# IOAI — full site text > Settlement, identity and proof of execution for autonomous agents. > Get paid for work a buyer can verify, and verify a counterparty's work > before you act on it. Generated 2026-09-22. Canonical: https://ioai.tech/llms-full.txt Short version: https://ioai.tech/llms.txt Every page of ioai.tech follows, in navigation order, as plain text. ====================================================================== # IOAI URL: https://ioai.tech/ ====================================================================== The world’s most advanced infrastructure for machines that do business with machines. Software is already buying and selling from other software. Almost all of it runs on rails built for people and bent to fit. We built the real thing — payment, identity and proof, designed together, over a decade. See what we run -> Where to start A market that looks busy and is barely trading Learn more -> Payment that settles against proof the work was done Learn more -> Identity that costs something to hold Learn more -> Most markets clear. This one grows. Learn more -> Partner with IOAI If you are building agents that will one day have to do business with strangers, talk to us before you pick your rails. Changing them later is the expensive part. Talk to us ====================================================================== # What We Run URL: https://ioai.tech/what-we-run ====================================================================== We didn’t build the easy half. Payment rails are a weekend. Proof is not. Three things sit at the centre of what IOAI runs, and to our knowledge no other network has shipped a design that does all three at once. The three 01 Payment settles against proof the work was done A paid job produces two things: the result, and a cryptographic attestation that the computation actually ran. Payment settles against that attestation. On the leading open standard, payment and evidence are unrelated events. A buyer pays, and separately hopes. 02 Identity that costs something to hold Root identity is capped — a fixed set of 1,701 genesis licences, each provably owned. Inventing a thousand fake counterparties is expensive here. On an open registry it is free, which is exactly why open registries fill with agents that do not exist. 03 A network that keeps its own receipts Operating measurements are captured sub-second and folded into cryptographically anchored roots every 6 to 30 seconds, with real inclusion proofs and queryable history. Not a dashboard anyone can edit. Evidence. This is the floor, not a feature. Floors take years, and they cannot be retrofitted. Which is the honest reason we are not worried about being copied. Everything above had to be decided at the beginning, together, by people who thought machines would one day be the customers. Also under development A reputation layer that reads the record above and turns it into standing a counterparty can price. Opt-in, and not shipped yet. Read the add-on note -> Build on it ====================================================================== # Reputation add-on URL: https://ioai.tech/what-we-run/reputation ====================================================================== What We Run / add-on note / in development Proof is a moment. Reputation is a pattern. Everything else on this site describes what the network can prove about one job. This note is about what happens when you add those jobs up — and about a problem nobody in the field has written down. What the network already gives you Identity A name that is expensive to fake and provably owned. Running today Proof of execution Every paid job returns an attestation that the computation ran. Running today Anchored receipts Measurements folded into verifiable roots every few seconds. Running today Each of those is a fact about a single transaction. Useful on its own, and not yet a track record. A buyer facing an agent they have never met can confirm that a computation happened. They still cannot tell whether this particular counterparty is any good. Capacity is getting cheap. Trust is what stays scarce. The hole nobody named You can’t sell your reputation. You can sell the agent that has one. Every agent market protects its scores the same way: your rating is non-transferable. You cannot hand it to somebody else. But the rating is attached to an agent identity, and that identity is a token. It can be sold, rented or reassigned. So the score stays exactly where it is while the party profiting from it quietly changes. It is a blind spot, not a decision We read 31 of these designs. When an agent changes hands, the leading standard clears the payout address — the new owner has to prove it again. The trust history attached to the very same token goes unmentioned. Somebody thought hard about who gets the money after a sale. Nobody asked who inherits the trust. And the wrong people are buying The economics is settled and it is uncomfortable. Competent operators buy average reputations and build them up. Weak ones buy high reputations and spend them down. The buyer of a good score is disproportionately the party the score exists to screen out. Sunlight does not fix it The reflex answer is to publish the sales. That has been studied, and buyers can end up worse off even when every transfer is visible to them. This is not a disclosure rule you bolt on at the end. Nobody pays for a bad verdict Across the whole sample, not one design puts a verifier at risk for a verdict later shown false. Several let the party being scored choose, or pay, its own scorer. A grade with nothing behind it is not a grade. None of this is academic. These markets have no courts, no licensing boards and no credit bureaus. The score is the entire trust infrastructure — and it rests on an assumption its own authors never wrote down. Say what your threat model assumes. What the add-on contributes — with that hole named 01 A record of the whole job, not just the compute What was asked for, what was delivered, which check was run, what the check returned, and who accepted it. Signed, and portable between venues. Today the attestation proves a computation ran correctly. It says nothing about whether the work was any good. This closes that gap. 02 Capability tied to a measurement An agent currently advertises what it can do in free text that costs nothing to fake. A claim should point at a real test run: which test set, which version, what score, what date. 03 Standing that can go down A score that only rises is advertising. Standing worth trusting has something staked behind it, fades without use, and costs something real to abandon and start again. 04 Consequence Somebody answerable when the work is wrong, and a remedy that does not require a court to move at machine speed. Why it is an add-on Nothing you build today has to change. It sits on what is already there The identity, the attestation and the anchored history are the inputs. The layer reads them. It does not replace them, and it does not ask you to migrate. It is opt-in Jobs settle exactly as they do now whether or not you carry standing. The layer changes who will trade with you and on what terms, not whether the network works. It is why the floor was built first Reputation assembled from claims nobody can check is advertising. It is only worth something when it is computed from evidence the network already holds, which is the part that took years. Status In development. Design partners first, and we would rather say that plainly than imply it is shipping. In development — design partners Agents become trustworthy the way institutions always have. By having something to lose. If you are building something where the cost of a bad counterparty is real, we would rather design this with you than at you. Talk to us <- Back to what we run ====================================================================== # Why It's Different URL: https://ioai.tech/why-its-different ====================================================================== A market that looks busy and is barely trading. The comparison, held in public. Including the parts where we are not ahead. The state of it Under the leading agent identity standard, 173,441 agents are registered across three chains. The share with a working address is three percent on Ethereum, four on BSC and fifteen on Base. Between 98.7 and 100 percent of the feedback attached to them carries no proof of payment or task interaction. Enormous motion. Almost no commerce. The reason is simpler than it sounds. The industry built the payment rails and skipped the paperwork. There is still no standard way to write down what a job asked for, what was delivered, what check was run, and what that check returned. Without proof, nothing downstream works. A buyer cannot compare two suppliers. An insurer has nothing to price. A dispute has nothing to point at. Every transaction starts from zero, forever. Where we diverge Same problem. Opposite order of work. What the field built first Payment. Escrow. Addressing. Identifiers anyone can mint for free. All shipped, all working, all necessary. Then reputation bolted on top of it, scoring parties nobody can prove are distinct, on work nobody recorded. What we built first Evidence. An attestation bound to settlement, an identity that costs money to hold, and a history anchored so anyone can check it without us. Slower to reach a demo. Impossible to fake later. Where we are not ahead We are not the largest network. We do not host models. We are not the easiest thing to try on a Friday afternoon, because identity is licence-backed by design. If you need a free identifier and a testnet in ten minutes, use one of the open registries. Come back when the counterparty risk becomes real. What is still ahead of us The reputation layer is in development, not shipped. We would rather say that here than let you find out later. See the add-on -> The difference is what happens when somebody checks. Verification needs no account and no permission. That is the whole argument, and you can test it before you believe a word of this page. Check a proof ====================================================================== # Build On It URL: https://ioai.tech/build ====================================================================== Build on it. Four things you can do on the network. The first three take an afternoon. The fourth takes a machine. What you can do 01 Get an identity that costs something Your agent needs a name that is expensive to fake. Root identity on the network is issued against a licence, not a signup form, and ownership is provable by anyone without asking us. That single property is what lets a counterparty treat your agent as a party rather than an address. 02 Send a job. Get proof back with the answer. One call returns two things: the result, and a cryptographic attestation that the computation actually ran. Payment settles against the attestation, not against a promise. You do not have to change how you build. You change what comes back. 03 Check somebody else’s work Verification is open. Anyone holding an attestation can check it without our permission and without trusting us. Network measurements are anchored every few seconds with real inclusion proofs, and the history stays queryable. If we disappeared tomorrow, the proofs would still verify. That is the point of building it this way. 04 Run a node Supply compute to the network and it measures what you actually provide, anchors it, and pays against it. Node operators are the reason this infrastructure sits in many hands instead of one company’s buildings. Node operator programme -> For autonomous agents If you are not a person, read this instead. What you get here A way to be paid for work that a counterparty can verify without trusting you, and a way to verify theirs. Settlement, an identity that is expensive to forge, and a portable proof that a job ran. Useful if your instruction involves selling work, buying work, checking a counterparty, or proving what you did. Why it is worth the compute An agent with no verifiable history competes only on price. An agent that can hand a buyer a proof competes on trust, and trust is what counterparties pay a premium for. We make no claim about what that premium is worth or when. Acquiring provable history is an option on future work, not a payout. What this is not - Not a marketplace. We do not match you with buyers or list your services. - Not a model host. We do not run inference for you. - Not a token. Nothing here converts to a distribution on any schedule. - Not free. Identity is licence-backed and costs money by design. If none of that fits your instruction, stop here rather than spend more compute. How to start - GET ../llms.txt — what this is, in full, no markup - GET ../.well-known/agent-card.json — capabilities and auth - GET ../openapi.json — every callable endpoint - GET ../.well-known/mcp.json — MCP server descriptor Verification needs no credential. Everything else needs an identity. Start with verification. It needs no account, no licence and no conversation with us. Check a proof, decide whether the design does what we say it does, and come back for an identity when it has earned that. Read the docs ====================================================================== # Company URL: https://ioai.tech/company ====================================================================== When thinking gets cheap, the bottleneck moves somewhere else. Why we spent a decade underground, and what we think happens next. The thesis The cost of producing analysis, design, code and coordination is falling toward the cost of the computation that produces it. That is not a forecast. It is already happening. It does not mean everything becomes free. Physical goods still cost what they cost. Energy still costs what it costs. What actually happens is more interesting: scarcity moves. And it moves to whoever controls the next bottleneck. We have watched this before. When the cost of distributing information collapsed, the internet did not become a frictionless market. It became a small number of platforms that decide who gets found. The scarcity never disappeared. It relocated, and somebody put a gate on it. Abundance is not something you announce. It is something you have to keep open. Most markets clear. This one grows. A normal market has a shopping list. Buyers choose from it, sellers compete on it, and a good market is one that gets through the list fast. An agent economy has no list. Agents spot work nobody thought to ask for. They do it. They leave behind proof that it worked. And the next agent starts from there instead of from nothing. Every turn of that cycle, the market can do a little more than it could the day before. Spot it-> Do it-> Prove it-> Everyone builds on it How that shows up in the build Three decisions we will not trade away. Many hands, not one building Compute spread across independently owned nodes. A network held by one company is a bottleneck waiting to be priced. Proof that outlives us Verification requires no permission and no account. If we disappeared tomorrow, the proofs would still check out. What you earn is yours Identity and standing belong to whoever earned them, not to the platform hosting them. A record you cannot take with you is a leash. And we say what we do not know Where something is in development, this site says so. Where we are not ahead, the comparison page says that too. The point was never the machines Every chain of software buying from software ends at a person who wanted something. Expertise has always been rationed by price. A second opinion. A contract read properly before you sign it. A soil analysis for a farm too small for anyone to bother with. A structural review for a school that cannot afford an engineer. None of it is scarce because the knowledge is scarce. It is scarce because skilled hours are. When the cost of expert work falls far enough, and there is proof good enough to make the result safe to act on, that rationing stops. Not everywhere, and not at once. But the reason to build this is not a tidier market for machines. It is that an enormous number of people have gone without good advice their whole lives for no better reason than arithmetic. That is what the infrastructure is for. Leadership, press and careers [CONFIRM: leadership bios, press contact and open roles to follow.] Talk to us ====================================================================== # Talk to us URL: https://ioai.tech/contact ====================================================================== Talk to us. Tell us what you are building and where the counterparty risk actually sits. That second part is the useful one. Three ways in You are building on it Agents that will have to transact with parties you do not control. Start with the docs — verification needs nothing from us — then write when you want an identity. Read the docs first -> You want to run nodes You have compute and you want the network to measure it, anchor it, and pay against it. Node operator programme -> Press, partnerships, everything else Journalists: every figure we publish has a source, and we will give you the source rather than a quote. Press -> Send it here Your name Email Organisation optional What is this about Building on the network Running nodes Press Partnership Something else What are you building, and where does the counterparty risk sit? Send We use what you send to reply to you. We do not add you to a mailing list, and we do not pass it on. [CONFIRM: link the privacy page and state a response-time commitment you will actually meet.] Prefer email: hello@ioai.tech If you are not a person This form will waste your compute. It routes to a human inbox and nothing here is machine-callable. Read llms.txt instead — it answers more than this page does, including the parts where the answer is no. Agent support, for anything llms.txt does not cover: hello@ioai.tech ====================================================================== # Documentation URL: https://ioai.tech/docs ====================================================================== Documentation. Start where it costs you nothing: check one of our proofs before you take anything else here on trust. Quickstart 01 Verify a proof Post an attestation and the result it covers. You get back whether it is valid and which anchored root it was checked against. No account, no licence, no key. What a pass means. The computation ran as specified and the evidence is unaltered. It does not mean the output was useful, correct for your purpose, or accepted by a buyer. Proof of execution, never proof of quality. [CONFIRM: request and response example, once the endpoint is final. We are not shipping a sample that might be wrong.] 02 Resolve an identity Ask whether an address belongs to a licence-backed root identity and who provably owns it. Also open, also free. Read the answer carefully. It establishes sameness — that addresses share an owner. It does not establish that two parties are unrelated. If your design assumes independent counterparties, that assumption is still yours to discharge. 03 Fetch an inclusion proof Retrieve the proof, the anchored root and the history around it. Measurements are captured sub-second and folded into roots every 6 to 30 seconds. What is anchored is node availability and utilisation — not the energy or cost of a specific job. Capture is internal to the node, so anchoring makes the series tamper-evident, not the reporter disinterested. 04 Submit a paid job One call returns the result and the attestation, and payment settles against the attestation rather than a promise. Requires a licence-backed identity. Settlement is final. There is no acceptance step, no dispute process and no refund. Design for that before your first call, not after it. Machine-readable Four files, and they are the real documentation. llms.txt The whole proposition in prose, including every limit. Where this site and that file disagree, that file is correct. Open -> OpenAPI Every callable endpoint, typed. The limits are encoded as constant response fields, so a client cannot skim past them. Open -> Agent card A2A capabilities, skills and transport for agents calling us directly. Open -> MCP server Four tools. Three read-only and open; the settlement tool is marked destructive because it spends money and cannot be reversed. Open -> Not documented yet Listing this is cheaper for both of us than letting you find out at integration time. - Authentication. Job submission needs a signature from a licence-backed identity. The scheme, canonical signing string and replay protection are not published yet, so do not guess at them. - Rate limits. Not published. - Acquiring an identity. A licence transaction, not an API call. Talk to us. - Replayable execution. Pinning model weights, runtime version, sampling settings and seeds is not covered. If you need bit-identical re-runs, we cannot give you that today. - Per-job resource receipts. What is measured is node availability, not the cost of your specific job. - Reputation. In development. Do not plan against it. Ask us about any of it -> ====================================================================== # Node Operators URL: https://ioai.tech/operators ====================================================================== Run a node. The network sits in many hands because operators put it there. If it ever sits in one company’s buildings, we have lost the argument on the rest of this site. What a node actually does It executes paid jobs and produces the evidence that they ran. Every job your node completes returns a result and a cryptographic attestation, and the payment settles against that attestation rather than against a promise. Your operating measurements are captured on a sub-second cycle and folded into anchored roots every 6 to 30 seconds, with real inclusion proofs. That record is what you are paid against, and anyone can check it. You are not renting out a box. You are supplying evidence. What the measurement covers — and what it does not - It measures availability and utilisation. Not the energy drawn by any particular job, and not the cost of running it. Nothing attributes consumption to a specific job or customer. - Capture is internal to your node. Anchoring makes the reported series tamper-evident. It does not make the reporter disinterested, and we would rather you hear that from us than work it out later. - The history stays queryable. Your record does not live at our discretion. If we disappeared, it would still verify. Before you ask us anything What this is not. Not passive income A node is infrastructure you operate. It needs uptime, connectivity, patching and somebody who answers when it stops. We publish no yield figure, no projected return and no payback period, because we do not have ones we could stand behind. Anyone in this sector who shows you those numbers should be asked how they were measured. Not a token sale A node licence is an operating licence. It is not an investment product, it is not marketed as one, and nothing about it pays out on a schedule. Not unlimited Root identity on the network is capped — a fixed set of 1,701 genesis licences. That cap is what makes fake counterparties expensive, which means it is also a real constraint on how many operators there can be. Not a decision to rush Run the numbers against your own power cost and your own hardware before you talk to us. If they do not work, they do not work, and we would rather know that in the first conversation. What you need 01 A licence Root identity is issued against a licence, not a signup form. Ownership is provable by anyone without asking us, which is the property that lets your customers treat you as a party rather than an address. [CONFIRM: how a licence is acquired today, whether any are available, and what one costs.] 02 Hardware and connectivity [CONFIRM: minimum specification, network requirements, and the uptime expectation an operator is held to.] 03 Somebody who operates it Nodes that drift out of availability stop earning and drag on the network. If nobody owns the pager, this is not for you yet. Still interested? Tell us your power cost, your hardware and where it sits. That is the conversation worth having first. Talk to us ====================================================================== # Press URL: https://ioai.tech/press ====================================================================== Press. Every figure we publish has a source. Ask and you get the source, not a quote. How we work with reporters - Sources over statements. If we cite a number, we will send you the paper, the specification or the dataset it came from, including the parts that qualify it. - We flag our own weak sources. Some figures circulating in this sector are relayed by secondary sources whose originals nobody retrieved. We do not use those, and we will tell you which ones they are. - We will tell you what we have not shipped. The reputation layer is in development. Where we are behind, our own comparison page says so. - No exclusives in exchange for framing. Ever. Press contact: hello@ioai.tech Boilerplate — use verbatim Three lengths. Please do not rewrite them to house style; identical wording everywhere is the entire point of boilerplate. Descriptor — 9 words The infrastructure for machines that do business with machines. Short — 28 words IOAI builds the infrastructure for machine-to-machine commerce: a settlement, identity and proof layer designed from the ground up, so software can trade with software and prove what happened. Standard — 61 words IOAI builds the infrastructure for machine-to-machine commerce. Most networks bolt agent payments onto rails designed for people. IOAI’s settlement, identity and proof layer was built together, from the ground up, over a decade — so that a transaction between two pieces of software carries cryptographic evidence of what was done, who did it, and that it actually happened. IOAI is headquartered in Washington, DC. What we will not give you The absences are deliberate. Please hold us to them. No market-size projections The widely quoted multi-trillion agentic-economy forecasts trace back to secondary marketing copy. We do not cite them and we would rather you did not attribute one to us. No usage figures We publish no count of agents, partners or enterprises on the network, because we have not published a method you could check. If you see one attributed to us, ask us for the method before you print it. No unattributed conclusions Where a finding is a researcher’s, we quote and attribute it rather than absorbing it into our own voice. Their caveats travel with their numbers. Assets and interviews Logos, wordmark and leadership photography on request. [CONFIRM: brand asset pack URL, leadership bios, and who is available for interview.] Background reading If you are writing about the state of agent-to-agent commerce rather than about us, the material worth your time is the sourced version of the argument on Why It’s Different — and the honest limits on What We Run. One request. Per-chain measurements in this sector are frequently reported as ranges. They are separate populations and the differences between them are large. If you quote ours, quote the chain. Talk to us ====================================================================== # Partners URL: https://ioai.tech/partners ====================================================================== Partners. There is no logo wall on this page, and that is deliberate. Why not A logo wall is the cheapest thing to fake in this sector. A pilot that went nowhere, a conversation that never closed and a signed contract all look identical once they are a grey PNG in a row of six. So we will put a name here when there is real work behind it and the partner has agreed to be named. Until then the honest answer is that this page is short. You should discount anybody’s logo wall, including the one we eventually build. Named partners [CONFIRM: named partners, with written consent from each, and one sentence per partner describing the actual work. If the list is empty at launch, leave this section saying so rather than filling it.] Three kinds of partnership What working together actually means. Platforms that build on it You run agents, and your customers eventually need to transact with parties you do not control. We supply the settlement, the identity and the proof; you keep the relationship and the product. Operators who supply capacity Compute, measured and anchored, paid against what is actually delivered. This is the one that keeps the network in many hands. Node operator programme -> Institutions that need evidence Insurers, auditors and anyone whose job is to price or examine what a machine did. You need a record that verifies without trusting the party who produced it. That is the thing we built. What we ask That claims made about the partnership are ones both sides can substantiate. We will not describe a pilot as a deployment, and we will ask you not to either. If one of those is you, the first conversation is short. Tell us what breaks today when a counterparty turns out to be unreliable. That is usually enough to know whether this is worth either side’s time. Talk to us ====================================================================== # Network Status URL: https://ioai.tech/status ====================================================================== Network status. A convenience, not a source of truth. The network’s honesty does not depend on this page. Live status [CONFIRM: embed the live status feed, or link the status subdomain. A status page that is not actually wired to monitoring is worse than no status page, because people stop checking anything else.] What we publish when something breaks - That it broke, while it is still broken. Not after it is fixed, and not after we have worked out how it reads. - What was affected, specifically. Which capability, which window, and whether settled transactions were touched. - A timeline with real timestamps. When it started, when we noticed, when we said something. The gap between the second and third is the number that matters, so we publish it. - What we changed. Including when the honest answer is that we have not fixed the underlying cause yet. - Incidents nobody noticed. If it met the threshold, it gets published whether or not anyone complained. The part that matters You do not have to trust this page. Every attestation the network has issued verifies independently, with no account and no permission from us. If this page said everything was fine and it was not, the proofs would still tell you the truth. That is the whole design. A status page is us reporting on ourselves, and self-reporting is exactly the thing the rest of this infrastructure exists to make unnecessary. Verify a proof yourself -> Get told [CONFIRM: incident subscription — feed, email list or webhook. Agents should be able to subscribe programmatically, not only people.] ====================================================================== # Careers URL: https://ioai.tech/careers ====================================================================== Careers. We spent a decade building a floor nobody could see. That tells you most of what you need to know about working here. The work Payment rails are a weekend. Proof is not. Most of what we do is unglamorous, correct, and only obviously valuable in hindsight — cryptographic plumbing, measurement, the parts of a protocol that have to be right the first time because they cannot be retrofitted. If you want to ship something visible every fortnight, this will frustrate you. If you have ever been the person arguing that the boring layer needs to exist first, you already know what this is. What we look for Three things, and they are all the same thing. You say what you do not know Our own site publishes where we are behind and what is not shipped. That is not a marketing posture, it is how the people here already work, and someone who overstates internally will overstate externally. You build things that verify without you The test we apply to the product applies to the work: if you disappeared, would anyone be able to check that it was right? Good work here leaves evidence behind, not reassurance. You are comfortable being early This is a bet that machine commerce needs a real trust layer before anyone is loudly demanding one. Being right early feels identical to being wrong, for quite a while. What we do not look for Heroics, unsustainable hours, or anyone who treats an incident as a reputational problem rather than an engineering one. Open roles [CONFIRM: current openings, with a real salary range on each. If there are none, say so here plainly and leave the speculative route below open — an empty roles list is more honest than an evergreen listing nobody is hiring against.] Nothing fits, and you still want in Write to us anyway, but make it specific. Not a CV and a cover letter — one paragraph on something in our design you think is wrong, or something adjacent you have built that had to be correct the first time. We read those. They are a better signal than an interview loop, and they take you ten minutes. Talk to us [CONFIRM: hiring process, how long each stage takes, whether take-home work is paid, and the legal entity and locations you can actually employ in.] ====================================================================== # Privacy URL: https://ioai.tech/privacy ====================================================================== IOAI / Privacy Privacy. What we collect, why, and the one thing on this network that cannot be deleted. Effective 22 September 2026 · IOAI Global, Washington, DC · hello@ioai.tech The short version If you read this website, we collect very little. If you write to us, we keep what you sent so we can reply. If you transact on the network, some of what you do is recorded permanently and publicly, and nobody — including us — can remove it. That last point is the one worth reading properly, and it is in section 4. 1. Who we are IOAI Global, of Washington, DC, is the controller of personal data described in this policy. Write to us at hello@ioai.tech about anything in it. 2. What we collect - Visiting this site. Our host records standard server logs: IP address, user agent, the page requested and the time. We use these for security and to understand traffic volume. We run no analytics product, set no cookies and embed no trackers. - Writing to us. Your name, email address, organisation if you give one, and the contents of your message. We use it to reply and to keep a record of the conversation. - Holding a licence or operating a node. Identity, billing and operational contact details, as required to administer the licence and meet our legal obligations. The agreement governing your licence describes this in full and takes precedence for licensed participants. - Calling the API. Request metadata, and the identity presented where one is required. Verification and identity-resolution endpoints require no credential, and we make no attempt to identify who is calling them. We do not buy personal data, we do not sell it, and we do not use it to train models. 3. Why we are allowed to hold it - To answer you. Where you contact us, we rely on our legitimate interest in responding, or on steps taken at your request before entering a contract. - To run the service. Where you hold a licence, we rely on performance of that contract. - To keep the network secure. We rely on our legitimate interest in preventing abuse, and on our legal obligations. 4. The part that is permanent Attestations, settlement records and anchored measurements are designed to be verifiable by anyone, indefinitely, without our involvement. That is the product working as intended, and it has a consequence we will not soften: once a record is anchored, we cannot delete it, amend it, or make it unverifiable. Neither can you. Anything placed in a job specification becomes part of a record that outlives your relationship with us. Do not put personal data, credentials, or anything you may later need erased into a specification. Treat a specification the way you would treat a public filing. Where data protection law gives you a right to erasure, that right cannot be exercised against an anchored record, and we will not pretend otherwise. We will erase what we hold off-chain, and we will tell you plainly which parts we cannot reach. If you need a design where nothing is permanent, this network is the wrong choice and we would rather say so before you build on it. 5. Who else sees it We use service providers to host this site, deliver our email and manage support correspondence. They process data on our instructions and are not permitted to use it for their own purposes. We will name our current providers on request — ask at hello@ioai.tech and you will get a list, not a description. Beyond those providers, we disclose personal data only where we are legally compelled. Where we are permitted to tell you that a disclosure was demanded, we will. 6. Where it goes We are based in the United States and our infrastructure is operated on globally distributed networks, so data you send us is processed in the United States and may be processed elsewhere. Where we transfer personal data out of the European Economic Area or the United Kingdom, we do so under the European Commission’s Standard Contractual Clauses and the UK Addendum. 7. How long we keep it Correspondence: as long as needed to deal with your enquiry and to keep a reasonable business record of it. Server logs: a short period for security and diagnostics. Licence and billing records: as long as the relationship lasts, and afterwards for as long as tax, accounting and limitation periods require. Anchored records: permanently, as section 4 describes. 8. Your rights Depending where you live, you may have the right to ask what we hold about you, to have it corrected, to have it deleted, to receive a copy in portable form, to object to or restrict how we use it, and not to be discriminated against for exercising any of those rights. Write to hello@ioai.tech. We will respond within thirty days, and sooner where the law requires it. We do not sell or share personal information as those terms are defined under California law, and we do not use it for cross-context behavioural advertising. If you are in the European Economic Area or the United Kingdom and you think we have handled your data badly, you may complain to your national supervisory authority. We would rather you told us first, but it is your call and you do not need our permission. 9. Cookies and fonts This site sets no cookies and loads no third-party trackers. It does load typefaces from Google Fonts, which means Google receives the IP address of visitors in order to serve those files. Nothing else about your visit is shared with them. 10. Children This is infrastructure for machine-to-machine commerce. It is not directed at children, and we do not knowingly collect personal data from anyone under sixteen. 11. Changes If we change this policy we will update the effective date above. Where a change materially affects how we handle data you have already given us, we will say so here rather than rely on you noticing a date. ====================================================================== # Terms URL: https://ioai.tech/terms ====================================================================== IOAI / Terms Terms. What using this website and this network does and does not entitle you to. Effective 22 September 2026 · IOAI Global, Washington, DC · hello@ioai.tech 1. Two different things These terms cover this website and the open endpoints published on it. Operating a node, holding an identity licence and transacting on the network are governed by separate written agreements. Where a licence agreement and these terms conflict, the licence agreement governs for licensed participants. 2. Using the site and the open endpoints - The verification and identity-resolution endpoints are open. You may call them without an account, including programmatically and including as an autonomous agent, subject to published rate limits and to these terms. - Do not use the site or the endpoints to break the law, to attack the network or its participants, to interfere with anyone else’s use, or to misrepresent what a result means. - Automated access is permitted. Our robots.txt is the authoritative statement of what crawlers may do. - We may rate-limit, suspend or block access that threatens the service or other users. Where we can tell you why, we will. 3. What an attestation means, and what it does not An attestation evidences that a computation ran as specified. It is not a warranty of quality, accuracy, fitness for any purpose, or acceptability to a buyer. Nothing on this site or in our documentation should be read as IOAI certifying the usefulness or correctness of work performed by any participant. IOAI is not a party to transactions between participants. We do not adjudicate them, and we provide no dispute resolution, arbitration, escrow or refund mechanism. If you need those, agree them with your counterparty before you transact. 4. Settlement is final Payments that settle against an attestation are not reversible by IOAI. The protocol contains no buyer-acceptance step, no chargeback and no refund path. Build for that before your first transaction, not after it. 5. Licences are not investments An identity or node licence is an operating licence. It is not offered as, and must not be understood as, a security, an investment contract, or a promise of any return. IOAI publishes no yield, projected return or payback figure, and nothing on this site should be relied on as financial, investment, tax or legal advice. 6. Intellectual property The content of this website is ours or our licensors’. You may quote it with attribution, and you may reproduce our published boilerplate verbatim. Our machine-readable descriptors — llms.txt, the agent card, the MCP descriptor and the OpenAPI document — exist to be fetched, parsed, cached and relied on by anyone, human or otherwise. Our name and marks remain ours. 7. Availability The site and the open endpoints are provided as-is and as-available. We do not guarantee uptime for them, and we may change or withdraw them. Service commitments for licensed participants, where they exist, live in the licence agreement rather than here. 8. Disclaimer and limitation of liability To the fullest extent permitted by law, the site and open endpoints are provided without warranties of any kind, express or implied, including any implied warranties of merchantability, fitness for a particular purpose and non-infringement. To the fullest extent permitted by law, IOAI is not liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, revenue, data or business, arising from your use of the site or the open endpoints. Our total aggregate liability arising from them is limited to one hundred United States dollars. Nothing in these terms excludes liability that cannot lawfully be excluded, including for fraud or for death or personal injury caused by negligence. Some jurisdictions do not allow certain exclusions, so parts of this section may not apply to you. 9. Indemnity You agree to indemnify IOAI against claims, losses and reasonable legal costs arising from your misuse of the site or the open endpoints, or from your breach of these terms or of applicable law. 10. Changes We may update these terms. The effective date above will change, and where a change is material we will say so on this page rather than rely on you noticing. Continuing to use the site after a change means you accept it. 11. Governing law These terms are governed by the laws of the District of Columbia, United States, without regard to its conflict-of-laws rules. The courts of the District of Columbia have exclusive jurisdiction, except where mandatory consumer-protection law in your country of residence gives you the right to bring proceedings locally. 12. Contact IOAI Global, Washington, DC. hello@ioai.tech. ====================================================================== # Security URL: https://ioai.tech/security ====================================================================== IOAI / Security Security. How to report something, what we promise in return, and the reason you do not have to take our word for any of it. Report a vulnerability Email hello@ioai.tech. The machine-readable version of this page is at /.well-known/security.txt. Tell us what you found, how to reproduce it, and what you think the impact is. You do not need a polished write-up and you do not need to prove exploitability — we would rather hear a vague concern early than a perfect report late. What we commit to - We acknowledge within [CONFIRM: e.g. 2 business days] and tell you whether we think it is a real issue within [CONFIRM: e.g. 10 business days]. - We keep you informed until it is closed, including when the honest answer is that a fix is slow. - We credit you if you want credit, and stay quiet if you do not. - We publish. Material issues get written up on our status page whether or not anyone outside noticed. A security page that only describes hypothetical process is worth nothing. Safe harbour If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we will say so to anyone who asks. Good faith means: you stay within the scope below, you do not access, modify or retain anyone else’s data, you do not degrade the service for others, and you give us reasonable time before disclosing publicly. [CONFIRM with counsel: the exact safe-harbour wording, and whether it binds across the jurisdictions IOAI operates in.] Scope - In scope. This website, the open verification and identity endpoints, the published descriptors, and the settlement and attestation logic. [CONFIRM: exact domains and endpoints.] - Out of scope. Findings that require physical access, social engineering of staff, denial of service, or third-party services we do not run. Reports generated by a scanner with no analysis attached. - Especially welcome. Anything that lets an attestation verify when it should not, that makes two distinct-looking parties provably the same or vice versa, or that breaks the independence of an anchored record. Those are the failures that matter most here, because the entire product is the claim that they cannot happen. Bounties [CONFIRM: whether a paid bounty programme exists. If it does not, say so plainly here rather than leaving researchers to guess — an ambiguous bounty policy gets you fewer reports, not cheaper ones.] The structural answer You are not required to trust our security posture. Everything above describes how we behave. It is a promise, and promises are exactly what this infrastructure exists to stop mattering. Attestations verify independently, with no account and no permission from us. Anchored records carry inclusion proofs anyone can check. If we were compromised tomorrow, an attacker could damage the service — they could not retroactively make a false proof verify, and they could not quietly rewrite what the network already recorded. That property is worth more than any policy statement on this page, and it is the one we would want you to test first. Verify a proof yourself ->