Ripple Custody integrates with Notabene to enable Travel Rule compliance for digital asset transfers. This integration automates the exchange of required customer information between Virtual Asset Service Providers (VASPs) during transactions.
Travel Rule compliance is available in Ripple Custody v1.30 and later.
When you send or receive digital assets above certain thresholds, regulators require you to exchange customer information with the counterparty. This is the Travel Rule — FATF Recommendation 16 — and it applies to VASPs globally.
Without Travel Rule compliance:
- Transactions may be blocked or delayed by counterparties
- Your organization risks regulatory penalties
- You cannot operate in jurisdictions with strict Travel Rule enforcement
Ripple Custody handles this automatically through its Notabene integration, so your transactions flow smoothly while meeting regulatory requirements.
A VASP (Virtual Asset Service Provider) is any business providing custody, exchange, or transfer services for digital assets. VASPs must exchange customer information for transactions above regulatory thresholds.
Notabene operates a global network connecting VASPs for Travel Rule compliance. When you send assets to another VASP on the network, Notabene facilitates the secure exchange of required information. Your organization is identified on this network by a DID (Decentralized Identifier)—a unique identifier like did:web:your-domain.com.
Customer information is exchanged using the IVMS-101 standard (Inter-VASP Messaging Standard). This includes:
- Natural persons: Name, address, date of birth
- Legal entities: Business name, registration number, address
- Account information: Wallet addresses, account identifiers
How PII flows depends on the transfer direction:
- Outgoing transfers: You collect the required PII and submit it through the Ripple Custody API, which forwards it to Notabene. You have two options:
- Append (plaintext submission): Submit PII in IVMS-101 format. Notabene encrypts it with keys that Notabene manages and stores it on both your Notabene entity and the beneficiary's.
- Present (pre-encrypted submission): Encrypt the PII yourself for end-to-end encryption. Notabene's end-to-end encryption uses ECDH-ES key agreement with the beneficiary VASP's public key from its DIDdoc and AES-256-GCM content encryption, and the encrypted payload is a JWE. Notabene can't read the payload. It forwards it to the beneficiary, and only the beneficiary side stores it. See Send assets with PII.
- Incoming transfers: The originator's VASP sends the Travel Rule message, including any PII, to your VASP in Notabene. Ripple Custody polls Notabene only for the message status to decide whether to release quarantined funds. The PII payload never transits Ripple Custody; your compliance team reviews it in Notabene.
Ripple Custody does not store or encrypt PII.
Travel Rule compliance integrates with existing transaction workflows in Ripple Custody:
For outgoing transactions:
- Create a Travel Rule message with counterparty information
- If PII is required, submit it through the API
- Create a transfer intent using the returned
suggestedIntentId - System screens the transaction for risk, then runs the Travel Rule check (a screening failure skips the Travel Rule check)
- Transaction executes when both checks pass
Follow this order. Create the Travel Rule message first, then the intent. Ripple Custody doesn't create a Notabene transfer from a transfer intent that has no Travel Rule message.
For incoming transactions:
- Indexer detects incoming transfer
- System quarantines the funds pending compliance checks
- System looks up the Travel Rule message that the originator's VASP sent to your VASP in Notabene, matching it by transaction hash
- System polls the message status and releases the quarantined funds when checks pass
Ripple Custody evaluates both risk screening and Travel Rule results. The strictest outcome determines the final decision:
| Combined Result | Decision |
|---|---|
| Both pass | AUTO_APPROVED — Transaction executes |
| Either flagged | FLAGGED — Manual review required |
| Either rejected | AUTO_REJECTED — Transaction blocked |
| Blockchain | Native Asset | CAIP-19 Identifier |
|---|---|---|
| Bitcoin | BTC | bip122:000000000019d6689c085ae165831e93/slip44:0 |
| Ethereum | ETH | eip155:1/slip44:60 |
| XRP Ledger | XRP | xrpl:mainnet/slip44:144 |
| Polygon | MATIC | eip155:137/slip44:966 |
| Stellar | XLM | stellar:pubnet/slip44:148 |
| Solana | SOL | solana:mainnet/slip44:501 |
| TRON | TRX | tron:mainnet/slip44:195 |
For tokens, use the format: {chain}/erc20:{contractAddress} (ERC-20), solana:mainnet/spl:{address} (SPL), or stellar:pubnet/asset:{code}:{issuer} (Stellar).
- Register with Notabene — Complete VASP registration and KYB verification
- Configure credentials — Connect your Notabene account by submitting your API credentials directly through the Ripple Custody API (you never share credentials with Ripple)
- Confirm address registration — Ripple Custody registers your existing wallet addresses with Notabene when you connect your account, and registers each new wallet when you create it
For detailed setup instructions, see Travel Rule setup.
For transaction workflows with API examples, see Travel Rule API.
| Term | Definition |
|---|---|
| VASP | Virtual Asset Service Provider — a business providing custody, exchange, or transfer services |
| DID | Decentralized Identifier — unique identifier for VASPs on Notabene (e.g., did:web:domain.com) |
| DIDdoc | DID Document — contains public keys for PII encryption and VASP discovery |
| IVMS-101 | Inter-VASP Messaging Standard — structured format for customer data exchange |
| PII | Personally Identifiable Information — customer data required for Travel Rule |
| CAIP-19 | Chain Agnostic Identifier Protocol — standard for identifying assets across blockchains |
| FATF | Financial Action Task Force — international body setting AML/CFT standards |
| Recommendation 16 | FATF guidance requiring VASPs to exchange originator/beneficiary information |
Travel Rule requirements vary by jurisdiction. This documentation provides technical guidance only. Consult legal counsel for regulatory advice.
- Transaction screening: Configure risk thresholds with Chainalysis or Elliptic
- Compliance overview: How screening and Travel Rule work together
- Policies: Create governance policies for compliance workflows