Defy Travel Rule is a self-hosted Travel Rule node and operator console. Share IVMS101 identity data with other VASPs and run Türkiye and European Union policy.
# PostgreSQL, backend, UI and gateway in one command
Defy Travel Rule is an open-source Travel Rule Protocol (TRP) node that a virtual asset service provider (VASP) runs inside its own environment. It exchanges originator and beneficiary identity data in the IVMS101 format with counterparty VASPs over mutually authenticated TLS, evaluates versioned policy profiles for Türkiye (MASAK) and the European Union (Transfer of Funds Regulation) before sending anything, and gives compliance teams an operator interface to review inquiries and cases. The node never holds assets and never broadcasts blockchain transactions.
Everything a VASP needs to run Travel Rule exchanges on its own terms.
Exchange inquiries, inquiry responses and confirmations with counterparty VASPs over the Travel Rule Protocol.
Evaluate the Türkiye and European Union policy profiles before anything leaves over the protocol.
Review transfers, inquiries, messages, tokens, events and compliance cases in an authenticated interface.
Protocol attempts, retries, dead-letter states, audit history and signed webhook delivery records are persisted in PostgreSQL.
Browser, internal API, database and external mTLS traffic run on separated surfaces.
Run the complete stack with Docker Compose and keep regulated data in your own environment.
Your custody or KYT system stays in charge of assets. The node handles identity exchange and compliance.
Your custody or KYT system sends the transfer to the versioned API with a scoped API key and can run a preflight check first.
The matching policy profile checks required party fields, fiat valuation and sanctions signals, then stores an immutable decision snapshot.
The node sends a protocol inquiry carrying IVMS101 data to the counterparty VASP over TLS and mTLS, then processes the inquiry response and confirmation.
Compliance teams review the case when needed, and your systems receive the outcome through HMAC-signed webhooks.
Browser traffic, partner protocol traffic, internal services and stored data each run in their own isolated layer.
Deployment at a glance
Local browser access
Mutually authenticated TLS
Sign-in, case and inquiry review
Peer authentication and the protocol allowlist
Authentication, orchestration and APIs
Transfers, cases and audit history
Two explicit, versioned profiles decide what must be collected and shared before a transfer leaves your node.
Rules built for Türkiye's MASAK Travel Rule requirements for crypto asset service providers.
Rules built for the EU Transfer of Funds Regulation (TFR) for crypto-asset transfers.
Regulated identity data gets the protection it needs at every layer.
Sensitive fields are stored in AES-256-GCM envelopes; the keyring supports key rotation and background re-encryption.
Each audit event is chained to the previous one with SHA-256, and case exports recompute the chain.
Five fixed roles, optional two-person approval for high-risk cases and immediate session revocation on role changes.
Logs and error records strip bodies, emails, secrets, tokens and keys before they are written.
Digest-pinned images run as non-root, read-only containers; the database is never published to the host.
OIDC tokens from your identity provider are optionally accepted; authorization stays in the node's own database.
Each team sees exactly what it needs.
Users, configuration, API clients and key management
Transfers, messages, tokens and delivery health
Inquiry and case review
Final decisions on high-risk cases
Read-only access to activity and cases
Docker Compose brings up the database, backend, console, gateway, local certificates and a local administrator together.
git clone https://github.com/getdefy-co/travel-rule.git
cd travel-ruledocker compose up --build --waitOpen the console in your browser and sign in with the local administrator described in the README.
The default administrator and generated certificates are for local development only. Production deployments need managed secrets, production PKI, backups and monitoring. Current version requirements and install notes live in the repository.
No. The node only exchanges identity data and compliance decisions. Your custody system keeps control of assets, and the fact that a transfer took place is reported through the versioned API.
It implements the Travel Rule Protocol (TRP) directly. Identity data is handled in IVMS101 format and shared with counterparty VASPs over mTLS.
Defy licenses the repository's original code and documentation under the Apache License 2.0. Review the NOTICE and third-party notices before redistribution.
In your own environment. The whole stack, including PostgreSQL, runs on your infrastructure, and the database is only reachable on an internal Docker network.
Yes. Community support is best-effort through GitHub. Contact our team for production deployment, integration and compliance support.
Explore the source code, or talk to us about deploying Defy Travel Rule in production.