Summarize with AI
Swapzone users do not exchange assets directly with Swapzone. The exchanges are completed through the available exchange partners, and each partner applies its own anti-money laundering (AML), Know Your Customer (KYC), transaction-monitoring, and risk-management rules. As a result, the information a user may be asked to provide depends on the selected provider, as well as the information about what happens to a transaction under review.
This research compares the published AML/KYC requirements of 17 Swapzone partners: AlfaCash, BaltEx, ChangeHero, Changelly, ChangeNOW, Coincraddle, EasyBit, Exolix, FixedFloat, Godex, LetsExchange1, n.exchange, Quickex, SideShift.ai, SimpleSwap, StealthEX, and Swapter.
About This Research
The research focuses on practical questions and is based on the partners’ published AML/KYC policies, Terms of Use, Privacy Policies, risk disclosures, FAQs, and related compliance documents. The documents were reviewed in September 2026. As a result, a provider may implement additional operational controls that are not described in public documents.
We distinguish three related processes.
- KYC identifies the customer. It can involve a government-issued ID, personal information, a selfie, or a liveness check.
- Transaction monitoring, sometimes described as Know Your Transaction or KYT, examines the crypto transaction itself. This includes the history of the sending wallet, exposure to sanctioned or illicit services, transaction patterns, and a risk score generated through blockchain analysis.
- Enhanced Due Diligence (EDD) is a deeper review used when a customer or transaction presents higher risk. EDD can go beyond identity verification and require proof of address, source of funds (SoF), source of wealth (SoW), wallet ownership, or other supporting evidence.
AML/KYC Requirements At a Glance
For many partners, the standard transaction does not start with full identity verification. Instead, the provider first looks at a transaction and customer risk. A suspicious wallet, sanctions exposure, unusual transaction pattern, high-risk jurisdiction, large transaction, or other risk signal can then move the transaction into additional review. The details of that escalation are different between providers. A service that does not require KYC before a normal exchange can potentially still monitor the transaction and request identity files later.
We separated partners into three groups.
How 17 Swapzone partners decide when KYC applies
Based on partners’ published AML/KYC policies, reviewed September 2026
Standard swaps proceed without ID. Verification starts only when a risk signal appears — suspicious wallet, high-risk jurisdiction, unusual pattern.
8 partnersKYC sits inside a formal due-diligence framework — low/medium/high risk tiers. Exact thresholds aren’t public, but escalation logic is described.
5 partnersAt least one concrete, disclosed threshold — a transaction amount or risk-score cutoff — is stated to trigger additional checks.
4 partnersKYC is Used Primarily When a Risk is Detected
In that case, standard swaps can generally proceed without identity verification. KYC is introduced when a compliance signal triggers a review.
| Partner | Main KYC / AML triggers | What may be required | If user declines/funds are flagged |
| AlfaCash | Blockchain/KYT risk score; customer/geographic/product risk | Phone/SMS; government ID; proof of address; privacy policy also mentions selfie/biometric data | Transactions may be suspended/refunded depending on risk; flagged reversals can incur fee |
| BaltEx | Failed risk checks; high-risk region; high-risk behavior | ID; selfie/liveness; proof of address; payment-method ownership; SoF | Usually refund minus network fees if KYC is declined; some cases require KYC before refund |
| ChangeNOW | Jurisdiction; fraud/stolen funds; AML requirements; fiat provider request; unusual/suspicious transaction | Government ID; supporting docs/SoF; additional case-specific information | Verification link lasts 3 days; then manual review; ultimate SLA not stated |
| Exolix | Amount/frequency; blockchain analysis; SoF; sanctions; geography; wallet risk; suspicious patterns; provider request | ID; selfie/liveness; address; SoF/SoW; proof of wallet ownership | Explicitly says KYC isn’t required for ordinary transaction-error refunds; suspicious funds can trigger verification |
| FixedFloat | Funds linked to criminal activity; external information/security checks; anti-abuse cases | Identity verification is only as an exception; SoF may be requested | Suspicious funds can be frozen; some cases are held until law enforcement request; refunds may depend on verification |
| SideShift.ai | Automated transaction screening; illegal/malicious association → human review | Specific KYC documents not disclosed | Verification can speed refund; mandatory for flagged deposits of a “serious nature”; holding period unspecified |
| SimpleSwap | Monitoring red flags; may also demand KYC at its discretion | Identity docs; PEP info; SoF/SoW; real-time liveness | Suspicious funds may be frozen pending EDD; returns can require ID, proof of address, and other evidence |
| Swapter | Undisclosed risk-scoring criteria | Identity verification handled through Sumsub; precise document set not detailed in the research card | Declining KYC → full refund, except for suspected illegal-activity cases; standard check stated as 3 days |
Risk-based verification is the dominant model across the reviewed partners. The lack of numerical detail is common here. Users may know which factors can lead to verification without knowing exactly what score or combination of factors will cause it. Exolix, for example, lists the next possible reasons for additional checks:
- transaction amount and frequency,
- blockchain-analysis results,
- geographic risk,
- sanctions screening,
- wallet risk,
- suspicious patterns,
- source-of-funds indicators,
- law enforcement requests.
KYC is Risk-Based and Has Predefined Compliance Levels
This applies to partners whose KYC is part of a more formal customer/due-diligence framework. Policies describe standard vs. enhanced levels of due diligence or low/medium/high risk. Even when exact thresholds are not public, the policies explain how verification becomes more extensive as risk increases.
| Partner | Main KYC / AML triggers | What may be required | If user declines/funds are flagged |
| Changelly | Proprietary scoring system flags suspicious transaction; EDD for high-risk cases | Name, DOB, address, government photo ID; SoF for EDD | Transaction held; more information can be requested; failed verification can lead to blacklist/SAR |
| EasyBit | Low → monitoring; Medium → SDD/KYC possible; High → EDD/KYC/SoF/SoW/manual review | ID/passport; selfie; liveness; SoF | Failed checks can lead to refund; suspected/non-cooperative cases can be frozen, including transfer to cold storage |
| Godex | Low/medium/high customer risk based on activity, volume, geography, relationship | Government-issued ID; ongoing monitoring/risk profiling | High-risk customers receive EDD; detailed refund/refusal path not disclosed in file |
| n.exchange | CDD/sanctions screening/transaction monitoring; thresholds not published | Government ID + selfie/date note; liveness; recent utility/bank statement; SoF; possible interview | “Suspended Order” can have no defined completion timeline; user bears asset-price fluctuation risk during hold |
| LetsExchange1 | LetsExchange1 discretion or underlying provider request | Identity information; EDD may include extra IDs, bank statements, tax returns, property/business records, SoF/SoW | Transaction held during verification; underlying provider can impose separate KYC |
EasyBit, for example, uses a three-level risk structure. Low-risk transactions receive standard monitoring. Medium-risk cases can move to Standard Due Diligence and KYC. High-risk cases can receive Enhanced Due Diligence, including KYC, source-of-funds or source-of-wealth checks, manual review, and a transaction hold.
Source-of-funds and source-of-wealth checks sound similar but serve different purposes. Source of funds concerns the money or crypto involved in a particular transaction. Source of wealth concerns how the person accumulated their broader wealth, showing a deeper level of financial review.
KYC with Specific Published Triggers
These providers published at least one concrete numerical trigger that can lead to KYC/EDD. We were looking for a transaction amount, risk score, or another measurable threshold.
| Partner | Main KYC / AML triggers | What may be required | If user declines/funds are flagged |
| ChangeHero | Automated risk scoring; €1,000+ occasional transaction; EDD for high-risk/PEP etc. | ID/passport/driver license; photograph; personal/address data; possible EDD | Refusal → exchange terminated and funds returned |
| Coincraddle | Risk Score >75% can trigger EDD/KYC/SoF | Standard documents plus a spoken passport video declaration and ≥10-second sending-platform screen recording | Verification up to 3 business days; AML refund up to 5 business days |
| Quickex | Risk Score >40% or specified high-risk labels | ID + selfie with handwritten date/signature; detailed transaction/source explanations; withdrawal/explorer/correspondence screenshots | Refund only after KYC; failure to provide information within 30 days can eliminate refund; no fixed review duration |
| StealthEX | Normal/Simplified/Enhanced/Continuous DD; publishes several numeric thresholds, including remote KYC triggers | Detailed questionnaire; government ID; remote video identification/interview; beneficial-owner/PEP information | Flagged assets can remain under compliance hold until review is complete. |
A smaller group of partners publishes concrete criterion values. ChangeHero states that Standard Due Diligence applies to occasional transactions of €1,000 or more. On Coincraddle, a transaction with a risk score above 75% may be suspended for EDD, including KYC and source-of-funds checks. Quickex uses an even lower published risk-score threshold of 40%. The policy lists categories including stolen funds, mixers, ransomware, phishing, fraud, sanctions, terrorism financing, and other high-risk activity.
What Information Can Partners Require?
The scope of verification varies almost as much as the triggers. At the basic level, KYC usually starts with personal information and a government-issued identity document. Depending on the partner, accepted documents often include:
- a passport,
- national identity card,
- driver’s license.
Many providers go further by requiring a selfie or liveness test. Liveness verification asks the user to prove that a real person is present during the verification process rather than submitting a stored photograph. EasyBit, for example, describes a selfie matched against the ID, a real-time liveness check, and source-of-funds documentation. Exolix can request a residential address, proof of address, citizenship, government-issued ID, selfie/liveness verification, SoF and SoW documentation, and proof of wallet ownership.
Some partners can also require evidence connecting the customer to the crypto transaction itself. Quickex’s policy can require the user to explain which platform the funds came from, provide screenshots of withdrawal history and blockchain-explorer links, state what service or activity generated the funds, provide the amount and time of the transaction, and submit information or correspondence concerning the sender.
At the other end of the spectrum, some partners describe verification only as an exceptional step. FixedFloat’s normal exchange process does not require registration or routine submission of personal information, although suspicious or prohibited activity can lead to additional checks.
What Happens When a Transaction is Flagged?
Same trigger, different endings
Two partners can both run risk-based KYC and still treat a flagged transaction very differently once the review starts.
- Refund goes to the original address, minus network fees
- Some cases still require KYC before any refund is released
- No response within 30 calendar days — refund is forfeited
- High-risk cases can be frozen for an unset review period
The consequences of an AML flag are quite important because verification may begin after the user has already transferred crypto. The refund rule is almost as important as the KYC trigger itself. Two services can both use risk-based KYC but expose users to very different outcomes once a transaction has been flagged.
A common sequence is the provider receives the deposit, its monitoring system identifies elevated risk, the transaction is suspended, and the user is asked for additional information. The exchange or refund then depends on the outcome of the review.
However, the rules for recovering funds are not consistent. BaltEx states that a user who chooses not to complete KYC will usually be offered a refund to the relevant address, minus network fees. It also warns that in some cases, users won’t get the refund unless KYC has been completed.
Quickex is considerably stricter. Its AML policy states that blocked assets can be returned only after KYC has been completed. If requested information is not provided within 30 calendar days, the policy states that no refund will be made. The review period is determined individually, and high-risk transactions may be frozen for an indefinite period.
Can AML/KYC Reviews Involve Fees?
What an AML/KYC review can cost you
Most reviewed partners charge no separate KYC fee. These four publish a concrete figure in their AML/KYC policy.
Compliance reviews can also affect the amount eventually returned to the user. Most reviewed partners do not publish a special percentage fee simply for undergoing KYC. Several, however, have specific charges connected to compliance cases or KYC-related refunds.
ChangeHero has one of the clearest examples. If a user refuses to complete the requested KYC/AML procedure, ChangeHero terminates the exchange and returns the deposited assets after deducting the network fee and an operational fee of 10% of the transferred assets, with a minimum charge of $100.
n.exchange reserves the right to charge an AML/KYC compliance fee of up to 5% of the submitted funds. Quickex’s AML policy describes a 5% commission on a refund after successful KYC and an additional charge of up to 5% for certain high-risk transactions.
Coincraddle takes the opposite approach. Its AML/KYC policy explicitly states that it does not charge additional fees related to AML procedures and that the user pays only applicable blockchain network fees. The service has a separate processing fee for certain ordinary transaction-error refunds, but that fee is not an AML/KYC charge.
Who Performs KYC and AML Checks?
Several partners identify Sum & Substance Ltd, commonly known as Sumsub, as an identity-verification provider. Sumsub-related arrangements are used by Changelly, ChangeNOW, LetsExchange1, and Swapter. Coincraddle uses AMLBot, but in a different role: transaction and wallet risk scoring. Many other partners simply state that third-party compliance or verification services may be used without identifying the provider. Exolix, for example, refers to authorized third parties and providers of blockchain analytics and compliance services but does not name them.
It becomes more complicated with aggregators. LetsExchange1 and Exolix can expose a user to more than one compliance layer because they route exchanges through third-party providers. A user may therefore satisfy the aggregator’s own checks and still face additional requirements imposed by the provider that actually executes the exchange. Exolix explicitly states that underlying third-party exchanges can request additional documents.
How Long is KYC Data Retained?
Retention policies also vary significantly. Exolix, for example, uses general language. SideShift.ai similarly states that personal information is retained for as long as reasonably necessary. Again, we are working with public information, but a five-year period appears repeatedly in the reviewed documents of other providers. Changelly and n.exchange state that identification information and verification records can be retained for five years under the conditions described in their policies.
EasyBit provides a more detailed distinction. Most transactions, contacts, and personal information can be kept for up to five years. SimpleSwap distinguishes between ordinary and suspicious cases. Its published policy provides for a shorter retention period for ordinary transaction-related end-user data, while information connected with suspicious transactions can be kept for at least five years.
Conclusion
The main difference between partners is not simply whether they require KYC, but how their compliance process works once additional checks are needed. Some publish clear thresholds for triggering verification, while others rely on internal risk assessments. The scope of these checks also varies: verification can range from a basic ID check to source-of-funds evidence, liveness verification, wallet ownership, or additional transaction records.
What happens to a flagged transaction differs as well. Depending on the provider and the reason for the review, funds may be held while verification is completed, returned if the user declines KYC, or remain unavailable until the compliance review is resolved. Most partners do not specify a separate KYC fee, although several policies provide for compliance- or refund-related charges.
Overall, the comparison shows that AML/KYC requirements are best understood as a process rather than a yes-or-no requirement. The key questions are what triggers additional checks, what information may be requested, and what happens to the transaction once a review begins.
LetsExchange was a non-custodial crypto exchange operating from March 2021 to October 1, 2026, when it ceased operations. It supported 6,149+ cryptocurrencies with no registration required. CPO Alex J. cited complex global regulatory requirements. Support remains open through Nov 30, 2026.
official statement posted on X
