API004 — Application Release Guidelines

Last updated: September 1, 2026

API App — Release to Production: Application guide for releasing an application to production.

Checklist

  • Diagram of flow of funds

  • Review functional app/integration on Sandbox

  • Customer's enrollment/sign-up process (remitter & beneficiary)

  • List any due diligence processes

    • What remitter and/or beneficiary details are collected upon initial sign-up

    • Each remitter must be onboarded separately

      • Ensure the master admin or remitter account is the proper person — the signatory authority

      • Completion of Advanced Profile application for remitters

  • Xtrm Terms and Conditions linked

  • Bank walkthrough of integration

  • Transfer walkthrough of integration

  • Foreign exchange rates agreement in place, if utilized

  • Help/support plan of integrator/managing account or remitter

    • Integrator and/or managing account needs to be the primary support

  • Integrator to register on the production server

  • Obtain API keys from the production account

    • Whitelist IP on production credentials

    • Run test transactions on the production server

The checklist explained

Actors and roles

Keeping the actors and roles clear is critical to knowing who is doing what for whom.

Ultimate remitter. The ultimate remitter is the source of funds — the company initiating the payment. A company may make payments on its own behalf, or these payments may be made by a third party (a managing company).

Remitter. The remitter is the company making the payment via Xtrm, either on its own behalf (in which case it's also the ultimate remitter) or on behalf of another company.

Beneficiary. The beneficiary is the entity (a company or individual) receiving the funds.

Xtrm. Xtrm holds funds on behalf of the ultimate remitter(s) as a third-party financial processor. Xtrm is responsible for KYC, KYB, money-laundering prevention, regulatory compliance, and tax reporting compliance. Once payments are processed by Xtrm, the funds belong to the beneficiary — the payment is completed. In many cases, Xtrm is then holding the funds for the beneficiary.

Diagram of flow of funds

A diagram of how money moves from party to party is a useful explanatory tool to help regulators understand the money flow.

For compliance purposes, the flow of money must be clear as to the source of the funds (the ultimate remitter) and the entity receiving those funds (the beneficiary). Companies that manage payment plans for other remitters cannot hold funds for their clients unless they have regulatory permission (as a third-party payor, such as Xtrm).

If Company A ("AliceCo") is making payments on behalf of Company B ("BobGmbH") to a third party C ("Carol"), to remain compliant, funds must always be in the possession of BobGmbH — even though AliceCo has permission to take actions on behalf of BobGmbH. In the Xtrm ecosystem, this means AliceCo is a managing company. Both AliceCo and BobGmbH must be onboarded as remitters, and payments made on behalf of BobGmbH must originate from wallets belonging to BobGmbH (which AliceCo has permission to access).

To remain compliant, AliceCo must not make payments on behalf of BobGmbH from wallets owned by AliceCo, nor may AliceCo receive money from BobGmbH for dispersal to other entities.

To remain compliant, funds in wallets owned by BobGmbH must originate from BobGmbH (AliceCo may not transfer funds into BobGmbH's wallets unless AliceCo is making a payment to BobGmbH). Even when AliceCo is making a payment to BobGmbH, this may be sufficient to draw a regulator's attention simply because it looks like a commingling of funds. A clear, well-laid-out flow diagram showing where funds originate and how they're dispersed can go a long way toward reassuring regulators that all transactions are compliant and transparent.

Funding for BobGmbH's wallets must originate from BobGmbH, typically via ACH, SWIFT, or check.

Each ultimate remitter must be onboarded separately

To remain compliant, each remitter is onboarded separately. Xtrm manages this a little differently than some other companies, where companies and conglomerates may have multiple accounts. Xtrm simplifies this process by requiring that a single company have a single account, regardless of geography or separation of business units. This allows a company, once onboarded, to enable Xtrm payments for any part of its business with minimal regulatory fuss. To maintain regional and business separation of funds, Xtrm supports fine-grained permissions for administrators — a particular administrator might have access only to regional or sub-regional wallets, or to wallets with funds for specific purposes.

At first glance, this might seem like a complication, but regulators require information about the ultimate source of funds (the parent company). Onboarding the parent company, and establishing wallets and administrators restricted along regional or business boundaries, means more transparency for regulators — which in turn keeps them satisfied.

Completion of Advanced Profile application

Onboarding happens in several steps, and the details are beyond the scope of this document. The general process is that companies supply information about themselves (tax documents, bank accounts, etc.), and as they do so, they complete their advanced profile. The more information Xtrm has about a company, the more complete the profile — and the more latitude Xtrm can extend, in terms of limits on the amount of funds transferred, the number of transfers permitted per day and per week, and overall velocity limits.

If these limits, even with a fully complete profile, are insufficient, please contact your partner manager or Xtrm support — we can increase these limits to support your requirements.

Due diligence / KYC / KYB

To comply with Xtrm's own regulatory burden, Xtrm performs Know Your Customer (KYC) and Know Your Business (KYB) checks. This is Xtrm's responsibility, and generally takes several business days when onboarding a new remitter. Xtrm will contact managing companies should any issues arise (this is unusual; most companies can be onboarded without difficulty). Likewise, Xtrm needs to know what information you're handling, which can help reduce your compliance burden further. See Onboarding Your Company Overview.

Review functional app/integration on Sandbox

Development and testing occur in a dedicated sandbox environment. This environment runs the same software as Xtrm's production systems, except that funds are not actual funds, and no real financial connections are maintained (no actual banks are linked, only test accounts). Xtrm places money in test accounts as needed for development and testing.

Before Xtrm enables any accounts on production, Xtrm requests an application walkthrough on the live sandbox (to see the API in use) to ensure the application is secure and compliant.

Monitor API requests (real time). During this test, Xtrm monitors the application in the sandbox and watches the API calls live.

Enroll/sign-up process

Collected information. Xtrm collects as little personally identifiable information (PII) as possible, as needed — and in many cases can remove significant quantities of PII from the remitter's systems.

Due diligence. Knowing what due diligence has already been completed by our remitters can speed up Xtrm's own due diligence process.

The master administrator

To properly assume regulatory and financial compliance, Xtrm needs the master administrator for every remitter to have signatory authority over the funds held for the remitter by Xtrm. The Chief Financial Officer (CFO) is often the right person, but not always — while a CFO or similar corporate officer may have the right authority, they don't always have the time or technical expertise to administer the account. To make administration simpler, Xtrm has four levels of users. More detail is available at: