$ cat terms-of-service.md

Terms of Service

Last updated: February 2026

1. Introduction and Acceptance

These Terms of Service ("Terms") constitute a legally binding agreement between you ("User," "you," or "your") and Attesso ("Attesso," "we," "us," or "our"). By accessing, registering for, or using any of Attesso's services, including our APIs, SDKs, dashboard, mobile applications, and website (collectively, the "Services"), you acknowledge that you have read, understood, and agree to be bound by these Terms, our Privacy Policy, and any additional terms or policies referenced herein.

If you are using the Services on behalf of a business, organization, or other legal entity, you represent and warrant that you have the authority to bind that entity to these Terms, and "you" and "your" will refer to that entity. If you do not agree to these Terms, you must not access or use the Services.

2. Definitions

For the purposes of these Terms:

  • "Agent" means any AI system, bot, automated process, or software application that uses the Services to execute financial transactions on behalf of an End User.
  • "Developer" means any person or entity that integrates the Services into their applications, platforms, or systems using our APIs, SDKs, or other developer tools.
  • "End User" means any individual who authorizes a Mandate for an Agent to transact on their behalf.
  • "Mandate" means a time-limited, scope-constrained financial authorization created by an End User that permits an Agent to execute transactions within defined parameters.
  • "Virtual Card" means a programmatically generated payment credential issued in connection with a Mandate for use on the Visa network.
  • "Restricted Key" means a scoped API credential issued to an Agent with limited permissions for mandate execution.
  • "Payment Processor" means Stripe, Inc. and its affiliates, which process payments on our behalf.

3. Eligibility

To use the Services, you must:

  • Be at least 18 years of age or the age of majority in your jurisdiction, whichever is greater.
  • Have the legal capacity to enter into a binding agreement.
  • Not be a person barred from receiving financial services under the laws of the United States or any other applicable jurisdiction.
  • Not be located in, or a resident of, any country subject to comprehensive U.S. sanctions (including Cuba, Iran, North Korea, Syria, and the Crimea, Donetsk, and Luhansk regions).
  • Not appear on any U.S. government restricted parties list, including the OFAC Specially Designated Nationals and Blocked Persons List (SDN List), the BIS Entity List, or equivalent lists maintained by the EU, UK, or other applicable jurisdictions.

4. Account Registration and Verification

To access the Services, you must create an account and provide accurate, current, and complete information. You agree to update your information promptly if it changes. We reserve the right to suspend or terminate accounts with inaccurate or incomplete information.

Developers who enable live mode must complete identity verification and bank account linking through our Payment Processor (Stripe Connect). This process may require submission of government-issued identification, business formation documents, tax identification numbers, and proof of address. We and our Payment Processor may perform additional due diligence, including sanctions screening and beneficial ownership verification, as required by applicable law.

You are solely responsible for maintaining the confidentiality of your account credentials, API keys, secret keys, and restricted keys. You must immediately notify us at security@attesso.com if you become aware of any unauthorized use of your account or any security breach. You are liable for all activity conducted through your account, whether or not authorized by you.

5. Description of Services

Attesso provides a financial infrastructure platform that enables AI agents to execute authorized transactions. Our Services include:

  • Mandate Management: Creation, authorization, and lifecycle management of scoped financial authorizations using FIDO2/WebAuthn hardware-bound authentication.
  • Virtual Card Issuance: Programmatic generation of Visa-network payment credentials with configurable spend limits, merchant category restrictions, and time-to-live constraints.
  • Transaction Processing: Authorization, capture, and settlement of card-based payments through the Visa network via our Payment Processor.
  • Developer APIs and SDKs: RESTful APIs, TypeScript SDKs, Vercel AI SDK bindings, and MCP server integrations for building agent-powered commerce applications.
  • Risk Assurance: Automated risk assessment, anomaly detection, and credential revocation to protect against unauthorized transactions.

Attesso is a technology platform and is not a bank, money transmitter, or licensed financial institution. Payment processing, card issuance, and funds settlement are provided by our Payment Processor and its banking partners. By using our Services, you also agree to the Stripe Services Agreement and Stripe Connected Account Agreement as applicable.

6. Mandates and Authorization

Mandates are the core authorization mechanism of the Services. When an End User creates a Mandate, they authorize a specific Agent to execute transactions within defined constraints. By creating a Mandate, the End User:

  • Authorizes their payment method to be charged for the Mandate amount plus applicable fees at the time of Mandate creation.
  • Acknowledges that the Agent may execute transactions up to the Mandate's spending limit without further approval.
  • Accepts responsibility for all transactions executed within the Mandate's defined parameters (amount, merchant categories, time window).
  • Understands that Mandates can be revoked at any time, but transactions already captured cannot be reversed through Attesso (standard card dispute processes apply).

Attesso is not responsible for the actions, decisions, or behavior of any Agent operating under a Mandate. The Developer who deployed the Agent and the End User who authorized the Mandate bear responsibility for transactions executed within the Mandate's scope.

We reserve the right to decline, suspend, or revoke any Mandate at our sole discretion if we reasonably believe it may be associated with fraud, money laundering, sanctions evasion, or any other prohibited activity.

7. Fees, Billing, and Refunds

Attesso charges fees for the use of the Services as described in our pricing documentation. Fees are subject to change with 30 days' notice. Current fees include:

  • Platform Fee: A percentage-based fee applied to each Mandate, charged to the Developer.
  • Processing Fees: Payment processing fees charged by our Payment Processor (Stripe), passed through at cost.
  • Developer Fees: Optional fees that Developers may configure and charge to their End Users.

Fees are calculated at Mandate creation and are non-refundable once the Mandate has been authorized, except where required by applicable law. The fee mode (markup or inclusive) determines how fees are applied relative to the Mandate amount.

You agree that Attesso may deduct applicable fees from settlement amounts before disbursement. Payouts are made to the bank account linked during Stripe Connect onboarding, subject to the payout schedule and holds established by our Payment Processor.

Chargebacks, disputes, and reversals initiated by cardholders or issuing banks are subject to the dispute resolution processes of the Visa network and our Payment Processor. You are responsible for all chargeback fees and losses resulting from disputes on transactions processed through your account. Attesso may debit your linked bank account or withhold future payouts to cover chargeback losses.

8. Developer Obligations

If you use the Services as a Developer, you additionally agree to:

  • Implement and maintain reasonable security measures to protect API keys, secret keys, and any credentials issued to you.
  • Not store, log, or transmit End User payment credentials, except through Attesso's designated APIs.
  • Clearly disclose to End Users how their financial data will be used before requesting Mandate authorization.
  • Implement Mandate amount limits and merchant category restrictions appropriate to your use case.
  • Respond to chargeback disputes and provide supporting documentation within the timeframes required by our Payment Processor.
  • Comply with the Visa Core Rules and Visa Product and Service Rules, Stripe's Acceptable Use Policy, and all applicable card network regulations.
  • Not use the Services to facilitate transactions for prohibited business categories, including but not limited to: illegal goods or services, unlicensed financial services, gambling (where prohibited), adult content, weapons, controlled substances, or cryptocurrency exchanges (unless separately approved).
  • Maintain accurate records of all Agent deployments and promptly revoke credentials for compromised or decommissioned Agents.
  • Not exceed published API rate limits or attempt to circumvent any technical restrictions.

9. End User Obligations

If you use the Services as an End User, you additionally agree to:

  • Only authorize Mandates for lawful purposes and legitimate transactions.
  • Set Mandate spending limits appropriate to the intended transaction and review them before confirming authorization.
  • Register FIDO2/WebAuthn credentials only on devices you own or are authorized to use.
  • Not share, transfer, or attempt to export your authentication credentials.
  • Promptly report any unauthorized transactions to Attesso and your card issuer.
  • Not initiate chargebacks for transactions that you authorized through a valid Mandate.

10. Prohibited Activities

You may not use the Services to:

  • Engage in fraud, money laundering, terrorist financing, or any financial crime.
  • Violate any applicable law, regulation, or sanctions program, including but not limited to the Bank Secrecy Act, USA PATRIOT Act, OFAC regulations, EU Anti-Money Laundering Directives, and UK Money Laundering Regulations.
  • Process transactions on behalf of, or for the benefit of, sanctioned persons, entities, or countries.
  • Create fictitious Mandates, inflate transaction volumes, or engage in transaction laundering.
  • Circumvent or attempt to circumvent spend limits, merchant category restrictions, risk controls, or any other safeguard.
  • Reverse-engineer, decompile, or disassemble any aspect of the Services.
  • Use the Services to create a competing product or service.
  • Interfere with or disrupt the integrity or performance of the Services, including through denial-of-service attacks or injection of malicious code.
  • Attempt to gain unauthorized access to any part of the Services, other users' accounts, or systems connected to the Services.
  • Use the Services in any manner that could damage, disable, or impair the Services or the experience of other users.

11. Intellectual Property

All rights, title, and interest in and to the Services, including all software, APIs, documentation, trademarks, trade names, logos, and other intellectual property, are and shall remain the exclusive property of Attesso and its licensors. These Terms do not grant you any right to use Attesso's trademarks, trade names, or logos without our prior written consent.

We grant you a limited, non-exclusive, non-transferable, revocable license to access and use the Services in accordance with these Terms and our documentation. This license terminates automatically upon termination of your account or violation of these Terms.

12. Third-Party Services

The Services integrate with and rely upon third-party services, including but not limited to Stripe for payment processing and card issuance, Clerk for authentication, and Visa for card network processing. Your use of these third-party services is subject to their respective terms and conditions. Attesso is not responsible for the availability, accuracy, or performance of any third-party service.

We may modify, add, or remove third-party service integrations at any time. If a change to a third-party integration materially affects your use of the Services, we will provide reasonable notice.

13. Service Availability and Modifications

We strive to maintain high availability of the Services but do not guarantee uninterrupted access. The Services may be temporarily unavailable due to scheduled maintenance, system upgrades, or circumstances beyond our reasonable control.

We reserve the right to modify, suspend, or discontinue any part of the Services at any time, with or without notice. We will make commercially reasonable efforts to provide advance notice of material changes. We shall not be liable to you or any third party for any modification, suspension, or discontinuation of the Services.

14. Disclaimer of Warranties

THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT.

WITHOUT LIMITING THE FOREGOING, ATTESSO DOES NOT WARRANT THAT: (A) THE SERVICES WILL MEET YOUR REQUIREMENTS OR EXPECTATIONS; (B) THE SERVICES WILL BE UNINTERRUPTED, TIMELY, SECURE, OR ERROR-FREE; (C) ANY TRANSACTIONS WILL BE PROCESSED SUCCESSFULLY OR WITHIN ANY SPECIFIC TIMEFRAME; (D) ANY DEFECTS IN THE SERVICES WILL BE CORRECTED; OR (E) THE RESULTS OBTAINED FROM THE USE OF THE SERVICES WILL BE ACCURATE OR RELIABLE.

ATTESSO MAKES NO WARRANTY REGARDING THE BEHAVIOR, RELIABILITY, OR ACCURACY OF ANY AI AGENT THAT USES THE SERVICES. YOU ACKNOWLEDGE THAT AI AGENTS MAY MAKE ERRORS, PRODUCE UNEXPECTED RESULTS, OR EXECUTE TRANSACTIONS THAT DO NOT ALIGN WITH YOUR INTENTIONS.

15. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL ATTESSO, ITS OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, AFFILIATES, SUCCESSORS, OR ASSIGNS BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, INCLUDING BUT NOT LIMITED TO: LOSS OF PROFITS, REVENUE, DATA, GOODWILL, OR BUSINESS OPPORTUNITIES; COST OF PROCUREMENT OF SUBSTITUTE SERVICES; OR DAMAGES ARISING FROM UNAUTHORIZED TRANSACTIONS, AI AGENT BEHAVIOR, OR THIRD-PARTY ACTIONS, REGARDLESS OF THE THEORY OF LIABILITY (CONTRACT, TORT, STRICT LIABILITY, OR OTHERWISE), EVEN IF ATTESSO HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

ATTESSO'S TOTAL AGGREGATE LIABILITY TO YOU FOR ALL CLAIMS ARISING OUT OF OR RELATED TO THESE TERMS OR THE SERVICES SHALL NOT EXCEED THE GREATER OF: (A) THE TOTAL FEES PAID BY YOU TO ATTESSO IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM; OR (B) ONE HUNDRED U.S. DOLLARS ($100).

THE LIMITATIONS IN THIS SECTION APPLY EVEN IF ANY LIMITED REMEDY FAILS OF ITS ESSENTIAL PURPOSE. SOME JURISDICTIONS DO NOT ALLOW THE EXCLUSION OR LIMITATION OF CERTAIN DAMAGES, SO SOME OF THE ABOVE LIMITATIONS MAY NOT APPLY TO YOU.

16. Indemnification

You agree to indemnify, defend, and hold harmless Attesso and its officers, directors, employees, agents, and affiliates from and against any and all claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of or related to: (a) your use of or inability to use the Services; (b) your violation of these Terms or any applicable law or regulation; (c) your violation of any rights of a third party; (d) transactions executed by Agents operating under Mandates you authorized or created; (e) chargebacks, disputes, or reversals initiated against transactions processed through your account; or (f) any content, data, or materials you submit to or through the Services.

17. Suspension and Termination

We may suspend or terminate your access to the Services immediately, without prior notice or liability, for any reason, including but not limited to:

  • Violation of these Terms or any applicable law or regulation.
  • Suspected fraud, money laundering, or other financial crime.
  • Excessive chargeback rates or dispute volume.
  • Failure to complete required identity verification or due diligence.
  • Activity that poses a risk to the security or integrity of the Services or the Visa network.
  • Request by law enforcement or a government agency.
  • Extended periods of inactivity.

You may terminate your account at any time by contacting us at info@attesso.com. Upon termination, all active Mandates will be revoked, all API keys will be invalidated, and pending payouts will be processed subject to any applicable holds or reserves.

The following sections survive termination: Definitions, Fees (for amounts owed), Intellectual Property, Disclaimer of Warranties, Limitation of Liability, Indemnification, Dispute Resolution, and Governing Law.

18. Dispute Resolution and Arbitration

Informal Resolution: Before filing any formal dispute, you agree to first contact us at info@attesso.com and attempt to resolve the dispute informally for at least 30 days.

Binding Arbitration: If informal resolution is unsuccessful, any dispute, claim, or controversy arising out of or relating to these Terms or the Services shall be resolved by binding arbitration administered by the American Arbitration Association ("AAA") under its Commercial Arbitration Rules. The arbitration shall be conducted by a single arbitrator in the State of Delaware, or at another mutually agreed location. The arbitrator's decision shall be final and binding and may be entered as a judgment in any court of competent jurisdiction.

Class Action Waiver: YOU AND ATTESSO AGREE THAT EACH MAY BRING CLAIMS AGAINST THE OTHER ONLY IN YOUR OR ITS INDIVIDUAL CAPACITY AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS OR REPRESENTATIVE PROCEEDING. The arbitrator may not consolidate the claims of multiple parties.

Exceptions: Either party may seek injunctive or equitable relief in any court of competent jurisdiction to protect its intellectual property rights or to prevent irreparable harm. Claims for amounts within the jurisdiction of a small claims court may be brought in such court.

19. Governing Law

These Terms shall be governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to its conflict of laws principles. To the extent that any lawsuit or court proceeding is permitted hereunder, you and Attesso agree to submit to the exclusive personal jurisdiction of the state and federal courts located in the State of Delaware for the purpose of litigating any such dispute.

20. Regulatory Compliance

Attesso operates as a technology platform and relies on licensed partners for regulated financial services. We cooperate with applicable regulatory authorities and comply with applicable laws and regulations, including but not limited to:

  • The Bank Secrecy Act (BSA) and its implementing regulations.
  • Office of Foreign Assets Control (OFAC) sanctions compliance.
  • The USA PATRIOT Act, including Customer Identification Program (CIP) requirements.
  • The Electronic Fund Transfer Act (EFTA) and Regulation E.
  • Applicable state money transmission laws (through our licensed partners).
  • The General Data Protection Regulation (GDPR) for users in the European Economic Area.
  • The California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) for California residents.
  • PCI DSS requirements for payment card data (through our Payment Processor).

21. Electronic Communications

By using the Services, you consent to receive electronic communications from us, including emails, push notifications, and in-app messages. You agree that all agreements, notices, disclosures, and other communications we provide electronically satisfy any legal requirement that such communications be in writing. You may opt out of promotional communications at any time, but you may not opt out of transactional or service-related communications necessary for the operation of your account.

22. Force Majeure

Attesso shall not be liable for any failure or delay in performing its obligations under these Terms caused by events beyond its reasonable control, including but not limited to: acts of God, natural disasters, epidemics, pandemics, war, terrorism, riots, government actions, power outages, internet or telecommunications failures, cyberattacks, or failures of third-party service providers (including our Payment Processor or the Visa network).

23. Modifications to Terms

We reserve the right to modify these Terms at any time. If we make material changes, we will provide at least 30 days' advance notice via email to the address associated with your account or through a prominent notice within the Services. Your continued use of the Services after the effective date of any modification constitutes your acceptance of the modified Terms. If you do not agree to the modified Terms, you must stop using the Services and close your account before the effective date.

24. General Provisions

Severability: If any provision of these Terms is held to be invalid or unenforceable, that provision shall be enforced to the maximum extent permissible, and the remaining provisions shall continue in full force and effect.

Waiver: The failure of Attesso to enforce any right or provision of these Terms shall not constitute a waiver of that right or provision.

Assignment: You may not assign or transfer these Terms or your rights or obligations hereunder without our prior written consent. Attesso may assign these Terms without restriction.

Entire Agreement: These Terms, together with the Privacy Policy and any other agreements expressly referenced herein, constitute the entire agreement between you and Attesso concerning the Services and supersede all prior or contemporaneous agreements, understandings, or representations.

No Third-Party Beneficiaries: These Terms do not create any third-party beneficiary rights, except as expressly stated herein.

25. Contact

For questions about these Terms of Service, please contact us at info@attesso.com.