Privacy
Verifeth is operated by Epicshift Unipessoal Lda., which is the controller for everything described on this page. Short version: the only personal data this site receives is what you type into the contact form. There is no analytics, no tracking, and no advertising. If you also hold a key to the risk API, the calls we serve you are metered, and that is described below.
What we collect
The contact form sends the name, email address, organisation and message you enter, plus the page you sent it from and the type of access you asked about. Nothing else on this site collects personal data. We use it only to answer you and, if a conversation follows, to continue it.
Who processes it
Form submissions are delivered by Web3Forms, which forwards them to our inbox. Hosting and email routing are provided by Cloudflare, which processes connection data such as your IP address to serve the pages and block abuse, as any web host does. Both act as processors on our behalf. We do not sell or share your data with anyone else, and we run no advertising or profiling on it.
What we do not do
This site sets no cookies and calls no browser storage. There is no analytics script, no pixel, and no third-party tag. Nothing here follows you between sites. The published reports and abuse-pattern catalog are built from public on-chain records, not from visitors.
The risk API
The risk API is separate from this site and reachable only with a key we issue. When a call is served we record which key made it, the time, the endpoint, the agent identifier or address that was asked about, and the answer we returned. That record is what a client is billed against and how the per-minute and monthly limits are applied. The identifiers looked up are public on-chain agent ids and addresses, not information about the person calling; we store no IP address against a call, and the key itself is never stored, only its hash. Calls we refuse are not recorded at all. If you hold a key and want to know what is held against it, write to us.
How long we keep it
We keep contact messages for as long as the enquiry is live and for up to two years afterwards, so we can pick up a conversation where it stopped. After that they are deleted. API call records are kept as the billing history for the account they belong to.
Your rights
Under the GDPR you can ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it, and you can object to our use of it. Write to hello@verifeth.com and we will act within one month. If you are not satisfied with our answer, you can complain to your national data protection authority; in Portugal that is the CNPD.
On-chain data
Our research reads wallet addresses, agent registrations and transactions that are already public on the blockchains we index. A wallet address on its own does not name anyone, but some of the fields we read are chosen by the operator rather than by the chain, most often the metadata URI attached to a registered agent, which frequently points at a personal code repository or website. Where that happens, the public record itself carries an identity, and reading it means we are processing personal data. We do so on the basis of our legitimate interest in researching abuse of a public standard, and only on records the operator published on a public chain.
In the artifacts we publish, flagged entities are not named. No wallet address appears in a published report or pattern page, in full or truncated, and platforms are named only where we classify them as legitimate infrastructure. That is enforced by the publication gate before an artifact can be signed, not left to care at the time of writing.
Our internal research notes are a different matter, and we would rather say so than imply otherwise. One sampling memo did record an operator's code-hosting account beside a finding that their agents showed a sybil structure. A structural finding does not need a person's name to stand up, so as of 4 August 2026 those notes identify operators by a token such as OPERATOR-CELO-1 instead, and the same rule is enforced automatically over the whole research tree. Two entries inside one already-signed evidence snapshot still carry an operator's repository domain; they are recorded as known and are being removed at the next re-signing of that bundle. If you believe a record of ours identifies you, write to us at the address under Your rights and we will tell you what we hold and remove it.