Sanctions Compliance.
v1.0 · Effective 2026-08-01 · Verity Software Inc.
1. Purpose & posture
Definitions for terms used here (Service, Your Content, Sub-processor, etc.) are in our definitions page.
Verity Software Inc. is a Canadian federal corporation distributing a consumer desktop and mobile SaaS product. At launch, Verity's sanctions-enforcement posture is deliberately narrow and honest:
- Payment-channel enforcement is delegated to Verity's Merchant of Record, which operates a compliance stack covering US OFAC, EU consolidated, UK OFSI, and Canadian sanctions regimes.
- A server-side embargoed-country block at signup prevents account creation from jurisdictions subject to comprehensive sanctions.
- In-product denied-persons screening, IP-resolution audit logs, dedicated FINTRAC operating procedures, and 5-year compliance retention machinery are NOT implemented at launch and are not promised to users or counterparties. They are scoped for a future iteration when revenue, scale, and risk justify the operational and privacy cost (see §8).
This posture is appropriate for a single-founder, pre-revenue consumer SaaS shipping to a small set of allow-listed destinations. It will be revisited if Verity reaches material scale, ships to higher-risk jurisdictions, or onboards enterprise/regulated counterparties.
2. Phase rollout & country allow-list
Verity launches with an explicit allow-list. Any country not on the list is implicitly blocked at signup (regardless of sanctions status).
Phase 1 — Launch (North America)
| Country | ISO 3166-1 |
|---|
| Canada | CA |
| United States | US |
| Mexico | MX |
Any signup from a country outside this list (and not on the embargoed deny-list in §3.2) receives a “not yet available in your region” message — not a legal-restriction error.
Phase 2 — Asia expansion
| Country | ISO 3166-1 |
|---|
| Japan | JP |
| South Korea | KR |
Phase 3 — Norway
| Country | ISO 3166-1 |
|---|
| Norway | NO |
Beyond Phase 3
Any further market addition requires (a) confirmation that our payment processor supports the jurisdiction; (b) a check that no comprehensive sanctions or export-control regime prohibits service; and (c) update of this document with the new effective date.
3. Enforcement layers
3.1 Layer 1 — Merchant of Record
Verity's Merchant of Record screens every payment attempt against:
- US OFAC Specially Designated Nationals (SDN) list
- EU consolidated sanctions list
- UK OFSI consolidated list
- Canadian sanctions lists administered under SEMA
Payment attempts originating from comprehensively sanctioned jurisdictions, or from designated persons identified by these regimes, are blocked at the payment-capture stage. No transaction is created, no funds settle, and Verity receives no revenue from a blocked attempt.
Verity relies on its payment processor's compliance stack to satisfy payment-channel obligations. Before launch, Verity will obtain the processor's published sanctions-compliance policy and file it with this document.
3.2 Layer 2 — Server-side embargoed-country block at signup
In addition to payment-stage screening, Verity's signup flow performs a coarse server-side check of the requesting connection's country against an embargoed-country ISO 3166 deny-list. Where the country resolves to a deny-listed jurisdiction, the signup is rejected with a generic legal-restriction message and no account is created.
Deny-list (initial): Cuba (CU), Iran (IR), North Korea (KP), Syria (SY), Russia (RU); plus the Russian-controlled Ukrainian territories of Crimea, Donetsk, Luhansk, Kherson, and Zaporizhzhia.
Implementation: a simple IP-to-country lookup using a free or built-in GeoIP source. No MaxMind dependency. No 5-year retention of resolved IPs. No audit-grade logging beyond ordinary error telemetry. False positives are addressed via a manual [email protected] contact path.
Limitations explicitly accepted: this layer does not defeat VPNs, residential proxies, or sub-national region spoofing. It is a coarse, low-cost barrier — not a defensible audit-grade screening control. The contractual hooks in §4 carry the legal weight against bad-faith circumvention.
3.3 NOT implemented at launch
For the avoidance of doubt, the following are not in scope at launch and are not promised to users, counterparties, or regulators:
- In-product denied-persons (SDN / EU / UK / Canadian) name screening
- IP-resolution audit logs with multi-year retention
- A dedicated FINTRAC reporting procedure beyond standard payment-channel obligations discharged by the Merchant of Record
- A dedicated screening-hit incident SLA or response runbook
- VPN / proxy / TOR detection or blocking
- CDN-edge geo-blocking of binary downloads or model-weight delivery
4. User obligations (contractual hook)
The contractual hook for sanctions enforcement lives in the user-facing legal stack:
- Terms of Service — Sanctions and Export Compliance: the user represents and warrants that they are not located in, ordinarily resident in, or accessing the Service from any comprehensively sanctioned jurisdiction; that they are not a designated person on the OFAC SDN, EU consolidated, UK OFSI, or Canadian sanctions lists; and that they will not use or re-export the Service in violation of applicable sanctions or export-control law.
- Acceptable Use Policy §5 — Embargoed-country prohibition: explicit prohibition on using the Service from, on behalf of, or for the benefit of any person located in or organised under the laws of a comprehensively sanctioned jurisdiction; explicit prohibition on any use that would result in export or re-export of the Service in violation of applicable law.
Together, these two clauses give Verity a contractual termination right against any user who circumvents the Layer-2 geo-block — for example by VPN, proxy, or relocation — and removes ambiguity about user responsibility for compliance with sanctions and export-control laws in the user's own jurisdiction.
5. Export controls (Verity's product)
The Verity desktop and mobile binaries incorporate standard transport encryption (TLS) and at-rest encryption (AES-256 class) for locally stored audio, transcripts, and credentials. Locally distributed model weights are derivatives of publicly trained base models fine-tuned on benchmark, synthetic, and public-domain data.
- United States (15 CFR §740.17 — License Exception ENC): the desktop app is “mass-market” encryption software under §740.17(b)(1). Eligible for ENC self-classification without pre-export review. Verity will file the Annual Self-Classification Report with BIS and NSA by 1 February of each year.
- European Union (Regulation 2021/821 — Recast Dual-Use): the product satisfies the Annex I Note 3 (“Cryptography Note”) criteria and does not require an EU export licence for Phase-1 markets.
- Canada (Export Control List Group 1): the General Software Note covers mass-market cryptographic software. No permit required for Phase-1 destinations.
- Model weights: derived from publicly available base models trained on public data. Not protected as dual-use items under any of the three regimes at the time of writing.
This position will be revisited if Verity incorporates proprietary cryptographic primitives, ships model weights with controlled export status, or materially changes its cryptographic architecture.
6. Compliance review
- Compliance Owner: the founder of Verity Software Inc. holds the Compliance Owner role for sanctions and export controls at launch.
- Annual review: this document is reviewed annually and updated as necessary.
- Reactive review: the Compliance Owner reviews this document on material sanctions news (new comprehensive embargo, major SDN additions, payment-processor compliance-stack change, App Store ERN regime change).
- Feeds subscribed: OFAC SDN Recent Actions feed; EU consolidated list update notifications; OFSI consolidated list notifications; Global Affairs Canada sanctions update mailing list; payment-processor compliance bulletins.
Material changes to the deny-list or to the user-facing posture trigger the change-notification regime under ToS §14 (30 days for material changes).
7. Out of scope (explicit)
The following are explicitly out of scope at launch:
- In-product denied-persons screening against SDN / EU / UK / Canadian lists
- FINTRAC suspicious-transaction or large-cash-transaction reporting procedures beyond standard payment-channel triggers (discharged by the payment processor)
- A dedicated screening-hit incident response SLA
- A 5-year IP-resolution / signup-attempt audit log
- CDN-edge or OTA-update geo-blocking of binary or model-weight delivery
- VPN, proxy, or TOR detection and blocking
- MaxMind or other paid GeoIP integration with a Data Processing Agreement
Items in this list are not commitments — they are deliberate omissions. Each will be revisited under §8.
8. Future roadmap
When Verity's revenue, scale, customer mix, or regulatory exposure justifies the investment, the following Layer-2 extensions become candidates:
- Denied-persons screening at signup and on payment events, against OFAC SDN / EU consolidated / UK OFSI / Canadian consolidated lists.
- CDN-edge geo-blocking of binary downloads, OTA updates, and model-weight delivery for embargoed countries.
- Dedicated SEMA Compliance Owner designation as a formal role, separated from the founder role.
- FINTRAC operating procedure if Verity grows into reporting-entity status (currently below threshold via the MoR's posture).
These items will be re-evaluated periodically or when material changes in applicable sanctions regimes occur.
Cross-references
- /legal/terms — Sanctions and Export Compliance warranty (user representation + termination right)
- /legal/aup — §5 embargoed-country and export-misuse prohibition
- /legal/privacy — data handling for the minimal signup-time geo-lookup
- /legal/sub-processors — Payment processor listing, including its role as the sanctions-enforcement payment channel
Prepared 2026-05-19. Internal compliance policy and user-facing companion document. Not legal advice. Counsel-reviewed v2 to follow post-revenue.