Skip to main content

Legal information

Acceptable use

What may not be done with IRON ID, why, and what happens when it is.

Last updated [DATE]

DraftThese documents are drafted and complete, but the contracting entity is being incorporated and counsel has not signed them off yet. Three points remain explicitly open and are marked in the text: the entity and the governing law, the liability cap in the terms of service, and the identity of the data protection officer.

1.Who this policy applies to

This policy applies to everyone who uses the services: members of your organization, external guests, and — where you integrate an Enterprise product — the users of your own applications.

It forms part of the terms of service. You answer for its observance by the people to whom you open access.

2.Prohibited content

You may not deposit, share, send or have signed through the services:

  • Content that is unlawful under the applicable law, or whose possession or distribution is an offence.
  • Content infringing a third party's rights, in particular intellectual property or image rights.
  • Malware, an exploit, or a file designed to compromise an information system.
  • Personal data obtained without a legal basis, or sensitive data you have no right to entrust to us for processing.
  • A document intended to mislead as to its origin, its author or its date.

3.Prohibited conduct

Nor may you:

  • Circumvent, or attempt to circumvent, authentication, permissions, isolation between organizations, or rate limits.
  • Probe, scan or test the vulnerability of the services outside the framework of clause 6.
  • Automate a volume of calls liable to degrade the service for other organizations.
  • Resell, sub-licence or make platform access available to a third party outside a signed partnership agreement.
  • Use the services to send unsolicited bulk messages.

4.The integrity of the proof

The value of these services rests on a proof produced by the platform being capable of standing up. Any attempt to falsify a fingerprint, a timestamp, a provenance manifest or an audit entry, or to present a simulated attestation as a real one, is a serious breach of this policy.

The site's public demonstrations — the sequence replayed on the technology page, for instance — are explicitly marked as simulated. Presenting them otherwise to a third party falls under the same prohibition.

5.Use of the Enterprise products

The KYC SDK produces a verifiable record of the checks actually performed. It is not a regulatory approval and it discharges none of your compliance obligations. Presenting it to your own customers as an accreditation is prohibited.

The Sign SDK provides the electronic signature level actually described on its product page. Claiming a higher level than the one provided, to a third party, is prohibited.

6.Security research and responsible disclosure

Good faith research is welcome. Report any vulnerability to security@iron-id.io: we acknowledge within two business days and will bring no action against research carried out in good faith.

That assumes not accessing another organization's data, not degrading the service, not exfiltrating data, and leaving us a reasonable period before any publication.

7.Reporting and consequences

Report abuse to abuse@iron-id.io. We review every report and inform the reporter of the outcome where that is possible.

Depending on severity, we may ask for content to be removed, issue a warning, suspend an account or an organization, or terminate the contract. Except in a security emergency or under a legal obligation, formal notice and an opportunity to remedy precede suspension.

Get started

See IRON ID for your organization.

Request a demo of the Platform, join early access to be onboarded in the first cohorts, or request a quote for a KYC or Sign SDK integration.

Reply within two business days · contact@iron-id.io