NEOCEX

ANTI-MONEY LAUNDERING AND COUNTER-TERRORIST FINANCING POLICY

Public version

Neocex Platform (neocex.com)

Operator: Boulder Tech, S.A.S. de C.V.

Effective date: [DATE]

Version: 1.0

Approved by: Sole Administrator, on the recommendation of the Compliance Officer

1. Purpose and scope

1.1. This Policy sets out the measures applied by Boulder Tech, S.A.S. de C.V. (the "Operator") to prevent the use of the Neocex platform for money laundering, terrorist financing, proliferation financing, sanctions evasion and related financial crime.

1.2. The Policy applies to all users of the Platform, to all Virtual Asset transactions processed by the Operator, and to all employees, contractors and service providers performing functions on the Operator's behalf.

1.3. This is the public version. The internal version, including the risk matrix, scoring parameters, escalation procedures and reporting templates, is held by the Compliance Officer and is filed with CNAD as part of the Operator's compliance documentation.

2.1. The Operator is a digital asset service provider registered with the National Commission of Digital Assets (CNAD) under registry entry PSAD-0038 (Resolution CNAD-CD-001-2025 of 6 January 2025) under the Digital Asset Issuance Law (LEAD).

2.2. The Policy implements:

3. Governance

3.1. Compliance Officer. The Operator appoints a Compliance Officer (Money Laundering Reporting Officer, MLRO) who is not a member of the executive management. The Compliance Officer is responsible for the design and operation of the AML/CFT programme, approval of high-risk onboarding, review of held transactions, reporting to the UIF, liaison with CNAD, staff training and the annual review of this Policy. [TO CONFIRM: name]

3.2. Three lines of defence. First line: onboarding and client support, which apply the procedures at the point of contact. Second line: the compliance and AML function headed by the Compliance Officer. Third line: independent review of the programme at least annually.

3.3. Escalation. Critical risk classifications and decisions to file a report with the UIF are taken by the Compliance Officer and recorded with their justification. The Compliance Officer reports to the Sole Administrator at least quarterly on the operation of the programme.

3.4. Independence. No commercial function may override a compliance decision. Compliance decisions may be taken without disclosure of reasons to the user where disclosure is prohibited by law.

4. Risk-based approach

4.1. The Operator maintains an enterprise-wide risk assessment covering client risk, geographic risk, product risk, transaction risk and delivery channel risk. The assessment is reviewed at least annually and upon any material change in products, jurisdictions or the regulatory environment.

4.2. Each user is assigned a risk classification: low, medium, high or critical. The classification determines the level of due diligence, the monitoring intensity and the frequency of review.

4.3. Product risk. The Platform is crypto-only: no fiat deposits or withdrawals, no cash, no top-up codes, no peer-to-peer trading, no credit. Blockchain transfer is the only funding method. This removes the cash and third-party payment risks and concentrates monitoring on on-chain provenance and trading behaviour.

5. Client acceptance and restricted jurisdictions

5.1. The Operator onboards natural persons aged 18 and over only. Legal entities are not onboarded.

5.2. The Operator does not provide services to residents of, or persons located in, the Restricted Jurisdictions listed in Appendix E of the Terms of Use, including jurisdictions on the FATF list of high-risk jurisdictions subject to a call for action and jurisdictions under comprehensive sanctions.

5.3. Geographic screening is applied at registration by IP address and device data and at verification by nationality, document issuing country and residential address. A user from a Restricted Jurisdiction is refused at the first step, before personal data is submitted.

5.4. The Operator does not onboard: persons on sanctions lists; persons acting on behalf of a third party without disclosure; persons who refuse to complete verification; persons whose source of funds cannot be established where it is required; politically exposed persons whose risk is assessed as unacceptable.

6. Customer due diligence (KYC)

6.1. Verification is performed through an external identity verification provider (Enface, platform.enface.ai; migration to Sumsub is planned and will be notified to CNAD). The Operator holds a provider-agnostic verification status, so that a change of provider does not change the procedure.

6.2. Levels.

Unverified: registration and email confirmation only. Market data in read-only mode. No orders, no deposits, no withdrawals.

Basic, required before any trading, deposit or withdrawal:

Advanced, required for Derivatives and for higher withdrawal limits:

6.3. Limits. Withdrawal and trading limits by level are published on the Platform. The Compliance Officer may reduce a user's limits or level at any time.

6.4. Ongoing due diligence. Verification is refreshed on the basis of risk: every 3 years for low risk, every 2 years for medium risk, annually for high risk, and immediately upon a trigger event (document expiry, change of residence, unusual activity, adverse media, sanctions list update, request from an authority).

6.5. Refusal and re-submission. A user whose verification is rejected receives the reason for rejection where disclosure is permitted and may re-submit. Repeated failure or evidence of forged documents results in permanent refusal and, where warranted, a report to the UIF.

7. Enhanced due diligence

7.1. Enhanced due diligence applies to users classified as high or critical risk, to politically exposed persons and their close associates, to users with exposure to high-risk jurisdictions, and to users whose transaction patterns deviate materially from their profile.

7.2. Measures include: source of funds and source of wealth documentation; explanation of the purpose of the relationship; verification of the origin of specific deposits through blockchain analytics; senior approval of the relationship by the Compliance Officer; increased monitoring frequency; lower limits.

7.3. Where enhanced due diligence cannot be completed, the relationship is not established or is terminated, available assets are returned to a verified address of the user where permitted, and a report is filed where the circumstances require it.

8. Sanctions screening

8.1. Users are screened against applicable sanctions lists at onboarding, at every re-verification and daily against list updates. Wallet addresses involved in deposits and withdrawals are screened against sanctioned address lists through the blockchain analytics provider.

8.2. A confirmed match results in immediate freezing of the assets, refusal of the transaction, escalation to the Compliance Officer and reporting to the competent authority. Frozen assets are not released without a decision of the competent authority or a documented determination that the match was false.

8.3. Users may not attempt to circumvent sanctions through transaction splitting, intermediaries, mixers or high-risk services. Attempted circumvention results in Account closure and reporting.

9. Transaction monitoring (KYT)

9.1. Every deposit, withdrawal and internal transfer is screened by the Operator's blockchain analytics provider (BitOK) before the funds are credited or released. Screening covers direct and indirect exposure of the counterparty address, the systematic or isolated nature of interaction with high-risk addresses, and the share of high-risk assets in the transaction.

9.2. Red flags include exposure to: sanctioned entities; darknet markets; stolen or fraudulently obtained funds; funds connected to trafficking in drugs, arms or persons, or to child exploitation; ransomware and malware proceeds; high-risk jurisdictions on the FATF lists; illegal gambling; mixers and anonymisers; terrorist financing; as well as rapid deposit and withdrawal patterns, structuring, and third-party funding inconsistent with the user's profile.

9.3. Thresholds. A transaction with cumulative risk exposure above 90% is held and reviewed by a compliance analyst. A direct sanctions hit is held regardless of the score and escalated to the Compliance Officer. No held transaction is released automatically. Target time for a decision on a held transaction: 24 hours; the user is informed that the transaction is under review.

9.4. Decisions on a held transaction: credit or release; return to the originating address where permitted; freeze pending authority decision; Account restriction; report to the UIF. Every decision is recorded with the identity of the decision maker and the justification.

9.5. Behavioural monitoring. Trading and account activity are monitored for patterns inconsistent with the user's profile, for market abuse (wash trading, spoofing, layering) and for indicators of account takeover or use by a third party.

9.6. Travel Rule. Where a transfer is made to or from another virtual asset service provider and the Travel Rule applies, the Operator transmits and receives the required originator and beneficiary information through the mechanisms supported by its provider and does not process transfers for which the required information cannot be obtained.

10. Reporting

10.1. The Compliance Officer files reports of suspicious operations with the UIF in the form and within the deadlines set by the applicable legislation, and files any threshold or periodic reports required of digital asset service providers.

10.2. Tipping-off is prohibited. Employees do not inform a user or any third party that a report has been or may be filed, or that a transaction is under investigation, beyond the neutral notification that a transaction is under compliance review.

10.3. Requests from CNAD, the UIF, courts and law enforcement are handled by the Compliance Officer and answered within the deadlines set by the requesting authority.

11. Record keeping

11.1. The Operator retains identity verification records, transaction records, screening results, monitoring alerts, decisions and reports for at least 5 years after the end of the business relationship or the date of the transaction, whichever is later, and longer where a proceeding or an authority request requires it.

11.2. Records are kept in a form that allows reconstruction of each transaction and each compliance decision and are made available to CNAD and the UIF on request.

12. Freezing, restriction and termination

12.1. The Operator may restrict functionality, suspend transactions and freeze assets where there are indicators of money laundering, terrorist financing, sanctions exposure, fraud or breach of the Terms of Use, and holds them until the review is complete or an authority decides.

12.2. The Operator terminates the relationship where verification cannot be completed, where enhanced due diligence is refused, where the user is found to be a Prohibited Person, or where continued service would breach this Policy. Available assets are returned to a verified address of the user where permitted by law and by the compliance decision.

13. Training

13.1. All staff with client, transaction or compliance responsibilities complete AML/CFT training on joining and at least annually. Training covers this Policy, red flags specific to Virtual Assets, sanctions, the tipping-off prohibition and internal escalation. Attendance is recorded.

14. Independent review

14.1. The AML/CFT programme is reviewed at least annually by a function independent of the compliance team or by an external reviewer. Findings are reported to the Sole Administrator and tracked to closure.

15. Service providers

15.1. Identity verification and blockchain analytics are performed by external providers under written agreements that set out the scope of the service, data protection obligations, service levels and audit rights. The Operator remains responsible for compliance with this Policy regardless of outsourcing. Provider performance is reviewed at least annually under the Outsourcing and Third-Party Management Policy.

16. Prohibited activities

16.1. The following are prohibited on the Platform and result in restriction, freezing, reporting and termination: money laundering, terrorist financing, sanctions evasion, use of mixers or anonymisers where prohibited, providing false information, using nominees or concealing the real user, structuring, transferring the Account to a third party, and any activity listed in the Acceptable Use Policy.

17. Review of this Policy

17.1. This Policy is reviewed at least annually and upon any material change in law, regulation, products or the risk assessment. The public version is published on the Platform; material changes are notified to users through the interface.

Boulder Tech, S.A.S. de C.V.

Sole Administrator and Legal Representative

Ruslans Grabaruks ________________________

Compliance Officer

[TO CONFIRM: name] ________________________