Skip to content

Trust & safety

Compliance & Security

How we're regulated, how client funds are held, and the controls we use to prevent financial crime.

Last updated 22 July 2026

01 Our regulatory status

Greengate Technologies Inc. is a registered Money Service Business (MSB). In the United Kingdom we operate under the oversight of His Majesty's Revenue & Customs (HMRC) as a registered MSB for anti-money laundering purposes, and we comply with the UK Money Laundering Regulations 2017 (as amended). In Nigeria, we operate in compliance with the Central Bank of Nigeria's guidelines for payment service providers.

Our compliance programme is reviewed annually by an independent third party. We maintain documented policies and procedures covering AML, KYC, sanctions, transaction monitoring and data protection.

02 Know Your Customer (KYC)

We verify the identity of every customer before they can send or receive money. Our KYC process uses a combination of government-issued document verification, biometric selfie matching, and database checks against politically exposed person (PEP) and adverse media lists.

  • Standard accounts: government-issued photo ID + selfie. Verified in seconds.
  • Enhanced due diligence: additional proof of address and source-of-funds documentation required for higher-risk accounts or transaction patterns.
  • Business accounts: company registration documents, director verification and beneficial ownership disclosure.

03 Anti-Money Laundering (AML)

Greengate maintains a comprehensive AML programme aligned with Financial Action Task Force (FATF) recommendations. Our programme includes a risk-based approach to customer due diligence, automated transaction monitoring with configurable rules, and a dedicated Money Laundering Reporting Officer (MLRO) who oversees all suspicious activity reports.

We file Suspicious Activity Reports (SARs) with the National Crime Agency (NCA) in the UK and with the Nigerian Financial Intelligence Unit (NFIU) where required by law. We never tip off customers that a SAR has been filed.

04 Sanctions compliance

All customers and transactions are screened in real time against applicable sanctions lists, including:

  • OFAC (US Office of Foreign Assets Control) SDN and consolidated lists
  • HMT (UK HM Treasury) Financial Sanctions Targets
  • UN Security Council consolidated list
  • EU Consolidated list of persons, groups and entities subject to EU financial sanctions
  • OFSI (UK Office of Financial Sanctions Implementation) register

Transactions involving sanctioned parties are blocked automatically. We conduct regular list updates and periodic retrospective screening of our customer base.

05 Data security

We take the security of your personal and financial data seriously. Our technical controls include:

  • Encryption in transit: TLS 1.3 for all data moving between your device and our servers.
  • Encryption at rest: AES-256 for all stored sensitive data, including personal information and transaction records.
  • Key management: Hardware Security Modules (HSMs) for cryptographic key storage and operations.
  • Access controls: role-based access control, least-privilege principles, and multi-factor authentication for all internal systems.
  • Penetration testing: annual third-party penetration tests plus continuous automated vulnerability scanning.
  • Incident response: a documented incident response plan with defined escalation procedures and regulatory notification timelines.

06 Segregation of client funds

Client fiat balances are held in dedicated client money accounts at regulated banking institutions, separate from Greengate's operational funds. In the event of Greengate's insolvency, client funds would not form part of the general estate available to creditors.

Note: crypto asset balances are not covered by any financial services compensation scheme. Please refer to our Terms of Use for the full risk disclosure.

07 Responsible disclosure

We welcome reports from security researchers who discover potential vulnerabilities in our systems. If you believe you have found a security issue, please report it responsibly to security@greengate.ng. We aim to acknowledge all reports within 24 hours and will work with you to resolve verified issues promptly.

Please do not disclose vulnerabilities publicly until we have had a reasonable opportunity to address them. We commit not to take legal action against researchers acting in good faith under this policy.

08 Regulatory inquiries

Regulators and law enforcement agencies should direct inquiries to our compliance team at compliance@greengate.ng. We will respond promptly to legitimate regulatory and legal requests. All requests are handled in accordance with applicable law and our documented legal process guidelines.