Privacy and data boundaries

Updated 1 October 2026. Operator: Vassiliy Lakhonin. Contact: vassiliy.lakhonin@gmail.com.

What the public service does

Deterministic evaluation of supplied evidence. Public evaluation is not transaction authorization, legal advice, a factuality guarantee or institutional certification. Human review is required before commercial action. Results describe the checks actually performed.

Data boundaries

Before production integration

Agree data categories, retention, DPA and subprocessors, incident response, support and any availability commitments in writing. No SOC 2, ISO certification, bank acceptance or default 99.9% SLA is represented here.

Place authorization on the mandatory execution path. Load policy from a trusted server-side source; bind decisions to the exact action, principal and expiry; protect against replay and concurrent overspending; stop on BLOCK, REVIEW, missing evidence or service failure. The public evaluator alone does not establish these deployment properties.

Commercial terms

The machine-readable catalog lists evaluation/API prices. Confirm human-service scope, deliverables and delivery date before payment. No automatic bank clearance or guaranteed signature is included. Invoicing, refunds and any service agreement are handled with the operator. Payment purchases the described service, never a favourable verdict.

Payments and task access

Pro access lasts 30 days with 10,000 evaluation attempts; validation failures can consume an attempt. Activation requires a signature from the paying wallet. New payment claims must be submitted within seven days. One payment funds one exact signed request. Activation does not consume that execution. Identical retries with the original signature recover the saved result for 24 hours; changes to the request require a separate payment. If a claimed payment has no delivered key or response, contact support with the transaction hash before paying again. There is no automatic activation or renewal.

A2A task status is retained for 24 hours with a hashed private continuation token, without storing full task inputs or artifacts in that task record. Keep the issued token private and send it as X-Task-Token for continuation and GetTask. Client labels do not authorize access. These task-record boundaries do not remove the separate telemetry and payment records described above.

Security and documentation

Vulnerability reporting · OpenAPI · Source code. These disclosures describe the current evaluation service and are not an independent security audit.