Terms of Service
1. Agreement to Terms
By accessing or using the Verified Credentials platform ("Service," "Platform," or "we"), you ("User," "you," or "your") agree to be bound by these Terms of Service ("Terms"). If you do not agree to these Terms, do not use the Service.
These Terms apply to all users of the Service, including Issuers, Verifiers, and Credential Subjects, as defined below.
2. Definitions
- Issuer: An entity registered on the Platform that issues W3C Verifiable Credentials to Credential Subjects. Issuers are assigned a Decentralized Identifier (DID) and an API key upon onboarding.
- Verifier: An entity registered on the Platform that verifies Verifiable Credentials presented by or on behalf of Credential Subjects.
- Credential Subject: The individual or entity described by a Verifiable Credential.
- Verifiable Credential (VC): A digitally signed, tamper-evident claim conforming to the W3C Verifiable Credentials Data Model v2.0.
- DID (Decentralized Identifier): A globally unique, cryptographically verifiable identifier generated for each Issuer and Subject on the Platform.
- API Key: A secret authentication token issued to Issuers and Verifiers for programmatic access to the Service.
- On-Chain Anchoring: The process of recording a SHA-256 hash of a credential on a public blockchain (Base network) for immutable timestamping and verification.
- Trust Tier: A classification level (Unverified, Verified, Regulated, Institutional) that determines an Issuer's permitted credential types and staking requirements.
- Stake: A monetary deposit required of Issuers at higher Trust Tiers, subject to slashing in the event of penalized disputes.
- Reputation Score: A numeric score (0-100) reflecting an Issuer's track record on the Platform.
3. Eligibility
You must be at least 18 years of age and have the legal capacity to enter into a binding agreement to use this Service. If you are using the Service on behalf of an organization, you represent and warrant that you have the authority to bind that organization to these Terms.
4. Account Registration and API Keys
4.1 Onboarding
When you onboard as an Issuer or Verifier, the Platform:
- Collects your organization name.
- Generates an ED25519 cryptographic keypair on your behalf.
- Derives a DID:key identifier from your public key.
- Issues a role-based API key (ADMIN for Issuers, CLIENT for Verifiers).
- Enrolls you in the applicable billing plan.
4.2 API Key Security
You are solely responsible for safeguarding your API key. API keys are cryptographically hashed (SHA-256) before storage; raw keys are displayed only once at creation and cannot be recovered. You must:
- Keep your API key confidential and not share it with unauthorized parties.
- Notify us immediately if you believe your API key has been compromised.
- Revoke compromised keys promptly through the API.
We are not liable for unauthorized access resulting from your failure to protect your API key.
4.3 Key Rotation
You may rotate your signing keys at any time. Previous key versions are retained to allow verification of credentials signed with older keys.
4.4 Rate Limiting
API access is subject to rate limits that vary by billing plan. Exceeding rate limits will result in temporary denial of service (HTTP 429). Repeated abuse of rate limits may result in account suspension.
5. Service Description
5.1 Credential Issuance
Issuers may issue Verifiable Credentials to Credential Subjects through the Platform's API. Each credential:
- Is digitally signed using the Issuer's private key (JWT format with EdDSA or ES256K signatures).
- Contains claims about the Credential Subject as provided by the Issuer.
- May be anchored on-chain, recording only the SHA-256 hash of the credential (never the credential contents) on the Base blockchain.
The Platform does not verify the truthfulness or accuracy of claims within credentials. Issuers are solely responsible for the accuracy, completeness, and lawfulness of credential claims they issue.
5.2 Credential Types
The Platform supports the following built-in credential types, subject to Trust Tier restrictions:
- KYC Basic Credential
- KYC Standard Credential
- KYC Enhanced Credential
- AML Screening Credential
- Accredited Investor Credential
Enterprise-tier Issuers may issue custom credential types.
5.3 Credential Verification
Verifiers may submit credentials for verification. The verification process includes:
- Cryptographic signature validation.
- Revocation status checking (StatusList2021).
- On-chain attestation status checking (if applicable).
- Trust tier and reputation assessment of the Issuer.
- Policy-based compliance evaluation.
Verification results include a compliance decision (APPROVE, DENY, or NEEDS_REVIEW) and a confidence score. These results are advisory and do not constitute legal, regulatory, or compliance advice.
5.4 Credential Revocation
Issuers may revoke credentials they have issued. Only the original Issuer of a credential may revoke it. Revocation is recorded both off-chain (via StatusList2021) and on-chain (if the credential was anchored). Revocation is irreversible.
5.5 Credential Renewal
Issuers may renew credentials approaching expiration. Renewal issues a new credential and optionally revokes the previous version.
6. Trust Tiers and Staking
6.1 Trust Tier System
Issuers are classified into Trust Tiers that determine their capabilities:
| Tier | Minimum Stake | Permitted Credential Types |
|---|---|---|
| Unverified | $0 | KYC Basic only |
| Verified | $100 | KYC Basic, KYC Standard, AML Screening |
| Regulated | $500 | All standard types |
| Institutional | $1,000 | All types including custom |
6.2 Staking
Higher Trust Tiers require monetary stakes. Stakes serve as a security deposit and economic incentive for responsible credential issuance. If an Issuer's stake falls below the minimum for their tier (due to slashing from dispute penalties), the Issuer's account may be automatically suspended until the stake is replenished.
6.3 Tier Upgrades
Tier upgrades require payment of a $50 tier upgrade fee in addition to meeting the minimum stake requirement for the target tier.
7. Dispute Resolution
7.1 Filing Disputes
Credential Subjects and Verifiers may file disputes against specific credentials. To file a dispute, the reporting party must:
- Identify the credential in question.
- Provide a reason for the dispute.
- Be authenticated with a DID-bound API key.
7.2 Evidence Submission
Parties to a dispute may submit evidence (up to 20 evidence items per dispute). Evidence must be relevant, accurate, and lawfully obtained.
7.3 Resolution
Disputes are resolved by Platform administrators as either:
- Cleared: The dispute is dismissed. The Issuer's reputation is positively adjusted (+5).
- Penalized: The dispute is upheld. The Issuer's reputation is negatively adjusted (-10), and a financial penalty may be assessed against the Issuer's stake.
7.4 Finality
Dispute resolutions are final. The Platform's dispute resolution process does not replace or preclude legal remedies available to the parties under applicable law.
8. Reputation System
8.1 Scoring
Each Issuer maintains a Reputation Score (0-100, starting at 50) calculated based on their activity:
| Event | Score Impact |
|---|---|
| Credential Issued | +1 |
| Credential Revoked | -3 |
| Dispute Won (Cleared) | +5 |
| Dispute Lost (Penalized) | -10 |
| Positive Verifier Feedback | +2 |
| Negative Verifier Feedback | -5 |
8.2 Consequences
Reputation scores are visible to Verifiers and may affect verification confidence scoring. Low reputation scores may trigger additional scrutiny during verification or result in reduced trust assessments.
8.3 Reputation Data Retention
Individual reputation events are retained for 90 days. The aggregate score persists for the lifetime of the Issuer account.
9. Billing and Payment
9.1 Plans
Issuer Plans:
| Plan | Price | Issuances/Month | Rate Limit |
|---|---|---|---|
| Starter | Free | 25 | 5 req/min |
| Professional | $99/month | 1,000 | 30 req/min |
| Enterprise | Custom | 10,000 | 300 req/min |
Verifier Plans:
| Plan | Price | Verifications/Month | Rate Limit |
|---|---|---|---|
| Developer | Free | 100 | 10 req/min |
| Protocol | $49/month | 10,000 | 120 req/min |
| Enterprise | Custom | 250,000 | 1,000 req/min |
9.2 Overage
Free-tier users who exceed their quota receive a 402 Payment Required response. Paid-plan users may incur per-unit overage charges as follows:
- Issuance overage: $0.12-$0.20 per credential (varies by plan)
- Verification overage: $0.01-$0.02 per verification (varies by plan)
9.3 Payment Processing
Payments are processed by Stripe, Inc. By subscribing to a paid plan, you agree to Stripe's Terms of Service. We do not store payment card details.
9.4 Cancellation
You may cancel your subscription at any time through the billing portal. Upon cancellation, your account reverts to the applicable free tier. Issued credentials remain valid after cancellation.
9.5 Platform Fees
Credential issuance incurs a platform fee of $1.00 per issuance, deducted from the Issuer's account balance or billed as overage.
10. Webhooks
10.1 Registration
You may register HTTPS webhook endpoints to receive real-time notifications of Platform events (verification results, credential revocations, dispute openings).
10.2 URL Requirements
Webhook URLs must:
- Use HTTPS (TLS encryption required).
- Resolve to public, non-private IP addresses.
- Not target internal, loopback, link-local, or cloud metadata endpoints.
10.3 Delivery
Webhook delivery uses exponential backoff retry (1 second, 5 seconds, 30 seconds). Failed deliveries after all retry attempts are logged to a dead-letter queue. We do not guarantee webhook delivery and you should not rely on webhooks as the sole source of truth for credential state.
10.4 Webhook Limits
The number of registered webhooks is limited by your billing plan (Starter: 2, Professional: 10, Enterprise: 50).
11. On-Chain Anchoring
11.1 Blockchain Data
When on-chain anchoring is enabled, the Platform records the following on the Base blockchain:
- SHA-256 hash of the credential (as bytes32).
- Issuer's Ethereum address.
- Timestamp of anchoring.
- Expiration timestamp (if applicable).
- Revocation status.
No credential content, personal data, or claims are ever written to the blockchain.
11.2 Immutability
Data written to a public blockchain is permanent and cannot be deleted, modified, or erased. By using the on-chain anchoring feature, you acknowledge and accept this immutability.
11.3 Gas Fees
On-chain operations consume blockchain gas fees. These fees are included in the Platform's service pricing and are not separately billed to users.
12. Acceptable Use
You agree not to:
- Use the Service to issue fraudulent, misleading, or unlawful credentials.
- Attempt to authenticate with forged, stolen, or revoked API keys.
- Circumvent rate limits, access controls, or security measures.
- Use the Service to facilitate identity fraud, money laundering, or terrorist financing.
- Submit credentials for verification with the intent to obtain unauthorized access to third-party systems.
- Attempt to reverse-engineer cryptographic keys or credential hashes.
- Issue credentials to yourself (self-issuance is prohibited).
- Revoke or tamper with credentials issued by other Issuers.
- Register webhook URLs that target internal services, cloud metadata endpoints, or third-party systems without authorization.
- Use the Service in violation of any applicable law or regulation.
13. Intellectual Property
13.1 Platform IP
The Service, including its software, APIs, documentation, and trade names, is the intellectual property of Verified Credentials. These Terms do not grant you any ownership rights in the Service.
13.2 Your Content
You retain ownership of all credential content, claims data, and other materials you submit to the Service. By using the Service, you grant us a limited license to process, store, and transmit this content solely to provide the Service.
13.3 Open Standards
Credentials issued through the Platform conform to open standards (W3C Verifiable Credentials Data Model v2.0, DID:key method). You are free to verify credentials using any conformant implementation.
14. Service Availability
14.1 SLO Targets
We target the following Service Level Objectives:
- Availability: 99.9% (approximately 43 minutes of downtime per month).
- Latency (p95): Less than 200 milliseconds.
- Latency (p99): Less than 500 milliseconds.
These are targets, not guarantees. We do not offer Service Level Agreements (SLAs) with financial remedies unless separately agreed in writing for Enterprise-tier customers.
14.2 Maintenance
We may perform scheduled maintenance that temporarily reduces availability. We will endeavor to provide advance notice of planned maintenance.
15. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW:
- THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.
- WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE.
- WE ARE NOT LIABLE FOR THE ACCURACY, LEGALITY, OR VALIDITY OF ANY CREDENTIAL CLAIMS ISSUED BY ISSUERS THROUGH THE PLATFORM.
- IN NO EVENT SHALL OUR TOTAL LIABILITY EXCEED THE GREATER OF (A) THE AMOUNTS YOU PAID TO US IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM, OR (B) ONE HUNDRED US DOLLARS ($100).
- WE SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING BUT NOT LIMITED TO LOSS OF PROFITS, DATA, OR BUSINESS OPPORTUNITIES.
16. Indemnification
You agree to indemnify, defend, and hold harmless Verified Credentials, its officers, directors, employees, and agents from and against any claims, liabilities, damages, losses, and expenses (including reasonable attorneys' fees) arising from:
- Your use of the Service.
- Credential claims you issue or submit.
- Your violation of these Terms.
- Your violation of any applicable law or regulation.
- Any dispute between you and a Credential Subject or third party.
17. Suspension and Termination
17.1 By You
You may discontinue use of the Service at any time by revoking your API keys and canceling your subscription.
17.2 By Us
We may suspend or terminate your access to the Service immediately, without prior notice, if:
- You violate these Terms or our Acceptable Use policy.
- Your Reputation Score falls to zero.
- Your stake falls below the minimum for your Trust Tier and is not replenished within a reasonable period.
- We are required to do so by law or regulatory order.
- We reasonably believe your account poses a security risk to the Platform or its users.
17.3 Effect of Termination
Upon termination:
- Your API keys are revoked.
- You lose access to issue new credentials or verify credentials through the Platform.
- Previously issued credentials remain cryptographically valid and verifiable through their embedded proofs and on-chain anchors (if applicable).
- Staked funds subject to pending disputes may be retained until dispute resolution.
18. Modifications to Terms
We reserve the right to modify these Terms at any time. Material changes will be communicated through the API (via response headers or a dedicated endpoint) at least 30 days before taking effect. Your continued use of the Service after such changes constitutes acceptance of the modified Terms.
19. Governing Law and Jurisdiction
These Terms shall be governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to its conflict of laws principles. Any disputes arising under these Terms shall be subject to the exclusive jurisdiction of the state and federal courts located in Delaware.
20. Severability
If any provision of these Terms is held to be unenforceable or invalid, that provision shall be modified to the minimum extent necessary to make it enforceable, and the remaining provisions shall continue in full force and effect.
21. Entire Agreement
These Terms, together with the Privacy Policy, constitute the entire agreement between you and Verified Credentials regarding your use of the Service and supersede all prior agreements and understandings.
22. Contact
For questions about these Terms, contact:
Verified Credentials
Email: pavon@vectorguardlabs.com
Website: https://vercre.vercel.app