We Are Not an Obligated Party, and That Is Load-Bearing for Anyone Buying From Us

We hold no Turkish financial registration or licence of any kind. Nothing here is legal advice.

The question a Turkish institution should ask first

Not what a vendor's product does. What the vendor is, in the regulator's classification.

Turkey's financial-crime regime places obligations on defined categories of business: banks, financial institutions, crypto-asset service providers, payment institutions and others. Those parties owe identification duties, record-keeping, reporting and supervision.

Everyone else is a supplier, and a supplier's relationship to the regime is entirely different.

Why "not regulated" cuts both ways, honestly

In your favour: you are not taking on a counterparty whose own supervisory problems become yours, and there is no licence of ours whose withdrawal interrupts your operations.

Against us: there is no supervisor examining what we do. Nobody inspects our controls, nobody reviews our procedures, and there is no regulatory record for you to check.

A buyer should read that second point as a real cost. Some of what you would normally get from a supervised counterparty, you have to obtain from us directly through diligence, contract and testing, because no authority is doing it on your behalf.

What we can and cannot evidence

We cannot evidence a compliance programme. No registration, no supervisory relationship, no independent audit, no certification of any kind. We have written that plainly on the security page rather than leaving it to be discovered.

What is already done, and what we can evidence, is technical: what the pipeline checks, what it retains and for how long, when deletion runs, what the credential discloses and what it withholds. Those are properties you or your auditor can examine directly rather than take on trust.

That is the trade. You get a supplier you can inspect and no supervisor inspecting them for you.

The specific thing worth knowing about the Turkish rules

The regime here is unusually concrete in one respect: for remote identification of foreign nationals it names the method rather than describing an outcome, which removes the usual argument about whether an approach is equivalent to something.

That works in a buyer's favour when evaluating any vendor, including us, because it converts a sales conversation into a technical question: does this implementation do the named thing correctly. We have written that up separately, including the two places our own claim has to stop.

What to ask any vendor selling into this market

"What is your regulatory classification here?" Obligated party or supplier. The answer changes everything about the relationship, and many vendors answer as though the distinction did not exist.

"Which of my obligations do you discharge?" The correct answer is none. A vendor claiming otherwise is offering something it cannot deliver.

"Who supervises you?" If nobody, say so, and expect the buyer to do more of their own diligence as a result. For us the answer is nobody.

"What can I verify myself rather than take on trust?" With an unsupervised supplier this is the list that matters, and it should be a long one.

Where this leaves a decision

If your requirement is a supervised counterparty with a registration you can check, we are not that and no part of our roadmap makes us that.

If your requirement is a supplier whose technical behaviour you can examine directly, who reduces what the identity leg costs, and who is explicit that your obligations remain entirely yours, that is what this is, and the absence of a supervisor is the thing to price in rather than overlook.

Keep reading

We Are Not an Obligated Party, and That Is Load-Bearing for Anyone Buying From Us · Solidus