1. Prohibited activities
- Fraud, misrepresentation or attempts to deceive verifiers.
- Issuing fake, forged or unauthorised credentials.
- Unauthorised access to accounts, tenants or institutional data.
- Automated abuse of the verification portal or APIs (scraping, mass enumeration, credential stuffing).
- API misuse: circumventing rate limits, sharing keys, reselling access without authorisation.
- Uploading malware, malicious payloads or actively harmful content.
- Tampering with, altering or attempting to alter issued credentials.
- Identity theft or impersonation of individuals or institutions.
- Reverse engineering, decompilation or unauthorised probing of the Platform.
- Any activity that is illegal under Ugandan law or the law of the user's jurisdiction.
- Platform abuse: harassment, spam, or interference with other users.
2. Enforcement
Depending on severity and history, we may take one or more of the following actions:
- Warn the responsible user or Institution.
- Throttle, restrict or revoke API access.
- Suspend or terminate accounts or Institution tenants.
- Preserve records for investigation.
- Cooperate with law enforcement where legally required.
3. Report abuse
To report suspected abuse or a fraudulent credential, contact security@verify.ug.