Logo
for platforms

You are about to let a business trade. What do you actually know about it?

Short answer

Company registry checks tell you whether a company is registered. For a business whose entire presence is a phone number and a Facebook page they return nothing — and in Moldova and Romania that is most of the market. We hold a different record: what we checked about a listed business, when, and by what method. Four of those facts are public and you can read them today. Two need the business’s own permission. We make no compliance claim, and we cannot tell you whether they deliver.

One credential, one endpoint, two tiers. The four public facts come back on every read. The two on the right are the merchant’s to give: they name your platform from their own dashboard and can withdraw it, and a read without that permission returns the public four plus a note saying what was withheld and why — never an error, because you are entitled to learn that permission is the thing you lack.

What you can read without asking anyone

These are already public — on the business’s own profile, and to any assistant that asks. One credential gets you them per listing, in a shape that will not move under you.

Which verification claim is in force

Human, automated, or none. An automated claim means machines proved control of the channels the record cites; it does not mean a person established who owns the business, and the response says so in the same breath rather than in a footnote.

Which channels were proved, and when

The kinds of channel with the date of the newest proof — never the values, because an endpoint returning those would be a contact scraper. A lapsed proof is excluded and counted separately: “had one and it expired” and “never had one” are different facts about a business.

When they last confirmed their own record

Three states, not two: confirmed on a date, asked and never answered, or never asked. The third is our gap rather than theirs, and it is reported as ours.

How much of the profile is usable

A completeness band and score, from the same calculation the merchant sees in their own dashboard. It counts fields present, not facts checked.

What only the business can give you

Two things are not public and will not become public because you are paying us. The business grants your platform access from its own dashboard, naming you specifically, and can withdraw it whenever it likes — withdrawal takes effect on your next request. We will not ask a merchant on your behalf, and there is no endpoint through which you can request it. Ask during your own onboarding, where they are already deciding whether to work with you.

What they committed to, and what they took back

Orders accepted through us inside the limits they set, orders they later withdrew, orders the buyer cancelled, and reschedules — over a year. Every figure is one the merchant can recompute from their own signed export, so it is not a score that only we can see.

Whether a person answers

How often a question had to reach a human, how often a human answered it, and the median hours it took — with the number of pairs that median was computed over printed next to it, because a median over one pair is not a median.

How to read it

Three requests. The credential is issued here by a person after a conversation rather than by a form, and that is deliberate: the permissioned tier discloses one business’s trading record to another company, and we would rather know who you are.

[01]

Exchange your credentials for a token

OAuth 2.1 client credentials at POST /api/v1/agents/token, returning a one-hour bearer token. The same endpoint every other agent surface here uses — there is no second identity system to learn.

[02]

Read the contract

GET /api/v1/platform/self returns every field, both tiers, and for each one what it establishes and what it does not. You can see exactly what permission would add, and what it still would not prove, before asking a single merchant for it.

[03]

Read a counterparty

GET /api/v1/platform/counterparty/entity/{slug}. Without permission you get the public four plus a note naming what was withheld and why — not an error. Never cached, because a verification can be revoked and permission withdrawn between one request and the next.

stated limits

What this does not establish

  • It is not a compliance product. We make no statement about any statutory or regulatory duty you may have, and this record does not discharge one. That is a conversation for your own counsel, not for our sales copy.

  • We are not an official register. We hold no identity documents and no payment-account details, and we do not want them.

  • It cannot tell you whether they deliver. Nothing here observes a delivery — no courier, no receipt, no buyer confirmation. A commitment nobody withdrew is not an order anybody carried out, which is why we do not call it one.

  • It is not a rating, a ranking or a prediction. There is deliberately no single score: one number invites you to skip the four facts that would actually have told you something.

  • Coverage is Moldova and Romania first, and it is thin. Better that you hear that from us than measure it yourself after signing something.

  • Withdrawn permission stops the next read. It cannot undo a read that already happened, and we say that to the merchant in those words too.

Questions people ask about this

Does this satisfy our trader-verification obligations?

No. We make no compliance claim of any kind — not on this page, not in the API response, not in a contract. If you have statutory duties concerning the traders on your platform, this record does not discharge them, and it should not be presented internally as if it does. What it can be is one input among several that you chose to collect.

Can we buy access to every merchant’s full record?

No. The permissioned fields need each business’s own permission, naming your platform, and there is no volume or price at which that changes. If that makes this less useful to you, that is the honest shape of it rather than a negotiating position.

Why is the credential not self-service?

Because the permissioned tier discloses one business’s trading history to another company, and a registration form collects a name typed by whoever is filling it in. A person issues it after a conversation. It is friction, and the friction is the control.

Will you hold our identity and payment documents for us?

No. Holding those would take on a deletion duty inside a system whose central record is append-only by design and cannot delete. We would rather refuse than ship something whose two halves contradict each other and only find out during a dispute.

What happens when a merchant withdraws permission?

Your next request returns the public fields with a note naming what was withheld and why. Deliberately not an error: you are entitled to learn that permission is the thing you lack, rather than concluding the business has no history.