Last updated 11 September 2026. This page summarises the terms under which Accredit Digital issues accreditation and the limits of what accreditation represents.
Accredit Digital separates three distinct concepts, and every published statement should be read accordingly.
The website passed Accredit Digital's defined technical assessment at the time of scanning. Assessment covers website reachability, SSL certificate configuration, HTTPS enforcement, exposed sensitive files, email domain security (SPF and DMARC), Google Safe Browsing status, malware pattern indicators and phishing pattern indicators.
The organization provided information and documents that were reviewed under Accredit Digital's organizational verification process. Review covers legal status and registration, organizational information and demonstrated operational capacity, assessed against the supporting evidence submitted.
Accredit Digital granted accreditation based on the applicable assessment criteria in force on the date of the decision.
Accreditation represents assessment against Accredit Digital's defined criteria and is not an unconditional guarantee of future website security, business performance, financial solvency, product quality, regulatory compliance beyond the stated verification scope, or the absence of future cyber incidents.
Malware and phishing pattern scanning are automated security assessment techniques. They do not constitute a guarantee that a website is completely free of malware or phishing activity. SPF and DMARC results are technical domain-security indicators and do not establish that an organization is legitimate.
A scan reflects the state of a website at the time it was performed. Accredit Digital re-scans accredited websites on a configurable schedule and monitors for material change, but no assessment can describe a website's state between scans.
Customers must provide accurate information. Supplying false information is grounds for suspension or revocation of accreditation.
Accredit Digital may suspend accreditation for any of the following reasons: website compromise, malware detection, phishing detection, SSL failure, material change to organization information, expiry of legal documentation, false information, policy violation, overdue accreditation fee, or another documented administrative reason. When accreditation is suspended the badge changes state immediately and the public verification page displays the suspension. The customer must not continue to present the organization as actively accredited.
Accredit Digital may permanently revoke accreditation. Revocation records the reason, date, deciding administrator, previous status and notes. The verification page retains an audit record so that a badge still displayed on a website can be identified as invalid.
An administrator may override an automated assessment result. Every override requires a written reason and is permanently recorded in the audit log.
Accreditation is issued for one year. Renewal reminders are sent in advance. Accreditation that is not renewed moves to Expiring Soon and then Expired, and the badge reflects that status.
Assessment is read-only and non-destructive. Accredit Digital applies rate limiting, request throttling, timeout controls, maximum crawl depth and page count, retry limits, DNS and HTTP timeouts and concurrency limits, and identifies its scanners by user agent. Accredit Digital does not attempt exploitation, brute force, file modification or authentication bypass.
Accredit Digital collects personal information necessary to operate accreditation: name, email, phone, country, job title, and organization details. Package 2 customers additionally submit organizational and legal documentation.
Public verification pages display only the website, accreditation ID, level, status, dates, technical assessment result and — for organizational verification — legal name, registration jurisdiction, verification status, date and scope. Confidential documents and sensitive personal information are never published. Listing in the public trust directory is opt-in.
Data is encrypted in transit and at rest. Uploaded documents are restricted by file type and size, scanned for malware and stored with access controls; executable files are never executed. Access is governed by role-based permissions and enforced at every API endpoint, and tenant isolation is enforced at the API and database level.
Accredit Digital defines retention policies for scan results, accreditation history, documents, audit logs, payment records and customer records. Historical accreditation records are retained sufficiently long to maintain verification integrity — a revoked or expired accreditation remains verifiable as such.
The Accredit Digital name, logo and Trusted Site badge are marks of Accredit Digital. A licence to display the badge is granted for the duration of a valid accreditation and for the accredited website only.
Displaying an Accredit Digital badge without a valid, current accreditation may be reported to trust@accreditdigital.com.
This page is a summary prepared for the platform prototype. Final contractual terms, privacy notice and jurisdiction-specific requirements should be confirmed with qualified legal counsel before launch.