Compliance at the front of entrepot trade increasingly rests on a deceptively low-level step: computing a SHA-256 fingerprint inside the customer's browser, hashing onboarding identity and counterparty due-diligence material locally, then posting the digest to the kyc/* prefix on OSS for record-keeping.

Why do it in the browser? Raw identity data — business licenses, beneficial owners, sanctions-screening results — should never leave the client in clear text. SHA-256 compresses any-length material into a fixed 256-bit digest; what gets uploaded is the digest plus minimal metadata, while the original files travel over an encrypted channel into the bucket, where no one holds a plaintext copy. This is the same hash-trust model we use for digital warehouse receipts, only the object shifts from title to identity.

Operationally, due diligence begins at onboarding. The moment a counterparty arrives, the system takes a device fingerprint plus a material hash and blocks immediately on any hit against the blacklist or sanctions set, before the workflow proceeds. For SNSUC's seven transshipment counterparties — refiners, traders, ship agents — one screening is reusable; every later letter of credit and settlement can trace back to that verified identity chain.

Regulators accept the logic. A hash digest is tamper-evident and independently reproducible; when the foreign-exchange authority or a bank asks, matching the digest against the original file's checksum proves the identity was real at onboarding and the material was not swapped afterward. Compliance shifts from retroactive paperwork to upfront evidence.