// attributes & scoring

_ transparent, rules-based — set once, recalculated automatically

Every service starts from two base scores of 50Privacy and Trust. The attributes in the catalog below add or subtract points (each axis capped 0–100). The headline grade is a weighted blend:

Overall = Privacy × 60% + Trust × 40%

Most attributes are set once by a moderator. Some are derived automatically from data we already have (marked auto) and update on their own over time — service age, Monero support, live-rate integration, our verification window. Nothing is a hand-tuned number: change a rule and every service recalculates.

A+ 90+ Excellent A 80–89 Very good B 70–79 Good C 58–69 Fair D 45–57 Weak F <45 / scam — avoid
KYC Policy
Guaranteed no-KYC +25 priv
Terms explicitly state identity verification will never be requested.
No KYC after AML flag +5 priv+5 trust
No identity check even when a deposit is flagged by AML screening.
Refunds without KYC on AML flag +2 trust
Returns AML-flagged funds without demanding identity verification.
Proven no-KYC (last 10 swaps) auto +5 trust
The 10 most recent on-platform swaps all stayed anonymous — no KYC was requested. Auto-removed if any of the last 10 asked for KYC.
Transaction monitoring -2 priv
Deposits are screened against blacklisted sources.
May freeze funds on AML -3 trust
Internal AML checks may freeze suspicious funds.
KYC required for AML refund -3 priv
Requires identity verification before returning AML-flagged funds.
KYC depends on partner -6 priv
KYC policy depends on the upstream liquidity provider.
Rare KYC -5 priv
No routine KYC, but may ask if compelled by authorities.
KYC for fiat only -2 priv
Identity verification is required only for fiat on/off-ramp; crypto-to-crypto swaps stay no-KYC.
Shotgun KYC -10 priv
May demand KYC or freeze funds mid-swap via AML checks.
Mandatory KYC -25 priv
Identity verification is mandatory for core features.
Privacy
No registration needed +6 priv
Usable without creating an account.
No-logs policy +6 priv
States it keeps no activity logs and does not store IP addresses.
Accepts Monero auto +5 priv
Supports Monero (XMR).
Tor / onion service +3 priv
Reachable over a Tor onion address.
I2P service +3 priv
Reachable over the I2P network (.i2p eepsite).
No email required +3 priv
No email address is required to swap.
No JavaScript needed +1 priv
Works without enabling JavaScript.
Usage detectable on-chain -1 priv
On transparent chains, service usage can be traced.
Account required -2 priv
An account must be created to use the service.
Email required -3 priv
An email address is required.
Data sharing -4 priv
Shares personal data with third parties or authorities.
Logs IP / metadata -4 priv
Its policy admits storing IP addresses or request metadata.
Phone number required -5 priv
A phone number / SMS verification is required.
Trust & Reliability
Verified auto +10 trust
Listed and stable on notkyc for 90+ days with no active incidents.
Mature service auto +6 trust
The service has been operating for 2+ years.
Live rates / API auto +4 trust
Provides live rates through an API integration.
Non-custodial +4 trust
Never takes custody of your funds.
Good customer support +4 trust
Responsive, helpful customer support.
Public policies +2 trust
Publishes its ToS / AML policy.
Legally registered +2 trust
Operates as a registered legal entity.
Established third-party reputation +5 trust
Has a verifiable positive track record across independent sources (Reddit, BitcoinTalk, Trustpilot, forums) — not just its own claims.
PGP-signed mirrors +4 trust
Publishes a PGP-signed list of canonical / onion mirror addresses to guard against phishing clones.
Warrant canary +3 trust
Maintains a warrant canary — a signal of transparency about legal requests.
Slow processing -3 trust
Slower-than-typical processing times.
No / unclear refund policy -3 trust
No or unclear refund policy.
No published policies -3 trust
Publishes no ToS / AML / dispute rules.
May freeze / suspend -4 trust
May freeze or suspend access at its own discretion.
No third-party history -6 trust
New or obscure with no independent reputation from third-party sources — only its own claims to go on.
New service auto -5 trust
Younger than one year.
Poor or no support -5 trust
Little or no customer support.
Custodial wallet -5 trust
Holds custody of your funds / private keys.
Recently added auto -8 trust
Recently added to notkyc — limited data so far.
Operating < 3 months auto -10 trust
Has been operating for less than 3 months.
Potential risk -15 trust
Operates abnormally or shows exit-scam patterns.
Scam -50 trust
Failed review or shows serious unresolved risk.
Security Incidents

A confirmed incident applies a one-time trust penalty that fades to zero over a window set by severity. The resolution outcome immediately shrinks the penalty, then the remainder decays.

SeverityPenaltyDecays over
Low−590 days
Medium−12180 days
High−22365 days
Critical−35540 days

Penalty retained by outcome: funds recovered 20% · users reimbursed 30% · partial recovery 50% · funds lost 75% · unknown 50%.