Defy
Open source · Apache-2.0

Your own Travel Rule node.Self-hosted, open source.

Defy Travel Rule is a self-hosted Travel Rule node and operator console. Share IVMS101 identity data with other VASPs and run Türkiye and European Union policy.

Start the stack

# PostgreSQL, backend, UI and gateway in one command

Native protocol
TRP
Identity data standard
IVMS101
Peer authentication
TLS + mTLS
Never holds or moves assets
Zero custody

What is Defy Travel Rule?

Defy Travel Rule is an open-source Travel Rule Protocol (TRP) node that a virtual asset service provider (VASP) runs inside its own environment. It exchanges originator and beneficiary identity data in the IVMS101 format with counterparty VASPs over mutually authenticated TLS, evaluates versioned policy profiles for Türkiye (MASAK) and the European Union (Transfer of Funds Regulation) before sending anything, and gives compliance teams an operator interface to review inquiries and cases. The node never holds assets and never broadcasts blockchain transactions.

Why Defy Travel Rule

Everything a VASP needs to run Travel Rule exchanges on its own terms.

Native TRP interoperability

Exchange inquiries, inquiry responses and confirmations with counterparty VASPs over the Travel Rule Protocol.

Policy-aware orchestration

Evaluate the Türkiye and European Union policy profiles before anything leaves over the protocol.

Operator workflows

Review transfers, inquiries, messages, tokens, events and compliance cases in an authenticated interface.

Reliable delivery

Protocol attempts, retries, dead-letter states, audit history and signed webhook delivery records are persisted in PostgreSQL.

Secure boundaries

Browser, internal API, database and external mTLS traffic run on separated surfaces.

Self-hosted control

Run the complete stack with Docker Compose and keep regulated data in your own environment.

How a transfer moves through the node

Your custody or KYT system stays in charge of assets. The node handles identity exchange and compliance.

  1. 1

    Submit the transfer

    Your custody or KYT system sends the transfer to the versioned API with a scoped API key and can run a preflight check first.

  2. 2

    Evaluate the policy

    The matching policy profile checks required party fields, fiat valuation and sanctions signals, then stores an immutable decision snapshot.

  3. 3

    Exchange with the peer

    The node sends a protocol inquiry carrying IVMS101 data to the counterparty VASP over TLS and mTLS, then processes the inquiry response and confirmation.

  4. 4

    Review and notify

    Compliance teams review the case when needed, and your systems receive the outcome through HMAC-signed webhooks.

Built with clear boundaries

Browser traffic, partner protocol traffic, internal services and stored data each run in their own isolated layer.

Deployment at a glance

Operator browser
Counterparty VASP

Local browser access

Mutually authenticated TLS

Gateway
Operator console
Application service
DatabaseEncrypted at rest
  • Operator consoleInternal only

    Sign-in, case and inquiry review

  • Protocol gatewayOpen to counterparty VASPs over mTLS

    Peer authentication and the protocol allowlist

  • Internal servicesNot reachable from outside

    Authentication, orchestration and APIs

  • Data layerInternal network only

    Transfers, cases and audit history

Policy profiles for Türkiye and the EU

Two explicit, versioned profiles decide what must be collected and shared before a transfer leaves your node.

Türkiye

MASAK profile

Rules built for Türkiye's MASAK Travel Rule requirements for crypto asset service providers.

European Union

EU TFR profile

Rules built for the EU Transfer of Funds Regulation (TFR) for crypto-asset transfers.

Both profiles

  • Require a fresh, sourced fiat valuation
  • Check the common originator and beneficiary fields
  • Reject the transfer on sanctions matches
  • Return stable reason codes
  • Persist immutable decision snapshots

Security by default

Regulated identity data gets the protection it needs at every layer.

Encrypted at rest

Sensitive fields are stored in AES-256-GCM envelopes; the keyring supports key rotation and background re-encryption.

Tamper-evident audit trail

Each audit event is chained to the previous one with SHA-256, and case exports recompute the chain.

Role-based access

Five fixed roles, optional two-person approval for high-risk cases and immediate session revocation on role changes.

Sanitized logging

Logs and error records strip bodies, emails, secrets, tokens and keys before they are written.

Hardened containers

Digest-pinned images run as non-root, read-only containers; the database is never published to the host.

OIDC support

OIDC tokens from your identity provider are optionally accepted; authorization stays in the node's own database.

One interface, five roles

Each team sees exactly what it needs.

  • Platform admin

    Users, configuration, API clients and key management

  • Integration operator

    Transfers, messages, tokens and delivery health

  • Compliance reviewer

    Inquiry and case review

  • Compliance approver

    Final decisions on high-risk cases

  • Auditor

    Read-only access to activity and cases

Running in minutes

Docker Compose brings up the database, backend, console, gateway, local certificates and a local administrator together.

  1. 1. Clone the repository

    git clone https://github.com/getdefy-co/travel-rule.git
    cd travel-rule
  2. 2. Start the stack

    docker compose up --build --wait
  3. 3. Open the interface

    Open the console in your browser and sign in with the local administrator described in the README.

Requirements

  • A Linux server
  • Docker with the Compose plugin
  • A few GB of available memory

The default administrator and generated certificates are for local development only. Production deployments need managed secrets, production PKI, backups and monitoring. Current version requirements and install notes live in the repository.

Read the deployment guide

Frequently asked questions

Does the node hold assets or send blockchain transactions?

No. The node only exchanges identity data and compliance decisions. Your custody system keeps control of assets, and the fact that a transfer took place is reported through the versioned API.

Which Travel Rule protocol does it support?

It implements the Travel Rule Protocol (TRP) directly. Identity data is handled in IVMS101 format and shared with counterparty VASPs over mTLS.

How is it licensed?

Defy licenses the repository's original code and documentation under the Apache License 2.0. Review the NOTICE and third-party notices before redistribution.

Where does my data live?

In your own environment. The whole stack, including PostgreSQL, runs on your infrastructure, and the database is only reachable on an internal Docker network.

Can Defy help us run it in production?

Yes. Community support is best-effort through GitHub. Contact our team for production deployment, integration and compliance support.

Run Travel Rule on your own infrastructure

Explore the source code, or talk to us about deploying Defy Travel Rule in production.