← Governance framework
Trust & Verification

Trust and Verification Policy

Rules for issuing, chaining, revoking and verifying TrustMark credentials (TMIDs) and ACDCs on the KERI backbone.

Version
v1.0
Effective
2026-07-19
Last reviewed
2026-07-19
Next review
2027-07-19
Owner
Chief Trust Officer
Approver
Trust & Verification Committee
Anchored by content hashissued 2026-07-29
Payload hash
8295ce09c465285704c852866bd4cd6042c1388c8d9c94d45e1cdbb6ce2b467d
SHA-256 digest of the receipt content
Issuer AID
EP1_FGkcwfHAuih6VUzv9kgAVBvvSoaswSUao61lkxhE
Party that issued this receipt
ImpactMiles handle
audit:governance:8295ce09c4652857

This receipt is anchored by content hash. A resolvable credential SAID is not available for this record.

Applies to

  • All credentials issued by ImpactMiles
  • TAS operators and admin verifiers

Jurisdictions

  • Hong Kong (PDPO, IRD s.88)
  • United Kingdom (UK GDPR, DPA 2018)
  • European Union (GDPR)
  • Singapore (PDPA)
  • Australia (Privacy Act 1988)
  • Japan (APPI)
  • Wider APAC per country taxonomy

How this is applied in-product

  • TAS sidecar issuance pipeline (keri.functions.ts)
  • Admin verifications workflow (/admin/verifications)
  • Public verification endpoints (/verify/$said, /lookup, /explorer)
  • Retry worker with backoff for anchoring

1. Issuance Principles

  • No personal data in payloads. Only organisational identifiers, amounts, references and hashes.
  • Every credential is chained to its predecessor SAID so the provenance graph is reconstructable.
  • Issuance is deterministic and reproducible from source records.

2. TrustMark ID (TMID)

Verified organisations receive a TMID with prefix tmid:im:. TMIDs are anchored via the TAS sidecar and displayed with the 'TrustMark - Verified' badge.

3. Verification Levels

  • Level 1 - Registration verified (Veraf.ai KYB pass).
  • Level 2 - AML clear and documentary evidence complete.
  • Level 3 - Certifications (s.88, GDPR, etc.) validated by an admin verifier.
  • Trust Index score aggregates these levels for public display.

4. Revocation and Dispute

  • Revocation is decided by the Trust & Verification Committee on evidence of fraud, misrepresentation or material control failure.
  • Revoked credentials remain visible with a REVOKED marker for transparency; downstream credentials show the break.
  • Disputes are lodged via /privacy or the direct contact channel and triaged within 5 business days.

5. Operational Assurance

  • TAS Issue and TAS Verify endpoints monitored with synthetic checks every 5 minutes.
  • Anchoring retry worker with exponential backoff, alerts after 3 consecutive failures.
  • Quarterly reconciliation between platform records and TAS ledger.
Questions or concerns about this policy? Contact the DPO.

Related policies