
The word license sounds reassuring, but it says little about what is actually protected for the client. Different licenses cover different actions, operate within different borders and grant different levels of protection. So it helps to read not the label itself but which authorization was granted and what it extends to.
What is actually licensed

It is not the company as a whole that is licensed but a specific activity. Holding client assets, exchanging one asset for another, managing funds and issuing stablecoins are different actions that require different authorizations. A company can hold a license for one action and offer the client something entirely different for which it has no authorization.
So the first step is to match what the company does in practice with what it is actually authorized to do. If a venue advertises yield but the license only covers exchange, the yield part stays outside supervision, and the client is unprotected exactly where the risk is highest.
The second layer is the country that granted the authorization. The same word license means a completely different volume of checks and requirements under a strict regime and under a soft one. A sensible client looks not at the fact of a license but at the reputation of whoever issued it.
A license is not a guarantee of quality

A license confirms that a company passed a certain threshold and agreed to supervision. It does not promise that the business is profitable, that reserves are sufficient or that the client will not lose money. Many loud collapses happened to companies that held at least one license, because the risk sat in the part of the business that supervision did not cover.
It is important to understand the line between conduct supervision and prudential supervision. The first watches that a company deals honestly with clients and follows the rules. The second watches that a company does not collapse under its own weight. Many crypto licenses cover only the first and barely touch the second.
So a license is best treated as a floor, not as a mark of quality. It filters out the crudest players but does not replace analysis of reserves, risk management and the specific terms of service.
Custodial and non custodial models

The key distinction in any license is whether the company holds client assets. A custodial model means the company keeps the funds and keys, so the client depends on its solvency and honesty. Here the license and the asset segregation rules carry enormous weight.
A non custodial model means the keys stay with the client and the company only provides an interface. Here the risk of the company’s bankruptcy is lower, but the client’s own responsibility for key storage is higher. Confusing these two models is dangerous because they place the risk on different people.
In practice many venues mix models, holding part of the funds themselves and giving part to an external custodian. A sensible client finds out who exactly holds their assets at each moment and how those assets would be separated in case of trouble.
Passporting and the borders of authorization

A license works only where it is recognized. In some regions an authorization from one country allows operation across the whole bloc through a passporting mechanism. In others each country requires its own authorization, and a neighbor’s license means nothing.
This matters for the client, because a company can be licensed in one country and serve clients from a completely different one where that license gives no protection. If something goes wrong, the client discovers there is nowhere to complain, because the local regulator has no relationship with the company.
So it is worth checking not only that a license exists but also whether it extends to your country and to the specific product you use. A gap between the place of the license and the place of the client is a common and expensive trap.
What to check in the authorization itself
It helps to find the license in the regulator’s public register rather than on the company’s own website. The register shows the exact name of the legal entity, the list of authorized actions and the status of the license. Often it turns out that one group entity holds the license while a different one serves the client.
It is worth checking the status: whether the license is active, suspended or granted temporarily for a transition period. Many companies operate under temporary permissions that may not be renewed, and this is not at all the same as a full license.
Finally, it helps to understand what obligations the license imposes on the company: asset segregation, reporting, capital requirements. It is these obligations, not the label itself, that determine how well the client is actually protected.
Capital and reserve requirements

A serious licensing regime requires a company to hold minimum capital and, for stablecoin issuers, real reserves against its liabilities. These requirements matter more than marketing promises, because they determine whether the company can withstand stress. Capital is a cushion that absorbs losses before they reach the client, and reserves are a guarantee that liabilities are backed by real assets.
The problem is that requirements differ sharply between regimes and sometimes exist only on paper. It helps to understand not only the size of the requirement but also how often and by whom compliance is checked. A capital requirement without regular verification is almost useless, and a reserve without an independent audit remains a promise. A sensible client looks at the frequency and quality of checks, not only at the figure in the law.
AML and KYC as part of the license
Much of the licensing burden is devoted not to protecting client money but to fighting money laundering and verifying identity. For the client this means stricter checks at entry, but it also lowers the risk that the venue becomes a channel for criminal funds and is suddenly frozen by a regulator. Strict AML is an inconvenience at the door but protection over the long run.
The flip side is that compliance with these rules also falls on the client. Funds can be frozen during a check, and a withdrawal to a new address may require extra documents. It helps to understand in advance which procedures the venue applies, because they determine how quickly and predictably the client can use their own money.
What happens when a license is revoked
A license can be lost as well as gained, and the revocation scenario matters no less than the fact of authorization. On revocation the regulator usually requires an orderly winddown: returning funds to clients, stopping new operations and handing over records. A well built regime protects the client at exactly this moment, while a weak one leaves them alone with the problem.
It helps the client to understand what would happen to their assets if the company lost its license. Whether their funds are segregated, who would return them and in which queue they stand. The answer rarely appears in advertising, but it is what defines the real value of the authorization in the worst case rather than in calm times.
Advertising and promises versus the real authorization

A frequent gap appears between what a company says in advertising and what the license actually covers. A venue may stress its regulated status but apply it only to a small part of the business, leaving the riskiest part outside supervision. A client who reads only the marketing easily overestimates their protection.
The sensible approach is to check every loud claim against the list of authorized actions in the register. If the company promises yield but the license covers only custody, the yield part stays unregulated. The gap between promise and authorization is not a detail but the main source of a false sense of security.
How to read the group of companies behind a brand

Behind a single brand there is often a group of several legal entities in different countries. One of them holds the license, while another signs the contract with the client, and the client protection depends precisely on whom they signed the agreement with. The brand on the website is not the same as the name of the licensed entity in the register.
So it helps to find the exact name of the counterparty in the user agreement and match it against the regulator register. If the names do not match, the client is dealing not with the licensed entity but with its relative, and the real protection may be far weaker than expected.
A practical checklist

Before trusting funds to a venue it helps to run a short list. Which activity the license covers and whether it matches what you do. Which regulator and which regime stand behind it. Whether it extends to your country. Whether the model is custodial and how client assets are segregated. Whether the license is active or a temporary status.
If the answers match what the company promises, the license genuinely reduces risk. If there is a gap between the label and the real service, it is wiser to treat the company as unregulated in the part that matters to you, and to act accordingly.
Examples and sources
To understand what an authorization actually grants, it helps to compare regimes: MiCA in the European Union, the VARA rules in Dubai and the approach of MAS in Singapore. Each regulator keeps a public register and a rulebook you can use to check which services a license really covers.



