LEGAL · PRIVACY
Collect what the service needs. Preserve what the chain requires.
Effective August 25, 2026. This notice describes how VERITAN handles information across public, certification, developer, registry, and enterprise services.
What we collect
Depending on the service, VERITAN may collect account and contact information, organization and membership information, project/environment identifiers, certification submissions, evidence, custody and audit records, credential metadata, usage and security telemetry, billing records, enterprise inquiry information, and support communications.
Why we process it
We process information to provide and secure services, authenticate users, issue and govern credentials, evaluate certification evidence, operate the registry, meter usage, bill customers, prevent fraud and abuse, comply with law, respond to support requests, and preserve audit and chain-of-custody records.
Public registry data
Certain credential information is intentionally public, including record identifier, current status, tier, scope, evidence coverage, issuer/reviewer information, signature status, limitations, and supersession or revocation state where applicable. Submission evidence is not automatically public.
Business identity and compliance
For higher-risk or enterprise services we may collect legal-entity, authorized-representative, beneficial-owner, sanctions, jurisdiction, and related compliance information where reasonably necessary.
Service providers
VERITAN may use infrastructure, payment, security, communications, analytics, and support providers to operate services. Providers receive information only as needed for their contracted function and applicable legal obligations.
Retention
Retention depends on the record. Audit, custody, certification, security, billing, fraud-prevention, and legal records may be retained longer than ordinary account data when continuity or legal obligations require it.
Security
We use technical and organizational controls intended to protect customer data, including scoped credentials, access controls, logging, encryption in transit, and restricted privileged operations. No system can guarantee absolute security.
Choices and requests
Users may request access, correction, or deletion where applicable. Some records cannot be deleted when retention is necessary for legal, security, accounting, fraud-prevention, or chain-of-custody purposes.
International and legal processing
Where data crosses jurisdictions, VERITAN will use applicable contractual and legal mechanisms. Enterprise customers may receive additional data-processing terms through a signed DPA or order form.