LEGAL · DEVELOPERS
One authority pipeline, every interface.
Effective August 25, 2026. These terms govern API, MCP, webhook, sandbox, and production developer access.
Interfaces
Authorized customers may access VERITAN through Console, API, MCP, and Events/Webhooks subject to the same organization, project, environment, credential, scope, entitlement, quota, spend, audit, and custody rules.
Sandbox and production
Sandbox or test responses may be synthetic, deterministic, or non-authoritative and must be clearly labeled. Production credentials are separately governed and may not be inferred from sandbox access.
Credentials
Keys and secrets are displayed only as permitted by the credential lifecycle and must be protected from disclosure. Credential sharing, resale, scraping, bypassing rotation, or defeating rate limits is prohibited.
Commercial model
Production developer access is governed by the current price book: $500/month for the published B2B API plan and $0.15 per additional VERITAN Operation above included volume, unless a signed rate card controls.
Idempotency and retries
Customers must use provided idempotency mechanisms for mutating or billable operations. A valid retry should not duplicate an accepted mutation or billable usage event.
Machine-readable results
A verification result may include current verdict, evidence coverage, limitations, issuer/reviewer authority, registry status, signature status, and permitted statement. Customers must not strip limitations or present a broader claim than the returned authority supports.
Caching and current state
Cached results may become stale after correction, supersession, revocation, expiration, or authority change. Customers are responsible for revalidating current state for decisions that depend on current credential status.
Webhooks
Customers are responsible for endpoint security, signature verification, replay protection, secret rotation, availability, and lawful processing of delivered event data.
Security and abuse
VERITAN may throttle, suspend, or revoke access for abuse, compromise, anomalous traffic, attempts to bypass controls, credential leakage, fraud, or threats to the platform or other customers.
No autonomous expansion of authority
AI agents receive no greater authority than the credential, organization, project, environment, scope, entitlement, and spend controls assigned to them.