Terms of Service
Updated: March 18, 2026
Preamble and Acceptance
Welcome to VestedProof. These Terms of Service ("Terms" or "Agreement") constitute a legally binding agreement between you, whether personally or on behalf of an entity ("User," "you," or "your"), and VestedProof ("we," "us," or "our"). This Agreement governs your access to and use of the VestedProof website (https://vestedproof.com), our e-signature platform, proprietary cryptographic verification tools, and associated services (collectively, the "Service").
BY ACCESSING OR USING ANY PART OF THE SERVICE, YOU AGREE THAT YOU HAVE READ, UNDERSTOOD, AND AGREED TO BE BOUND BY THESE TERMS. IF YOU DO NOT AGREE TO BE BOUND BY THIS AGREEMENT, YOU ARE EXPRESSLY PROHIBITED FROM USING THE SERVICE AND MUST DISCONTINUE USE IMMEDIATELY.
VestedProof reserves the right, in its sole discretion, to modify or replace these Terms at any time. We will provide notice of material changes by posting the updated Terms on the website. Continued use of the Service after such changes constitutes your acceptance of the new Terms.
1. COMPREHENSIVE DEFINITIONS
To ensure clarity and legal precision, the following terms are used throughout this Agreement:
1.1 "Account" means a unique authorization granted to a User or Entity to access and use the Service, identified by a email address, and password.
1.2 "Advanced Electronic Signature (AdES)" refers to an electronic signature that meets the technical standards for signer identification and document integrity, as defined under relevant international frameworks such as the eIDAS Regulation (EU No 910/2014) or similar standards.
1.3 "Authorized User" means any individual authorized by a primary Account holder to use the Service in accordance with their designated permissions.
1.4 "Certificate of Completion" means the document generated by VestedProof upon the finalization of a signature process, containing the audit trail, SHA-256 hashes, and digital fingerprints of the signatories.
1.5 "Customer Data" means all data, graphics, images, files, and other content provided by you to VestedProof for processing in connection with the Service. Customer Data does not include Usage Data.
1.6 "Document Hash" means the output of the SHA-256 (Secure Hash Algorithm 256-bit) cryptographic function, providing a unique "digital fingerprint" for every file.
1.7 "e-Signature Law" refers collectively to the ESIGN Act (US), UETA (US), and international equivalents such as the Electronic Communications Act (UK) and others.
1.8 "Intellectual Property Rights" means all patent, copyright, trademark, trade secret, and other intellectual property rights worldwide.
1.9 "Self-Verifying Technology" refers to the VestedProof mechanism where validation and integrity proof are cryptographically anchored to the document itself, allowing for independent verification.
1.10 "Simple Electronic Signature (SES)" means data in electronic form which is attached to or logically associated with other data in electronic form and used by the signatory to sign.
1.11 "Stripe" refers to Stripe, Inc. and its affiliates, our primary payment processing partner.
1.12 "Usage Data" means diagnostic, technical, and statistical data collected automatically regarding your interaction with the Service.
2. ELIGIBILITY, REGISTRATION, AND ACCOUNT MANAGEMENT
2.1 Age and Authority. You must be at least 18 years old to create an Account. By registering, you represent that you possess the legal capacity to enter into a binding contract. If you represent an Entity, you warrant that you are an authorized representative with the power to bind said Entity to these Terms.
2.2 Account Accuracy. You agree to provide true, accurate, current, and complete information during registration. Registration with false information is a material breach of this Agreement.
2.3 Credential Security. You are solely responsible for the confidentiality of your login credentials. You are liable for all activities occurring under your Account, whether or not authorized.
2.4 Unauthorized Use. You must notify VestedProof immediately at support@vestedproof.com upon discovering any unauthorized use of your Account.
3. SERVICE SCOPE AND "SELF-VERIFYING" ARCHITECTURE
3.1 Standard e-Signature Workflow. VestedProof facilitates the upload, distribution, signing, and tracking of electronic documents using SES and AdES standards.
3.2 Cryptographic Integrity (SHA-256). VestedProof applies a SHA-256 hash to every document. This hash is immutable. If a document is modified after signing, the hash will change, and verification will fail.
3.3 Self-Verification Principle. VestedProof issues a digital Certificate that contains the necessary cryptographic proof. Documents can be verified independently using the VestedProof verification tools.
3.4 No Legal Advice. VestedProof provides the tools for signatures, not legal advice. The choice of signature type and suitability for specific transactions rests solely with the User.
4. SUBSCRIPTIONS, CREDITS, AND FINANCIAL TERMS
4.1 Pricing. Current pricing and plan features are available on our landing page at https://vestedproof.com or as part of your settings page https://app.vestedproof.com/settings. We offer various professional tiers.
4.2 Payment Processor. We use Stripe for all financial transactions. We do not store your full credit card information on our servers.
4.3 Pay As You Go Credits. Credits purchased under the Pay As You Go model do not expire as long as your Account remains active (at least one login every 12 months).
4.4 Automatic Renewal. Subscriptions automatically renew unless canceled. You authorize us to charge your payment method on file at the start of each renewal period.
4.5 Cancellation. You may cancel your subscription at any time. No refunds are provided for partial periods or unused credits, except as required by law.
5. USER CONDUCT AND PROHIBITED ACTIONS
5.1 Compliance with Laws. You agree to comply with all local, state, national, and international laws, including data privacy (GDPR, CCPA) and anti-spam regulations.
5.2 Prohibited Interference. You shall not attempt to bypass security features, distribute malware, misrepresent your identity, or use the Service for high-risk activities.
5.3 Document Content. VestedProof does not monitor document content. You are solely responsible for ensuring legality and appropriate rights.
6. DOCUMENT STORAGE, RETENTION, AND DELETION
6.1 Retention Policy. VestedProof stores documents and metadata only as long as your Account remains active or until you explicitly delete the document.
6.2 Deletion on Termination. Upon the closure of your Account, all associated Customer Data is permanently deleted from our primary servers for maximum privacy.
6.3 User Responsibility for Archival. It is your responsibility to download and securely store signed documents. VestedProof is not a permanent backup service.
7. INTELLECTUAL PROPERTY AND LICENSING
7.1 Ownership of Service. VestedProof and its licensors own all rights to the Service. No ownership is transferred to you.
7.2 Ownership of Documents. You retain 100% ownership of your documents. You grant us a limited license solely for the purpose of executing the signature request.
8. CONFIDENTIALITY AND DATA PROTECTION
8.1 Confidentiality. We implement industry-standard security measures to protect the confidentiality of your data.
8.2 Privacy Policy. Your use of the Service is also governed by our Privacy Policy, incorporated here by reference.
9. DISCLAIMERS OF WARRANTIES
THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE." TO THE FULLEST EXTENT PERMITTED BY LAW, VESTEDPROOF DISCLAIMS ALL WARRANTIES, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE, AND WARRANTIES REGARDING THE LEGAL VALIDITY OF ANY SIGNATURE IN ANY SPECIFIC JURISDICTION.
10. LIMITATION OF LIABILITY AND INDEMNIFICATION
10.1 Total Liability Cap. VestedProof’s total liability shall not exceed the amount paid by you to VestedProof in the twelve (12) months preceding the claim, or $100, whichever is higher.
10.2 Exclusion of Damages. In no event shall VestedProof be liable for lost profits, lost data, or any indirect or consequential damages.
11. GOVERNING LAW AND DISPUTE RESOLUTION
11.1 Governing Law. This Agreement is governed by the laws of the State of Delaware, USA, without regard to conflict of law principles.
11.2 Jurisdiction. Any dispute arising from these Terms or the Service shall be resolved exclusively in the courts located in Delaware, USA.
12. MISCELLANEOUS
12.1 Severability. If any provision is found invalid, the remaining provisions remain in full force.
13. DETAILED DOCUMENT LIFECYCLE MANAGEMENT
13.1 Upload and Hashing Protocol. When a User uploads and send a document by VestedProof, our system immediately generates a SHA-256 fingerprint. This fingerprint is used as the foundational anchor for all subsequent signature operations. The hashing process ensures that the document content remains immutable.
13.2 Invitation and Signature Phase. Upon initiating a signature request, invitations are sent via transactional email (Postmark) to the designated signatories. Signatories must complete the verification challenges (SES or AdES) before applying their cryptographic signature.
13.3 Finalization and Certification. Once all parties have applied their signatures, VestedProof generates the final signed PDF and the Certificate of Completion. The Certificate contains the complete audit trail and technical metadata required for independent verification.
13.4 Archival and Deletion Strategy. As specified in Section 6, VestedProof is not a permanent storage service. Documents are maintained only as long as the User Account is active or until the User manually deletes them. Deleting an account or a specific document results in the permanent removal of the document and all associated signatures from our primary storage.
14. CRYPTOGRAPHIC SIGNATURE PROTOCOL (DEEP DIVE)
VestedProof implements a multi-layered cryptographic protocol to ensure the authenticity and non-repudiation of every electronic signature:
14.1 Signer Identification. For Simple Electronic Signatures (SES), identity is verified through a unique, one-time link sent to the signatory's email. For Advanced Electronic Signatures (AdES), an additional layer of verification is added, typically through an SMS-based two-factor authentication (2FA) code or other multifactor mechanisms.
14.2 Technical Linkage. Every signature is cryptographically linked to the specific Document Hash. This ensures that the signature is only valid for that specific version of the document. Any modification to the document after the signature has been applied will break this link, rendering the signature invalid.
14.3 Immutable Audit Trail. The VestedProof engine records every technical event associated with the document. This includes the IP address of the signer, the browser "fingerprint" (user-agent), the exact timestamp (UTC), and the success or failure of various verification challenges.
15. GLOBAL LEGAL DEFENSIBILITY AND COMPLIANCE STANDARDS
VestedProof is designed to provide "Strong Evidence" in legal proceedings across various jurisdictions:
15.1 United States (ESIGN and UETA). Our workflows comply with the federal Electronic Signatures in Global and National Commerce (ESIGN) Act and the Uniform Electronic Transactions Act (UETA) as adopted by and applied in the State of Delaware.
15.2 European Union (eIDAS). VestedProof facilitates compliance with the eIDAS Regulation (EU No 910/2014) for both Simple (SES) and Advanced (AdES) electronic signatures. Note that VestedProof does not currently provide Qualified Electronic Signatures (QES).
15.3 Commonwealth Countries. Our signature protocols are designed to meet the standards set in the Electronic Transactions Acts of Australia, the United Kingdom, Canada, and Singapore.
16. USER TRAINING AND PROTOCOL FOR ENTERPRISE CLIENTS
To maximize the benefits of the VestedProof platform, we recommend the following protocols for our enterprise and professional users:
16.1 Internal Policy Alignment. Users should ensure that their internal document management policies are updated to reflect the use of electronic signatures and the Self-Verifying architecture of VestedProof.
16.2 Security Awareness for Signatories. Users are encouraged to inform their signatories about the importance of secure email and SMS practices to maintain the integrity of the signature process.
16.3 Audit Trail Management. We recommend that Users download and archive the Certificate of Completion for every finalized document to ensure they have the necessary evidence for any future legal audits or disputes.
17. ACCESSIBILITY AND INCLUSIVITY COMMITMENT
VestedProof is committed to ensuring that our electronic signature tools are accessible to all individuals, including those with disabilities:
17.1 WCAG Compliance. We strive to maintain our signing interface in accordance with the Web Content Accessibility Guidelines (WCAG) 2.1 Level AA.
17.2 Screen Reader Optimization. Our platform uses semantic HTML and ARIA roles to ensure that signatories using screen readers can easily navigate the signing process.
17.3 Continuous Improvement. We regularly review and update our interface based on feedback from users with accessibility needs to ensure we are providing the most inclusive experience possible.
18. ENVIRONMENTAL IMPACT AND SUSTAINABILITY
VestedProof is a "Green-First" platform. By transitioning from traditional paper-based workflows to VestedProof, you are contributing to global sustainability efforts:
18.1 Reduction in Resource Consumption. Electronic signatures eliminate the need for paper, ink, and water used in traditional printing and physical document handling.
18.2 Carbon Footprint Mitigation. By removing the need for physical document transport and courier services, we help our users significantly reduce the carbon emissions associated with their administrative processes.
18.3 Operational Efficiency. Digital workflows are not only faster but also significantly more resource-efficient than traditional physical processes.
APPENDIX A: ROBUST TECHNICAL SPECIFICATION
To provide the transparency required for professional use, the following technical details are specified:
A.1 Hashing and Integrity
We utilize the SHA-256 (Secure Hash Algorithm 2) as specified in FIPS 180-4. This ensures that every document has a unique, collision-resistant digital fingerprint.
A.2 Time-Stamping
Time-stamps applied to signatures are synchronized with Stratum-1 time sources during the signing process to ensure chronological accuracy.
A.3 Infrastructure and Security
The Service is hosted 100% on Google Cloud Platform (GCP) in the us-central1 region (Iowa, USA). We leverage native Google security controls and infrastructure for maximum reliability.
APPENDIX B: FUTURE ROADMAP AND INNOVATION
B.1 Blockchain Verification
While not currently a core feature of the standard Service tiers, VestedProof plans to introduce decentralized blockchain anchoring for document hashes to provide even greater, platform-independent verification longevity.
APPENDIX C: EXHAUSTIVE TECHNICAL GLOSSARY
-
AES-256 (Advanced Encryption Standard): An electronic data encryption specification established by the U.N. National Institute of Standards and Technology (NIST) in 2001. VestedProof uses AES-256 for data at rest.
-
AdES (Advanced Electronic Signature): An electronic signature which is uniquely linked to the signatory, is capable of identifying the signatory, and is linked to the data signed in such a manner that any subsequent change in the data is detectable.
-
Asymmetric Cryptography: Also known as public-key cryptography, it uses pairs of keys: public keys which may be disseminated widely, and private keys which are known only to the owner.
-
Audit Log: A security-relevant chronological record, set of records, and/or destination and source of records that provide documentary evidence of the sequence of activities that have affected at any time a specific operation, procedure, or event.
-
Bit Depth: In cryptography, the length of the binary string used for keys. VestedProof uses 256-bit hashes.
-
Cipher: An algorithm for performing encryption or decryption—a series of well-defined steps that can be followed as a procedure.
-
Collision Resistance: A property of cryptographic hash functions: it is computationally infeasible to find two different inputs that produce the same output.
-
Cryptanalysis: The study of analyzing information systems in order to study the hidden aspects of the systems.
-
Digital Signature: A mathematical scheme for demonstrating the authenticity of digital messages or documents.
-
Entropy: A measure of the randomness or unpredictability of data, critical for generating secure cryptographic keys.
-
Envelopes: A VestedProof "Envelope" is a digital container that holds one or more documents to be sent for signature.
-
FIPS 140-2: A U.S. government computer security standard used to approve cryptographic modules.
-
Hash Function: Any function that can be used to map data of arbitrary size to fixed-size values.
-
HMAC (Hash-based Message Authentication Code): A specific type of message authentication code involving a cryptographic hash function in combination with a secret key.
-
Initialization Vector (IV): A fixed-size input to a cryptographic primitive that is typically required to be random or pseudorandom.
-
Key Management: The various processes that help an organization to manage the lifecycle of cryptographic keys.
-
Latency: The time delay between a request for data and the return of that data. VestedProof optimizes for low-latency signature execution via GCP.
-
Logarithmic Complexity: A measure of the efficiency of an algorithm.
-
Multifactor Authentication (MFA): An electronic authentication method in which a user is granted access to a website or application only after successfully presenting two or more pieces of evidence to an authentication mechanism.
-
Nonce (Number used once): An arbitrary number that can be used just once in a cryptographic communication.
-
Non-repudiation: The assurance that someone cannot deny the validity of something.
-
On-Premise vs. Cloud: VestedProof is a "Cloud-First" platform hosted on GCP, though document verification can occur in any environment, but provide also on-premise services which means that our enterprice clients are able to run our services 100% on their own infrastructure where data do not leave the company infrastructure and we (VestedProof) have not knowledge about the data in on-premise solution except technical log to analyze app functionality or usage statistics related to enterprise billing needs.
-
Protocol: A system of rules that allow two or more entities of a communications system to transmit information.
-
Public Key Infrastructure (PKI): A set of roles, policies, hardware, software and procedures needed to create, manage, distribute, use, store and revoke digital certificates and manage public-key encryption.
-
Salt: Random data that is used as an additional input to a one-way function that "hashes" data, a password or passphrase.
-
SHA-256 Message Digest: The 256-bit (32-byte) output of the SHA-256 hash algorithm.
-
Throughput: The amount of data moved successfully from one place to another in a given time period.
-
TLS 1.3 (Transport Layer Security): The latest version of the TLS protocol, providing improved security and performance.
-
Webhook: A method of augmenting or altering the behavior of a web page or web application with custom callbacks.
-
Secure Processing Architecture: A design principle where unencrypted document content is processed only in volatile memory during the signing process and is never stored in a readable format by the service provider beyond the duration of the active session.
APPENDIX D: DETAILED COMPLIANCE MAPPING
TABLE OF LAWS AND STANDARDS
| Jurisdiction | Primary Law | Status |
|---|---|---|
| USA | ESIGN Act, UETA | Compliant |
| European Union | eIDAS Regulation | Compliant (SES/AdES) |
| United Kingdom | ECA 2000 | Compliant |
| Australia | ETA 1999 | Compliant |
| Canada | PIPEDA | Compliant |
| Brazil | LGPD | Compliant |
APPENDIX E: USER FAQ (EXTENDED)
Q: How do I know if my document is secure? A: Every document is hashed with SHA-256. This fingerprint is recorded on the Certificate of Completion. If the document is changed by even one bit, the hash will not match.
Q: Can I use VestedProof for real estate? A: Yes, in jurisdictions where e-signatures are accepted for real estate transactions. Always check with your local recording office.
Q: What happens if VestedProof goes out of business? A: Because of our "Self-Verifying" architecture, your signed documents and Certificates remain verifiable independently of our platform using standard cryptographic tools.
Ak máte akékoľvek okamžité otázky týkajúce sa našich terms & conditions, kontaktujte nás na
support@vestedproof.com.