CoreID

Terms of Service

Last updated: 27/06/2026

These Terms of Service ("Terms") govern access to and use of the CoreID platform, including the CoreID Enterprise Portal and the Public CoreID Registry (together, the "Services"), operated by Velari Protocol Pty Ltd ("CoreID", "we", "us", or "our").

By accessing or using the Services, you agree to be bound by these Terms.

Terms of Service

Last updated: 27/06/2026

These Terms of Service ("Terms") govern access to and use of the CoreID platform, including the CoreID Enterprise Portal and the Public CoreID Registry (together, the "Services"), operated by Velari Protocol Pty Ltd ("CoreID", "we", "us", or "our").

By accessing or using the Services, you agree to be bound by these Terms.

1. Acceptance of Terms

By accessing or using the Services, you confirm that you are authorized to act on behalf of an organization and that you agree to these Terms on behalf of that organization.

You further represent and warrant that you are legally authorized to bind the organization to these Terms and that all information and documentation submitted during registration or verification is accurate, complete, and not misleading.

If you do not agree to these Terms, you must not access or use the Services.

2. Incorporated Policies

These Terms incorporate by reference the following policies, which together govern use of the Services:

  • Privacy Policy
  • Subscription & Billing Policy
  • Data Retention, Storage & Archiving Policy
  • Cookie Policy
  • Acceptable Use Policy

By accessing or using the Services, you agree to be bound by all incorporated policies, as updated from time to time.

3. Enterprise-Only Use

CoreID is provided exclusively for enterprise, institutional, and organizational use.

The Services are not intended for personal, consumer, or household use. Individuals may access the Services only as authorized users of an organization.

4. Description of the Services

CoreID provides an identity-anchored platform designed to support governance, accountability, disclosure, and compliance-related recordkeeping for intelligent systems.

The Services include:

  • the Enterprise Portal, through which organizations manage CoreIDs, governance records, compliance workflows, disclosures, and audit history
  • the Public CoreID Registry, which displays limited, non-sensitive metadata only where an organization has explicitly enabled public disclosure

CoreID also provides an organizational verification framework to support onboarding and accountability processes. Further details regarding verification classifications and processes are set out in Section 8.

CoreID functions as a structured system-of-record for governance and lifecycle data submitted by organizations. Records maintained within the platform reflect information submitted by organizations and do not constitute certification, endorsement, or regulatory approval by CoreID.

CoreID may update, modify, or evolve the Services over time.

5. Governance, Review, and Audit Activities

CoreID provides infrastructure to support governance, review, and audit workflows. All governance decisions, reviews, attestations, and audit outcomes are performed by authorized users acting on behalf of their organizations.

CoreID does not:

  • conduct reviews or audits on behalf of organizations
  • determine the adequacy or quality of review outcomes
  • endorse or approve governance or audit decisions

Responsibility for governance, review, and audit activities remains solely with the organization.

Where governance workflows result in issuance, modification, or revocation of CoreIDs, such actions are performed by authorized users acting on behalf of their organizations. CoreID provides the technical infrastructure only and does not independently validate governance decisions.

CoreID may provide structured fields for organizations to declare audit cycles, attestation frequencies, framework alignments, data protection measures, security controls, or other compliance-related information. All such declarations are made solely by the organization. CoreID does not independently verify, validate, certify, or assess the sufficiency, accuracy, or effectiveness of any declared governance or compliance measures. Organizations remain fully responsible for the accuracy and regulatory adequacy of their declared controls.

CoreID permits organizations to configure governance models in accordance with their internal structures, including self-governed configurations where a single authorized user may perform multiple roles. CoreID does not mandate separation of duties, independent oversight, or multi-party review unless expressly stated. The choice of governance model, role assignment structure, and level of internal review remains the sole responsibility of the organization.

CoreID may provide system-generated update classifications or versioning indicators to support lifecycle tracking and record-keeping. Such indicators are informational only and do not constitute approval, validation, regulatory assessment, or a determination of governance sufficiency. Organizations remain solely responsible for determining the appropriate level of review, oversight, escalation, and regulatory assessment required for any system update.

6. What CoreID Does Not Do

CoreID does not:

  • certify, approve, or validate AI systems
  • guarantee regulatory or legal compliance
  • interpret laws or regulations
  • provide legal, regulatory, or professional advice
  • act as a regulator, auditor, or authority
  • make risk determinations on behalf of users

The Services support governance and compliance processes but do not replace organizational responsibility, independent oversight, or regulatory authorities.

CoreID does not independently verify the legal existence, operational standing, or regulatory status of organizations. Verification classifications reflect information submitted by the organization and platform-level validation where available.

CoreID may provide automated framework mappings, jurisdictional suggestions, risk classifications, or other system-generated outputs based on information submitted by users and internal platform logic. These outputs are informational tools designed to support organizational governance and compliance preparation only. They do not constitute legal advice, regulatory determinations, compliance certification, or binding assessments. Organizations remain solely responsible for validating the applicability of any framework, classification, or regulatory obligation.

CoreID is entitled to rely on information, declarations, and documentation submitted by organizations without independent investigation, except where the platform expressly states otherwise.

7. User Obligations and Acceptable Use

You agree to:

  • provide accurate and up-to-date information
  • ensure that uploaded content is lawful, authorized, and that the organization has the legal right to submit such content to the platform
  • maintain the confidentiality of account credentials
  • use the Services only for legitimate organizational purposes
  • upload only authentic and authorized corporate documentation where required for verification purposes
  • not submit fraudulent, altered, or misleading verification documentation

You must not:

  • misuse or attempt to manipulate the Services
  • upload unlawful, infringing, or malicious content
  • attempt to reverse engineer or bypass platform safeguards
  • scrape, crawl, or bulk extract data from the Public CoreID Registry
  • interfere with platform integrity or availability
  • attempt to circumvent verification requirements, registry checks, or platform safeguards related to organizational classification

Violation of these obligations may result in restriction, suspension, or termination of access to the Services.

CoreID may implement automated monitoring mechanisms, including activity velocity monitoring, to detect misuse, abuse, or abnormal platform activity. Excessive automated, scripted, or anomalous activity may trigger internal review, restriction, or suspension.

8. Organizational Verification Framework

CoreID requires organizations to complete an attestation and upload verification documentation during registration. This establishes accountability but does not automatically constitute independent legal validation.

Verification classifications include:

  • Attested - Documentation and binding attestation on file. This is the current verification method available during the prototype period.

Additional verification classifications (such as independent registry validation) may be introduced as the platform evolves. Any new classifications will be documented in updated Terms.

CoreID may suspend, restrict, reclassify, or downgrade verification status where fraudulent documentation, material inconsistencies, or policy violations are identified in accordance with these Terms.

Verification status may lapse due to expiry or policy non-compliance. Lapse does not invalidate previously issued CoreIDs but may restrict future submissions.

CoreID may remove or disable subsidiary structures where parent verification status is downgraded or lapsed.

9. Disclosure and Public Registry

Public disclosure of CoreID metadata is optional and controlled by the organization.

Where disclosure is enabled:

  • only predefined, non-sensitive metadata appears in the Public CoreID Registry
  • disclosure may be revoked at any time

Information displayed in the Public CoreID Registry is provided by organizations. Any reliance on registry information by third parties is at their own discretion and risk. CoreID does not guarantee accuracy, completeness, or suitability for any particular purpose.

Verification status labels displayed within the Enterprise Portal (e.g., "Attested," "Registry Validated," or "Inherited") are internal classifications used for platform governance purposes and do not constitute governmental approval, certification, or legal confirmation of entity legitimacy.

10. CoreID Ownership and Transfer Between Organizations

A CoreID represents a registered governance identifier linked to a specific governing organization at the time of registration within the CoreID Registry. Control of a CoreID is exclusively linked to the governing organization recorded within the CoreID Registry.

A CoreID is a registry-based governance record and does not constitute personal property or an independently tradable asset. A CoreID may only be transferred between organizations through the official CoreID Registry transfer process.

Transfers may be initiated by the verified Authorized Officer of the current governing organization. The receiving organization must designate a verified Authorized Officer to accept the transfer.

Upon completion of a transfer:

  • The receiving governing organization assumes responsibility for the AI system associated with the CoreID from the recorded transfer date forward.
  • All historical governance records, risk classifications, compliance attestations, audit logs, and lifecycle history remain permanently attached to the CoreID.
  • Historical records cannot be altered or removed as a result of the transfer.
  • The previous governing organization remains responsible for all representations, attestations, and declarations made prior to the recorded transfer date.
  • The CoreID Registry records the transfer event as part of the permanent lifecycle history of the CoreID.

11. AI-Assisted Features

CoreID may offer optional AI-assisted features to support governance and compliance workflows.

  • AI features are assistive only and do not replace human review or accountability
  • AI outputs are provided without guarantees of accuracy, completeness, or regulatory sufficiency
  • Organizations remain responsible for decisions made using AI-assisted outputs.

12. Intellectual Property

CoreID retains all rights, title, and interest in the Services, including software, interfaces, and platform components.

Organizations retain ownership of their content, data, and records submitted to the Services.

By using the Services, organizations grant CoreID a limited, non-exclusive license to process their content solely for the purpose of operating the platform.

13. Confidentiality

Non-public information accessed through the Services is confidential.

Users must protect confidential information and must not disclose it except as authorized or required by law.

14. Data Integrity, Records, and Audit Trails

CoreID maintains integrity controls, audit logs, and historical records to support traceability, accountability, and platform security. Certain platform-generated system records may be retained even after account deactivation where required for legal, security, or audit purposes, in accordance with the Data Retention, Storage & Archiving Policy.

CoreID provides an audit history interface within the Enterprise Portal that records governance and lifecycle events associated with CoreIDs, including submissions, attestations, overrides, transfers, status changes, and other recorded platform actions.

Organizations may upload and maintain Model Governance Documents within the Enterprise Portal, including documentation, evidence, and governance artifacts relevant to their internal compliance processes. Organizations remain solely responsible for the accuracy, legality, and sufficiency of all uploaded Model Governance Documents.

CoreID separately maintains platform-generated audit logs, system event records, integrity controls, and administrative action logs to preserve evidentiary traceability and system security. Access to platform-generated logs is restricted to authorized personnel and system processes required to operate and secure the Services.

Organizational onboarding documentation is stored securely and is not publicly accessible.

Processing of personal information is governed by the Privacy Policy.

15. Subscription, Billing, and Payment

Certain features of the Services require a paid subscription. Fees, billing cycles, plan changes, cancellation, and payment handling are governed by the Subscription & Billing Policy.

Failure to pay applicable fees may result in restriction, suspension, or termination of access in accordance with these Terms and the Subscription & Billing Policy.

16. Suspension and Termination

CoreID may suspend or terminate access to the Services where:

  • these Terms are violated
  • unlawful activity is suspected
  • continued access poses a security or integrity risk
  • verification documentation is determined to be fraudulent, materially inaccurate, or not provided within required timeframes

Upon termination:

  • access to the Enterprise Portal is disabled
  • public registry disclosures may be removed
  • retained records remain subject to legal and integrity requirements

Suspension or termination of access does not necessarily result in deletion of records, audit logs, or governance history. Data retention and access following suspension or termination are governed by the Data Retention, Storage & Archiving Policy.

Suspension of an organization's verification status (including downgrade to unverified status) may result in restriction of submission, issuance, or subsidiary management features while preserving historical governance records.

17. Disclaimers

The Services are provided "as is" and "as available."

To the maximum extent permitted by law, CoreID disclaims all warranties, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement.

CoreID does not warrant that the Services will be uninterrupted, error-free, or meet specific regulatory or operational requirements.

18. Limitation of Liability

To the maximum extent permitted by law, CoreID shall not be liable for any indirect, incidental, consequential, special, punitive, or exemplary damages, including loss of profits, revenue, data, business opportunity, goodwill, or anticipated savings, arising out of or relating to the Services, even if advised of the possibility of such damages.

To the maximum extent permitted by law, CoreID's total aggregate liability arising out of or relating to the Services, whether in contract, tort (including negligence), statute, or otherwise, shall not exceed the total fees paid by the organization to CoreID in the twelve (12) months preceding the event giving rise to the claim.

Nothing in these Terms excludes or limits liability to the extent that such liability cannot be excluded or limited under applicable law.

19. Indemnification

You agree to indemnify and hold harmless CoreID from claims, damages, losses, and expenses arising from:

  • misuse of the Services,
  • unlawful or unauthorized content,
  • violation of these Terms or applicable laws

20. Enterprise Agreements

Where CoreID and an organization enter into a separate written agreement governing access to or use of the Services (including a Master Services Agreement, Enterprise Agreement, or similar contract), the terms of that separate agreement shall prevail to the extent of any inconsistency with these Terms.

21. Governing Law and Jurisdiction

These Terms are governed by the laws of Australia.

Any disputes shall be subject to the exclusive jurisdiction of the courts of Australia.

22. Changes to These Terms

We may update these Terms from time to time. Continued use of the Services after changes become effective constitutes acceptance of the updated Terms.

23. Contact Information

For questions regarding these Terms, please contact: