Prepared by Glenn Lyvers, Instant Access · Version 0.1 · 13 September 2026 · Draft for review by counsel
01 Scope
- Instant Access [legal entity name, form, and registered address — to be inserted] (the "Operator") is organised in and operates from the United States. It is a U.S. person for the purposes of the sanctions programmes administered by the U.S. Treasury Department's Office of Foreign Assets Control (OFAC).
- OFAC's Sanctions Compliance Guidance for the Virtual Currency Industry (October 2021) states that all U.S. persons must comply with OFAC regulations — including all individuals and entities within the United States and all entities organised under U.S. law, wherever located — and that this applies whether a transaction is denominated in virtual currency or in fiat. The Operator does not rely on the location of any server, hosting provider, or domain registrar to alter that.
- The same guidance encourages "miners", among other participants in the virtual-currency industry, to develop and maintain a tailored, risk-based sanctions compliance programme. This policy is that programme for Spearmint Mining.
- This policy applies to every connection to a Spearmint Mining endpoint, every share the service records, every payout the service makes, and every notification registration it accepts.
02 What miners represent
By connecting a worker and by each share submitted, a miner represents to the Operator that:
- They are not listed on OFAC's Specially Designated Nationals and Blocked Persons (SDN) List or any other U.S. sanctions list, and are not 50% or more owned, or otherwise controlled, by anyone who is.
- They are not located in, organised under the laws of, or ordinarily resident in a jurisdiction listed in section 03.
- They are not acting for or on behalf of any such person or jurisdiction, and the payout address they mine under is not controlled by any such person.
- They are not using a VPN, proxy, relay, or any other method to disguise their location from the service's controls.
- Their use of the service does not violate any sanctions, export-control, or similar law that applies to them.
These representations are also in the Terms of Service. They are the service's principal control for the information it does not and cannot collect.
03 Restricted jurisdictions
- Connections from, and payouts attributable to, the following comprehensively sanctioned jurisdictions are refused: Cuba; Iran; North Korea (the Democratic People's Republic of Korea); and the Crimea region of Ukraine and the so-called Donetsk People's Republic and Luhansk People's Republic regions of Ukraine.
- Syria is not on this list. The comprehensive Syria sanctions programme was revoked by Executive Order 14312 (30 June 2025, effective 1 July 2025) and OFAC removed the Syrian Sanctions Regulations from the Code of Federal Regulations effective 26 August 2025. Targeted designations of specific persons continue under other authorities and are covered by list screening in section 04, not by a country block.
- The list in this section follows OFAC's programmes as they stand. It is reviewed at least quarterly and whenever OFAC announces a change, and updates are published at /updates/. If OFAC adds or removes a comprehensive programme, this section changes with it.
- Other jurisdictions are subject to targeted (list-based) sanctions rather than country-wide restrictions. The service does not block them by country; it screens against the lists.
04 Controls
OFAC's 2021 guidance specifically recommends geolocation and IP-blocking tools, screening of digital-currency and IP addresses against the SDN List, and the use of information gathered for other purposes — such as security — in sanctions screening. The controls below implement that, and no more than that, for the information the service holds.
- IP-country blocking, web and Stratum. Connections whose IP address geolocates to a jurisdiction in section 03 are refused at both the website and the Stratum endpoints. Stratum is included because it is the service; blocking only the website would leave the actual mining path open.
- Payout-address screening. Every payout address is screened, on first connection and before each payout run, against the digital-currency addresses OFAC publishes on the SDN List. OFAC lists addresses on specific chains; a Spearmint address will not match a listed Bitcoin address, so this control is expected to produce few or no matches, but the screen runs so that a listed Spearmint address, should one ever be published, is caught.
- Email screening. Where a miner registers a notification email, the address is screened against SDN List entries that include email addresses.
- VPN and anomaly indicators. Connections from IP ranges known to belong to anonymising VPN or proxy services, and worker patterns that change country improbably quickly, are flagged for review rather than blocked automatically. Review decisions are logged.
- Compliance decision log. Every refusal, flag, review outcome, withheld payout, and list update is recorded with a timestamp, the basis, the address or IP-country involved, and the person or system that decided. Nothing is refused or withheld without a log entry.
- Record retention. Compliance records are kept for at least five years, consistent with OFAC recordkeeping requirements.
- List currency. The SDN List and the country list are refreshed automatically at least daily from OFAC's published sources.
05 What happens on a match
- A connection from a restricted jurisdiction is refused. No shares are recorded and no allocation is created.
- If a payout address, or a miner behind it, is found to match a sanctions list after shares have been recorded, further shares from that address are declined and any pending payout to it is withheld and segregated pending counsel's instruction.
- The Operator will comply with OFAC's blocking and reporting requirements as counsel specifies them, including the initial blocked-property report and the annual report where applicable.
- A miner who believes they have been refused or withheld in error may contact the Operator (section 08). Because the service holds no identity information, resolving a false positive may require the miner to provide information they would not otherwise have to give; the Operator will ask for the minimum needed and will say why.
06 What the Operator does not do
- The Operator does not collect names, government identification, or other know-your-customer information as a condition of mining. The service can be operated, and the controls above can be run, without it. Collecting it would create a data set the service has no other use for.
- The Operator does not screen what it does not hold. There is no name screening because there are no names.
- The Operator does not treat a foreign hosting location as reducing its obligations, and does not treat a miner's use of the service as reducing the miner's own.
- If a future legal requirement, or counsel's advice, means the service must collect identifying information in some circumstance, that is a compliance-significant change to the service and goes through the regulatory change-control list and this policy before it starts.
07 Programme elements
OFAC's Framework for OFAC Compliance Commitments, referenced in the 2021 guidance, sets out five components of an effective programme. This is how each is met.
| Component | How Spearmint Mining meets it |
|---|---|
| Management commitment | The Operator's principal is named, owns this policy, and approves any change to it. Compliance decisions may not be overridden by anyone else. Resources for list subscriptions, screening tooling, and counsel are budgeted before opening. |
| Risk assessment | Written assessment of the service's exposure: a pseudonymous, global Stratum service with no identity collection and payouts on an as-yet-unlisted chain. Reviewed annually and on any change to the service or to OFAC's programmes. Records where the residual risk lies and why the controls are proportionate. |
| Internal controls | The controls in section 04, implemented in software, with the decision log as evidence. Written procedures for refusal, withholding, review, and release. The regulatory change-control list prevents new data flows from bypassing screening. |
| Testing and auditing | Quarterly test of the IP block against known addresses in each restricted jurisdiction; quarterly test that the SDN feed is current and that a synthetic listed address is caught; annual review of the decision log for consistency; findings recorded in the build log. |
| Training | Everyone with access to the compliance log or the ability to change the controls reads this policy and the procedures before access is granted, and again on each revision. Training is recorded. |
08 Reporting a concern
- To report a suspected sanctions issue, or to contest a refusal or a withheld payout, write to [email protected] with the subject line "Sanctions". Include the payout address concerned. Do not include a private key.
- Reports are logged and reviewed by the Operator's principal with counsel where needed.
09 Version
- version
- 0.1 — draft for attorney review
- revised
- 13 September 2026
- effective
- Not in force; the service is not open
- list reviewed
- 13 September 2026 — Cuba, Iran, North Korea, Crimea/DNR/LNR; Syria removed following E.O. 14312
- sources
- OFAC Sanctions Compliance Guidance for the Virtual Currency Industry (Oct 2021); OFAC Framework for OFAC Compliance Commitments; E.O. 14312 (30 Jun 2025); OFAC FAQ 559