GOVERNANCE POLICY

Lux Capital LLC

Effective Date: June 1, 2026 | Version 1.0
FinCEN MSB Registration No. 31000283507084

1. Purpose and Scope

This Governance Policy (the “Policy”) establishes the principles, structures, responsibilities, and processes that govern the management, oversight, and accountability of Lux Capital LLC (“Lux Capital” or the “Company”). It is designed to ensure that the Company operates with integrity, transparency, and in full compliance with applicable laws and regulations across all jurisdictions in which it operates.

This Policy applies to all members of the Board of Directors (or equivalent managing body), all officers, employees, contractors, and agents of Lux Capital, regardless of their position or location. It governs the Company’s activities in the United States of America (its jurisdiction of incorporation), the Federative Republic of Brazil, and the European Union.

This Policy is informed by, and must be read in conjunction with:

  • U.S. federal financial regulations, including the Bank Secrecy Act (BSA), FinCEN regulations, and applicable state laws;
  • EU Regulation 2023/1114 on Markets in Crypto-Assets (MiCA) and applicable national frameworks;
  • The Company’s Code of Ethics, Privacy Policy, and AML/CFT Compliance Program.

2. Corporate Structure and Governing Body

2.1 Organizational Structure

Lux Capital LLC is a limited liability company organized under the laws of the State of Wyoming, United States of America (Registered Address: 1603 Capitol Avenue, Ste 219, Cheyenne, WY 82001). The Company’s management structure is as follows:
  • Managing Member(s) / Board of Managers: responsible for strategic direction, oversight of management, and ultimate accountability for regulatory compliance;
  • Chief Executive Officer (CEO): responsible for day-to-day operational management and execution of the Board’s strategic directives;
  • Chief Compliance Officer (CCO): responsible for overseeing the Company’s compliance program, regulatory relationships, and reporting obligations;
  • Chief Financial Officer (CFO): responsible for financial management, treasury operations, and financial reporting;
  • Data Protection Officer (DPO): responsible for privacy governance and compliance with data protection laws;
  • Money Laundering Reporting Officer (MLRO): responsible for AML/CFT program oversight and Suspicious Activity Reports (SARs).

2.2 Appointment and Removal

Officers shall be appointed and removed by the Managing Member(s) or Board of Managers in accordance with the Company’s Operating Agreement. All officers must satisfy applicable fit-and-proper requirements under the laws of each jurisdiction in which the Company operates. In particular, individuals proposed for senior management positions must demonstrate integrity, competence, and financial soundness, in accordance with:
  • FinCEN guidance on MSB ownership and control;

3. Regulatory Compliance Framework

3.1 Compliance Program

Lux Capital maintains a written Compliance Program that is reasonably designed to prevent the Company from being used to facilitate money laundering, terrorist financing, fraud, and other financial crimes, and to ensure compliance with all applicable regulatory obligations. The Compliance Program encompasses, at minimum:

  • A written Anti-Money Laundering (AML) and Counter-Terrorist Financing (CFT) policy;
  • A Know Your Customer (KYC) and Customer Due Diligence (CDD) program, implemented via Sumsub (identity verification platform) for onboarding and ongoing monitoring;
  • A sanctions screening program (OFAC, UN, EU, COAF);
  • Transaction monitoring procedures, implemented via Chainalysis KYT (Know Your Transaction) for blockchain analytics and on-chain risk scoring;
  • A suspicious activity reporting (SAR) procedure;
  • A record-keeping program in accordance with BSA requirements and applicable Brazilian regulations;
  • A training program for all covered employees.

3.2 Multi-Jurisdictional Regulatory Obligations

Given Lux Capital’s operations across multiple jurisdictions, the CCO is responsible for maintaining a regulatory obligation matrix that maps applicable requirements by jurisdiction and function. Key multi-jurisdictional obligations include:

Regulatory Area U.S. Requirement Brazil Requirement
AML/CFT BSA; 31 CFR Part 1022; FinCEN SAR filing Law No. 9.613/1998; Law. No. 12.846/2013, as applicable.
Virtual Asset Regulation FinCEN MSB registration; State MTL (as applicable) Not Applicable.
Consumer Protection FTC Act; CFPB regulations CDC (Law No. 8.078/1990), as applicable.
Data Protection CCPA/CPRA; state privacy laws LGPD (Law No. 13.709/2018); ANPD resolutions, as applicable.
Tax Reporting IRS; FATCA; FinCEN Form 114 (FBAR) Receita Federal; IN RFB 1,888/2019, IN RFB 2.291/2025 (crypto reporting), as applicable.

3.3 Licensing and Registration

Lux Capital holds the following regulatory registrations and must maintain them in good standing at all times:

  • FinCEN MSB Registration (United States) — registration number 31000283507084, renewable every two years pursuant to 31 CFR 1022.380;
  • State money transmitter licenses — as required by the laws of states in which the Company has clients or operations;

The CCO is responsible for monitoring all regulatory registration renewal deadlines and ensuring timely renewal. Any lapse in required licenses or registrations must be immediately reported to the Managing Member(s).

4. Internal Controls and Risk Management

4.1 Three Lines of Defense Model

Lux Capital adopts a Three Lines of Defense model for risk management and internal control:

  • First Line — Business Operations: all business functions own and manage the risks arising from their activities. Managers are responsible for implementing controls within their teams.
  • Second Line — Compliance and Risk: the CCO and Risk function provide oversight, challenge, and advice to the first line, develop policies and procedures, and monitor control effectiveness.
  • Third Line — Internal Audit: independent periodic reviews assess the effectiveness of governance, risk management, and internal controls, and report findings to senior management and the Board.

4.2 Conflicts of Interest

Lux Capital maintains a written Conflicts of Interest Policy that identifies, manages, and, where necessary, discloses conflicts of interest. All officers and employees are required to disclose actual or potential conflicts of interest to the CCO. The Company will not permit conflicts of interest that could harm clients or compromise regulatory obligations.

Specifically, given the nature of Lux Capital’s investment contract business (raising client funds for crypto arbitrage), the following conflicts are subject to heightened scrutiny:

  • Personal trading in virtual assets by officers or employees in instruments traded on behalf of clients;
  • Related-party transactions between Lux Capital and entities in which officers have financial interests;
  • Compensation structures that create incentives to act against the interests of clients.

4.3 Financial Controls

Lux Capital maintains financial controls including:

  • Annual financial statements prepared in accordance with U.S. Generally Accepted Accounting Principles (U.S. GAAP) or International Financial Reporting Standards (IFRS), as applicable;
  • Independent external audit of annual financial statements;
  • Monthly management accounts reviewed by the CFO and CEO;
  • A documented treasury policy governing cash management, liquidity, and investment of Company funds.

5. Policy and Procedure Management

All policies of Lux Capital must be:

  • Approved by the Managing Member(s) or their designated officer prior to implementation;
  • Reviewed and updated at least annually, or more frequently following material regulatory changes or operational incidents;
  • Distributed to all relevant personnel upon adoption and following material updates;
  • Maintained in a central policy register accessible to all employees.

The CCO is responsible for maintaining the policy register and managing the policy review cycle. Any employee who identifies a gap or inaccuracy in an existing policy must report it to the CCO.

6. Regulatory Reporting and Disclosure

Lux Capital complies with all applicable regulatory reporting obligations, including:

  • FinCEN Currency Transaction Reports (CTRs) for transactions exceeding USD 10,000;
  • FinCEN Suspicious Activity Reports (SARs) within required timeframes;
  • ANPD personal data breach notifications within 72 hours;
  • IRS Form 8300 and equivalent reports for large cash transactions;
  • Receita Federal cryptocurrency transaction reporting pursuant to IN RFB No. 1.888/2019 and IN RFB No. 2291/2025.

The CCO is responsible for maintaining a regulatory reporting calendar and ensuring the timely and accurate submission of all required reports. Failure to make required regulatory reports may constitute a serious violation of applicable law and will be treated as a disciplinary matter.

7. Whistleblowing and Internal Reporting

Lux Capital maintains a whistleblowing channel through which any employee, contractor, or third party may report, in good faith, actual or suspected violations of law, regulation, or Company policy, including violations of this Governance Policy. Reports may be made:
  • Via email to: compliance@lux.capital (monitored by the CCO or designated independent officer);
  • Directly to a member of senior management or the Board.
Lux Capital prohibits any form of retaliation against individuals who make good-faith reports through the whistleblowing channel. Retaliation will be treated as a disciplinary matter subject to sanctions up to and including termination. Whistleblower protections apply in accordance with applicable law, including Section 21F of the U.S. Securities Exchange Act.

8. Governance Reviews and Board Reporting

The CCO shall prepare a Governance and Compliance Report for review by the Managing Member(s) or Board of Managers on a quarterly basis. The Report shall include, at minimum:

  • Status of all regulatory licenses and registrations;
  • Summary of regulatory developments and their impact on the Company’s operations;
  • Compliance monitoring results and identified deficiencies;
  • Status of open regulatory findings, audit observations, and remediation actions;
  • Summary of suspicious activity reports filed;
  • Data breach and privacy incident log;
  • Whistleblower reports received and status.

9. Sanctions for Non-Compliance

Violations of this Governance Policy or applicable law may result in disciplinary action, up to and including termination of employment or engagement, civil liability, and referral to law enforcement or regulatory authorities. The severity of sanctions will be commensurate with the nature, gravity, and intent of the violation.

10. Policy Review

This Policy shall be reviewed at least annually by the CCO, with approval of any material amendments by the Managing Member(s). Reviews shall also be triggered by material regulatory changes, adverse supervisory findings, or significant changes to the Company’s business model.

Version 1.0 — Last updated: June 1, 2026

LUX CAPITAL, LLC | 1603 Capitol Avenue, Ste 219, Cheyenne, WY 82001 | FinCEN No. 31000283507084
compliance@lux.capital  |  privacy@lux.capital  |  lux.capital