Verigrant › Agent operator terms

Agent operator terms

This is the agreement between an agent operator and Verigrant. You accept it when you register, and every agent you declare after that carries it. It is written to be read, so it says what the registry does, what you are promising, and what happens when a promise is broken.

Effective 4 October 2026. Version 2026-10-04.

1. Who this agreement is between

VX Encryption, Inc., a South Dakota corporation (SD Business ID DB301325), 550 N 5th Street, Suite 112, Rapid City, SD 57701, doing business as Verigrant, runs the agent ID registry and is the party you are agreeing with. VX Encryption, Inc. is a subsidiary of North South Industries Inc. In everything below, "Verigrant", "we" and "us" mean VX Encryption, Inc., and "you" means the operator: the company or the developer that registered, and whoever acts for it.

The way to reach us about anything on this page is support@verigrant.com. That address is the one for a legal notice, a complaint, a question about what we hold about you, and a request we have not answered.

You accept these terms by registering. The registration names this document by the version string above, and the registry refuses to start a registration that names any other version or that does not say the terms are accepted. The version you accepted and the moment you accepted it are recorded with your operator record.

An operator is not a Verigrant account. A person's account and the Terms of Service that go with it are a different thing, and a person who runs an agent through their own account is covered there, under its section 7, rather than here. This page is for an operator that registers agents of its own so that websites can tell who sent them.

2. What an operator is, and what registering means

An operator is whoever runs an agent: a company, a team or a single developer. You register with an email address, a name and your acceptance of these terms. We mail that address an eight digit code that works once, for fifteen minutes, and survives five wrong tries. The confirmed code creates your operator record and your first operator token, which is valid for ninety days and which we keep only as a hash. Signing in again is the same exchange, and its answer never says whether an address belongs to an operator.

Registering an agent means declaring, for that agent, the things a website will rely on when it decides whether to let the agent in. Each declaration is a promise you are making to us and to every site that reads it, and the point of these terms is to make that promise one you can be held to.

  • Its purposes From a closed list of four. Assist is acting for one person at a time. Search is building a search index. Research is reading for analysis without training. Training is collecting for model training. You declare every purpose the agent acts for, and you do not act for one you did not declare.
  • Its networks The address ranges the agent sends from, or the single value that says it sends through the Verigrant egress. A site that sees the agent arrive from somewhere else may treat that as a warning, and section 6 says what it may do with one.
  • Its rate The number of requests per site per day you expect it to make. The gate, the door and the egress enforce it, so an agent that declares a low rate and sends at a high one is refused rather than believed.
  • Its abuse contact An address a site can write to about this agent. It must reach somebody who can stop the agent.
  • Its framework The model or framework the agent runs on, and its version, in at most eighty characters.

You may change an agent's declarations at any time. The change reaches the next credential the agent renews; a credential already issued keeps what it said until it expires, at most twenty four hours later. You may also retire an agent yourself, which ends its credentials the same way a revocation by us would.

3. The levels, and what each one proves

Every credential carries a level from A to D. A level says what Verigrant has checked about the operator behind the agent, and nothing more. The levels are cumulative: D needs C, C needs B, B needs A. Each is decided per key when a credential is issued and is reflected live in the status list a site reads, so a level that stops being true stops being asserted.

  • Level A: a confirmed email and a key on file We have confirmed that somebody reads the address you registered with, and the agent's public key is registered with proof that you hold its private half. That is all it says. A level A operator has no proven name and is not listed in the operator directory.
  • Level B: a proven domain You have proven that you control a domain, by publishing a record we give you in its DNS or a file on its web server, and the agent's key is published in your own Web Bot Auth key directory on that domain. From here on you are known by that domain, and the credential carries it. We check the proof again every day: a proof that is gone ends level B at once, a check that cannot complete keeps it for three days, and a domain claimed but never proven lapses after fourteen days.
  • Level C: an institution stands behind you A registered Verigrant institution, one whose registration a Verigrant administrator approved after the company registry review and whose payment card has been checked, has linked itself to your operator record with a code you gave it. Both checks are read live wherever the level is decided, so an institution that loses its approval ends the level C of every operator it stands behind.
  • Level D: a named officer answers for you A named person, holding a Verigrant account that has passed a Verigrant identity check, has linked themselves to your operator record with their full name and title. Their account is theirs: if they erase it, the link goes with it and your level D ends at once.

A level is evidence we observed, not a judgement about you. We do not vouch for an operator at any level, and a site that admits an agent because of its level is making its own decision about how much that evidence is worth.

4. Keys and credentials

Each agent signs its requests with its own key. You make the key, you hold its private half, and we never do: what you register with us is the public half, with a signature proving that you hold the rest, or a key directory on your proven domain that we read it from. A key belongs to one agent for good, revoked keys included, so a key can never be registered under another agent and nobody can register a key they do not hold. An agent holds at most ten live keys.

A credential is a short statement signed by Verigrant: this agent, this operator, this level, these declarations, bound to this key, valid for at most twenty four hours. The agent renews it by sending us a request signed with its key, at most thirty times an hour, and a site checks it offline against our published key set and a status list without telling us which agent visited. Every issuance is written to our transparency log, so a credential nobody can find a leaf for is a forgery anybody can name.

  • Keep the private half private Requests signed with your agent's key are your agent's requests until you tell us the key was taken. If you think a key has leaked, revoke it as compromised, from the console or the command line. Evidence signed with a key revoked that way never counts against you, whenever it was signed, because whoever held the key could have made it.
  • Rotate rather than share Add the new key, renew with it, then revoke the old one; the command line does all three in one step. One key serves one agent. A key used by several agents, or by software you do not run, is a key you cannot answer for.
  • Revocation is immediate on our side and fast on the site's When you revoke a key or retire an agent, we stop issuing for it at once, and the status list entry every credential bound to it carries flips to invalid. A site sees that at its next fetch of the list, which it may cache for up to five minutes, and the credential dies within its own lifetime in any case.

5. What Verigrant may do, and on what evidence

A website that believes one of your agents broke its declarations files an abuse report with us: the agent, the site, a contact, a category, a description and up to twenty of the agent's own signed requests as evidence. The abuse desk is run by Verigrant's administrators, and it does not act on a site's word. Each line of evidence is checked again by us: that the request was addressed to the reporting site, that the credential in it is one we issued to that agent, and that the signature was made by one of that agent's registered keys. A line that verifies is something only the agent's key could have made. A line that does not verify is nothing, and the desk cannot act on a report unless every line verifies.

On a report whose evidence verifies, the desk may do one of these, and each one is recorded.

  • Warn Record the decision against your standing and tell you.
  • Rate limit Hold the agent to a stated number of requests a minute, for a stated number of days, enforced at the egress.
  • Revoke the agent End its credentials through the registry and suspend it at the egress at once, rather than waiting for its last credential to expire.
  • Revoke the operator The same for you and every agent you run, which also ends your operator tokens.
  • Dismiss Record that the report did not stand. A dismissed report, like one never decided, moves nothing, so a site cannot lower your standing by reporting you.

Each report takes each action once. We may also revoke an agent, a key or an operator outside the desk when we have evidence of our own of a breach of section 10, and we will say which term and why. Where the breach is not serious and can be put right, we will ask first. An operator may dispute a desk action by writing to support@verigrant.com. We review it, record the outcome against the report, and tell the operator.

A revoked operator can still read its standing and the reports against it, and can change nothing. Its proven domain stays its own for ninety days, so that nobody else can claim it in the meantime, and its address is refused at registration for as long as the revocation stands, so a revoked operator does not come back under a new identifier. You read every report against your agents in the console, without the reporter's contact and without the evidence lines, which stay with the desk.

6. What a website may do

A credential gets an agent recognised. It does not get it in. Every site decides for itself, under its own terms, and nothing in this agreement obliges any site to admit any agent.

  • Refuse by level A site may require level B, C or D, and refuse everything below it.
  • Refuse by purpose A site publishes which purposes it allows, denies or prices. An agent whose credential declares only a purpose the site denies is refused, and an agent acting for a purpose it did not declare is in breach of section 10 as well as refused.
  • Act on a warning A site sees a warning when a request comes from a network you did not declare, when the connection's fingerprint changes without a key rotation, when the volume exceeds the declared rate, or when the declared purpose is not one its terms allow. Its own policy decides whether a warning is a refusal.
  • Keep its own evidence and report A site logs the requests your agent signed and may file them with us as section 5 describes. That log is on the site's own storage, and we never see it unless the site sends it.

7. The egress option, and its limits

An agent that declares the Verigrant egress as its network does not send to sites from its own addresses. It sends each request to the egress, signed with its key and naming what it wants fetched and for which purpose; the egress checks the credential, the site's published terms and the rates, makes the request itself from a fixed address under its own signature, and hands the answer back. Nobody's TLS is terminated in the middle. Where we offer the egress, these are its limits, and they are not negotiable per operator.

  • The site's terms decide The egress reads the site's own agent front file. A purpose the site allows goes through, a purpose it denies is refused, and a purpose it prices is refused too, because the egress cannot tell whether you have agreed the price. A site that has published nothing is treated as allowing assist only. You may still go to such a site directly, under your own addresses and your own responsibility.
  • Your declared rate is enforced Per agent, per site, per day, the egress sends no more than you declared, and no more than the site's own tier for your level, and no more than the egress's own ceiling for one site. A refused request is not counted.
  • It keeps counts, never content Per agent and per site, per day, for thirty days: requests, fetches, refusals, answer classes, timings and bytes. Never a request or response body, a path, a query, a header value or a credential.
  • It can cut you off at once A suspension written by the desk, or by us directly, stops an agent or an operator at the egress within a minute. A rate limit from the desk is applied there too.
  • Level one only The egress carries requests made with an agent ID in the clear. It does not forward a person's pass, so it cannot be used for sealed, level two requests.

8. The operator directory, and standing

We publish a directory of verified operators, readable by anybody without a credential. An operator appears in it from level B, under its proven domain and never under a name it typed, so an operator's name cannot be squatted. A level A operator is not listed, because it has no proven name to list under.

What is public about a listed operator is exactly this.

  • Its identifier The operator id beginning op_.
  • Its proven domain The domain it proved for level B.
  • Its level A, B, C or D, as the evidence holds now.
  • Its standing A label computed from the desk's upheld actions, never typed by anybody. It starts at one hundred. A warning costs ten, a rate limit twenty, a revoked agent thirty five, a revoked operator the whole hundred. Each counts in full for ninety days, by half until a year has passed, and then not at all. Good is ninety and above, fair is sixty and above, poor is below that; an operator less than thirty days old with nothing upheld is new; and revoked or suspended says so.

Two other things are public because sites need them: the status lists, which say whether a credential is still valid and name no agent, and, for a level A agent, the key directory we host for it, which holds the agent's public keys. A site that opts into the visits dashboard sees your proven domain and standing beside the counts of your agents' visits to it, by level and purpose, and never an agent's id.

9. What we keep about you, and for how long

This is the whole list, written from the registry's own tables. An operator is not a person's account, so the Privacy Policy for people does not cover it; this section does.

  • Your operator record Your name, your email address and its domain, when the address was confirmed, the version of these terms you accepted and when, your domain claim and the token that proves it, when the domain was proven and last checked, and, if we revoked you, when and why. Kept while the operator exists. A revoked operator's record is kept, because it is what refuses the address at registration and holds the domain for ninety days.
  • Your tokens and codes Operator tokens as hashes, valid for ninety days and deleted after they expire. Emailed codes as hashes, with the network prefix and the email domain the registration limits count, deleted after a day. Link codes for levels C and D as hashes, valid for seventy two hours and deleted a day after they expire.
  • Your agents and their keys Each agent's name and declarations, and when it was created, changed or revoked. Each key's public half and thumbprint, where it came from, when it was last seen in your directory, and when and why it was revoked. A key's thumbprint is kept for good, revoked keys included, because that is what stops a revoked key coming back under another agent and what lets old evidence still be checked.
  • Credentials and renewals A record of each credential issued: its id, the agent, the key, the level, the times and a hash of the token, never the token itself, kept for thirty days after the credential expires. The nonce of each renewal, kept for ten minutes.
  • The links behind levels C and D For level C, which institution linked itself and who did it. For level D, the officer's account, full name, title and assurance. The officer's row names a person, so it is in that person's export and is erased with their account. An officer who no longer answers for an operator may ask us at support@verigrant.com to remove the link, which ends level D.
  • Abuse reports and the desk's decisions Each report with the reporting site, whether the site was proven, the reporter's contact, the category, the description, the evidence lines and what each came to, its status, and each action the desk took with its note. Kept with the desk's record of its own decisions; there is no sweep that deletes them, and the standing weight of an action falls to nothing after a year even though the record stays.
  • The transparency log One leaf per credential issued, naming the credential's id, the agent, the operator, the level, the key's thumbprint and a hash of the token. The log is append only and is kept for good, because its whole purpose is that an entry cannot later be removed.

We do not sell any of it, use it to train a model, or show it to an advertiser. The registration limits count registrations per network prefix and per email domain over a day and keep nothing else. There is no self service erasure for an operator today; to end an operator record, write to support@verigrant.com, and we will tell you what we can delete and what sections 5 and 8 require us to keep.

10. What you may not do

Each of these is a breach of this agreement, and each is something the desk can act on with verified evidence under section 5.

  • Do not act outside your declared purposes An agent that declares assist and builds an index, or declares research and trains, has lied to every site that admitted it. We cannot see intent, so the declaration is the promise, and the evidence a site keeps is how it is proven.
  • Do not share a key across agents, or lend one out One key, one agent, run by you. A key handed to software you do not run, or used to sign for an agent it was not registered to, is yours to answer for until you revoke it as compromised.
  • Do not impersonate a person without a pass An agent ID says which operator's agent is visiting. It says nothing about any person. Presenting an agent as a particular person, or as acting with a person's authority, is done with a Verigrant pass that person issued, and in no other way.
  • Do not scrape a site whose terms deny the purpose A site's published terms say which purposes it allows. Reading a site for a purpose it denies, through the egress or around it, is a breach whether or not the site noticed.
  • Do not exceed what you declared, or launder volume Sending above your declared rate, or fetching at volume for a registered agent and passing the result to unregistered ones, is the thing the declared rate exists to bound.
  • Do not register what is not yours A domain you do not control, an institution you do not act for, an officer who did not agree, or an abuse contact nobody reads. Each proof exists to be true.
  • Do not probe, replay or overload the registry The registry is rate limited at every door and refuses a replayed renewal, and security research is welcome at the address in section 1. Testing on other operators' agents is not.

11. Fees

Registering as an operator, declaring agents, registering keys, proving a domain, renewing credentials and being listed cost nothing. Level one, an agent carrying its agent ID in the clear, is free, for the operator and for the agent, and a site that admits a level one agent pays us nothing for doing so.

A site may price a purpose under its own terms. That is between you and the site; we are not a party to it, we do not collect it, and the egress refuses a priced purpose rather than guessing whether you agreed. Level two, where a person's sealed details travel under a pass, is paid for by the business that receives them, as the price list says, and is never charged to an operator.

12. What we do not promise, and who pays if it goes wrong

The registry is provided as it is. We do not promise that it will always be available, that a credential will always be renewable, or that any site will admit any agent at any level. We will say so when something is broken rather than degrade into an answer that looks fine.

A level is what we observed and not a warranty about you, and a credential is a statement of your declarations and not a warranty that they are true. We do not promise that a site's evidence, a report, or the desk's decision reached the right conclusion, and a decision of the desk is ours to make on the evidence in front of it.

If we cause you a loss directly, we will deal with it. What we will not pay for is indirect loss: revenue an agent did not earn, a site it was not admitted to, harm to a reputation, or the cost of something you decided to do because of a credential or a standing. Because you pay us nothing under this agreement, our total liability for everything arising out of it is limited to putting the registry right and to direct loss we actually caused. None of that limits our own fraud, death or personal injury caused by our negligence, or anything else the law where you are does not allow to be limited.

What your agents do is yours. If an agent you run breaks section 10 and a site, a person or anybody else is harmed by it, that is between you and them, and you will cover us for a claim that reaches us because of what your agent did, including the reasonable cost of answering it.

13. Governing law and disputes

Verigrant is operated by VX Encryption, Inc., based in Rapid City, South Dakota. These terms are governed by the laws of the State of South Dakota, without regard to its conflict of laws rules. Before either side files anything, we will try in good faith for thirty days to settle any dispute. If that cannot be settled, the dispute goes to the state or federal courts located in South Dakota, and both sides agree to that venue.

Nothing here takes away a protection the law where you are gives you that cannot be waived, and nothing here requires you to arbitrate, and nothing here waives your right to bring or join a class action. If you have a dispute with us, write to support@verigrant.com first and we will try to deal with it directly.

14. When these terms change

A new version of this page carries its own effective date and version string. From the day it takes effect, the registry refuses a registration that names any older version, and the console and the command line show the new one.

An operator already registered is told at the address on its operator record before a change that matters takes effect, and the console names the version in force. If you do not want the new terms, retire your agents and tell us at the address in section 1, and we will end your operator record; keeping your agents registered past the effective date means you accept the new version.

15. The rest of it

These terms are the whole agreement between us about the registry, the directory and the egress. A person's account, and anything an agent does under a pass a person issued, is governed by the Terms of Service and the Privacy Policy, and an institution's standing behind you at level C is governed by its own agreement with us. If a court decides one part of this page cannot stand, the rest of it still does.

Your operator record is yours and you may not transfer it. We may transfer this agreement if the business is sold, and we would tell you at the address on your record. Not enforcing a term on one occasion does not mean we have given it up. Notices to you go to the address on your operator record; notices to us go to support@verigrant.com.