Regulated, compliant, and transparent from the ground up
Legacy28 Global operates as a VARA-regulated Virtual Asset Broker-Dealer and Asset-Referenced Virtual Asset Issuer within the DMCC Free Zone. KYC is mandatory before any account activity — enforced at the contract level, not just the application layer.
| Framework | Status |
|---|---|
| VARA (Virtual Assets Regulatory Authority, Dubai) | VARA-regulated Virtual Asset Broker-Dealer and Asset-Referenced Virtual Asset Issuer. Licenced to issue and broker digital assets representing real-world asset exposure. DMCC Free Zone, Dubai. |
| UAE Federal Decree-Law No. 4 of 2022 | Compliant with UAE federal virtual asset legislation establishing the legal basis for VARA authority over digital asset activities across the Emirate of Dubai. |
| UAE AML/CTF Legislation | Full AML/CTF programme. Appointed MLRO. Connected to UAE FIU goAML system for STR filing. |
| FATF Recommendations | Framework aligned with FATF Recommendations for VASPs, including Travel Rule (Recommendation 16). |
| DMCC Free Zone Requirements | Incorporated and licensed within DMCC. Annual compliance filings and corporate governance standards maintained. |
| Identity Verification (Third-Party Provider) | Production-tier identity verification with biometric capture, document verification, and ongoing monitoring. Sanctions and PEP screening on onboarding and on the documented periodic cadence. |
| Chain Analytics (Third-Party Provider) | Institutional-tier chain analytics. Inbound and outbound wallet screening on every transaction. Wallet risk scoring, exposure tracing, and investigative tooling. |
| Smart Contract Audit | Pre-launch audit on every Participation Token contract, identity registry contract, bridge contract, and custom compliance hook by an institutional-grade audit firm. |
- ✓Government-issued identity document (passport, Emirates ID, or national equivalent)
- ✓Liveness check — real-time biometric verification
- ✓Proof of address dated within 3 months
- ✓Sanctions screening — OFAC, UN Security Council, EU, UAE local sanctions lists
- ✓PEP screening at onboarding and recurring basis
- ✓Adverse media screening — automated, regulatory enforcement history
- ✓Real-time AML transaction monitoring, 24 hours a day
- ✓Sanctions screening on every transaction, not just at onboarding
- ✓Daily automated reconciliation of all participant records and escrow positions
- ✓Annual independent external audit of all platform operations
- ✓Immutable on-chain audit record anchored daily
- ✓STR reporting to UAE FIU through goAML
Every onboarded counterparty and wallet is screened against the consolidated lists of the United Nations Security Council, the U.S. Office of Foreign Assets Control (OFAC), the European Union, the United Kingdom, and the local terrorism-finance list. The lists are refreshed at least once every business day and the full active population is re-screened on each refresh.
Every Participation Token is an ERC-3643 security token with the full T-REX identity stack (OnchainID identity contracts, identity registry, claim-topics registry, trusted-issuers registry). Transfers are gated at the token level by verified on-chain identity.
Compliance, audit, and transaction records are retained for at least eight years and are available to the Internal Auditor on a read-only basis.
For compliance questions, contact compliance@28legacy.com
Scope Notice: VARA regulation applies within the jurisdiction of the Dubai emirate. The platform's regulatory status does not constitute compliance certification in any other jurisdiction. Participants are solely responsible for understanding whether virtual asset participation is permitted under the laws of their own jurisdiction. The platform does not provide financial, investment, legal, or tax advice.