Customer Due Diligence Policy (KYC / KYB)

Customer Due Diligence Policy (KYC / KYB)

Public Version

CompanyProsox LLC (incorporated in the State of Delaware, USA)
VersionPublic, Version 1.0
Effective DateAugust 10, 2026
ScopeAll clients of Prosox LLC
Related DocumentsAcceptable Use Policy (AUP); Privacy Policy
This Policy sets out the approach of Prosox LLC (hereinafter, the “Company,” “Prosox”) to client identification and due diligence, sanctions compliance, and the prevention of the use of the Company’s services for unlawful purposes. This document is informational in nature and is published for the benefit of clients and partners. It applies together with the Acceptable Use Policy (AUP) and the Privacy Policy. The Company’s internal procedures, risk-assessment methodologies, and internal forms are not included in this public document.

1. General Provisions and Scope of Application

This Policy establishes a risk-based procedure for the identification and due diligence of Prosox LLC’s clients prior to the commencement of service provision and throughout the entire period of the business relationship.

Objectives of due diligence:

  • to establish and confirm who the client is and who controls it (ultimate beneficial owners);
  • to understand the nature and purpose of the business relationship and the intended use of the services;
  • to screen the client and related parties against sanctions and other watchlists;
  • to prevent the use of the services for money laundering, terrorist financing, sanctions evasion, fraud, and other unlawful activity;
  • to protect the Company’s infrastructure, business reputation, and legal standing.

This Policy applies to all clients of the Company — both legal entities and individuals — and to all Prosox services, including the resale of proxy and IP infrastructure.

2. Standards and Principles

The Company relies on leading international standards and applicable law:

  • FATF Recommendations: the risk-based approach, and customer due diligence (CDD) and enhanced due diligence (EDD);
  • U.S. sanctions law: the jurisdiction in which the Company is incorporated, including OFAC programs and lists;
  • International sanctions regimes: the United Nations, European Union, and United Kingdom (OFSI/HMT) lists;
  • Personal data protection: the GDPR (for EU data subjects), the DIFC Data Protection Law (Dubai), and the legislation of the Republic of Uzbekistan, including data-localization requirements (Law No. ЗРУ-1125);
Prosox is not a financial institution. The Company applies AML/CFT-level standards on a voluntary basis — as a matter of best practice, and to meet sanctions requirements and contractual obligations owed to infrastructure providers. References to specific lists and jurisdictions are dynamic in nature: their current versions are verified as of the date on which the applicable due diligence is performed.

3. Risk-Based Approach

The scope and depth of due diligence are proportionate to the level of risk presented by the client. Each client is assigned a risk level upon onboarding, which is subsequently reviewed and updated.

The Company applies three levels of due diligence:

  • Simplified Due Diligence (SDD): for low-risk clients — a baseline set of information and screening;
  • Customer Due Diligence (CDD): the standard scope — a full set of information, document verification, and screening;
  • Enhanced Due Diligence (EDD): for higher-risk clients — additional documentation, verification of the source of funds, senior-management approval, and enhanced monitoring.

4. When Due Diligence Is Conducted

  • Initial due diligence: conducted prior to the commencement of service provision; services are not activated until the mandatory information has been collected, sanctions screening has been completed, and a risk level has been assigned;
  • Periodic due diligence: client information is updated at intervals depending on the assigned risk level;
  • Event-driven due diligence: conducted upon a material change in the scope of services, detection of suspicious activity, receipt of abuse complaints, a change in ownership structure or use case, an update to sanctions lists, payment anomalies, or a request from a competent authority.

5. Verification of Legal Entities (KYB)

Information requested as a mandatory matter:

  • full company name, country of incorporation, registration number, and registered address;
  • official website and corporate e-mail address;
  • information regarding the company’s representative and that person’s authority.

Depending on the assigned risk level, the Company may additionally request:

  • a Certificate of Incorporation and an extract from the relevant government register;
  • constitutional (organizational) documents and confirmation of the representative’s authority;
  • information on ultimate beneficial owners (UBOs) and the taxpayer identification number;
  • for higher-risk clients — information on the source of funds and the origin of capital.

Verification includes a check against the government register of the country of incorporation, verification of the domain and website, confirmation that the corporate e-mail address corresponds to the company’s official domain, confirmation of the identity and authority of the representative, mapping of the ownership structure down to natural persons, and screening of the company, its representative, and all UBOs against sanctions lists, PEP lists, and adverse media.

6. Verification of Individuals (KYC)

Information requested: a passport or identity document (ID), proof of identity, and contact details; for higher-risk clients — proof of address and information on the source of funds.

Verification includes confirming the authenticity and validity of the documents submitted, as well as screening against sanctions lists, PEP lists, and adverse media. Where onboarding is conducted remotely and the client is higher-risk, additional identity verification is performed without the collection of biometric data: a video call with visual comparison of the client’s face against the photograph in the identity document (without automated facial recognition) and/or proof of address. The Company does not use automated liveness checks or biometric identification.

7. Ultimate Beneficial Owners (UBOs)

The Company identifies the ultimate beneficial owners of a client that is a legal entity:

  • Threshold: a natural person who directly or indirectly owns or controls 25% or more of the shares or voting rights, or who otherwise exercises control;
  • Multi-layered structures: the ownership chain is traced through to the natural persons who are the ultimate beneficiaries;
  • No 25% holder: the Company identifies the person(s) who otherwise exercise control, or, failing that, the senior managing official;
  • Nominees, trusts, and foundations: the Company identifies the settlor, the trustee/manager, and the beneficiaries;
  • Screening: all identified UBOs are screened against sanctions lists, PEP lists, and adverse media.

8. Purpose of Use and Prohibited Uses

Understanding the purpose of use is a key element of due diligence. The client is required to disclose the intended purpose of use of the services, its industry, the websites or services it intends to use, whether it will engage in resale of the services, and whether end users will be involved.

Services are not provided, and are subject to immediate termination, where used for prohibited purposes, including (the list is non-exhaustive):

  • fraud of any kind;
  • credential stuffing and account takeover;
  • carding and payment fraud;
  • DDoS/DoS attacks and other interference with the operation of systems;
  • spam, phishing, malware distribution, and botnet operation;
  • advertising and click fraud;
  • scraping in violation of law or of the terms of use of the target resources;
  • accessing or distributing child sexual abuse material (CSAM);
  • unlawful circumvention of sanctions and geo-blocking;
  • unlawful surveillance and stalking;
  • unauthorized access, hacking, and intrusion into information systems.

Even where the stated purpose is, on its face, permissible, heightened attention is warranted for use cases involving financial institutions, government resources, and login/authentication pages, as well as the mass creation of accounts. Such use cases place the client in the enhanced-risk (EDD) category and may be accompanied by restrictions on target resources and volume limits. The complete list of prohibited uses is set out in the Acceptable Use Policy (AUP).

9. Sanctions Screening

The client, its representative, and all ultimate beneficial owners are screened against sanctions and other lists: OFAC (the SDN List, as well as the consolidated and sectoral U.S. lists), the United Nations, the European Union, the United Kingdom (OFSI/HMT), politically exposed persons (PEP) databases, and adverse media.

Screening is performed during initial due diligence, upon each update to the relevant lists, and periodically in accordance with the assigned risk level. In the event of a true (confirmed) match, the Company declines to provide services or terminates the relationship and acts in accordance with applicable law, including any obligations to notify competent authorities and any restrictions on disclosure of information.

10. Prohibited Clients and Jurisdictions

The Company does not provide services to:

  • persons and entities included on sanctions lists, and persons and entities controlled by them;
  • clients who refuse to provide mandatory information or to disclose their ultimate beneficial owners;
  • clients with prohibited use cases;
  • entities incorporated in jurisdictions subject to comprehensive sanctions.

Approach to jurisdictions:

  • jurisdictions subject to comprehensive sanctions — services are prohibited;
  • FATF “black list” jurisdictions (“call for action”) — services are prohibited;
  • FATF “grey list” jurisdictions (“under increased monitoring”) — treated as enhanced risk, requiring mandatory enhanced due diligence (EDD).

Lists of sanctioned and high-risk jurisdictions are subject to change and are verified against official sources (OFAC, the EU, the UN, OFSI, and FATF publications) as of the date on which due diligence is performed.

11. Enhanced Due Diligence (EDD)

Enhanced due diligence applies to higher-risk clients. Principal risk factors include:

  • resale of the services (reselling, sub-distribution);
  • use of a large number of IP addresses;
  • dealings with government, financial, or cryptocurrency-related services;
  • anonymous or cryptocurrency payments;
  • inconsistent or incomplete information provided;
  • a high-risk jurisdiction;
  • involvement of a politically exposed person (PEP);
  • a complex or non-transparent ownership structure;
  • a prior history of abuse.

Enhanced due diligence measures include requesting additional documents and information, verifying the source of funds, obtaining senior-management approval, enhanced monitoring, restrictions on target resources and volume limits, and prepayment or deposit requirements.

12. Politically Exposed Persons (PEPs)

A politically exposed person (PEP) is a person who is or has been entrusted with a prominent public function, together with that person’s family members and close associates. PEPs are automatically assigned an elevated risk level: mandatory enhanced due diligence (EDD), senior-management approval to establish and continue the relationship, verification of the source of funds, and enhanced monitoring.

13. Ongoing Monitoring

Following onboarding, the Company conducts behavioral monitoring for anomalies and indicators of abuse, periodically refreshes client information in accordance with the assigned risk level, conducts rescreening upon updates to sanctions lists, and, where applicable, monitors the further use of the services by resellers’ end users.

14. Protection of Personal Data

The Company’s handling of personal data is governed by the Privacy Policy. With respect to client due diligence, the following principles apply:

  • Purpose limitation: data is collected solely for compliance and due-diligence purposes;
  • Data minimization: only the necessary scope of data is requested;
  • Legal basis: for clients located in the EU/EEA, processing is carried out primarily on the basis of the Company’s legitimate interest (Art. 6(1)(f) GDPR), subject to a balancing-of-interests test; Art. 6(1)(c) applies with respect to obligations genuinely applicable to the Company;
  • Security: access restrictions, encryption, and secure data storage;
  • Localization: Law No. ЗРУ-1125 applies to data subjects and processing in the Republic of Uzbekistan; the Company does not collect biometric or genetic data in the course of client due diligence;
  • Data subject rights: afforded in accordance with applicable law.

15. Record Retention

The Company retains information and documents obtained in the course of due diligence for no longer than is necessary for the purposes for which they were collected, in accordance with the storage-limitation principle (Art. 5(1)(e) GDPR). The specific retention period is determined based on:

  • the limitation period applicable to protect the Company against potential claims and disputes;
  • sanctions-compliance record-retention requirements: a five-year retention period applies to information and documents relating to sanctions screening and to blocked or rejected transactions, in accordance with OFAC’s record-retention rules;
  • contractual obligations owed to infrastructure providers;
  • the requirements of applicable law.

Upon expiry of the applicable retention period, data is deleted or anonymized. During the retention period, data is held securely with restricted access.

16. Right to Refuse, Suspend, and Terminate

Prosox reserves the right to refuse to provide services, to request additional documents, to suspend the provision of services, or to terminate the relationship, including, in particular, where:

  • required information or documents are not provided, or inaccurate information or documents are provided;
  • a true (confirmed) match against sanctions lists is identified;
  • a prohibited use case is identified;
  • suspicious activity is detected or an unacceptable level of risk is identified;
  • the client refuses to undergo periodic or ad hoc due diligence.

Suspension and termination are carried out subject to the terms of the applicable agreement.

17. Policy Updates and Contacts

This Policy is reviewed at least once a year, and on an ad hoc basis in the event of changes in applicable law or in the Company’s business model. Document version control is maintained.

For questions relating to this Policy, please contact Prosox LLC’s compliance function at: support@prosox.io