top of page

GSCA Acceptable Use & Trust Integrity Policy

Effective Date: August 9, 2026
Last Updated: August 9, 2026

Global Standard Certified Alliance ("GSCA"), operated by Techevent Limited and its affiliated entities ("GSCA", "we", "us", or "our"), provides a global digital trust infrastructure designed to support trusted identities, digital assets, certificates, credentials, authenticity, provenance, and verification.

This GSCA Acceptable Use & Trust Integrity Policy ("Policy") establishes the activities and conduct permitted when using GSCA websites, platforms, applications, APIs, digital trust services, verification mechanisms, and related technologies (collectively, the "GSCA Services").

The purpose of this Policy is to protect the integrity of the GSCA Trust Protocol, our users, organizations, partners, issuers, verifiers, and the wider trust ecosystem.

This Policy forms part of the GSCA Terms of Service.

 

1. Our Trust Principle

GSCA is built on a fundamental principle:

Digital trust depends on the integrity of the identity, asset, credential, provenance, and verification information associated with it.

Accordingly, GSCA Services must not be used to create, issue, manipulate, represent, or verify information in a manner that is fraudulent, misleading, unauthorized, or inconsistent with the intended purpose of the GSCA Trust Protocol.

 

2. Who This Policy Applies To

This Policy applies to all persons and organizations using or interacting with GSCA Services, including:

  1. Individual users;

  2. Organizations;

  3. Issuers;

  4. Credential holders;

  5. Verifiers;

  6. Manufacturers;

  7. Product owners;

  8. Educational institutions;

  9. Veterinary or pet-related organizations;

  10. Partners;

  11. Resellers;

  12. Agencies;

  13. Developers;

  14. API users;

  15. Administrators;

  16. Service providers;

  17. Other authorized participants in GSCA-enabled ecosystems.

Where an organization provides access to GSCA Services to its employees, customers, members, students, agents, or other end-users, the organization is responsible for ensuring that those users comply with this Policy.

 

3. Authorized Use

GSCA Services may be used for legitimate purposes including:

  1. Issuing digital certificates and credentials;

  2. Managing trusted identities;

  3. Creating and managing eAssets;

  4. Verifying digital credentials;

  5. Establishing product identity;

  6. Recording and verifying provenance;

  7. Product authenticity verification;

  8. Membership and organizational credentials;

  9. Education and professional credentials;

  10. Pet identification and related records;

  11. Warranty and ownership records;

  12. NFC and QR-based verification;

  13. Digital forms and eStamp services;

  14. Authorized API integrations;

  15. Other legitimate trust-related applications.

Users must only access functions and information for which they have appropriate authorization.

 

4. Trust Integrity Requirements

Users must maintain the accuracy and integrity of information submitted to GSCA.

Users must not knowingly:

  1. Submit false information;

  2. Create fraudulent identities;

  3. Issue credentials without authority;

  4. Misrepresent the identity of a credential holder;

  5. Misrepresent ownership;

  6. Falsify product information;

  7. Falsify provenance;

  8. Create misleading certificates;

  9. Manipulate verification information;

  10. Alter or falsify timestamps or records;

  11. Misrepresent the status of an eAsset;

  12. Use a valid credential for an unauthorized person, product, animal, or entity.

 

5. Unauthorized Issuance

Only authorized Issuers may create or issue GSCA credentials, certificates, eAssets, or other trusted records.

You must not:

  1. Issue credentials on behalf of another organization without authorization;

  2. Use another organization's Issuer account;

  3. Use another organization's credentials or signing authority;

  4. Create certificates representing an authority you do not possess;

  5. Delegate issuing authority to unauthorized individuals;

  6. Circumvent GSCA authorization controls.

GSCA may suspend or revoke issuing privileges where unauthorized issuance is suspected.

 

6. Digital Credentials and eAssets

GSCA eAssets and digital credentials must only be used for their intended purpose.

You must not:

  1. Clone or counterfeit an eAsset;

  2. Modify a GSCA credential outside authorized functionality;

  3. Remove security or verification information;

  4. Misrepresent an expired or revoked credential as valid;

  5. Transfer a non-transferable credential without authorization;

  6. Use another person's credential;

  7. Create a duplicate identity intended to deceive a verifier;

  8. Attempt to bypass credential status controls.

 

7. NFC, QR Codes and Physical Trust Identifiers

GSCA may connect physical objects with digital records through NFC tags, QR codes, identifiers, or other technologies.

Users must not intentionally:

  1. Clone a GSCA NFC identifier for fraudulent purposes;

  2. Replace an authorized tag with a counterfeit tag;

  3. Redirect a verification mechanism to an unauthorized destination;

  4. Tamper with a physical identifier to mislead a verifier;

  5. Associate a physical identifier with a different identity or asset without authorization;

  6. Use copied identifiers to impersonate another product, credential, pet, person, or organization.

Where a physical tag is legitimately transferred or replaced, the applicable GSCA process must be followed.

 

8. Product Authenticity and Provenance

Where GSCA Services are used for product identity, authenticity, origin, or provenance, users must not knowingly provide false or misleading information concerning:

  1. Manufacturer;

  2. Brand;

  3. Product identity;

  4. Serial number;

  5. Batch number;

  6. Country of origin;

  7. Production information;

  8. Certification;

  9. Import or export information;

  10. Warranty;

  11. Distribution;

  12. Ownership;

  13. Provenance.

GSCA Services must not be used to create false evidence of product authenticity or origin.

 

9. Pet ID and Animal-Related Services

Where GSCA Pet ID or related services are used, users must not knowingly:

  1. Create a false Pet ID;

  2. Register an animal as belonging to another person without authorization;

  3. Submit fraudulent vaccination or veterinary records;

  4. Alter medical or veterinary information without appropriate authority;

  5. Use another animal's identity;

  6. Use Pet ID information to facilitate fraud, abuse, or unauthorized transfer of ownership.

Veterinary, medical, ownership, and other professional records must only be created or updated by appropriately authorized parties.

 

10. Privacy and Personal Information

GSCA Services must not be used to collect, expose, distribute, or process personal information without appropriate authorization or a lawful basis.

Users must not:

  1. Publish private personal information without authorization;

  2. Use GSCA credentials to harass or stalk individuals;

  3. Collect personal information through unauthorized scraping;

  4. Use verification functions to build unauthorized personal databases;

  5. Expose sensitive information beyond the intended purpose of a credential or service.

Users must comply with applicable privacy and data protection laws.

 

11. Security and System Integrity

Users must not attempt to compromise, interfere with, or circumvent the security of GSCA Services.

Prohibited activities include:

  1. Unauthorized access;

  2. Credential theft;

  3. Account takeover;

  4. Security bypass;

  5. Vulnerability exploitation;

  6. Malware deployment;

  7. Reverse engineering of protected systems;

  8. Unauthorized penetration testing;

  9. Denial-of-service attacks;

  10. Network flooding;

  11. Automated attacks intended to disrupt services;

  12. Circumvention of rate limits or access controls;

  13. Unauthorized extraction of GSCA databases;

  14. Attempted manipulation of verification systems.

Authorized security testing may only be conducted with prior written permission from GSCA.

 

12. API and Automated Access

Where GSCA provides APIs or automated access, users must use them in accordance with the applicable API documentation, technical limits, and authorization requirements.

You must not:

  1. Share API credentials without authorization;

  2. Use another organization's API credentials;

  3. Circumvent rate limits;

  4. Generate excessive automated requests;

  5. Scrape GSCA services;

  6. Use APIs to create fraudulent records;

  7. Attempt to reverse engineer restricted APIs;

  8. Use APIs to access information beyond your authorization.

GSCA may suspend API access where automated activity threatens service availability, security, or integrity.

 

13. Fraud and Misrepresentation

GSCA Services must not be used to facilitate:

  1. Identity fraud;

  2. Certificate fraud;

  3. Product counterfeiting;

  4. Credential fraud;

  5. Impersonation;

  6. False claims of accreditation;

  7. False claims of GSCA membership;

  8. False claims of GSCA certification;

  9. Unauthorized representation of GSCA;

  10. Fraudulent commercial activity;

  11. Deceptive marketing;

  12. Financial fraud;

  13. Any other unlawful or deceptive activity.

 

14. Spam and Unsolicited Communications

GSCA Services must not be used to send unlawful or unauthorized bulk communications, spam, phishing messages, or other unsolicited communications.

You must comply with applicable laws governing:

  1. Email;

  2. SMS;

  3. Messaging;

  4. Telephone communications;

  5. Marketing communications;

  6. Electronic advertising.

 

15. Harmful, Abusive or Illegal Content

GSCA Services must not be used to create, transmit, store, or distribute content that:

  1. Violates applicable law;

  2. Facilitates criminal activity;

  3. Contains malicious code;

  4. Fraudulently impersonates another person or organization;

  5. Threatens or harasses individuals;

  6. Infringes intellectual property rights;

  7. Violates privacy rights;

  8. Facilitates violence or physical harm;

  9. Facilitates exploitation or abuse;

  10. Is intended to deceive or defraud.

GSCA may remove, restrict, or disable access to content where reasonably necessary to protect users, the infrastructure, or comply with applicable law.

 

16. Prohibited Use of GSCA Identity and Branding

You must not falsely represent that you are:

  1. GSCA;

  2. Techevent Limited;

  3. An authorized GSCA representative;

  4. A GSCA employee;

  5. A GSCA-certified organization;

  6. A GSCA-authorized Issuer;

  7. A GSCA partner;

  8. A GSCA agent or reseller.

You must not use GSCA names, trademarks, logos, certificates, badges, or other brand assets to create a false impression of authorization, endorsement, certification, partnership, or affiliation.

Authorized brand usage remains subject to applicable GSCA brand guidelines or written authorization.

 

17. Circumvention and Abuse of Trust

Because GSCA provides infrastructure intended to support trusted interactions, users must not intentionally use GSCA Services to undermine the trust mechanisms themselves.

This includes:

  1. Circumventing verification;

  2. Manipulating trust status;

  3. Creating multiple identities to evade controls;

  4. Repeatedly creating and deleting fraudulent credentials;

  5. Exploiting system behavior to create false verification results;

  6. Attempting to make invalid information appear valid;

  7. Using legitimate credentials in a misleading context;

  8. Deliberately exploiting weaknesses in trust relationships between organizations.

 

18. Fair and Responsible Use

GSCA Services are intended to operate within reasonable and authorized usage patterns.

Where excessive or abnormal usage affects the security, stability, performance, or availability of GSCA Services, GSCA may:

  1. Apply technical limits;

  2. Request corrective action;

  3. Temporarily restrict access;

  4. Suspend specific functions;

  5. Require an appropriate enterprise arrangement.

Where applicable, additional commercial charges may apply according to the relevant service or commercial agreement.

 

19. Customer and Organization Responsibility

Organizations are responsible for the conduct of users who access GSCA Services through their accounts, systems, credentials, or authorization.

Organizations should implement reasonable security measures including:

  1. Access controls;

  2. Password protection;

  3. Credential management;

  4. Role-based authorization;

  5. Appropriate staff training;

  6. Prompt removal of former users;

  7. Monitoring of suspicious activity.

If an organization discovers unauthorized access or misuse, it should notify GSCA promptly.

 

20. Reporting Abuse or Security Concerns

If you discover suspected:

  1. Fraudulent GSCA credentials;

  2. Counterfeit certificates;

  3. Unauthorized GSCA branding;

  4. Suspicious NFC or QR identifiers;

  5. Unauthorized use of GSCA services;

  6. Security vulnerabilities;

  7. Account compromise;

  8. Misuse of GSCA verification systems;

please contact GSCA as soon as reasonably possible.

GSCA

Email: neksun@ecert.app

We may investigate reports and take appropriate action to protect the integrity of the GSCA ecosystem.

 

21. Enforcement

Where GSCA reasonably believes that this Policy has been violated, GSCA may take appropriate action, including:

  1. Warning the user;

  2. Requesting corrective action;

  3. Restricting functionality;

  4. Suspending an account;

  5. Suspending issuing privileges;

  6. Revoking API access;

  7. Disabling a credential or asset where appropriate;

  8. Terminating services;

  9. Preserving relevant security records;

  10. Cooperating with lawful investigations or authorities.

The action taken will depend on the nature, severity, frequency, and potential impact of the violation.

Where permitted by law, GSCA may take immediate action where necessary to protect the security or integrity of the Trust Infrastructure.

 

22. No Guaranteed Detection

GSCA employs technical and organizational measures designed to support security, verification, and fraud prevention.

However, no technology can guarantee detection or prevention of every fraudulent, malicious, or unauthorized activity.

Users remain responsible for exercising appropriate judgment when relying upon a credential, product record, identity, certificate, or verification result.

 

23. Relationship with Other GSCA Policies

This Policy forms part of the GSCA legal and governance framework and should be read together with:

  1. GSCA Privacy Policy 

  2. GSCA Terms of Service 

  3. GSCA Cookie Policy 

  4. Applicable Partner or Reseller Agreements

  5. Applicable Enterprise or SaaS Agreements

  6. Applicable API Terms

  7. GSCA Trust and Security documentation

Where a specific written agreement contains provisions that expressly govern a particular service or relationship, those provisions may apply to the extent permitted by law.

 

24. Changes to This Policy

GSCA may update this Policy from time to time to reflect:

  1. Changes to the GSCA Trust Protocol;

  2. New GSCA services;

  3. Changes in technology;

  4. New security requirements;

  5. Changes in applicable law;

  6. Changes in GSCA's operating environment.

The latest version will be published on the applicable GSCA website.

Unless otherwise required by law, continued use of GSCA Services after the effective date of an updated Policy constitutes acceptance of the revised Policy.

 

25. Contact Us

For questions concerning this Policy, suspected misuse, trust integrity, security concerns, or reports of unauthorized activity:

Global Standard Certified Alliance (GSCA)
Operated by Techevent Limited


Email: cs@ecert.app
Website: www.ecert.app / www.gsca.cc

bottom of page