. Regulatory posture summary. How deployments are designed to support authorised firms in EU and MENA markets.
  5. Security posture pack. See the security overview.
  6. Sample audit-log export. Structured format for your finance and compliance teams.
  7. Joint incident playbook template.
  8. MSA template. The commercial agreement frame.

Data protection.

  • TrueThing Ltd. acts as data processor for partner data. You are the controller for your end-users.
  • Legal bases: contract (the partner relationship) and legitimate interest (security and fraud prevention).
  • Data-protection contact: [email protected]. Appointment detail is available to partners under NDA.
  • Supervisory authority: Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tallinn. TrueThing Ltd.'s main establishment is Estonia under GDPR Art. 56.
  • A GDPR Article 28 DPA is signed with every partner before production.

Legal entity.

TrueThing Ltd. (operating as "OVAAL")

  • Jurisdiction: Republic of Estonia
  • e-Business Register number: 12568013 (identifier EE-12568013)
  • Public corporate record: ariregister.rik.ee (TrueThing OÜ). Registered office, VAT status and directors are verifiable there.

Pre-clear OVAAL with your team.

Book an architecture review and we will walk your compliance and legal stakeholders through the responsibility matrix and the integration path. The compliance pack gives your team enough to assess OVAAL before the first call.