Version 2026-09-21. This policy is part of our Terms of Service. It applies to everyone who uses the Services, including the free audit and free resolver.
You must not
- Publish false or misleading claims. Do not use the Services to seal or publish any claim you know, or ought to know, is false, misleading or unsubstantiated. This includes forging an attestation, or impersonating an issuer, observer or agent vendor.
- Imply that a regulator has approved you. Do not present a grade, seal or Record as approval, certification or endorsement by us, by the ASA, CMA or FCA, or by any other regulator. For example, you must not say "WorldAuth-certified compliant". If you display a grade publicly, say it is our commissioned opinion and link to the rubric (Terms A2.4B).
- Publish unlawful promotions. Do not publish financial promotions, health claims or other regulated advertising that has not been made or approved as the law requires.
- Impersonate or infringe. Do not use another person's brand, name or trade marks in a way that suggests you are them or that they are connected with you. Do not infringe anyone's intellectual property.
- Put in data that doesn't belong. Do not paste personal data into the free audit or resolver. Never submit special category data, children's data, credentials, card numbers or secrets.
- Attack or overload the Services. Do not:
- probe, scan or test the vulnerability of the Services, except under our security disclosure process (security@worldauth.com);
- get round rate limits, authentication or access controls;
- send automated traffic designed to degrade the Services.
- Manufacture traffic or evidence. Do not generate artificial resolutions, renders or receipts to inflate metrics, invocation rates or billing.
- Use the Services unlawfully. Do not use them to do anything unlawful, or anything that breaches sanctions, export control or consumer protection law.
- Resell or build a copy. Do not resell the paid Services, or use them to build a competing dataset or product, without our written agreement.
What we may do
If you breach this policy, we may:
- remove content;
- withdraw Records;
- suspend or close accounts;
- block traffic;
- report unlawful activity to the relevant authorities.
Where it is lawful and safe to do so, we will tell you first and give you a chance to put things right.
Reporting
To report misuse, including a Record that impersonates you, email legal@worldauth.com. For security issues, email security@worldauth.com.