Legal
Terms of Use
These cover the website and a product account. The verification service is supplied under a separate signed agreement, and where the two disagree that one governs.
Version 0.1 - 1 September 2026
1. What these terms cover, and what they do not
These terms govern your use of this website and of a Presoja product account. They are a use agreement, not a services agreement.
The verification service is supplied under a separate written agreement between us and your organisation - the order form and the terms it incorporates. That agreement carries the fees, the term, the service levels, the disclosure basis, the liability position and the data processing terms. Where anything on this page conflicts with it, that agreement governs and this page does not.
If you have not signed one, what these terms give you is a website and an account. They do not entitle you to a verification run, an evidence pack or a report.
2. Your account and your credentials
You are responsible for what happens under your account and under any API key issued to it. A key authenticates a system rather than a person, so treat it as a production credential: it is shown once, at the moment it is issued, and we cannot show it to you again.
Tell us promptly if you believe a key or an account has been compromised. We can revoke a key immediately; we cannot un-run a job that key already triggered.
3. Acceptable use
Use the site and the product for their purpose. Do not attempt to reach another organisation's data, probe the service for vulnerabilities without our written agreement, resell access, or use automated means to place a load on the public tools that a person could not.
The public exposure checker and the deprecation feed are free and unauthenticated. We may rate-limit, change or withdraw either at any time.
4. The material you give us, and the right to give it
The corpus a vendor uploads is usually their own customer's material rather than their own. That makes us a fourth party to somebody else's information, and it is why this clause is a warranty rather than a courtesy.
You warrant that you are entitled to give us everything you give us - that you hold the rights and the permissions needed for us to process it for the purposes of the service, and that doing so breaches no agreement you have with the person whose material it is.
You keep ownership of your material. We use it to run the service and to produce the records the service exists to produce, and for nothing else. We do not use it to train models.
5. What we bind ourselves to
The service is only worth what its controls are worth, so they are terms:
- The test set is held in our custody, and every change to it is logged with who made it and when.
- Thresholds are fixed before a run and never adjusted after seeing a result.
- Every run is recorded, pass or fail. There are no unrecorded re-runs, and a run you dislike stays in the record.
- A comparison in which more than one field changed is reported as confounded rather than given a verdict.
- Consent to disclose a report to your own customer is given once, at contract time, on the basis your order form records - not per report.
6. What we do not claim and do not warrant
We are not an accredited body and we do not issue a certificate. What we produce is a record with its method attached, which a validator reads rather than accepts.
A result describes the cases in the test set. It is not a statement that your system is correct in general, and no finite test set could support one.
You are the party paying us, which is a conflict we disclose rather than one we have solved. The full statement is on what we don't claim, and it is part of these terms by reference.
Retirement and deprecation dates in the public feed are read from the providers' own published pages. Where a provider disagrees with us, the provider is right.
7. Sealed records cannot be unsealed
An evidence pack is sealed by a chain of hashes over the runs it covers. That is what makes it evidence, and it has a consequence worth knowing before you rely on it: a sealed record cannot afterwards be altered or deleted at your request, because either would break the chain that makes the rest of it verifiable.
Content captured alongside a sealed record is stored separately, under its own retention, and bound to the record by hash rather than by inclusion - so it can be deleted without breaking the seal. Which content is captured is a setting on your deployment. The privacy policy says what each option means.
8. Liability
Nothing in these terms limits liability that cannot lawfully be limited, including liability for death or personal injury caused by negligence, or for fraud.
Subject to that, the limits and exclusions of liability that apply to the service are those in your signed agreement. This page sets none of its own, and no statement here should be read as agreeing a cap.
9. Suspension, termination and what happens to your data
We may suspend an account that is being used in breach of clause 3, or where a credential appears to be compromised, and will tell you when we do.
On termination we delete your material on the timetable in the privacy policy, with the exception in clause 7: sealed records survive, because the reason your customer can rely on them is that they cannot be withdrawn.
10. Changes to these terms
We may change these terms. The version line at the top of this page changes with them, and a material change is notified to account holders by email before it takes effect.
11. Governing law
The governing law and the forum for disputes are those in your signed agreement.
12. Contact
Questions about these terms: legal@presoja.com.