Issuer obligations
Accredited organizations must maintain accurate source records, revoke compromised credentials without delay, and keep authorized officers current.
Verifier rights
Any relying party may confirm a credential's authenticity and status. Verifiers see attestation results — never the issuer's underlying database.
Holder rights
Credential holders control sharing through time-boxed, revocable links, and can see exactly who verified their documents and when.
Dispute resolution
Disputed results are escalated to the issuing organization first, then to the Verify.ug Trust Committee within 10 working days.
Levels of assurance
Every verification result carries the issuer's assurance level so relying parties can calibrate their own risk decisions.
LoA 1 — Declared
Self-asserted organization profile. Credentials verify as issued, but the issuer is not yet accredited.
LoA 2 — Verified issuer (KYB)
Legal identity, registration number, TIN and authorized officers confirmed by Verify.ug.
LoA 3 — Accredited issuer
KYB plus signed trust agreement, key management review and annual attestation.
LoA 4 — Authoritative source
Statutory register connected through a government connector (UGPass / UGHub class integration).
Governance bodies
| Body | Mandate | Cadence |
|---|---|---|
| Trust Committee | Owns the trust framework, accreditation decisions and appeals. | Quarterly |
| Security & Privacy Board | Reviews incidents, cryptographic controls, retention and data protection. | Monthly |
| Issuer Council | Representatives of accredited organizations; advises on policy and roadmap. | Bi-annual |
| Change Advisory Group | Approves breaking API changes, deprecations and connector activations. | As needed |
Framework lifecycle
The framework is versioned. Material changes are published 30 days before they take effect, with a comment window for accredited issuers. Current version: v1.0 (pilot).