Verigrant › Terms of Service
Terms of Service
This is the agreement between you and Verigrant. It is written to be read, so it says what the service does and what it will not do, in the order somebody would actually want to know it.
Effective 17 September 2026. Version 2026-09-17.
1. Who this agreement is between
Verigrant operates this service and is the party you are agreeing with. In everything below, "Verigrant", "we" and "us" mean the operator, and "you" means whoever holds the account: a person applying for something, an institution acting through the people on its roster, or an administrator of a deployment.
Until a verigrant.com address exists, the way to reach us about anything on this page is support@vxctrl.com. That address is the one for a legal notice, a complaint, a question about your record, and a request we have not answered.
You accept these terms by creating an account. That acceptance is recorded: the moment your account exists, your client writes a consent record naming this document and the version string above, and you can read it back in your own consent trail and in your export. There is no separate place where the agreement is kept and no version of it you cannot see.
2. What the service is, and what it is not
Verigrant is a custody and consent layer. It holds a person's application record, and it lends named parts of that record to an institution when, and only when, the person issues a grant that says so. The grant is a row this service reads again on every use, which is what makes a revocation immediate rather than eventual. That is the whole product: custody on one side, delegation on the other.
Three things it is not, said plainly because each is a thing people reasonably assume.
- Verigrant is not a verifier of your record Nothing this service holds is asserted by us to be true. What a person writes about themselves is their claim, and it stays labelled as their claim wherever it travels. A check is a separate thing and section 8 says exactly what one means.
- Verigrant is not a consumer reporting agency We do not assemble or evaluate information about a person for the purpose of furnishing a consumer report to anybody, and we do not sell, rent or broker access to a record. What moves is what its owner delegated, to the party they named, for as long as they left the delegation standing.
- Verigrant is not a party to your application Whether an institution reads, advances, refuses or ignores an application is that institution's decision, made on its own systems under the law that governs it. We carry the consent and the data. We do not make the decision and we do not review it.
3. Accounts, and who may hold one
There is one kind of account. A person applying for something and a member of an institution's staff hold the same thing, and what differs is what they went on to do with it: an institution is an organisation record with a roster, and being on that roster is what lets somebody act for it. An administrator of a deployment is an ordinary account that the deployment's own configuration names, which is why there is no administrator sign up and could not be one.
To hold an account you must be old enough, where you live, to enter into an agreement like this one, and you must not be somebody we have already suspended for breaking these terms. You give a real email address, because that address is how a sign in is routed and how we reach you. Somebody who creates an account for an institution is saying that they may bind that institution to section 5, and we rely on that.
Your credentials are yours to look after, and the way this service is built makes that more than a formality. Your password never leaves your browser: it is stretched there, and what reaches us is a derived credential and a wrapped key we cannot open. Your recovery key is shown once, at sign up, and we keep no copy. If you lose both, we can give you an account back and we cannot give you your record back. That is a real consequence of the design and not a disclaimer about it.
Tell us at once if you think somebody else has your password, your recovery key or a Vera ID you issued. You can end every session and revoke every delegation yourself, from inside the application, without waiting for us.
4. Your record is yours, and a grant is how it moves
You own what you put into your record. Verigrant claims no ownership of it and takes no licence over it beyond what running the service you asked for requires: storing it, serving it back to you, and handing the parts you delegated to the party you delegated them to. We do not sell your record. We do not use it to train a model. We do not show it to an advertiser, and there is no advertiser on this site to show it to.
Most of the record is encrypted in your browser under a key derived from your password, so for the narrative core, your work history, your education and your skills the sentence above is a property rather than a promise: we could not sell what we cannot open. The Privacy Policy lists exactly what is plaintext and exactly what is not, without rounding either way.
A grant is how anything leaves. It is a set of scopes and an expiry, recorded as a row and handed out once as a signed token. The holder presents the token, we check the signature, then read the row, then check that the scope covers what is being asked for. Revoke it and the next request made with it is refused, because nothing trusts the token on its own. Every use is counted, timestamped and written into your own audit trail, so a delegation's whole history is something you can read back.
You may withdraw a grant at any time, for any reason or none. What a withdrawal cannot do is reach into an institution's systems and delete what they already took in under a standing delegation, and section 5 is where that is dealt with rather than wished away.
5. What an institution agrees to
This section binds every institution with an account, every institution registered as a reading party, and every person acting for one. It is short because each line of it is enforced somewhere in the service as well as promised here.
- Read only what a grant delegates A scope you were not given is not a scope you may go looking for. Do not attempt to read a record, a document, an answer or a regulated section that the presented delegation does not carry, and do not combine credentials to assemble a read that no single grant authorised. Every read you make is logged into the record owner's own trail, so this is a term they can audit rather than take on faith.
- Ingest only when a candidate advances The preview stage exists so a round can be sorted without anybody's full application being taken in. Pull the full record into your own systems only for the applicants you are advancing, and only for the purpose the applicant granted it for. An institution that ingests everything it previewed has defeated the design and taken on the liability the design was avoiding.
- Do not resell, and do not repurpose What you were shown is for the application in front of you. You may not sell it, rent it, syndicate it, hand it to a data broker, use it to build a profile for anything else, or feed it to a model as training data. Sharing it with a processor acting for you on the same application is not a resale, and remains your responsibility.
- Honour a withdrawal, and keep only what you need When a grant is revoked or expires you stop reading. For what you already ingested, you keep it no longer than the purpose it was granted for and the law you are subject to require, and you delete it after that. Verigrant cannot enforce this inside your systems, which is precisely why it is a term you agree to.
- You are the regulated party for what you hold Once a record is in your systems you are the one governed by the law about how an applicant's information is used, how a hiring or admissions or lending decision is made, and what an applicant must be told. That includes any use of a check as an input to a decision. Verigrant is not your compliance function and does not act as one.
- Look after your credentials Your API key, your roster and the private half of any key you registered are yours to protect. Acts made with them are attributed to you until you tell us they were not.
6. Acceptable use
These apply to everybody, whichever side of the service you are on.
- Do not apply in somebody else's name without their authority An application made for a person is made because that person authorised it, through their own account or through a Vera ID they issued. Nothing else counts as authority, and impersonating an applicant is the one misuse of this service that harms a person who never came here.
- Do not present a credential you were not issued A grant token, a session, an API key and a Vera ID are each held by somebody in particular. Using one you found, bought or guessed is unauthorised access, whatever the service happens to answer.
- Do not probe, scrape or overload Do not attempt to read records you hold no delegation for, to defeat a rate limit, to enumerate accounts, or to take the service down. Security research is welcome and the address for it is the one in section 1; what is not welcome is testing on other people's records.
- Do not upload what you have no right to upload Malware, somebody else's documents, and anything unlawful to hold do not belong here. Your record should be about you.
- Do not misrepresent what a check says An approval says one kind of check was reviewed and approved on a date. Presenting it as a warranty that a record is true, or forging one, is a misuse serious enough to end an account on its own.
- Do not use this service to discriminate unlawfully The voluntary self identification answers exist to fill in the block on a form that asks for them, and nothing in this service scores, ranks or searches on them. Using them, or anything else here, as an input to a decision the law forbids them to inform is a breach of this agreement as well as of that law.
7. Agents, and the Vera ID
An AI agent does not hold an account here and cannot create one. It holds a Vera ID, which is issued by a person from their own account, shown to them once, and stored by us only as a hash. An agent's standing therefore comes entirely from a person, and it lasts exactly as long as that person leaves it standing.
There are two modes and the difference matters. In review mode a Vera ID lets an agent do one thing: write a pending row saying which institution it would like to apply to and under which scopes. That row unlocks nothing by existing. The person reviews it, and the sealing that actually delegates a read happens in their own browser after they have looked at what was asked for and chosen how long it lasts. In auto mode a Vera ID carries a mandate the person signed in advance, naming the scopes, the limits and the window, and lets the agent issue inside those limits without being asked again.
Either mode may be revoked at any moment by the person who issued it, and revocation ends everything the id could do. Until it is revoked, the person who issued it is responsible for what is done under it, and whoever operates the agent is responsible for keeping it secret and for staying inside the mandate. An agent that files applications a person did not want is not a bug in the delegation model; it is the agent's operator breaking this section, and we will revoke the id.
Agents are never charged for using this service. See section 9.
8. What a check is, and what it is not
A verification is a review, by a member of Verigrant staff working a queue, of a claim you asked us to look at. Identity, employment, education and income are the kinds we model. Outside verification vendors are not connected today, and until they are, a request for one is refused rather than answered with something that looks like a vendor result.
An approved check travels as a note signed with our key, and what the signature says is bounded on purpose: this kind of check was reviewed and approved on this date. It does not say your record is true, it does not say the underlying facts were confirmed beyond what the reviewer saw, and nobody may present it as though it did. A check note is delivered to you; whether and to whom you pass it on is your choice. A refusal is written where you can read it, in the reviewer's own words, because a person refused is entitled to know why.
Manual review is a service we perform with care and it is not a guarantee. We do not warrant the correctness of any review, and an institution that relies on one is making its own decision about how much weight to give a note that says what it says. Section 11 is where that consequence is stated in the language of liability.
9. Who pays, and for what
A person applying is never charged. Holding a record, editing it, exporting it, issuing grants, revoking them, opening a check and erasing the whole account are free, and there is no tier above them that costs money. An agent is never charged either. Neither of those is an introductory position we are reserving the right to reverse: charging the person whose record it is would make the custody claim on the rest of this site false.
Institutions may be charged, on two bases. The first is per application taken into their own systems, which is to say per full ingest at the moment a candidate is advanced, and never for previewing, for publishing a vacancy or for reading the open postings feed. The second is by separate written contract, for volume, for integration work, or for terms that neither side wants to leave to a page like this one. Where a contract and this page disagree about money, the contract wins.
There is no billing portal in the product today, so charges are arranged by agreement rather than by a card on file. If we change what institutions are charged, the change applies from the next contract or the next billing period, and never to something already taken in.
10. Ending it, and erasure
You may end your account whenever you like, from inside the application, confirmed with your own credential. Doing so destroys the account and every row held under it, including your sessions, your grants, your documents on disk, your consent trail and your audit trail, and you are handed a receipt saying how many rows went from each table. It is irreversible and there is no soft delete behind it. Take your export first if you want one, because afterwards there is nothing left to export.
One thing survives, and it carries no name and no address: a single row recording that an erasure happened, when, and how many rows it destroyed. A service that could not account for its own deletions would be asking you to take them on trust.
An organisation you were the only owner of is left standing with no owner rather than destroyed, because it belongs to its whole roster and erasing it would erase other people's work. Transfer ownership before you go if that matters to you.
We may suspend or end an account that breaks these terms, and we will say which term and why. Where the breach is not serious and can be put right, we will ask first. An institution's obligations in section 5 about data it has already ingested outlive its account, for the same reason they existed in the first place.
We may also stop offering the service. If we do, we will give notice and leave the export route working through it, because a record you cannot take with you is not one you own.
11. What we do not promise
The service is provided as it is. We do not promise that it will always be available, that it will never have a fault, or that it will suit a purpose you have in mind and have not told us about. We will say so when something is broken rather than degrade into an answer that looks fine.
We make no promise about the truth, accuracy or completeness of anything a person wrote about themselves, and none about what an institution does with what it was shown or what an agent does with a delegation it was given. We do not promise that a check reached the right conclusion. We do not promise an outcome: no job, no place, no tenancy and no loan follows from using this service.
We do not promise that an encrypted record can be recovered when both the password and the recovery key are gone. It cannot, and that is the point of the encryption rather than a shortcoming of it.
Where the law where you live gives you a right that this section would take away, the law wins and this section does not apply to you in that respect.
12. What we will pay if we get it wrong
If we cause you a loss directly, we will deal with it. What we will not pay for is indirect loss: profits you did not make, an opportunity you did not get, a role you were not offered, harm to a reputation, or the cost of something you decided to do because of a conclusion you drew from this service.
For an institution, our total liability for everything arising out of this agreement is limited to the fees that institution paid us in the twelve months before the claim arose. For a person applying, who pays us nothing, our liability is limited to putting the service right and to direct loss we actually caused.
None of that limits the things a limit cannot cover: our own fraud or fraudulent misrepresentation, death or personal injury caused by our negligence, and anything else the law where you live does not allow to be limited.
If you break section 5 or section 6 and somebody else is harmed by it, that is between you and them, and you will cover us for a claim that reaches us because of what you did.
13. When these terms change
A new version of this page carries its own effective date and its own version string, and your agreement to it is recorded the same way your agreement to this one was: as a consent record you can read back. A consent to version 2026-09-17 is not a consent to a later version, and the record is built so that it can say which one you actually agreed to.
We will tell you inside the application before a change that matters takes effect. If you do not want the new terms, the answer available to you is the one in section 10, and it works.
14. Governing law and disputes
The law that governs this agreement, and where a dispute under it would be heard, are not settled on this page yet. We would rather leave that open and say so than name a jurisdiction we have not taken advice on and have you rely on it.
Until it is settled, nothing here waives any right you have to bring a claim where you live, and nothing here requires you to arbitrate. If you have a dispute with us, write to support@vxctrl.com first and we will try to deal with it directly, which is faster than either of the alternatives for both of us.
15. The rest of it
These terms and the Privacy Policy are the whole agreement between us about the service, except where a signed contract with an institution says otherwise about the things it covers. If a court decides one part of this page cannot stand, the rest of it still does.
Your account is yours and you may not transfer it to somebody else. We may transfer this agreement if the business is sold, and if that happens the Privacy Policy tells you what it would mean for your record.
Not enforcing a term on one occasion does not mean we have given it up. Notices to you go to the address on your account and to the notifications inside the application; notices to us go to support@vxctrl.com.