Service commitments

What Veridion commits to for the Disclosure API, and — at least as important — what it does not. Every absence on this page is stated deliberately. A commitment we could not keep would be worth less than the gap it covered.

Stated 2026-09-21. Policy, not a live measurement.

Availability

No availability SLA is offered, and no uptime percentage is published.

What an SLA would require is a request-outcome log, and it does not exist yet. Every request Veridion serves, with its status, its latency and its caller, retained over a window long enough to compute an error budget. The canary samples the API 48 times a day from one region; it is evidence the contract holds, not a measurement of what callers experienced. No availability percentage is published from it and no availability SLA is offered until the log exists.

Veridion will execute a contractual SLA once ninety days of request-outcome history exist, with the committed thresholds derived from that measured history rather than asserted in advance. Until then the conformance record is published in full, including its failures and its denominators.

Every canary run ever recorded, including the failures and the two excluded runs with the reason each was excluded: /data-api/reliability. What the API is doing right now: /api/v1/status.

Support

TierChannelResponse commitment
Freesupport@veridionmarkets.com, best effortNone. Questions are answered when they can be; no response time is promised and none should be relied on.
Developersupport@veridionmarkets.comNone contractually. In practice a human reads every message and a key issue is handled the same day it arrives. That is a description of what happens, not a term of service.
Professionalsupport@veridionmarkets.com, plus a named contact agreed at signingQuoted per engagement and written into the agreement. It is quoted rather than published because it is the part a buyer negotiates.

Data processing

Everything the Disclosure API serves is a United States government record published by the House Clerk, the Senate eFD system or the U.S. Office of Government Ethics. Those records carry no copyright and their subjects are public officials filing under a statutory disclosure duty. Veridion does not collect, infer or enrich personal data about private individuals, and there is no personal data of yours inside the served corpus.

What Veridion holds about an API customer is the account email address, a hash of the issued key, and per-key usage counters. Nothing else about a caller is retained by the API, and query contents are not stored against an account. The full account-data position is at /privacy.

On a DPA

No data-processing agreement is published here, and one should not be inferred from this page. A DPA is a signed instrument with defined liabilities; drafting one without counsel would be the same unearned claim this company refuses to make everywhere else. If your procurement requires a countersigned DPA, say so and it goes to counsel before anything is agreed.

Security posture

Anonymous and authenticated roles cannot read the raw warehouse or the billing tables.

Migration 0214 revokes them; a deploy gate re-checks the grants on every build.

Only rows Veridion collected first-party from the government system of record are served.

Migration 0137 is an allowlist that fails closed, and deploy gate 20 refuses any serving file without a reviewed manifest entry.

No fabricated data, no vendor names and no unsupported claims reach production.

33 deploy gates, all of which must pass before a build ships.

Secrets and dependency advisories are scanned on every pull request.

gitleaks, semgrep and npm audit run in CI and block the merge.

A security issue has a published contact and a canonical disclosure record.

RFC 9116 security.txt at /.well-known/security.txt, contact support@veridionmarkets.com.

Not offered

Listed so these read as stated gaps rather than arrive as surprises during diligence. A buyer's checklist contains them either way; better they come from us.

  • ·An availability SLA, or any uptime percentage.
  • ·A contractual support response time at Free or Developer.
  • ·A countersigned data-processing agreement without counsel review.
  • ·Redistribution or resale rights at any published tier.
  • ·Institutional delivery: institutional_delivery.available reads false on /api/v1/status and stays false until four published clearing requirements are met.
  • ·A SOC 2 report or an external penetration test. Neither has been performed.

Asking about any of this

Write to support@veridionmarkets.com. Commercial terms beyond the published tiers are quoted per engagement, and the licence that governs every tier is at /data-api/license.

Weekly Veridion brief

Rating changes, public disclosure activity, methodology notes, and product updates. One email per week. No advertising list resale.