This is a first draft pending review by counsel. It is not a binding agreement and no one is contracting under it. Bracketed items are open facts, not omissions.
Terms of Service
1Agreement
These Terms govern use of the agentvalidate service operated by [LEGAL ENTITY — unresolved, see §15.5 of the master doc] ("Regent", "we"). By creating an account, using an API key, or calling any endpoint, you ("Customer") accept these Terms. If you are accepting on behalf of an organization, you represent that you have authority to bind it.
Where an executed order form or written agreement conflicts with these Terms, that document controls for the conflicting provision only.
2Definitions
- Service — the agentvalidate APIs, dashboards, gateway, sidecar, and SDKs.
- Agent — an automated, non-human software client that authenticates by cryptographic signature.
- Owner — the natural person or legal entity accountable for an Agent's actions and spending.
- Output — any response of the Service, including lookup responses, passports, decisions, and receipts.
- Passport — a signed attestation about an Agent's registry state.
- Receipt — a signed record of an authorization decision.
- End User — Customer's own customer, whose Agent may interact with Customer's service.
3What the Service is — and is not
The Service authenticates automated requests, reports the registry state of a signing key, evaluates whether a request falls within limits an Owner has authorized, and produces verifiable records of those determinations.
The Service is not a consumer reporting agency, a payment processor, a money transmitter, a custodian of funds, an escrow, an insurer, or a provider of legal, credit, or financial advice. It does not evaluate natural persons: its assessments pertain to software Agents and to individual transactions.
4Permitted and prohibited uses
Customer may use the Service solely to authenticate automated (non-human) requests, to determine whether a given request is authorized by an accountable party, and to prevent fraud in connection with such requests.
Customer shall not use the Service, or any Output, in whole or in part:
- as a factor in establishing an individual's eligibility for credit or insurance to be used primarily for personal, family, or household purposes;
- as a factor in any employment decision, including hiring, promotion, reassignment, or retention;
- as a factor in any decision regarding housing, tenancy, or rental eligibility;
- for any other purpose enumerated in 15 U.S.C. §1681b, or for any purpose that would cause Output to constitute a "consumer report" or Regent to be a "consumer reporting agency" as those terms are defined in the Fair Credit Reporting Act; or
- to make any decision about a natural person as distinct from the automated Agent to which the Output pertains.
Customer acknowledges that Regent is not a consumer reporting agency, that Output is not a consumer report, and that Regent does not authorize any use of the Service requiring compliance with the FCRA. Customer shall not resell, redistribute, or aggregate Output into any product used for the purposes prohibited above. Customer shall certify the purpose for which it accesses Output when issued an API key, and shall notify Regent promptly if that purpose changes. Regent may audit compliance with this Section and may suspend or terminate access for breach.
Customer also shall not: circumvent metering or rate limits; probe or enumerate the registry; misrepresent Output as Regent's assessment of a person; or use the Service to build a competing registry from Output obtained through it.
5No money movement
Regent does not hold, transmit, or disburse Customer funds or End User funds, and never possesses card numbers, payment credentials, or wallet private keys. Where a transaction results from an authorization, funds move on a licensed rail operated by a third party — Customer's own payment service provider, or directly between wallets. Customer remains the merchant of record for its own sales and remains solely responsible for its obligations under card network rules, applicable payments law, tax, and its agreements with its payment providers.
6Attestations are not guarantees
A Passport, lookup response, or Receipt states what was verified at the time of issuance, and nothing more. It is not a warranty of an Agent's future behavior, of an Owner's trustworthiness or solvency, or of the legitimacy of any transaction. Registry state changes: a key valid at one moment may be revoked the next, which is why revocation is publicly checkable at all times.
Receipts are cryptographic records of authorization decisions and are designed to be independently verifiable. Regent makes no representation that any Receipt will be accepted by, or produce any particular outcome in, any card network, issuer, acquirer, dispute, arbitration, or judicial process.
7Customer responsibilities
The policy is Customer's. The Service supplies information and enforcement mechanics; the decision to accept, limit, or refuse any request is Customer's alone, as are the consequences of that decision.
Customer will: keep API keys confidential and rotate them on suspected compromise; configure prices, limits, and policy accurately; maintain its own agreements with and disclosures to its End Users, including any notice or consent required by law for processing their data; and comply with applicable law in its own jurisdiction.
8Availability and fail-closed behavior
The Service fails closed by design. If the authorization path is unreachable or a determination cannot be made, a money-moving request is refused rather than allowed on stale state. Customer acknowledges that unavailability of the Service may therefore cause refusal of transactions that would otherwise have been permitted, and that this behavior is intended.
Except as stated in a written service level agreement, the Service is provided without any availability, latency, or throughput commitment. Published performance figures describe measurements in our own benchmarks and are not guarantees.
9Data
Regent collects what is needed to operate the Service: registry records, tenant configuration, metering, decisions, and evidence. Regent does not collect or store payment card data, wallet private keys, or identity-verification documents; identity verification is performed by a licensed third-party provider that retains such documents, and Regent receives only a binary result and an identifier.
Each party will comply with applicable data protection law in its role. Where Regent processes personal data on Customer's behalf, the parties will enter a data processing addendum. Details of collection, publication, and retention are in the Privacy Policy.
10Fees
Fees, metering units, and the billing period are those stated at purchase or in the applicable order form. Fees are exclusive of taxes. Unless stated otherwise, fees are non-refundable, charges are metered per decision rather than per seat, and Regent may change pricing for a renewal term on notice before that term begins.
11Confidentiality
Each party will protect the other's non-public information disclosed under these Terms with at least reasonable care and use it only to perform under these Terms. This does not apply to information that is public, independently developed, or lawfully received from a third party, and does not prevent disclosure required by law.
12Intellectual property and feedback
Regent retains all rights in the Service. Customer retains all rights in its own data and configuration. Customer grants Regent a licence to process that data solely to provide the Service. Regent may use aggregated, de-identified statistics that do not identify Customer or any End User to operate and improve the Service. Feedback Customer chooses to give may be used without obligation.
13Disclaimer
Except as expressly stated, the Service is provided "as is" and Regent disclaims all implied warranties, including merchantability, fitness for a particular purpose, non-infringement, and any warranty that the Service will detect every fraudulent, unauthorized, or malicious Agent. No detection system is complete.
14Limitation of liability
Neither party is liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits, revenue, or data. Each party's aggregate liability arising out of these Terms is limited to the fees paid or payable by Customer in the [12 months? — confirm] preceding the event giving rise to the claim. These limits do not apply to Customer's breach of Section 4, either party's breach of confidentiality, or liability that cannot be limited by law.
15Indemnification
Customer will defend and indemnify Regent against third-party claims arising from Customer's use of Output for a purpose prohibited by Section 4, Customer's own products and transactions, or Customer's breach of law. Regent will defend and indemnify Customer against third-party claims that the Service as provided infringes an intellectual property right.
16Term, suspension, termination
These Terms run while Customer uses the Service. Either party may terminate for material breach uncured after 30 days' notice. Regent may suspend access immediately for a breach of Section 4, a security incident, or non-payment. On termination, API keys stop working and Customer's configuration is deleted after [RETENTION PERIOD — confirm]. Receipts already issued remain valid and independently verifiable — that is their purpose — and are retained as evidence records. Sections 4, 5, 6, 11, 12, 13, 14, 15, and 18 survive.
17Changes to these Terms
Regent may update these Terms on reasonable notice. Material changes take effect at the start of Customer's next billing period; continued use after that date is acceptance. If Customer does not accept a material change, its remedy is to stop using the Service before that date.
18Governing law and disputes
These Terms are governed by the laws of [JURISDICTION — depends on the entity in §1], excluding its conflict-of-laws rules, and the parties submit to the exclusive jurisdiction of its courts. [Arbitration? Venue? — for counsel]
19General
Neither party may assign these Terms without the other's consent, except in a merger or sale of substantially all assets. If a provision is unenforceable, the rest stands. Failure to enforce is not a waiver. There are no third-party beneficiaries. Notices go to info@regentprotocol.org and to [CUSTOMER NOTICE ADDRESS / OURS].