Blog

Regulatory analysis and compliance intelligence for founders and compliance teams — BOI, GDPR, MiCA, crypto forensics, and compliance program structure, written by practicing attorneys.

Corporate Compliance

BOI Filing Guide: Beneficial Ownership Information Report (2025)

Who must file, what information is required, filing deadlines, the 23 exemptions, and penalties for non-compliance.

Privacy & Data

GDPR Compliance Checklist for SaaS Startups (2025)

Legal bases for processing, privacy notices, data processor agreements, breach notification, and international transfers — all 7 phases.

Crypto Regulation

MiCA Regulation: What Crypto Startups Must Do

CASP authorization requirements, token whitepaper rules, ART/EMT obligations, and MiCA extraterritorial reach for non-EU companies.

Compliance Strategy

Fractional CCO vs Compliance Retainer: Which Do You Need?

Cost comparison, use-case matrix, and when each model fits — for pre-Series B teams with real compliance obligations but not enough for a full-time hire.

Crypto Forensics

How to Investigate a Crypto Wallet: Forensic Analysis Guide

What on-chain forensics reveals, when to commission a blockchain investigation, what data sources are used, and how to use wallet reports for legal proceedings.

Compliance Posture

Compliance Health Score for SaaS Startups: What It Means

What a compliance health score measures, why enterprise customers ask for it, which frameworks it covers, and how to improve your score before an audit.

Security & Compliance

SOC 2 Compliance Checklist for SaaS Startups (2025)

Type I vs Type II, the five Trust Service Criteria, what auditors collect as evidence, the timeline from zero to report, and the controls most SaaS companies are missing.

Crypto Compliance

AML & KYC Compliance Checklist for Crypto Companies (2025)

FATF Travel Rule implementation, FinCEN MSB registration, EU AMLD obligations, transaction monitoring red flags, and the AML program components regulators require.

Crypto Licensing

VARA Licensing Guide: Getting Licensed in Dubai for Crypto (2025)

VARA license categories, capital requirements, the three-stage application process, mandatory insurance, and how VARA compares to MiCA and ADGM for crypto businesses.

AI Regulation

EU AI Act Compliance Guide for SaaS & AI Companies (2025)

Article 6 + Annex III risk classification, GPAI model obligations, the 10 high-risk system requirements, conformity assessment, and the 2026-08-02 deadline — for SaaS founders and AI product teams.

Privacy Law

India DPDPA Compliance Guide for B2B SaaS (2025)

Does DPDPA apply to you? Notice + consent requirements, data principal rights, Significant Data Fiduciary criteria, and the ₹250 crore fine schedule — for SaaS with India-resident users.

Privacy & Data

Privacy Policy Compliance Guide for SaaS Startups (2025)

7 frameworks, 6 policy sections, 6 events that make your policy stale immediately. GDPR, CCPA, CPRA, Quebec Law 25, Colorado, Connecticut, Texas DPSA. Real enforcement cases, real fines.

Tax Compliance

Marketplace Tax & 1099-K Compliance Guide for Platforms (2025)

1099-K threshold drops to $600 in 2025. Platform-by-platform reporting rules, marketplace facilitator laws in 45 states, and the per-form penalty schedule for getting it wrong.

AI Regulation

AI Governance Framework Guide for SaaS & Enterprises (2025)

NIST AI RMF vs ISO/IEC 42001 vs EU AI Act: who needs what, the 6-component governance program, the 8 high-risk use cases, and penalty comparison across all three frameworks.

Contracts

Contract Risk Analysis Guide: 7 Red Flags in Every Vendor Agreement (2025)

Unlimited liability, unilateral modification, auto-renewal traps, perpetual data license grants. The 7 clauses that destroy startups — and the counter-position for each.

Security & Compliance

ISO 27001 vs SOC 2: Which Does Your SaaS Startup Need? (2025)

ISO 27001 takes 9-18 months and costs $40-80K. SOC 2 takes 4-9 months and costs $20-50K. Which one enterprise customers actually require — and when you need both.

Compliance Strategy

Startup Compliance Program Guide: When You Need One and How to Build It (2025)

6 triggers that make a compliance program non-negotiable. 7 program components. 4 staffing models. The 12-month compliance calendar every fintech founder needs.

Healthcare Privacy

HIPAA Compliance Checklist for Healthcare SaaS (2025)

The three HIPAA rules, Business Associate Agreement requirements, ePHI technical safeguards, breach notification timelines, and the 2024 HIPAA Safe Harbor for cybersecurity frameworks.

EU Financial Regulation

DORA Compliance Guide for ICT Vendors and EU Financial Entities (2025)

Five DORA pillars, Article 30 contract checklist (audit rights, incident notification, exit strategies), 4h/72h/1-month incident reporting, CTPP designation, and TLPT obligations.

US Securities Law

SEC Crypto Compliance Guide for Token Issuers and Web3 Startups (2025)

Howey Test token classification, Reg D / Reg S / Reg CF exemptions, SAFT structures, broker-dealer registration triggers, and the post-Ripple SEC enforcement landscape for crypto founders.

Payment Security

PCI DSS Compliance Guide for SaaS Startups (2025)

Merchant level tiers, SAQ A vs SAQ D scope, PCI DSS v4.0 changes (script integrity, MFA requirements), tokenization scope reduction, and what your merchant service agreement says about breach liability.

US Commodities Law

CFTC Crypto Regulation Guide: Commodity vs Security Classification (2025)

CFTC jurisdiction over Bitcoin and Ethereum, crypto derivatives exchange registration (DCM, SEF), ECP requirements, CFTC enforcement record (BitMEX, Binance), and the FIT21 digital commodity framework.

Privacy & Data

GDPR Data Processing Agreement (DPA) Guide: Article 28 Requirements (2025)

The 12 mandatory DPA terms under Article 28 GDPR, controller-processor role analysis, sub-processor chain management, SCC integration for international transfers, and enterprise DPA negotiation strategy.

US Financial Regulation

FinCEN MSB Registration Guide for Crypto and Fintech Startups (2025)

When your crypto exchange, wallet, or payments product qualifies as a Money Services Business, FinCEN Form 107 registration, state money transmitter licenses, VASP/Travel Rule obligations, and criminal penalties for unregistered operation.

Contract Risk

SaaS Vendor Agreement Review Guide: What to Check Before Signing (2025)

Uncapped liability exposure, broad AI training data rights, auto-renewal traps, IP ownership of work product, uptime SLA gaps, and termination rights — the 10 highest-risk clauses in SaaS vendor agreements and how to negotiate each one.

Contract Risk

NDA Review Guide: Red Flags and What to Negotiate Before Signing (2025)

One-way vs mutual NDAs, overbroad confidentiality scope, perpetual duration, residuals clauses, uncapped liquidated damages, permitted disclosure gaps, and the 8 provisions every legal team should check before signing a non-disclosure agreement.

Employment Law

Independent Contractor Agreement Guide: Avoiding Misclassification (2025)

The ABC test (California AB5), IRS 20-factor test, UK IR35, and EU Platform Work Directive — misclassification penalties and the 5 contractor agreement clauses that most often trigger reclassification findings.

Contract Risk

Terms of Service Compliance Guide for SaaS Startups (2025)

FTC Click-to-Cancel rule (2024), limitation of liability caps, DMCA safe harbor registration, class action waiver enforceability, EU Digital Services Act obligations, and clickwrap vs. browsewrap assent — the 14 ToS provisions every SaaS company must address.

Privacy Law

CCPA / CPRA Compliance Checklist for SaaS Startups (2025)

CCPA applicability thresholds ($25M revenue / 100K consumers), 6 consumer rights (including CPRA right to correct and sensitive PI limits), service provider DPA requirements, GPC signal compliance, and CPPA $7,500-per-violation enforcement powers.

Incident Response

Data Breach Response Guide: Notification Timelines and Legal Obligations (2025)

GDPR 72-hour supervisory authority notification, HIPAA 60-day breach reporting, CCPA breach obligations, 50-state notification laws (30-90 day patchwork), DPA breach clauses, and the first 72-hour legal response playbook.

Intellectual Property

IP Assignment Agreement Guide: Who Owns Code, Inventions, and Work Product (2025)

Work-for-hire doctrine only covers 9 statutory categories — standalone software is not one of them. Employee PIIA requirements, contractor IP assignment clauses, co-founder IP gaps that kill Series A due diligence, and the timing of execution relative to when work begins.

Intellectual Property

Open Source License Compliance Guide for SaaS (2025): GPL, AGPL, MIT, Apache 2.0

Does AGPL require you to open-source your SaaS product? GPL copyleft propagation, MIT vs Apache 2.0 patent clauses, LGPL dynamic linking rules, SSPL and BSL source-available licenses, and the SBOM compliance program every SaaS company needs before acquisition diligence.

Crypto Regulation

UK FCA Crypto Compliance Guide (2025): Financial Promotions, VASP Registration, PSR Travel Rule

UK Financial Promotions Regime for crypto (October 2023), mandatory risk warning text, Section 21 approval process, FCA VASP/MLR registration, PSR Travel Rule (all transfers, no threshold), incentives ban, 24-hour cooling-off period, and comparison with EU MiCA.

Privacy & Data

EU-US Data Transfer Guide (2025): SCCs, DPF, UK IDTA, and Schrems II Compliance

EU-US Data Privacy Framework (DPF) 2023 — valid but under Schrems III challenge. Standard Contractual Clauses 2021 (Module 2 for SaaS), Transfer Impact Assessments, UK IDTA and UK Data Bridge, Binding Corporate Rules, and the practical fallback strategy if DPF is invalidated again.

Startup Law

Equity Compensation Guide for Startups (2025): ISO vs NSO, 409A, QSBS, 83(b) Election

Incentive Stock Options vs Non-Qualified Stock Options (ordinary income vs long-term capital gains), 409A safe harbor valuation requirements, QSBS Section 1202 $10M exclusion, the 30-day 83(b) election window, and the vesting red flags every startup employee should identify before signing.

Contract Law

SaaS MSA Guide for Vendors (2025): Drafting Your Customer Agreement

Limitation of liability caps as a % of ARR, IP indemnification carve-outs, SLA credit caps and exclusive remedy clauses, DPA/GDPR Article 28 requirements, auto-renewal price escalation rights, and how to respond to the 8 most common enterprise legal team redlines.

Crypto Regulation

Crypto Token Launch Compliance Guide (2025): Howey Test, Reg D, SAFT, MiCA

Whether your token is a security (Howey test), Reg D 506(c) accredited investor exemption, Reg S offshore exemption, the SAFT framework and why it fails as a legal shield, MiCA whitepaper requirements for EU launches, utility token myths, and the jurisdictions favored for compliant 2025 token launches.

Employment Law

Startup Employment Agreement Guide (2025): At-Will, PIIA, Non-Competes, Worker Classification

At-will employment and its exceptions, the 6 required PIIA provisions (and why "agrees to assign" is weaker than "hereby assigns"), non-compete enforceability by state (void in California, Minnesota, Oklahoma, and North Dakota), the IRS 20-factor test for W-2 vs 1099 misclassification, and the offer letter provisions that preserve at-will status.

Fintech Compliance

Payment Processing Compliance Guide (2025): Chargebacks, High-Risk Merchants, MSB, PCI DSS

Visa (0.9% VDMP) and Mastercard (1.5% ECM) chargeback thresholds and MATCH-listing consequences, payment facilitator vs merchant of record legal liability, high-risk merchant category codes, FinCEN MSB registration triggers, PCI DSS SAQ scope for SaaS, and cross-border OFAC screening and VAT/GST obligations.

Crypto Regulation

DAO Legal Structure Guide (2025): Wyoming DAO LLC, Marshall Islands, Unincorporated DAO Risks

Why an unincorporated DAO is a general partnership (bZx DAO, Ooki DAO precedents), Wyoming DAO LLC SF 0038 formation requirements, Marshall Islands DAO LLC comparison, SEC investment contract risk for governance tokens, DAO operating agreement required provisions, and the tax obligations of DAO members.

Startup Law

Venture Capital Term Sheet Guide (2025): Liquidation Preferences, Anti-Dilution, Pro-Rata, Drag-Along

1× non-participating vs participating preferred (and why participation matters more than valuation in median exits), broad-based weighted average vs full-ratchet anti-dilution, pro-rata and super pro-rata rights, drag-along thresholds, the option pool shuffle, founder vesting acceleration, and the 5 Series A closing documents and what each one governs.

Privacy & Data

Data Retention and Deletion Policy Guide (2025): GDPR Article 17, CCPA, HIPAA, Litigation Holds

GDPR Article 17 right to erasure (when you can refuse and when you cannot), CCPA deletion request 45-day deadline and 9 exemptions, HIPAA 6-year minimum retention vs GDPR conflict, building a data retention schedule by category, litigation hold obligations when legal proceedings are anticipated, and the 3 common gaps that expose SaaS companies to enforcement.

AI Compliance

AI Vendor Due Diligence Guide (2025): EU AI Act Deployer Obligations, GDPR Article 22, AI Contract Provisions

EU AI Act deployer obligations (FRIA, human oversight, log retention, worker notification), GDPR Article 22 automated decision-making restrictions, AI vendor contract provisions to demand (data training prohibition, model cards, bias testing, exit rights, sub-processor disclosure), algorithmic impact assessments, AI disclosure requirements, and the 10-question AI vendor procurement framework.

Consumer Protection

SaaS Billing Compliance Guide (2025): FTC Click-to-Cancel Rule, Automatic Renewal Laws, EU Omnibus Directive

FTC Click-to-Cancel Rule requirements (effective January 2025), California ARL affirmative consent and 30-day renewal notice, New York automatic renewal statute, EU Omnibus Directive 30-day prior price disclosure for discounts, CFPB unfair billing enforcement patterns (Adobe $13M, Peloton $19.2M, Amazon $25M), free trial to paid conversion disclosure requirements, and subscription agreement drafting to satisfy all frameworks simultaneously.

HIPAA Compliance

HIPAA Business Associate Agreement Guide (2025): 9 Required Provisions, SaaS Vendor Templates, Cloud Provider BAAs

Who qualifies as a covered entity vs business associate, 9 required BAA provisions under 45 C.F.R. §164.504(e)(2), OCR enforcement actions for missing BAAs (OHSU $2.7M, North Memorial $1.55M, Anthem $16M), what a SaaS vendor BAA must include beyond the minimum, cloud provider BAA coverage (AWS, Azure, Google Cloud), and the 30-point BAA review checklist for covered entities.

Employment Law

Non-Compete Agreement Guide (2025): State Enforcement Map, FTC Rule Update, California SB 699, Non-Solicitation Alternatives

Non-compete enforceability by state (California void / SB 699 applies nationwide, Minnesota void 2023, Florida employer-favorable, Texas blue-pencil), FTC rule blocked by federal court, California AB 1076 notification obligation, 5 drafting errors that void enforcement, garden leave vs non-compete, non-solicitation enforceability when non-compete fails, and founder/VC non-compete drafting in M&A and investment contexts.

Crypto Tax

Cryptocurrency Tax Compliance Guide (2025): IRS Virtual Currency Rules, Cost Basis, DeFi Staking Income, Form 1099-DA

IRS treats crypto as property (Notice 2014-21) — every trade, swap, and payment is taxable. Cost basis methods (FIFO vs Specific Identification), staking rewards as ordinary income (Rev. Rul. 2023-14), DeFi and liquidity pool tax treatment, Form 1099-DA broker reporting starting 2025, FBAR obligations for offshore exchange accounts, and 7 common crypto tax errors that trigger IRS audits.

GDPR & Privacy

GDPR Legitimate Interests Guide (2025): Legitimate Interests Assessment (LIA), B2B Direct Marketing, Right to Object

GDPR Article 6(1)(f) legitimate interests is the most misused legal basis. How to conduct a 3-part LIA balancing test, when B2B direct marketing can rely on legitimate interests (vs B2C where consent is required), EDPB guidance on using legitimate interests for profiling and analytics, the absolute right to object to direct marketing under Article 21, and the 6 LIA mistakes that create DPA enforcement risk.

Security Compliance

SOC 2 Type I vs Type II Guide (2025): Trust Service Criteria, Audit Timeline, How to Read a Vendor SOC 2 Report

SOC 2 Type I is a point-in-time assessment; Type II proves controls operated over 6-12 months — and enterprise buyers require Type II. The 5 Trust Service Criteria and what auditors actually test in each, readiness timeline and cost (13-22 months to first Type II report), how to read a vendor's SOC 2 report including exceptions and carve-outs, and SOC 2 vs ISO 27001 comparison.

Contract Law

Software Development Agreement Guide (2025): IP Ownership, Work-for-Hire, Source Code Escrow, Acceptance Testing

Paying for software development does not transfer IP ownership — the developer owns the code by default under US copyright law. Work-for-hire doctrine does not cover standalone software created by contractors. IP assignment must use present-tense language ("hereby assigns"), cover all IP categories, and include a defined Background IP carve-out. Plus: acceptance testing frameworks, open source GPL/AGPL contamination risk, source code escrow triggers, and 5 dangerous red flags in developer agreements.

Financial Crime Prevention

Wire Transfer Fraud Prevention Guide (2025): Business Email Compromise (BEC), Financial Fraud Kill Chain, Legal Liability

BEC caused $2.9 billion in 2023 US losses — the highest-loss cybercrime category. Under UCC Article 4A, the business that sends the fraudulently-induced wire bears the loss, not the bank. The 5 BEC attack vectors (CEO impersonation, vendor payment change, real estate hijacking, attorney impersonation, payroll diversion), the 72-hour Financial Fraud Kill Chain response, cyber insurance BEC requirements, and vendor contract provisions that create BEC risk.

M&A & Corporate

M&A Legal Due Diligence Guide (2025): IP Audit, Data Privacy, Employment, Change-of-Control, and Representation & Warranty Insurance

The 8 most common deal-killing findings in technology M&A: IP chain-of-title gaps, open source contamination, worker misclassification, PIIA deficiencies, undisclosed regulatory exposure, data privacy violations, change-of-control triggers in material contracts, and option plan administration errors. IP diligence data room requirements, data privacy due diligence scope, employment law M&A issues, COC provisions management, and RWI policy structure.

GDPR & Privacy

GDPR Data Subject Rights & DSAR Response Guide (2025): 30-Day Deadline, Exemptions, Identity Verification, and Operational Process

8 GDPR data subject rights taxonomy (which are absolute vs conditional), the 1-month response deadline (3-month extension conditions), proportionate identity verification without creating unnecessary barriers, Article 15 DSAR response content requirements (all 9 elements), 12 Article 23 exemption categories, and how to build an operational DSAR process (intake, data mapping, templates, records).

GDPR & Privacy

GDPR Cookie Consent & ePrivacy Guide (2025): Valid Consent, Strictly Necessary Exemption, Google Analytics, IAB TCF, and PECR

Cookie consent governed by ePrivacy Directive (PECR in UK) + GDPR — both apply. CJEU Planet49 consent standard (no pre-ticked boxes, no "browsing as consent"), 7 cookie categories with consent requirements, Google Analytics DPF compliance update (post-Austrian DSB decisions), IAB TCF vs custom CMP, strictly necessary exemption (session cookies/security tokens qualify; analytics/social sharing do NOT), and UK PECR post-Brexit divergence.

EU AI Act & AI Regulation

EU AI Act High-Risk AI Systems Guide (2025): Annex III Categories, Conformity Assessment, CE Marking, QMS, and GPAI Obligations

The 8 EU AI Act Annex III high-risk categories (biometrics, critical infrastructure, education, employment/HR screening, essential services/credit scoring, law enforcement, migration, administration of justice), conformity assessment routes (internal vs notified body), Article 17 QMS requirements, compliance timeline (Feb 2025/Aug 2025/Aug 2026), provider vs deployer obligation split, and GPAI model systemic risk obligations for models trained above 10^25 FLOPs.

Employment Law

Independent Contractor vs Employee Classification Guide (2025): IRS 20-Factor Test, California ABC Test (AB5), FLSA DOL 2024 Rule, and Misclassification Liability

Worker misclassification guide: IRS 20-factor behavioral/financial/relationship test, California Dynamex ABC test and AB5, FLSA DOL 2024 Final Rule 6-factor economic reality test, PAGA penalties, 5 high-risk contractor patterns that trigger misclassification (exclusive engineers, data labelers, sales contractors, fractional roles, content creators), and remediation options (prospective conversion, IRS VCSP, PAGA cure under AB 2288 2024 reform).

Fintech / Payments

Regulation E Electronic Fund Transfer Compliance Guide for Fintech (2025): Error Resolution, Unauthorized EFT Liability, P2P Platforms, Provisional Credit

CFPB Regulation E compliance guide for fintech, neobanks, and P2P payment platforms: error resolution procedures (10-business-day provisional credit rule, 45-day investigation limit), unauthorized EFT consumer liability tiers ($0/$50/$500/unlimited based on notification timing), P2P platform obligations under Reg E, required account-opening disclosures, 60-day statement rule, and CFPB enforcement priorities for P2P platforms.

Securities Law

Regulation D Private Placement Exemption Guide (2025): Rule 506(b) vs 506(c), Accredited Investor Definition, General Solicitation, Form D Filing

Regulation D compliance for startup fundraising: Rule 506(b) vs 506(c) comparison (general solicitation prohibition, verification requirements), 2020 accredited investor definition expansion (Series 7/65/82, knowledgeable employees), Form D 15-day filing deadline and EDGAR mechanics, state blue sky preemption and notice filings, bad actor disqualification under Rule 506(d), and the integration safe harbor doctrine.

Security / SOC 2

SOC 2 Trust Services Criteria Deep Dive (2025): CC6 Logical Access, CC7 System Operations, CC8 Change Management, CC9 Vendor Risk, Auditor Evidence Requirements

SOC 2 Trust Services Criteria technical guide: all 5 Trust Services Categories, CC6 logical access controls (MFA, access provisioning/deprovisioning, vendor access, privileged access management), CC7 system operations and incident management, CC8 change management PR review and emergency change controls, CC9 vendor management and business continuity, Type 1 vs Type 2 distinctions, and exact auditor evidence samples for each criterion.

HIPAA / Health Tech

HIPAA Security Rule Technical Safeguards Guide (2025): § 164.312 Encryption, Audit Controls, Person Authentication, Transmission Security for SaaS

HIPAA Security Rule § 164.312 technical safeguards for SaaS business associates: access control (unique user IDs, emergency access, automatic logoff, AES-256 at-rest encryption), audit controls (6-year log retention, SIEM, immutable logs), integrity controls, person authentication (MFA / NIST AAL2), transmission security (TLS 1.2+/TLS 1.3), OCR enforcement patterns and penalty tiers, 2023 NPRM proposed changes (MFA Required, encryption Required, quarterly vulnerability scans), and HIPAA / SOC 2 dual-compliance approach.

Privacy & Data

CCPA/CPRA Data Subject Request Operations Guide (2025): 45-Day Response, Opt-Out of Sale/Sharing, GPC Signal, Sensitive Personal Information, Enforcement

CCPA/CPRA DSR operations guide for SaaS companies: 45-day response deadline and verification tiers, right to know / delete / correct / opt-out / limit SPI, Global Privacy Control (GPC) signal compliance (mandatory under 11 CCR § 7025), authorized agent procedures, employee and B2B exemption expiration (January 2023), AB 2370 right-to-cure elimination (January 2025), Sephora $1.2M enforcement, CPPA enforcement authority, and service provider vs business classification for B2B SaaS.

Privacy & Data

Cross-Border Data Transfer Guide (2025): SCCs Module Selection, Transfer Impact Assessment, UK IDTA, EU-US DPF Adequacy Decision, BCRs for Multinational Groups

GDPR Chapter V cross-border transfer mechanisms: 2021 EU SCCs Module 1/2/3/4 selection (Controller-Controller, Controller-Processor, Processor-Processor, Processor-Controller), Transfer Impact Assessment (TIA) 6-step EDPB methodology (FISA 702, supplementary technical measures), UK IDTA and ICO Addendum to EU SCCs post-Brexit, EU-US Data Privacy Framework (DPF) adequacy decision (July 2023) and Schrems III risk, BCR-Controller and BCR-Processor for intra-group transfers, and 2010 SCC expiration (December 27, 2024).

Consumer Protection

FTC Section 5 Unfair and Deceptive Practices Guide for SaaS (2025): Dark Patterns, Click-to-Cancel Rule, Data Security Enforcement, COPPA, Multi-Regulator Coordination

FTC Act Section 5 guide for SaaS and fintech: unfairness (substantial injury, not outweighed, consumer cannot avoid) vs deception (material misrepresentation, reasonable consumer standard); dark patterns enforcement (Amazon Prime $25M, Vonage $100M, Epic Games $520M); Negative Option Rule click-to-cancel (16 CFR Part 425, effective January 2025); FTC data security enforcement (Drizly personal liability, CafePress $500K, Wyndham); COPPA for children's apps (TikTok $5.7M, YouTube $170M, Fortnite $275M); FTC/CFPB/state AG coordination.

AML / FinCEN

AML/BSA Compliance Program Guide for Fintech and Neobanks (2025): 5 Pillars, CDD Rule, SAR Filing, CTR Requirements, Structuring Prohibition, FinCEN Enforcement

Bank Secrecy Act 5-pillar program requirements (31 USC § 5318), FinCEN CDD Final Rule (31 CFR § 1010.230) beneficial ownership 4-element framework, SAR thresholds ($2K MSBs/$5K banks) and 30/60-day deadlines, CTR $10K threshold and aggregation rules, structuring prohibition (31 USC § 5324), FinCEN enforcement (Capital One $390M, BitMEX $100M, Coinbase $50M), and virtual asset VASP AML obligations.

OFAC / Sanctions

OFAC Sanctions Compliance Guide for Crypto, Fintech, and B2B SaaS (2025): SDN List, 50% Rule, Blocking vs Rejecting, Voluntary Self-Disclosure, Virtual Currency Enforcement

OFAC SDN screening, the 50% Rule for indirectly blocked entities, blocking vs rejecting procedures (10-day reporting), voluntary self-disclosure (VSD) and 50% penalty mitigation, civil penalty calculation (egregious vs non-egregious), crypto enforcement (Bittrex $29M, Poloniex $7.6M, Tornado Cash SDN designation), 5-element compliance program, secondary sanctions, and NYDFS BitLicense sanctions requirements.

SaaS / Contracts

SaaS Terms of Service Deep Dive (2025): Limitation of Liability Cap, Indemnification Carve-Outs, Warranty Disclaimers, AUP, Auto-Renewal Compliance, and Governing Law Strategy

SaaS ToS clause-by-clause analysis: LoL cap (12-month fee formula, mutual vs asymmetric, floor for new contracts), indemnification (IP vendor obligations + carve-outs, customer data indemnification), UCC § 2-316 warranty disclaimers (merchantability/fitness magic words, AS IS conspicuousness), AUP CFAA (Van Buren 2021, post-termination access, data scraping), FTC click-to-cancel rule (Jan 2025), California ARL, Delaware vs New York vs California governing law.

Need compliance support beyond what a post can provide?

Scan a Contract — $97