Skip to content

Ripple Custody integrates with Notabene to enable Travel Rule compliance for digital asset transfers. This integration automates the exchange of required customer information between Virtual Asset Service Providers (VASPs) during transactions.

Travel Rule compliance is available in Ripple Custody v1.30 and later.

Why Travel Rule matters

When you send or receive digital assets above certain thresholds, regulators require you to exchange customer information with the counterparty. This is the Travel Rule — FATF Recommendation 16 — and it applies to VASPs globally.

Without Travel Rule compliance:

  • Transactions may be blocked or delayed by counterparties
  • Your organization risks regulatory penalties
  • You cannot operate in jurisdictions with strict Travel Rule enforcement

Ripple Custody handles this automatically through its Notabene integration, so your transactions flow smoothly while meeting regulatory requirements.

Key concepts

VASPs and the Notabene network

A VASP (Virtual Asset Service Provider) is any business providing custody, exchange, or transfer services for digital assets. VASPs must exchange customer information for transactions above regulatory thresholds.

Notabene operates a global network connecting VASPs for Travel Rule compliance. When you send assets to another VASP on the network, Notabene facilitates the secure exchange of required information. Your organization is identified on this network by a DID (Decentralized Identifier)—a unique identifier like did:web:your-domain.com.

IVMS-101 data format

Customer information is exchanged using the IVMS-101 standard (Inter-VASP Messaging Standard). This includes:

  • Natural persons: Name, address, date of birth
  • Legal entities: Business name, registration number, address
  • Account information: Wallet addresses, account identifiers

PII handling

How PII flows depends on the transfer direction:

  • Outgoing transfers: You collect the required PII and submit it through the Ripple Custody API, which forwards it to Notabene. You have two options:
    • Append (plaintext submission): Submit PII in IVMS-101 format. Notabene encrypts it with keys that Notabene manages and stores it on both your Notabene entity and the beneficiary's.
    • Present (pre-encrypted submission): Encrypt the PII yourself for end-to-end encryption. Notabene's end-to-end encryption uses ECDH-ES key agreement with the beneficiary VASP's public key from its DIDdoc and AES-256-GCM content encryption, and the encrypted payload is a JWE. Notabene can't read the payload. It forwards it to the beneficiary, and only the beneficiary side stores it. See Send assets with PII.
  • Incoming transfers: The originator's VASP sends the Travel Rule message, including any PII, to your VASP in Notabene. Ripple Custody polls Notabene only for the message status to decide whether to release quarantined funds. The PII payload never transits Ripple Custody; your compliance team reviews it in Notabene.

Ripple Custody does not store or encrypt PII.

How it works

Travel Rule compliance integrates with existing transaction workflows in Ripple Custody:

Pass

Fail

Customer Request

Compliance Service

Transaction Screening
(Chainalysis/Elliptic)

Travel Rule
(Notabene)

Combined Decision

Transaction Execution

Pass

Fail

Customer Request

Compliance Service

Transaction Screening
(Chainalysis/Elliptic)

Travel Rule
(Notabene)

Combined Decision

Transaction Execution

For outgoing transactions:

  1. Create a Travel Rule message with counterparty information
  2. If PII is required, submit it through the API
  3. Create a transfer intent using the returned suggestedIntentId
  4. System screens the transaction for risk, then runs the Travel Rule check (a screening failure skips the Travel Rule check)
  5. Transaction executes when both checks pass

Follow this order. Create the Travel Rule message first, then the intent. Ripple Custody doesn't create a Notabene transfer from a transfer intent that has no Travel Rule message.

For incoming transactions:

  1. Indexer detects incoming transfer
  2. System quarantines the funds pending compliance checks
  3. System looks up the Travel Rule message that the originator's VASP sent to your VASP in Notabene, matching it by transaction hash
  4. System polls the message status and releases the quarantined funds when checks pass

Compliance decisions

Ripple Custody evaluates both risk screening and Travel Rule results. The strictest outcome determines the final decision:

Combined ResultDecision
Both passAUTO_APPROVED — Transaction executes
Either flaggedFLAGGED — Manual review required
Either rejectedAUTO_REJECTED — Transaction blocked

Supported blockchains

BlockchainNative AssetCAIP-19 Identifier
BitcoinBTCbip122:000000000019d6689c085ae165831e93/slip44:0
EthereumETHeip155:1/slip44:60
XRP LedgerXRPxrpl:mainnet/slip44:144
PolygonMATICeip155:137/slip44:966
StellarXLMstellar:pubnet/slip44:148
SolanaSOLsolana:mainnet/slip44:501
TRONTRXtron:mainnet/slip44:195

For tokens, use the format: {chain}/erc20:{contractAddress} (ERC-20), solana:mainnet/spl:{address} (SPL), or stellar:pubnet/asset:{code}:{issuer} (Stellar).

Getting started

  1. Register with Notabene — Complete VASP registration and KYB verification
  2. Configure credentials — Connect your Notabene account by submitting your API credentials directly through the Ripple Custody API (you never share credentials with Ripple)
  3. Confirm address registration — Ripple Custody registers your existing wallet addresses with Notabene when you connect your account, and registers each new wallet when you create it

For detailed setup instructions, see Travel Rule setup.

For transaction workflows with API examples, see Travel Rule API.

Glossary

TermDefinition
VASPVirtual Asset Service Provider — a business providing custody, exchange, or transfer services
DIDDecentralized Identifier — unique identifier for VASPs on Notabene (e.g., did:web:domain.com)
DIDdocDID Document — contains public keys for PII encryption and VASP discovery
IVMS-101Inter-VASP Messaging Standard — structured format for customer data exchange
PIIPersonally Identifiable Information — customer data required for Travel Rule
CAIP-19Chain Agnostic Identifier Protocol — standard for identifying assets across blockchains
FATFFinancial Action Task Force — international body setting AML/CFT standards
Recommendation 16FATF guidance requiring VASPs to exchange originator/beneficiary information

Travel Rule requirements vary by jurisdiction. This documentation provides technical guidance only. Consult legal counsel for regulatory advice.


Next steps