# Travel Rule compliance

Ripple Custody integrates with [Notabene](https://notabene.id/) to enable Travel Rule compliance for digital asset transfers. This integration automates the exchange of required customer information between Virtual Asset Service Providers (VASPs) during transactions.

Travel Rule compliance is available in Ripple Custody v1.30 and later.

## Why Travel Rule matters

When you send or receive digital assets above certain thresholds, regulators require you to exchange customer information with the counterparty. This is the Travel Rule — FATF Recommendation 16 — and it applies to VASPs globally.

Without Travel Rule compliance:

- Transactions may be blocked or delayed by counterparties
- Your organization risks regulatory penalties
- You cannot operate in jurisdictions with strict Travel Rule enforcement


Ripple Custody handles this automatically through its Notabene integration, so your transactions flow smoothly while meeting regulatory requirements.

## Key concepts

### VASPs and the Notabene network

A **VASP** (Virtual Asset Service Provider) is any business providing custody, exchange, or transfer services for digital assets. VASPs must exchange customer information for transactions above regulatory thresholds.

[Notabene](https://notabene.id/) operates a global network connecting VASPs for Travel Rule compliance. When you send assets to another VASP on the network, Notabene facilitates the secure exchange of required information. Your organization is identified on this network by a **DID** (Decentralized Identifier)—a unique identifier like `did:web:your-domain.com`.

### IVMS-101 data format

Customer information is exchanged using the **IVMS-101** standard (Inter-VASP Messaging Standard). This includes:

- **Natural persons**: Name, address, date of birth
- **Legal entities**: Business name, registration number, address
- **Account information**: Wallet addresses, account identifiers


### PII handling

How PII flows depends on the transfer direction:

- **Outgoing transfers**: You collect the required PII and submit it through the Ripple Custody API, which forwards it to Notabene. You have two options:
  - **Append (plaintext submission)**: Submit PII in IVMS-101 format. Notabene encrypts it with keys that Notabene manages and stores it on both your Notabene entity and the beneficiary's.
  - **Present (pre-encrypted submission)**: Encrypt the PII yourself for end-to-end encryption. Notabene's end-to-end encryption uses ECDH-ES key agreement with the beneficiary VASP's public key from its DIDdoc and AES-256-GCM content encryption, and the encrypted payload is a JWE. Notabene can't read the payload. It forwards it to the beneficiary, and only the beneficiary side stores it. See [Send assets with PII](/pt-br/products/custody/compliance/travel-rule/outgoing-with-pii).
- **Incoming transfers**: The originator's VASP sends the Travel Rule message, including any PII, to your VASP in Notabene. Ripple Custody polls Notabene only for the message *status* to decide whether to release quarantined funds. The PII payload never transits Ripple Custody; your compliance team reviews it in Notabene.


Ripple Custody does not store or encrypt PII.

## How it works

Travel Rule compliance integrates with existing transaction workflows in Ripple Custody:

```mermaid
flowchart TD
    Request["Customer Request"]
    Compliance["Compliance Service"]
    Screening["Transaction Screening<br/>(Chainalysis/Elliptic)"]
    TravelRule["Travel Rule<br/>(Notabene)"]
    Decision["Combined Decision"]
    Execute["Transaction Execution"]

    Request --> Compliance
    Compliance --> Screening
    Screening -->|Pass| TravelRule
    Screening -->|Fail| Decision
    TravelRule --> Decision
    Decision --> Execute
```

For **outgoing transactions**:

1. Create a Travel Rule message with counterparty information
2. If PII is required, submit it through the API
3. Create a transfer intent using the returned `suggestedIntentId`
4. System screens the transaction for risk, then runs the Travel Rule check (a screening failure skips the Travel Rule check)
5. Transaction executes when both checks pass


Follow this order. Create the Travel Rule message first, then the intent. Ripple Custody doesn't create a Notabene transfer from a transfer intent that has no Travel Rule message.

For **incoming transactions**:

1. Indexer detects incoming transfer
2. System quarantines the funds pending compliance checks
3. System looks up the Travel Rule message that the originator's VASP sent to your VASP in Notabene, matching it by transaction hash
4. System polls the message status and releases the quarantined funds when checks pass


### Compliance decisions

Ripple Custody evaluates both risk screening and Travel Rule results. The strictest outcome determines the final decision:

| Combined Result | Decision |
|  --- | --- |
| Both pass | `AUTO_APPROVED` — Transaction executes |
| Either flagged | `FLAGGED` — Manual review required |
| Either rejected | `AUTO_REJECTED` — Transaction blocked |


## Supported blockchains

| Blockchain | Native Asset | CAIP-19 Identifier |
|  --- | --- | --- |
| Bitcoin | BTC | `bip122:000000000019d6689c085ae165831e93/slip44:0` |
| Ethereum | ETH | `eip155:1/slip44:60` |
| XRP Ledger | XRP | `xrpl:mainnet/slip44:144` |
| Polygon | MATIC | `eip155:137/slip44:966` |
| Stellar | XLM | `stellar:pubnet/slip44:148` |
| Solana | SOL | `solana:mainnet/slip44:501` |
| TRON | TRX | `tron:mainnet/slip44:195` |


For tokens, use the format: `{chain}/erc20:{contractAddress}` (ERC-20), `solana:mainnet/spl:{address}` (SPL), or `stellar:pubnet/asset:{code}:{issuer}` (Stellar).

## Getting started

1. **Register with Notabene** — Complete VASP registration and KYB verification
2. **Configure credentials** — Connect your Notabene account by submitting your API credentials directly through the Ripple Custody API (you never share credentials with Ripple)
3. **Confirm address registration** — Ripple Custody registers your existing wallet addresses with Notabene when you connect your account, and registers each new wallet when you create it


For detailed setup instructions, see [Travel Rule setup](/pt-br/products/custody/compliance/travel-rule/setup).

For transaction workflows with API examples, see [Send assets without PII](/pt-br/products/custody/compliance/travel-rule/outgoing-no-pii), [Send assets with PII](/pt-br/products/custody/compliance/travel-rule/outgoing-with-pii), and [Receive assets with Travel Rule](/pt-br/products/custody/compliance/travel-rule/incoming).

## Glossary

| Term | Definition |
|  --- | --- |
| **VASP** | Virtual Asset Service Provider — a business providing custody, exchange, or transfer services |
| **DID** | Decentralized Identifier — unique identifier for VASPs on Notabene (e.g., `did:web:domain.com`) |
| **DIDdoc** | DID Document — contains public keys for PII encryption and VASP discovery |
| **IVMS-101** | Inter-VASP Messaging Standard — structured format for customer data exchange |
| **PII** | Personally Identifiable Information — customer data required for Travel Rule |
| **CAIP-19** | Chain Agnostic Identifier Protocol — standard for identifying assets across blockchains |
| **FATF** | Financial Action Task Force — international body setting AML/CFT standards |
| **Recommendation 16** | FATF guidance requiring VASPs to exchange originator/beneficiary information |


Travel Rule requirements vary by jurisdiction. This documentation provides technical guidance only. Consult legal counsel for regulatory advice.

## Next steps

- [Transaction screening](/pt-br/products/custody/compliance/transaction-screening/concept): Configure risk thresholds with Chainalysis or Elliptic
- [Compliance overview](/pt-br/products/custody/compliance): How screening and Travel Rule work together
- [Policies](/pt-br/products/custody/governance/policies): Create governance policies for compliance workflows