# General Information

* **Mauve is a permissioned non-custodial exchange**, with its own operating entity (Mauve Ltd.), that holds a VASP registration from the Cayman Islands Monetary Authority (CIMA).
* Mauve operates as an automated market maker (AMM) protocol and is a Uniswap V3 fork, including significant parts of its frontend application. We are grateful to be standing on the shoulders of the broader Uniswap community.
* Mauve does not operate a token and permissioning includes the ability to swap and add liquidity. Listing new assets is at the discretion of Mauve Ltd.

{% hint style="info" %}
**Mauve permissioning and compliance runs on** [**Violet**](https://www.violet.co/) - privacy preserving, reusable on-chain compliance rails. All authentication and authorization operations, as well as enrolment, run through Violet.&#x20;
{% endhint %}

We will be publishing comprehensive documentation very soon - stay tuned! In the meantime, our team is reachable on our [public Discord here](https://discord.com/invite/hRJpPQtKSh), as well as through email at <info@mauve.org>, and you can [follow us on X ](https://twitter.com/mauve_org)for updates.


# How to use Mauve

* Using Mauve requires a VioletID and your own wallet (e.g., through using a service like Coinbase wallet or MetaMask) with available funds. Currently the only way to get a VioletID is through using Mauve.
* Mauve is currently only available on the Ethereum mainnet, with more deployments planned for the near future.
* Upon your first action on Mauve, identity verification through Violet will commence. This includes a KYC/B check, as well verifying geolocation and on-chain transaction history. More in the Violet section below. Violet also requires you to enroll a second auth factor for additional safeguarding.

{% hint style="warning" %}
Important: [all of your personal information is stored fully encrypted off-chain](https://docs.violet.co/for-developers/data-storage).&#x20;
{% endhint %}

* Once your verification is completed, your VioletID will be [issued on-chain](https://github.com/violetprotocol/VioletID), and certain relevant attributes (is-US, is-Investor, has-VioletID) are stored on-chain. **At this point, you can now use Mauve!**

{% hint style="info" %}

* Today, the status of your VioletID and attributes is reflected in an on-chain registry. In the future, we will give users optionality to mint a non-transferable and non-fungible (NTT) token that will become their on-chain VioletID reflection.
* There are no additional gas fees for you in relation to the issuance of your VioletID.
  {% endhint %}

- Mauve requires users to authenticate every time they use the app, with authentication sessions lasting 24h. If a user is outside a valid session, re-authentication through wallet authentication (Sign In With Ethereum) and the initially enrolled second auth factor is required.

**If you are looking to access Mauve through a programmatic interface, then we can provide you with an API key for authentication.** Please contact us for details.


# Trading Pairs

The currently available trading pairs on Mauve can be found on this page.

| Pair       | Description             |
| ---------- | ----------------------- |
| USDC/WETH  | USD Coin to Wrapped ETH |
| USDC/EUROC | USD Coin to Euro Coin   |
| blB01/USDC | Backed IB01 to USD Coin |

blB01 stands for Backed IB01 $ Treasury Bond 0-1yr (bIB01), find out more about this asset on <https://assets.backed.fi/products/bib01>.

You can also find the relevant fees for each trading pair on the [Fee Structure](/fee-structure) page.


# Fee Structure

## Mauve Exchange Fee Structure

***

Mauve Exchange, standing on the shoulders of Uniswap V3, is a non-custodial automated market maker (AMM) protocol specifically tailored for real-world asset (RWA) markets. Our platform provides liquidity providers with full control over fee generation, innovative security features, and compliance measures in a user-centric trading environment.

### Key Features

* **Fixed Fees:** Each liquidity pool has a predetermined fixed fee, ensuring consistency and reliability for liquidity providers.
* **Curated Pools:** Mauve does not support user-created pools. All pools are carefully developed and maintained by the Mauve DEX developers to meet strategic standards and compliance.
* **Full Fee Allocation:** All trading fees are awarded to liquidity providers without any portion taken by the platform.

### Liquidity Pools and Fees

| Pair       | Fee   | Pool Address                               |
| ---------- | ----- | ------------------------------------------ |
| USDC/WETH  | 0.04% | 0xe45b4d18ac887ed9c221efe28b4fca230107f25f |
| USDC/EUROC | 0.01% | 0x3b65b3a277116cc27e024b7e6bdfa2a961996cb0 |
| blB01/USDC | 0.01% | 0xa0bd33c1450e89106c04c4c5c07110e66da24f31 |

### Concentrated Liquidity

* **Targeted Range:** Liquidity providers can specify the price range in which their capital is active, enabling higher capital efficiency and fee generation within the bounds of market price movements.
* **No Native Token:** Mauve does not issue a native liquidity token, aligning with our ethos of simplicity and direct rewards to liquidity providers.

### Full Fee Allocation to Liquidity Providers

* 100% of trading fees are allocated to liquidity providers.
* There are no fees taken by the Mauve platform; all collected fees go directly to those providing liquidity.

### No Native Liquidity Token

* Mauve does not have a native platform token.
* Liquidity providers are not issued any native tokens as rewards, reflecting our streamlined and utility-focused tokenomics.

### Transparency and Openness

* As a fork of Uniswap V3, Mauve inherits the innovative features of concentrated liquidity and multiple fee tiers, adapted for our unique platform requirements.
* Our commitment to transparency ensures that liquidity providers are fully informed about their potential earnings and the workings of the liquidity pools.

### Contact and Support

For any inquiries regarding the fee structure or to seek guidance on providing liquidity, reach out to our support team at [Mauve Support](mailto:support@mauve.org).


# Protocol Concepts


# Transaction Authorization

Mauve, built upon the foundation of Uniswap-V3, extends its capabilities with added functionality and security measures while preserving its core ethos as a peer-to-peer platform for cryptocurrency exchanges. A pivotal aspect of this enhancement is integrating a robust transaction authorization mechanism underpinned by interoperability with the [Violet](https://docs.violet.co/) subsystem.

#### Transaction Flow

1. **Transaction Initiation**: Whenever a user initiates a transaction on Mauve, an authorization request is automatically forwarded to the Violet subsystem.
2. **Authorization Request**: Violet carefully analyzes the user's wallet, the identity of the entity behind it, and the transaction request against comprehensive compliance criteria to ascertain the transaction's legitimacy.
3. **Token Issuance**: Violet appends an Ethereum Access Token (EAT) to the transaction data upon successful evaluation. This EAT acts as a distinctive identifier, facilitating the Mauve protocol to seamlessly recognize and authorize the transaction.

#### Enhanced Security

Introducing this transaction authorization mechanism significantly elevates the protocol's security and trustworthiness, ensuring that only legitimate and compliant transactions are processed. This mechanism is instrumental in fostering a secure trading environment akin to established centralized exchanges without compromising user privacy.

#### Comparison with Centralized Exchanges

Mauve transcends the conventional decentralized exchange model by integrating security measures typical of centralized exchanges, like Know Your Customer (KYC) procedures and advanced AML controls. Unlike centralized platforms, Mauve achieves this level of security without encroaching on user privacy, thanks to its robust transaction authorization mechanism. This innovative approach empowers Mauve to provide a secure, trustworthy, yet decentralized platform for cryptocurrency trading, blending the security features of centralized exchanges with the principles of transparency, decentralization, and user privacy intrinsic to the DeFi ecosystem.

#### Further Reading

For more in-depth understanding, refer to the [Uniswap protocol documentation](https://docs.uniswap.org/) or explore our [open-source repository on GitHub](https://github.com/violetprotocol/mauve-dex) for technical insights into the Mauve protocol's transaction authorization mechanism. You can also check the [audits](https://docs.mauve.org/security/audits) that we received from specialized entities.


# Ethereum Access Token

The Ethereum Access Token (EAT) embodies an on-chain verification mechanism designed to authorize access to wallets through cryptographic tokens. Analogous to JSON Web Tokens (JWTs), EATs are issued to users following a verification procedure, facilitating secure invocation of on-chain transactions akin to OpenID Connect (OIDC) flows.

#### Usage in Mauve

Upon initial interaction with Mauve, users are guided to enroll in the Violet subsystem, which reflects the meticulous compliance analysis akin to KYC/KYB procedures in traditional exchanges. Post-successful enrollment and compliance verification, a Violet account is set up for the user, and their wallet address is issued as an on-chain ID. With both the Violet account and VioletID meeting regulatory standards, the Violet subsystem backend processes user transaction requests, encompassing action types (e.g., swaps, liquidity management), transaction parameters, wallet address, and other metadata for fraud detection.

#### EAT Issuance Process

On verification of transaction legitimacy concerning Mauve smart contracts, the Violet subsystem issues an Ethereum Access Token, which is included in the transaction for successful execution on the blockchain. EATs are time-sensitive tokens cryptographically signed by an issuer and verified by on-chain smart contracts, ensuring secure transaction execution.

#### Technical Overview

EATs implement the EIP-712 standard for signed access token verification, with a structure as follows:

```json
{
  "expiry": <unix_seconds-uint256>,
  "functionCall": {
    "functionSignature": <solidity_function_sig_hex-string>,
    "target": <contract_address_of_tx_target-string>,
    "caller": <user_address_of_tx_caller-string>,
    "parameters": <hexadecimal_representation_of_parameters-string>
  }
}

```

Applications that integrate with Ethereum Access Token must be compatible with accepting the EAT structure for certain function calls that require restrictions gated with extra verification.

#### Integration with Violet

Mauve's permissioning infrastructure leverages Violet's on-chain compliance rails, with EATs as a key component. All authentication, authorization, and enrollment operations run through Violet, providing a robust compliance framework.

For a deeper understanding of EATs and their implementation, refer to this [open-source repository on GitHub](https://github.com/violetprotocol/ethereum-access-token) or the [Violet documentation](https://docs.violet.co/for-developers/core-concepts/ethereum-access-token).


# VioletID

**VioletID**, a critical component used by **Mauve**, is an onchain registry of attributes by wallet address, maintained by Violet. It serves as the foundation for the issuance of 'statuses' that represent a user's verification and trustworthiness within the Violet ecosystem. Possessing a specific status ID serves as a clear indicator of successful completion of a verification process tailored to that specific status.

Within the realm of VioletID, various significant status IDs exist, each having a distinct on-chain presence. For illustrative purposes, two noteworthy status IDs are **Enrolled (statusId 1)** and **Mauve-Compliant (statusId 4)**. The first status represents successful enrollment of an individual or business within the Violet ecosystem, while the second indicates compliance with all specific requirements that a user must comply with in order to be allowed to interact with Mauve. Both of these statuses adhere to stringent compliance standards set forth by Mauve and Violet. Currently, these standards encompass **Know Your Customer (KYC)** and **Know Your Business (KYB)** processes, which individuals and businesses must diligently go through. Upon completion, Violet grants the relevant statuses to the user's address by updating the state of the registry in the VioletID smart contract.

<table><thead><tr><th width="139">StatusId</th><th>Status, which denotes that the entity behind the wallet address is:</th></tr></thead><tbody><tr><td>1</td><td>Enrolled and KYC'ed in Violet</td></tr><tr><td>2</td><td>Present on a sanctions list</td></tr><tr><td>3</td><td>A US Citizen</td></tr><tr><td>4</td><td>Enrolled and compliant to use Mauve</td></tr><tr><td>5</td><td>An Accredited Investor</td></tr></tbody></table>

The table above outlines the current statuses that a wallet address can be granted in the VioletID onchain registry. Please note that this list is subject to change, and new statuses can be added at any time at the discretion of Violet to better support its partners.

### Technical Implementation

Moreover, these statuses are represented on-chain as a bitmap on the **VioletID Contract**. A status combination ID is computed simply by summing the values obtained from 2 raised to the power of the `statusId` (the index of the bit on the bitmap) for each status. For example, if a wallet address is:

* Enrolled and KYC'ed in Violet (statusId 1)
* Enrolled and compliant to use Mauve (statusId 4)

<mark style="color:yellow;">**The calculation would be: 2^1 + 2^4 = 18. Thus, this wallet address would have a status combination ID of 18, representing the combination of the aforementioned statuses.**</mark>

To inquire about the status combination of a wallet address, you can easily utilize the **hasStatuses(address, uint8)** function from the **VioletID contract**. Alternatively, you can use the **hasStatus(address, uint256)** function to query individual statuses of a wallet address. Both functions return a boolean value and can be employed as follows:

* Is the wallet 0x123 Enrolled and KYC'ed in Violet?
  * `hasStatus(0x123, 1)`
* Is the wallet 0x123 listed in a sanction list AND a US Citizen?
  * `hasStatuses(0x123, 12)`

VioletID assumes a pivotal role within Mauve's ecosystem, where trust and compliance are paramount. It ensures protocol integrity by serving as a reliable mechanism for verifying users and entities. Its impact extends beyond mere token issuance, with far-reaching implications for Mauve's ecosystem.

Additionally, VioletID provides the flexibility to assign multiple status IDs or combinations to a specific wallet. This feature empowers VioletID to represent diverse sets of compliance statuses for an individual. For example, it can indicate whether an individual operates within a regulatory environment unsupported by Mauve, such as the United States, or whether an individual appears on OFAC sanctions lists.

Partners and developers can seamlessly integrate with VioletID to leverage all compliance requirements from Violet by simply checking the status of a wallet on-chain. For further information, please refer to Violet website: <https://www.violet.co/>

#### Role in the Escape Hatch Mechanism

VioletID also plays a pivotal role in the [**Escape Hatch Mechanism**](/security/escape-hatch), a critical security feature of Mauve. This mechanism ensures that even in the unlikely event of a compromise to the Violet subsystem by an attacker, user wallets cannot have their funds locked within the protocol. The emergency mode, facilitated by VioletID, enables users to execute actions without requiring an **Ethereum Access Token (EAT)**, as long as their wallet maintains the correct statuses within the VioletID smart contract. This emergency mode serves as a failsafe, preserving the user's ability to interact with the protocol under exceptional circumstances.

If you seek a deeper understanding of how VioletID operates behind the scenes or wish to integrate with this vital component, we encourage you to reach out to us via [Discord](https://discord.gg/uzt5QjNhCc). We are more than happy to provide guidance and support to facilitate a seamless integration and address any inquiries you may have regarding VioletID and its role in Mauve's ecosystem.


# Dev


# Integrating Mauve

Coming very soon...


# Programmatic Access

Coming very soon...


# Error Codes

Coming very soon...


# Who can use Mauve

{% hint style="info" %}
Non-sanctioned persons and entities who pass Violet’s compliance standard (more below) can use Mauve. For regulatory reasons, we cannot currently allow access to anyone who holds US citizenship and / or is on US soil.
{% endhint %}


# Security


# Audits

Mauve operates a modified Uniswap V3 fork, one of the most battle tested and throughout audited DEX codebases. In addition, two further smart contract audits were conducted:

| [OAK Security](https://www.oaksecurity.io/) | [Full report available here. ](https://github.com/solidified-platform/audits/blob/master/Audit%20Report%20-%20Mauve.pdf) |
| ------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| [Halborn](https://www.halborn.com/)         | [Full report available here. ](https://drive.google.com/file/d/15rjffI17K62iCibGiJbx1jQq2eJV1c8r/view?usp=sharing)       |

In addition to Mauve smart contracts, all smart contracts relating to VioletID have been audited as well:

| [Halborn](https://www.halborn.com/) | [Full report available here. ](https://drive.google.com/file/d/1a1pIacLwtDm_5YHZ454OLpdqeEZ48KcN/view?usp=sharing) |
| ----------------------------------- | ------------------------------------------------------------------------------------------------------------------ |

Mauve’s interface with Violet, including cloud infrastructure and frontends, have undergone additional outside security review, including extensive pen testing through Halborn.


# Repositories

**All core Mauve repositories are open sourced here:**

* <https://github.com/violetprotocol/mauve-dex>
* <https://github.com/violetprotocol/mauve-smart-order-router>
* <https://github.com/violetprotocol/mauve-core>
* <https://github.com/violetprotocol/mauve-periphery>
* <https://github.com/violetprotocol/mauve-swap-router-contracts>
* <https://github.com/violetprotocol/mauve-sdk-core>
* <https://github.com/violetprotocol/mauve-v3-sdk>
* <https://github.com/violetprotocol/mauve-router-sdk>
* <https://github.com/violetprotocol/mauve-subgraph>

**VioletID repository:**

* <https://github.com/violetprotocol/VioletID>


# Deployments

**Mauve is currently deployed on the Ethereum mainnet**. We also have a Optimisim Görli deployment for testing purposes. If you are interested in trying Mauve on a testnet (e.g. for integration purposes), please contact us.

| **Name**                   | **Address**                                                                                                           |
| -------------------------- | --------------------------------------------------------------------------------------------------------------------- |
| MauveFactory               | [0x0569168709a869e7f4Ba142c49BFF7faA14f76C8](https://etherscan.io/address/0x0569168709a869e7f4Ba142c49BFF7faA14f76C8) |
| NonfungiblePositionManager | [0x26c2bd020BfBe8366F79FFDA1A0cfAC5A7b52108](https://etherscan.io/address/0x26c2bd020BfBe8366F79FFDA1A0cfAC5A7b52108) |
| MauveSwapRouter            | [0x6FAEB511989E280D3A51ca45ED756C90e736b012](https://etherscan.io/address/0x6FAEB511989E280D3A51ca45ED756C90e736b012) |
| AccessTokenVerifier        | [0xe8F42626ba40be4478B4B13566E9B26faff33663](https://etherscan.io/address/0xe8F42626ba40be4478B4B13566E9B26faff33663) |
| Quoter                     | [0xe0303307187E8d66a884E8E7aFA18Dad9217F2A6](https://etherscan.io/address/0xe0303307187E8d66a884E8E7aFA18Dad9217F2A6) |
| QuoterV2                   | [0x8443289e5dd694eFA46440B52C7Fe4b828E668D6](https://etherscan.io/address/0x8443289e5dd694eFA46440B52C7Fe4b828E668D6) |


# Escape hatch

* In catastrophic scenarios, in order to protect our users, as well as comply with regulatory requirements, we have implemented an emergency mode where all functionality is paused. This will disable swapping, adding liquidity, collecting fees etc.
* To avoid a situation where our users are unable to retrieve their liquidity, we have implemented an Escape Hatch which allows VioletID holders to be able to exclusively remove their liquidity from Mauve without having to request an authorization from Violet’s backend.&#x20;
* **This means that valid VioletID holders can withdraw funds at any time**, either through requesting authorization from Violet in normal operating mode, or just by virtue of their VioletID status on-chain.
* Once we have deemed Mauve safe to use again, we will re-enable Mauve by disabling the emergency mode.


# Violet FAQ

{% hint style="info" %}
Head to [Violet webpage](https://www.violet.co/) to learn more. [Violet Docs are accessible here](https://docs.violet.co/).&#x20;
{% endhint %}

* **What is Violet and a VioletID?**
  * Violet is a highly customizable compliance and identity management tool provided by DeFi Labs GmbH. Violet was formed to create best-in-class anti-money laundering, privacy-preserving compliance credentials for use in decentralized finance, crypto more broadly, and web3 use cases. Violet is committed to user privacy and aims to balance legitimate governmental interests with privacy protection.&#x20;
  * Your VioletID provides a standardized method to issue compliance credentials and map smart-contract access controls on the Ethereum mainnet and EVM-compatible chains. VioletID achieves this purpose in a way that allows integrated partners to fulfill traditional legal compliance requirements like Know Your Customer (KYC), Know Your Business Customer (KYB), sanctions checks, and anti-money laundering (AML) rules in an on-chain verifiable way while preserving your privacy in a way that regulators will accept today. Indeed, Violet’s compliance program was the backbone for Mauve’s VASP registration approval. The specific compliance checks that Violet supports are expected to grow over time, and you will be able to opt-in for additional checks in order to access different products and services that need the extra verification.
  * Before signing up with a new service or engaging in a transaction using a smart contract that requires you to have a VioletID, you should confirm your understanding of the checks that Violet will be required to perform and whether the service or transaction may require independent access to your data (e.g., in the future, permissioned token issuers may require your data to satisfy their regulatory reporting requirements if you opt to hold their tokens). We will not access your data for any reason other than what is disclosed in our Privacy Notice.

{% hint style="info" %}
Today, the status of your VioletID and attributes is reflected in an on-chain registry. In the future, we will give users optionality to mint a non-transferable and non-fungible (NTT) token that will become their on-chain VioletID reflection.
{% endhint %}

* **How does Violet confirm my compliance before a transaction?**
  * Violet relies on [Ethereum Access Token (EAT) integration](https://docs.violet.co/for-developers/core-concepts/ethereum-access-token) to provide real-time compliance checks in connection with a transaction authorization. EAT gating provides the ability for users and protocols to accept virtually any signal via an EAT due to its composability without disclosing the user’s underlying personal information to the service unless required by law for regulatory reasons. The EAT is issued from Violet’s backend and passed client side where it is added to the user’s transaction, thereby embedding the EAT on-chain. The EAT is then verified by the relevant protocol calling Violet’s verification smart contract. If you have already obtained an EAT and completed the required compliance checks within the last 24 hours, then you’re able to proceed without additional screening as part of an ongoing session. This session-based approach avoids unnecessary authorization delays and checks.&#x20;
* **Where can I use my VioletID?**
  * Today, for non-US users, you can immediately access Mauve, a non-custodial exchange where every user has to have a VioletID in order to swap tokens or provide liquidity to a pool. Relying on Violet, Mauve gives you a place to exchange your tokens without taking unnecessary counterparty or sanctions risk and without having to trust an intermediary with custody of your tokens.&#x20;
  * VioletID also functions as a proof of humanity / personhood, meaning there can only be one you. We foresee an incredible number of use cases where you need to prove your identity, or an aspect of your identity, to use a service – you’d be able to use your VioletID to meet that requirement in a programmatic, privacy protective way.&#x20;
* **Who is DeFi Labs?**
  * DeFi Labs is the parent entity behind Violet and Mauve. DeFi Labs is a German limited liability company, headquartered in Berlin.
* **What happens with my identity data during verification?**
  * Your data is processed via our verification partner Persona (for individuals) or SumSub (for businesses). We (DeFi Labs) take custody of the data, and no individual user’s personal information is retained by our enrollment partners long term. At this time, KYB data for business users is retained by SumSub. Our [Privacy Notice](https://www.violet.co/privacy-notice) explains in detail what is collected, how it’s stored, how we will (and more importantly, won’t) use your personal data, and your rights.
* **What sanctions and AML checks does Violet run?**
  * Violet built its compliance program in direct consultation with Mauve to ensure that Mauve is able to satisfy existing, traditional finance anti-money laundering requirements. Violet thus requires a full know your customer (via Persona) or know your business customer (via SumSub) check of every person or business who wants to obtain a VioletID. For individuals, this process requires you to provide standard KYC information including self-reported permanent address along with documentary proof (e.g., a utility bill), as well as geolocation information tied to an IP address – this geolocation confirmation is necessary for sanctions compliance. Violet does not currently allow users to enroll while using a VPN or Tor under our Terms of Use, and we will block your access when detected. A liveness check also is required to ensure that Violet has a reasonable belief that we know the true identity of our registrants, which is a guarantee a service like Mauve needs to meet its legal obligations. You will also enroll a second factor through Authenticator to ensure that the wallet you registered with us remains in your possession at the time of a transaction requiring your VioletID. For business users, the process is similar but with increased checks around beneficial owners (down to the 10% level), directors and executive officers, and confirmation of company details like shareholders and confirmation of company registration. The KYB process is manual at the start, and we appreciate your patience as we get you onboarded! Initial sanctions checks are run by Persona or SumSub. You may request a manual review by emailing <compliance@violet.co> if you are unable to successfully navigate the automated enrollment process, but certain issues (e.g., unreadable identity documents) cannot be resolved manually.&#x20;
  * Violet uses TRM Labs to screen your wallet at the time of enrollment to ensure that your on-chain activity has not resulted in sanctions violations or other behavior indicative of money laundering that would not be permitted on Mauve. Violet took great care, in consultation with Mauve, about what risk tolerance is appropriate for a self-custody wallet, recognizing that compliance and regulation is new to the industry. Violet has adopted a custom approach that ultimately relies on aggregated risk scores attributed to “Ownership,”  “Counterparty,” and “Indirect” risk totals generated by the blockchain analytics screening. The permissible “Ownership” risk score (i.e., the risk is directly tied to activity by the wallet) is lower than the permissible “Counterparty” risk score (i.e., the risk is tied to a third-party wallet that your wallet directly interacted with) and the “Indirect” risk score (i.e., the risk is tied to a third-party wallet that is more attenuated from your wallet). Violet also has adopted specific “percentage of funds” scores for many of the identified risk categories (e.g., extortion & blackmail, investment fraud, violent extremism, scams). Where the overall percentage of funds transacted from a wallet is significant (e.g., greater than 15% of all in-bound funds are attributed to a certain risk category), then Violet will view you as a greater money laundering risk. Importantly, the inverse is also true: where a tiny amount of funds (e.g., .01% or less of all in-bound funds) are attributable to an indirect risk category, Violet will reduce the ordinary risk score for that category to “1” because you likely have not, in fact, engaged in an activity that materially increases your money laundering risk profile. Violet has also adopted specific rules designed to detect flags for Tornado Cash-related sanctions issues and to discount those risk scores appropriately due to the Tornado Cash dusting that was beyond your control. All told, Violet does not currently expect most users who have acted in good faith, consistent with prior norms in crypto, to have an issue with enrollment due to the blockchain analytics screen. As always, we are committed to being transparent about our approach, and we are equally committed to working with Mauve to revise the details of this implementation if initial registration does not proceed as anticipated and false positives are high.
  * Violet runs ongoing anti-money laundering and sanctions checks against your personal information as well as a blockchain analytics check before any transaction requiring your VioletID. ComplyAdvantage checks your off-chain personal information against reputable and relevant government sanctions, warnings, PEP lists, and adverse media lists that have been specifically identified by Violet and Mauve as relevant to the provision of Mauve’s service. ComplyAdvantage will alert Violet’s compliance team if there is a significant change to your risk profile (e.g., you now appear to be listed on the OFAC sanctions list or are on a most-wanted list). Violet will manually review these flags to determine if the alert is a false positive. If the ComplyAdvantage alert is accurate, Violet will update your verifiable credentials as required based on the type of alert, which may result in you being unable to use Mauve or in the elimination of your VioletID. Before any transaction, if no check has been done in the past 24 hours, Violet will rescreen your wallet using TRM Labs’ analytics tool. If there has been a change to your on-chain risk score that is material, then the transaction will fail and no transactions will be possible. Violet’s compliance team will confirm whether the updated risk score is correct and determine the necessary action, which may include the inability to use Mauve or the elimination of your VioletID.
* **How is my personal data stored and protected?**
  * All personal data is encrypted on our backend and stored with AWS. AWS does not have access to plaintext (i.e., unencrypted) data. We made this choice to minimize the risk of data leakage and to impose as much protection as possible over your personal information. Decryption is secured by an internal permissioning system to ensure only explicitly designated parties are allowed access to your personal data and only for the specific reasons set out in our [Privacy Notice](https://www.violet.co/privacy-notice). All access to your data is recorded in an audit log – no one at Violet can access your data without there being a record that will be retained for at least 5 years as part of Violet’s data retention policy.
  * Our Privacy Notice and documentation is as transparent as possible about what data is collected, stored, and who can access it. We intend to provide you access to a self-service portal in the near future, where you will always be able to view the data stored by Violet after completing your registration on the [VioletID app](https://app.violet.co/). You will also be able to add additional information as necessary to obtain unique credentials for certain use cases (e.g., accredited investor status in order to acquire and hold permissioned tokens).
  * To be clear: Violet does not use your data for our own purposes – we do not and will not provide it to other third parties for any reason other than provision of the services you asked us to provide or in response to a compulsory legal demand. You can review how strictly we handle legal information demands in [our policy](https://github.com/violetprotocol/legal_terms/blob/main/access_guidelines.md). It’s your data, not ours, and our goal is to reduce even our access to it over time. We published a blog post on our general data protection and privacy philosophy that is [available here](https://mirror.xyz/violetprotocol.eth/G8PouCrFsCqzVE4U-f2FQydELNzu3msFAVS-9f2rERk). Our [Privacy Notice](https://www.violet.co/privacy-notice) controls if there is any difference between the blog post and the Notice.
* What is the blB01 asset?
  * blB01 stands for Backed IB01 $ Treasury Bond 0-1yr (bIB01), you can find out more about this asset on <https://assets.backed.fi/products/bib01>.

{% hint style="warning" %}
**How can I request my data to be deleted?**

Please contact us at <privacy@violet.co>. Additional information is provided in our [Privacy Notice](https://www.violet.co/privacy-notice), and we encourage you to review it!
{% endhint %}


