SourcePay AI
SourcePayAI
Source Pay AI Network
Back to home
Compliance

Accountability you can audit.

Verified payments require verified operators. Here is the regulatory and audit framework that keeps SourcePay AI accountable to the businesses, donors, and regulators who depend on us.

Last updated · June 11, 2026

01.Regulatory posture

SourcePay AI operates as a payments facilitator in partnership with regulated banking and money-services partners. We adhere to U.S. FinCEN BSA/AML rules, OFAC sanctions screening, and applicable state money-transmitter requirements.

02.KYC & KYB verification

  • Individual KYC — government ID, liveness check, and address verification.
  • Business KYB — entity formation documents, EIN, and beneficial ownership disclosure.
  • Ongoing screening against global sanctions, PEP, and adverse-media lists.
  • Risk-based enhanced due diligence for higher-value or higher-risk vendors.

03.Frameworks & attestations

  • SOC 2 Type II — annual attestation covering security, availability, and confidentiality.
  • PCI DSS — out of scope; we never store raw card data. Payment partners are PCI Level 1.
  • GDPR & UK-GDPR — Data Processing Addendum available to all enterprise customers.
  • HIPAA — supported for benevolence funds via BAA on Enterprise plans.

04.Reporting & transparency

Verified businesses receive quarterly transparency reports covering payout volumes, dispute outcomes, and any regulator-mandated disclosures. Suspicious-activity reports are filed where required by law.

Questions about this policy?

Email our trust & safety team at trust@sourcepayai.com — we typically respond within one business day.