Compliance
How Arena approaches data protection, financial-crime prevention and international operations — with honesty about what is in place today and what is on the roadmap.
Last updated: 12 June 2026
Our approach
Arena is designed for cross-border, high-value transactions. That means compliance is core, not cosmetic — and we are transparent about our current maturity.
Transparency note
Arena is a maturing platform. Regulated financial activity is delegated to licensed partners. Where a certification is in progress rather than complete, we say so plainly.
Data protection (GDPR)
- Lawful bases mapped to every processing purpose (see Privacy Policy).
- Data minimisation and role-based access enforced across operations.
- Data Processing Addendum available for business customers.
- Data-subject rights honoured within statutory timeframes.
AML & KYC
Anti-money-laundering and know-your-customer checks are performed through our regulated payment partner, which is licensed to carry out these obligations.
- Identity verification
- Performed when an operation requires funds to be released.
- Sanctions & PEP screening
- Handled by the regulated payment partner.
- Record-keeping
- Operation and verification records retained to meet AML obligations.
Regulated financial partners
Custody and movement of funds are provided by a licensed payment-infrastructure institution. Arena coordinates the operation and never holds client money directly. This independent model keeps regulated activity with the party licensed to perform it.
Sub-processors
We work with a small, vetted set of sub-processors, each under a data-processing agreement.
| Sub-processor | Role | Region |
|---|---|---|
| Payment-infrastructure partner | Custody, KYC, payouts | International |
| Resend | Transactional email delivery | EU / US |
| Cloud & object storage | Hosting and encrypted document storage | EU |
| Sentry | Error monitoring | EU / US |
The current list is available on request via the Trust Center.
Certifications & roadmap
- GDPR-aligned data handling — in place.
- Encryption in transit and at rest — in place.
- Formal information-security certification (e.g. SOC 2 / ISO 27001) — on the roadmap.
- Independent penetration testing — planned as the platform scales.
Honest status
We do not claim certifications we have not achieved. This page will be updated as each milestone is reached.
Related documents
Questions about this document? Our team is here to help.
