Developer / API Terms
- Version
- 1.0
- Effective
- August 15, 2026
- Last updated
- August 15, 2026
Scope
These Developer/API Terms govern any use of TRUSTTICA API credentials, endpoints, SDKs and related documentation (collectively, the "API"), and apply in addition to the general Terms of Service.
Credentials & Authentication
- API credentials are issued per account/application and must not be shared or committed to public source control
- Requests must be authenticated using the method described in the API Documentation (developer portal)
- Compromised credentials must be reported immediately and will be rotated
Permitted Use & Consent
- The API may be used only for lawful, authorized identity/presence verification workflows
- Developers must obtain any consent from end users that is legally required before initiating a verification, including biometric consent where applicable
- Developers must not use the API to build a competing verification platform without authorization
Data Minimization & Storage
- Request and store only the data reasonably necessary for your integration
- Do not persist raw biometric or identity-document images outside of what TRUSTTICA returns unless independently authorized and lawful
- Comply with the retention and deletion obligations described in the Enterprise Data Processing information where applicable
Rate Limits & Fair Use
API usage is subject to rate limits described in the API Documentation (developer portal). Circumventing rate limits, scraping, or automated abuse is prohibited under the Acceptable Use Policy.
Webhook Security
- Verify webhook signatures before trusting payloads
- Serve webhook endpoints over HTTPS only
- Do not expose verification results or Evidence Vault data to unauthenticated parties
Verification-Result Use & Evidence Access
Verification results and Evidence Vault records accessed via the API may be used only for the purpose disclosed to the end user at the time of verification, and must be handled consistently with the Privacy Policy.
Suspension & Revocation
TRUSTTICA may suspend or revoke API access for security concerns, suspected abuse, or violation of these terms, consistent with the general Terms of Service.
Versioning
API versioning and deprecation policy are described in the API Documentation (developer portal).