CITAQ

Legal · Verification Disclaimer

What Verification Status Means

Every verification credential CITAQ issues is designed to include a mandatory point-in-time disclaimer. This page explains the complete scope, limitations, evidence tier lifecycles, and jurisdiction-specific constraints of that verification.

Standard Verification Disclaimer

Required disclaimer — for issued credentials

"This credential represents point-in-time evidence verification. It does not constitute ISO 17065 certification, regulatory approval, or product performance guarantee."

Four required explicit negations — architecture PROHIBITION-006

Not ISO 17065

This credential does not represent conformity assessment body certification under ISO 17065 standards.

Not regulatory approval

This credential is not regulatory approval from any government body, standards organization, or regulatory agency.

Not performance guarantee

This credential does not guarantee that the product performs as claimed. It confirms evidence linkage only.

Not endorsement

This credential is not a product endorsement or commercial recommendation by CITAQ or any third party.

This disclaimer is a constitutional constraint (PROHIBITION-006) designed to be embedded in every issued credential. It cannot be disabled, customized, or removed by operators or administrators.

Point-in-Time Verification Explained

A credential issued on a given date confirms that on that date: the linked evidence was valid, the claims matched the evidence, and the evidence came from a recognized source. It makes no claim about the state of affairs before or after that date.

Evidence expires

When a laboratory certification or compliance document passes its expiry date, verification status is designed to update. Operators are notified on a defined schedule (see Notification Schedule below) before expiry.

Claims change

If product claims are modified after verification, affected claims revert to unverified status immediately. New evidence must be linked before the claim returns to verified status.

Evidence revoked

If a certifying body revokes a certificate, the linked verification status is invalidated. Revocation is designed to propagate across consumer surfaces promptly.

Evidence Tier Lifecycle

Evidence sources are classified into tiers based on source reliability and independence. Each tier has a defined recertification period. When evidence expires, a 30-day grace period begins before automatic downgrade.

TierSource TypeRecertificationGrace PeriodOn Expiry
L0Cryptographic / Blockchain attestationNeverN/APermanent unless revoked
L1Physical in-person verificationNever (point-in-time)N/APermanent record; claim state frozen at verification date
L2Structured data from authoritative body48 months30 daysAuto-downgrade to L1 (irreversible without fresh evidence)
L3Third-party laboratory / certification36 months30 daysAuto-downgrade to L1 (irreversible without fresh evidence)
L4Empirical / manufacturer-submitted evidence24 months30 daysAuto-downgrade to L1 (irreversible without fresh evidence)

Downgrade is irreversible without fresh evidence. When an L2, L3, or L4 evidence source expires and the grace period elapses, the claim is designed to downgrade to L1 status automatically. To restore the original tier, new evidence from a qualifying source must be submitted and linked.

Evidence Expiry Notification Schedule

CITAQ is designed to send notifications on the following schedule before evidence expiry. Notifications are sent to the operator email on file and available in the platform dashboard.

TimingNotification TypeAction Required
90 days beforeInformationalNone — awareness notification
60 days beforeUpcoming WarningBegin evidence renewal process
30 days beforeUrgent WarningEvidence renewal required
7 days beforeFinal WarningImmediate renewal required
1 day beforeLast ChanceRenewal deadline imminent
Day of expiryGrace Period Begins30-day grace period active — status frozen
End of grace periodTier Downgrade ExecutedEvidence auto-downgraded — new evidence required

Revocation Propagation

Revocation propagation

When a certifying body revokes a certificate, or when CITAQ issues an administrative revocation, the status change is designed to propagate across consumer surfaces promptly. Cache invalidation is triggered on revocation events.

Prompt

Read-your-own-revocations

Operators who trigger a revocation are designed to see it reflected in their own dashboard view, so they are not shown stale credentials after their own revocation action.

By design

Scope Limitations

Verification CoversVerification Does Not Cover
Claim-evidence linkage at point in timeProduct safety guarantee
Evidence source validation and authenticationProduct performance warranty
Credential timestamp and cryptographic signatureLegal compliance determination
Evidence freshness relative to issue dateISO 17065 certification
Certifying body recognition and statusRegulatory agency approval
Jurisdiction-specific claim applicability (where configured)Universal legal compliance

High-Risk Category Rules

Certain product categories have structural constraints that override all verification workflows. These are not operator-configurable.

Medical products — hard block

Claims containing the words "cures", "treats", "heals", or "prevents disease" are designed to be blocked (HTTP 422) before reaching any verification workflow. This applies regardless of evidence submitted.

Verification of medical product claims does not constitute medical device approval, FDA clearance, or clinical validation (FDA 21 CFR 101.93). Consult qualified regulatory counsel for medical category compliance.

Batteries — EU DPP deadline

Battery products are subject to EU Digital Product Passport (EU DPP) requirements. EU DPP mandatory date for batteries: February 18, 2027.

Battery operators must have EU DPP-compliant evidence linked before this date. Verification credentials issued after the deadline without DPP evidence are designed to carry a compliance gap flag.

Electronics

Verification of electronics compliance claims (RoHS, WEEE, CE Marking, FCC) confirms evidence linkage to submitted documentation only. Regulatory approval determinations require qualified compliance assessment by a recognized certifying body. Textiles category: EU DPP mandatory compliance expected mid-2027.

Food and beverage

Food and beverage claims are designed to be subject to hard-block rules for prohibited health claims. Verification confirms evidence linkage to ingredient declarations, certifications, and sourcing documentation. It does not constitute FDA food safety approval or nutritional claim substantiation under FTC standards.

Jurisdiction-Specific Claim Adaptation

Chameleon Engine — jurisdiction fencing

CITAQ is designed to apply jurisdiction-specific claim fencing based on ISO 3166-1 country codes. Claims that are valid in one jurisdiction may be restricted or stripped in another.

ClaimRuleTransition
"FDA Approved" claimRestricted in EU markets — FDA approval is a US-specific regulatory classification not recognized in the EUUS (valid) → EU (restricted)
CE Marking claimOnly valid for EU, EEA, and applicable global markets. Auto-restricted for markets without CE recognitionEU (valid) → Non-EU (flagged)
Health claims under EFSAEU Regulation 1924/2006 health claim rules applied for EU-facing surfaces. Non-EU claims use local regulatory frameworkJurisdiction-specific → Jurisdiction-fenced

Jurisdiction tagging is designed to be applied to issued credentials. Operators are responsible for ensuring their claims comply with the regulations of every jurisdiction where their products are sold. CITAQ's jurisdiction fencing reduces risk but does not constitute legal compliance determination.

Technical Enforcement

HTTP enforcement header

X-CITAQ-Verification: point-in-time
X-CITAQ-Classification: verification-infrastructure
X-CITAQ-Disclaimer: required

CITAQ's verification API is designed to include verification classification headers on responses. Consumers of the API must respect these headers.

VC schema constraint

credentialStatus: point-in-time
disclaimerRequired: true
expiryDate: ISO-8601
jurisdiction: ISO-3166-1

CITAQ's W3C Verifiable Credentials are designed to include embedded disclaimer fields; credentials cannot be issued without these fields.

HARD_BLOCK enforcement

HTTP 422 Unprocessable Entity
Code: HARD_BLOCK_MEDICAL_DISEASE_CLAIM

CITAQ's claim validator is designed to return HTTP 422 for blocked submissions before any verification logic executes.

Badge watermark

watermark: point-in-time-verified
timestamp: [credential-issue-date]
disclaimer: embedded

Verification badges issued for Shopify and other platform integrations are designed to include an embedded watermark with issue timestamp and disclaimer reference.

Contact

Questions about verification status: verification@citaq.io

High-risk category inquiries: compliance@citaq.io

Prompt revocation propagation · Read-your-own-revocations