Legal
Terms of Service
Effective Date: March 4, 2026
1. Acceptance of Terms
By accessing or using the Truthlocks verification infrastructure, associated application programming interfaces (APIs), software development kits (SDKs), console dashboards, consumer portal, documentation, or websites (collectively, the "Services"), you agree to be bound by these Terms of Service ("Terms") and all referenced policies, including our Privacy Policy. If you do not agree to these Terms, you may not access or use the Services.
If you are entering into these Terms on behalf of an organization, enterprise, government entity, or other legal entity, you represent and warrant that you have the authority to bind that entity to these Terms. In such cases, "you" and "your" refer to that entity.
2. Definitions
- "Attestation" means a cryptographically signed digital credential or claim issued through the Truthlocks platform.
- "Issuer" means an organization or individual authorized to create and sign Attestations using the Services.
- "Consumer" means an individual who receives, holds, or presents Attestations via the Truthlocks consumer portal (verify.truthlocks.com).
- "Verifier" means any party that checks the validity, provenance, or status of an Attestation.
- "Tenant" means an organizational account on the Truthlocks platform, identified by a unique tenant identifier.
- "Platform" means the Truthlocks verification infrastructure, including all backend services, APIs, SDKs, dashboards, and related tooling.
- "Transparency Log" means the append-only, cryptographically verifiable record of Attestation operations maintained by Truthlocks.
- "Proof Bundle" means a portable, self-contained verification package containing an Attestation, its cryptographic proof, and associated metadata.
3. Account Registration & Eligibility
To access the Services, you must create an account by providing accurate, current, and complete registration information. You are responsible for maintaining the confidentiality of your account credentials, API keys, and access tokens. You agree to notify Truthlocks immediately of any unauthorized use of your account.
You must be at least 18 years of age (or the age of legal majority in your jurisdiction) to create an account. If you are registering on behalf of an organization, you must be authorized to act on its behalf and bind it to these Terms.
Each Tenant account must designate at least one "Owner" with full administrative authority. Owners are responsible for managing team members, roles, permissions, and billing within their Tenant.
4. Service Description & License Grant
Subject to your compliance with these Terms, Truthlocks grants you a limited, non-exclusive, non-transferable, non-sublicensable, and revocable license to access and use the Services for lawful purposes related to issuing, managing, verifying, and revoking cryptographic Attestations.
The Services include, but are not limited to:
- Attestation Service: Issuance, management, revocation, and supersession of cryptographically signed credentials across 35+ standardized schemas.
- Verification Service: Real-time cryptographic verification of Attestation validity, revocation status, and provenance.
- Trust Registry: Organizational identity management, issuer registration, key lifecycle management, and RBAC governance.
- Transparency Log: Append-only, Merkle-tree backed audit log with cryptographic checkpoint anchoring.
- Consumer Portal: End-user interface for credential holders to view, manage, and share received Attestations.
- Console Dashboard: Administrative interface for Issuers to manage Attestations, team members, API keys, governance workflows, and billing.
- SDKs & APIs: Go and JavaScript/TypeScript SDKs, RESTful APIs, and webhook integrations for programmatic access.
5. Acceptable Use & Restrictions
You agree not to:
- Attempt to bypass, disable, or interfere with cryptographic, security, rate-limiting, governance, or access control mechanisms.
- Use the Services for unlawful, deceptive, or abusive activities, including fraud, impersonation, unauthorized surveillance, or rights violations.
- Reverse engineer, decompile, disassemble, or attempt to extract source code, signing logic, or verification algorithms except where expressly permitted by applicable law.
- Issue, mint, or distribute falsified, misleading, or unauthorized credentials or Attestations.
- Resell, redistribute, or sublicense access to the Services without prior written authorization from Truthlocks.
- Use automated means (bots, scrapers, crawlers) to access or interact with the Services in a manner that exceeds reasonable use or circumvents rate limits.
- Transmit malware, viruses, or other malicious code through the Services.
- Interfere with or disrupt the integrity, security, or performance of the Services or the experience of other users.
- Use the Services to create a competitive product or service, or to benchmark the Services without prior written consent.
Truthlocks reserves the right to investigate suspected violations and to suspend or terminate access to the Services at its sole discretion if a violation is determined to have occurred.
6. Cryptographic Responsibility
You acknowledge and agree that you are solely responsible for the generation, custody, management, rotation, and security of any cryptographic keys, credentials, API keys, or secrets used in connection with the Services.
Truthlocks does not store, escrow, or recover private signing keys controlled by Issuers unless explicitly agreed under a separate enterprise arrangement with Hardware Security Module (HSM) integration.
Loss, compromise, or unauthorized disclosure of private keys may result in permanent loss of control over associated Attestations or credentials. You must promptly report any suspected key compromise through the Console's key compromise workflow, which will trigger automatic revocation of affected Attestations and issuance of replacement keys.
Truthlocks is not responsible for any damages, losses, or consequences arising from key mismanagement, unauthorized key use, or failure to rotate keys in accordance with your organization's security policies.
7. Intellectual Property
All intellectual property rights in the Services, including but not limited to software, algorithms, designs, documentation, trademarks, logos, and trade secrets, are and shall remain the exclusive property of Truthlocks, Inc. or its licensors. These Terms do not grant you any right, title, or interest in or to the Services except for the limited license expressly stated herein.
You retain all rights in and to the data, claims, and content you submit to or through the Services ("Your Data"). You grant Truthlocks a limited, non-exclusive license to process, store, and transmit Your Data solely as necessary to provide the Services to you.
Feedback, suggestions, or enhancement requests you provide to Truthlocks may be used without obligation or compensation.
8. Fees, Billing & Payment
Certain features of the Services are available under paid subscription plans or usage-based pricing. By selecting a paid plan, you agree to pay all applicable fees as described in the pricing terms presented at the time of purchase or as detailed in an executed Order Form.
Usage-based charges (e.g., per-attestation minting fees, per-verification fees) are metered in real time and billed in arrears according to your billing cycle. All fees are stated in U.S. dollars unless otherwise agreed.
Fees are non-refundable except as required by applicable law or as expressly stated in an enterprise agreement. Truthlocks reserves the right to modify pricing with at least thirty (30) days' prior written notice. Continued use of the Services after a pricing change constitutes acceptance of the new fees.
If payment is not received within thirty (30) days of the due date, Truthlocks may suspend access to the Services until all outstanding amounts are paid in full. Truthlocks may charge interest on overdue balances at the lesser of 1.5% per month or the maximum rate permitted by applicable law.
You are responsible for all taxes, duties, and levies applicable to your use of the Services, excluding taxes based on Truthlocks' net income.
9. Confidentiality
Each party agrees that all non-public information disclosed by the other party in connection with these Terms or the Services, including business plans, technical data, API keys, pricing terms, and security configurations ("Confidential Information"), shall be kept confidential and not disclosed to third parties without the disclosing party's prior written consent.
Confidential Information does not include information that: (a) is or becomes publicly available through no fault of the receiving party; (b) was lawfully known to the receiving party prior to disclosure; (c) is independently developed by the receiving party; or (d) is required to be disclosed by law, regulation, or court order, provided the receiving party gives reasonable prior notice.
This confidentiality obligation survives for three (3) years following termination of these Terms, or indefinitely for trade secrets.
10. Data Processing & Privacy
Our collection, use, and protection of personal data is governed by our Privacy Policy, which is incorporated herein by reference. To the extent that you provide or submit personal data to the Services, you represent that you have the necessary rights, consents, and legal bases to do so.
For enterprise customers subject to data protection regulations (including GDPR, CCPA/CPRA, HIPAA, or equivalent frameworks), Truthlocks will enter into a Data Processing Agreement (DPA) upon request. Enterprise DPAs may include Standard Contractual Clauses (SCCs) for international data transfers.
11. Service Levels & Availability
Unless otherwise agreed in a signed Service Level Agreement (SLA), the Services are provided on an "as-is" and "as-available" basis. Truthlocks targets 99.9% uptime for production API endpoints but does not guarantee uninterrupted availability, error-free operation, or compatibility with all systems or use cases.
Scheduled maintenance windows will be communicated via the Truthlocks Status Page. Emergency maintenance may occur without prior notice when necessary to protect the security or integrity of the Services.
Enterprise and Institutional customers may be eligible for enhanced service levels, uptime commitments (up to 99.99%), priority support with defined response times, and dedicated infrastructure pursuant to a separate SLA or Master Service Agreement (MSA).
12. Warranties & Disclaimers
EXCEPT AS EXPRESSLY SET FORTH IN THESE TERMS OR A SIGNED ENTERPRISE AGREEMENT, THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, ACCURACY, OR AVAILABILITY.
Truthlocks does not warrant that the Services will meet your specific requirements, that results obtained from the Services will be accurate or reliable, or that the Services will be compatible with any third-party software, hardware, or systems.
Truthlocks does not warrant the legal validity, enforceability, or admissibility of any Attestation in any jurisdiction. Issuers are solely responsible for ensuring that their use of the Services complies with applicable laws and regulations.
13. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, TRUTHLOCKS SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING BUT NOT LIMITED TO LOSS OF PROFITS, REVENUE, DATA, BUSINESS OPPORTUNITIES, GOODWILL, OR REPUTATIONAL HARM, ARISING OUT OF OR RELATED TO YOUR USE OF OR INABILITY TO USE THE SERVICES, REGARDLESS OF THE THEORY OF LIABILITY (CONTRACT, TORT, STRICT LIABILITY, OR OTHERWISE).
IN NO EVENT SHALL TRUTHLOCKS' TOTAL AGGREGATE LIABILITY EXCEED THE GREATER OF: (A) THE AMOUNTS PAID BY YOU TO TRUTHLOCKS FOR THE SERVICES DURING THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM; OR (B) ONE HUNDRED U.S. DOLLARS (USD $100).
THE FOREGOING LIMITATIONS APPLY EVEN IF TRUTHLOCKS HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. SOME JURISDICTIONS DO NOT ALLOW THE EXCLUSION OR LIMITATION OF CERTAIN DAMAGES; IN SUCH JURISDICTIONS, OUR LIABILITY IS LIMITED TO THE MAXIMUM EXTENT PERMITTED BY LAW.
14. Indemnification
You agree to indemnify, defend, and hold harmless Truthlocks, its affiliates, officers, directors, employees, agents, and licensors from and against any and all claims, liabilities, damages, losses, costs, and expenses (including reasonable attorneys' fees) arising out of or related to: (a) your use of the Services; (b) your violation of these Terms; (c) your violation of any third-party right, including intellectual property, privacy, or contractual rights; (d) any Attestation you issue, including claims that an Attestation is false, misleading, or unauthorized; or (e) any claim by a third party arising from Your Data.
15. Term, Termination & Suspension
These Terms are effective upon your first access to the Services and remain in effect until terminated by either party.
Termination by You: You may terminate your account at any time by contacting support or through your Console settings. Termination does not entitle you to a refund of pre-paid fees.
Termination by Truthlocks: Truthlocks may terminate or suspend your access to the Services immediately, without prior notice, if: (a) you breach these Terms; (b) your account is delinquent for more than thirty (30) days; (c) we are required to do so by law; or (d) we reasonably believe your use poses a security threat to the Services or other users.
Effect of Termination: Upon termination, your right to access and use the Services ceases immediately. You must stop using all API keys, SDKs, and credentials associated with your account. Truthlocks will retain Your Data for thirty (30) days following termination, during which you may request an export. After that period, Your Data may be permanently deleted.
Issued Attestations recorded on the Transparency Log will persist beyond account termination, as the Transparency Log is append-only by design. Revocation of Attestations may still be processed during the 30-day retention period.
16. Governing Law & Dispute Resolution
These Terms shall be governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to its conflict of law provisions.
Any dispute arising out of or relating to these Terms or the Services shall first be resolved through good-faith negotiation between the parties for a period of thirty (30) days. If the dispute is not resolved through negotiation, it shall be submitted to binding arbitration administered by the American Arbitration Association (AAA) under its Commercial Arbitration Rules, with the seat of arbitration in Wilmington, Delaware.
Notwithstanding the foregoing, either party may seek injunctive or equitable relief in any court of competent jurisdiction to protect its intellectual property rights, confidential information, or to enforce the restrictive covenants of these Terms.
CLASS ACTION WAIVER: TO THE MAXIMUM EXTENT PERMITTED BY LAW, YOU AND TRUTHLOCKS AGREE THAT EACH MAY BRING CLAIMS AGAINST THE OTHER ONLY IN YOUR OR ITS INDIVIDUAL CAPACITY AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS OR REPRESENTATIVE ACTION.
17. Force Majeure
Neither party shall be liable for any failure or delay in performance due to causes beyond its reasonable control, including but not limited to acts of God, natural disasters, pandemics, war, terrorism, government actions, labor disputes, power outages, internet service disruptions, or cyberattacks, provided that the affected party promptly notifies the other party and uses commercially reasonable efforts to mitigate the impact.
18. Modifications to Terms
Truthlocks reserves the right to modify these Terms at any time. Material changes will be communicated via email to the address associated with your account or through a prominent notice on our website at least thirty (30) days before they take effect. Your continued use of the Services after the effective date of any modification constitutes your acceptance of the revised Terms.
For enterprise customers with executed MSAs or Order Forms, modifications to these Terms shall not override the terms of such agreements unless expressly stated.
19. General Provisions
Entire Agreement
These Terms, together with the Privacy Policy and any executed Order Forms, MSAs, or DPAs, constitute the entire agreement between you and Truthlocks regarding the Services and supersede all prior and contemporaneous agreements, proposals, and communications.
Severability
If any provision of these Terms is held to be invalid, illegal, or unenforceable, the remaining provisions shall continue in full force and effect. The invalid provision shall be modified to the minimum extent necessary to make it valid and enforceable.
Waiver
The failure of Truthlocks to enforce any right or provision of these Terms shall not constitute a waiver of such right or provision.
Assignment
You may not assign or transfer these Terms, or any rights or obligations hereunder, without the prior written consent of Truthlocks. Truthlocks may assign these Terms in connection with a merger, acquisition, reorganization, or sale of all or substantially all of its assets without your consent.
Notices
All notices required or permitted under these Terms shall be in writing and shall be deemed given when sent by email to legal@truthlocks.com (for notices to Truthlocks) or to the email address associated with your account (for notices to you).
Export Compliance
You agree to comply with all applicable export control laws and regulations. You shall not, directly or indirectly, export, re-export, or transfer the Services or any technical data to any country, entity, or individual prohibited by applicable sanctions or export control laws.
Government End Users
If you are a U.S. government end user, the Services are provided as "commercial items" as defined in 48 C.F.R. § 2.101, consisting of "commercial computer software" and "commercial computer software documentation," and are licensed to you with only those rights granted to all other end users under these Terms.
Contact Information
For legal inquiries, Master Service Agreements, Data Processing Agreements, or questions about these Terms:
Truthlocks, Inc.
Email: legal@truthlocks.com
