Verification checklist
- ✓Does the license number resolve as active in the regulator's own public register, and does its scope cover crypto assets?
- ✓Does the registered entity named in the terms of service exactly match the entity the license and registry record are issued to?
- ✓Is the reserve proof issued recurringly by a named independent auditor, or just a self-published screenshot?
- ✓Are KYC tiers and withdrawal limits actually enforced in the product, not just written in the terms?
1. "Compliant" is a claim — separate marketing copy from verifiable evidence
Homepages routinely say "regulated," "licensed," or "certified by X," and legally these statements are almost always self-reported claims, not something the regulator itself has confirmed. Verifiable evidence generally falls into three categories. First, the license itself — the issuing authority, license number, business scope, and validity period, all of which should, in principle, be searchable in that regulator's public register. Second, entity information — the registered jurisdiction, registration number, and legal representative or beneficial owner, which can typically be checked against that jurisdiction's public company registry. Third, third-party attestations — reserve proofs, penetration test reports, and similar documents that should trace back to a named issuing organization rather than a screenshot the platform laid out itself. Anything labeled "compliant" that cannot be traced to one of these three verifiable categories should be treated as an unverified claim, not an established fact.
2. Verifying the license: does the number, jurisdiction, and scope actually line up
The first step is finding the issuing regulator's public register — most financial regulators, whether for money-service licenses, payment-institution licenses, or virtual-asset-service-provider licenses, maintain a searchable list where entering a license number or company name returns whether that entry's status is "active." The second step is checking that the jurisdiction the badge represents matches the entity you're actually onboarding with — some platforms display a well-known jurisdiction's license badge, but a closer look shows the license is held by an affiliated company, not the legal entity your account and deposits actually go through. This "license-badging" pattern shows up more often among offshore exchanges than one might expect. The third step is scope: many money-service or currency-exchange licenses don't inherently cover crypto-asset custody or trading, so if the badge's license type doesn't actually match the crypto trading, custody, or lending services the platform provides, that mismatch itself is a signal worth chasing down — "has a license" does not automatically mean "the business it's running is covered by it."
3. Verifying the registered entity: is the terms-of-service counterparty the licensed one
A license number checking out doesn't mean the entity users actually contract with is the licensed one. Group-structured exchanges commonly operate multiple legal entities that separately handle regulatory compliance, technical operations, and the user agreement you click "accept" on — and that agreement's counterparty may be an affiliate registered in a very different, more permissive jurisdiction than the licensed entity shown on the compliance page. The verification method: open the terms of service and find the exact counterparty name and registration number stated in the contract, then cross-check that name and number against the public company registry for that jurisdiction to confirm the company actually exists, is in active standing, and matches what the site discloses; then compare that contracting entity against the licensed entity shown elsewhere on the site — if they differ, work out the relationship between the two and, more importantly, who is actually accountable if something goes wrong.
4. Reserve proofs and custody structure: who holds the assets, how often is it audited
Proof of Reserves has become a common trust signal, but its credibility varies enormously, and there are at least three things to check. First, who issues it — a reserve proof from a credentialed independent auditor is meaningfully more credible than a number the platform compiles and publishes itself. Second, what it actually covers — a snapshot that only confirms an asset balance at one point in time, without also confirming the liabilities side (what users are collectively owed), cannot demonstrate the platform can actually make users whole; a meaningful reserve proof discloses both assets and liabilities and states a reserve ratio. Third, frequency and freshness — a one-time reserve proof only reflects the state on the day it was issued, and an ongoing platform should refresh it on a recurring basis (quarterly is common); a reserve proof that hasn't been updated in a long time loses relevance fast. Separately, verify the custody structure itself: are user assets held by the platform directly, or by an independent third-party custodian — the latter can, in principle, provide an added layer of asset segregation if the platform itself runs into trouble, though the actual strength of that segregation still depends on how the local jurisdiction's law treats client assets.
5. KYC tiers and withdrawal limits: does the compliance posture actually reach the product
One practical way to sanity-check whether a compliance claim is real is to see whether the stated KYC tier system actually governs the product. A properly built platform enforces tiered identity verification, systematically limiting daily or monthly withdrawal amounts for accounts that haven't completed higher-tier verification — and that limit should be enforced at the product level, not just written into terms that never actually trigger. A few concrete checks: does the terms page or help center state exact withdrawal-limit numbers tied to each verification tier; does attempting a withdrawal near that stated limit without completing higher-tier verification actually get blocked by the system; and do independent user reports from forums or communities about actual withdrawal limits match what the terms describe. A platform whose terms are detailed but whose limits are never actually enforced in practice is often more worth worrying about than a platform with no KYC system at all — the detailed-but-unenforced version is more likely to lull a user into a false sense of protection.
6. Using a go-global navigation site to find your starting points
The first obstacle to doing the checks above usually isn't "not knowing how to look it up" — it's "not knowing where to start looking." Regulator registers, company registries, and third-party auditor directories for different jurisdictions are scattered across dozens of separate sites, and hunting them down individually takes real time. chdh.me is one example of this kind of tool — the site describes itself as a navigation directory for going-global tools and resources, aggregating entry points across categories that include compliance lookups, company registration, and cross-border services, which in principle could serve as a starting point for finding the regulator registers and company-registry search tools referenced in the sections above, saving some of the time spent searching for each one individually. To be clear, this description is drawn solely from the site's own self-reported positioning — it is a third-party directory and makes no determination about the compliance status of any site or platform it links to. The accuracy, freshness, and reliability of any individual resource it points to still needs to be verified independently using the methods in Sections 2 through 5 above; this article offers no endorsement or guarantee of the directory or anything it lists.
7. Summary and verification checklist
- "Licensed" and "compliant" are claims, not evidence — evidence is what you can independently confirm in a regulator's register, a company registry, or a named auditor's records.
- Check license validity, whether the jurisdiction matches the actual operating entity, and whether the license's scope covers crypto assets.
- Check whether the contracting entity in the terms of service is the same legal entity the license was issued to.
- Check whether reserve proofs are independently issued, cover both assets and liabilities, and are refreshed on a recurring basis.
- Verify KYC tiers and withdrawal limits are actually enforced in the product, not just written into terms.
- Use a go-global navigation site to save time finding entry points, but still verify each individual resource using the methods above — the directory doesn't replace the check itself.
Frequently asked: is a regulatory badge on the homepage trustworthy? Not on its own — take the license number to the regulator's own public register and confirm it's active. Are reserve proofs and audit reports the same thing? No — a reserve proof by itself only reflects an asset balance; a meaningful version discloses liabilities too and states a reserve ratio, ideally from an independent issuer. What if KYC tiers seem unenforced? Detailed terms paired with withdrawals that never actually get blocked is a signal worth cross-checking against independent community reports. This article is for learning and research purposes only and does not constitute investment advice; choosing an offshore exchange carries compliance, legal, and asset-security risk, so please make your own judgment and take responsibility for your own decisions.