Compliance & Security
LYRIA is registered with FINTRAC as a Money Services Business and operates a compliance and security posture built around ongoing monitoring, not a one-time check.
Regulatory standing
Risk & compliance program
AML Program
A documented Anti-Money Laundering program covering risk assessment, ongoing transaction monitoring, and recordkeeping consistent with FINTRAC requirements for Money Services Businesses.
KYC / Identity Verification
Customers and merchants are identity-verified before onboarding, with risk-based due diligence applied according to transaction profile.
Sanctions Screening
Transactions and counterparties are screened against applicable sanctions and watch lists on an ongoing basis, not only at onboarding.
Regulatory Reporting
Recordkeeping and reporting obligations are met on an ongoing basis as a registered Money Services Business.
Security model
Encryption
Data is encrypted in transit using TLS 1.2+ and at rest. Cardholder data is tokenized and never stored in raw form.
PCI-DSS Level 1 scope
Covers the full lifecycle of cardholder data handling — the highest compliance tier defined by the PCI Security Standards Council.
Fraud Monitoring
Transactions are screened against fraud signals, velocity rules, and behavioral patterns prior to authorization.
Access Control
Access to production systems and payment data is role-based, logged, and reviewed on a recurring basis.
Incident Response
A documented process governs detection, containment, and disclosure in the event of a security incident.
Responsible Disclosure
Security researchers can report a suspected vulnerability to security@lyria.one.