Yocto Capitals — Legal
Compliance & security
Last updated June 24, 2026
Yocto Capitals is built money-first: controls are enforced in the service layer where the money moves, not bolted on at the edge. This page summarizes our approach to verification, approvals, data protection and platform security.
Regulatory status
This website is operated by Yocto Capitals LLC. Yocto Capitals is authorized by the Financial Services Commission (FSC) in Mauritius with registration number 189726 and Investment Dealer (Full Service Dealer, Excluding Underwriting) license number GB202451602.
Registered office: 8th Floor, NEXSKY Building, Ebène Cybercity, Quatre Bornes 72249, Mauritius.
Know Your Customer (KYC)
Access to deposits and withdrawals is gated on identity verification. Applicants submit identity documents, proof of address, a selfie, and structured personal details, which a compliance reviewer assesses before approving the account.
- Personal data is encrypted at rest the moment it is submitted.
- Only an authorized reviewer can decrypt a profile, and only for review.
- The money surface stays locked until verification is approved.
Anti-Money-Laundering (AML) controls
Money movement is layered with controls that make abuse expensive and reviewable: per-tier rolling-24h withdrawal limits, configurable cool-down windows between requests, and server-authoritative caps on every deposit and withdrawal.
Two-person approval
Withdrawals at or above a configurable threshold require two distinct approvers. Approvals are recorded individually, so a single operator physically cannot satisfy both — the payout step re-verifies the approval count before any funds settle.
Data protection & encryption
Sensitive fields — KYC personal data, two-factor secrets and withdrawal destinations — are encrypted at rest with AES-256-GCM. We store ciphertext, never plaintext, and decrypt only server-side for an authorized purpose.
Operational security
The platform is hardened end to end: distributed rate limiting on authentication and money endpoints, CSRF protection on every mutation, short-rotation httpOnly session cookies, and idempotent financial operations so retries never double-spend.
Auditability
Privileged actions are written to an append-only audit log, and every balance is derived from an immutable double-entry ledger. The complete history of any account can be reconstructed and proven from the transaction record.
This page is provided for general information and does not constitute legal, tax or investment advice.