Terms of Service
The agreement governing your use of the PasskeyBridge platform, APIs, and dashboard.
1. Acceptance of Terms
By accessing or using the PasskeyBridge™ platform, APIs, dashboard, documentation, or any related services (collectively, the "Service") provided by PasskeyBridge LLC, a Wyoming limited liability company, you agree to be bound by these Terms of Service.
2. Service Description
PasskeyBridge™ is an Identity Threat Response as a Service (ITRaaS) platform that provides:
- Real-time identity threat signal ingestion and orchestration.
- Configurable playbooks for automated threat response actions.
- Pillar II (Legal Identity) verification via self-hosted W3C Verifiable Credential engine with OpenID4VP presentation exchange, batch VP Token verification (up to 20 tokens per request), and W3C StatusList2021 credential status management with ETag-based conditional caching.
- Pillar III (Biometric Binding) orchestration via WebAuthn/Passkey credential management.
- VC Wallet SDK (PBWallet) for client-side credential storage, presentation, and lifecycle management.
- Agent Delegate provisioning for scoped, time-limited autonomous agent access.
- Shadow Proxy identities (disposable email and phone proxies forwarded through encrypted relays).
- BLAST Protocol encrypted tunnels for zero-knowledge signal resolution.
- Atomic Fingerprint capture and Spatial Binding for device-level EMI, thermal, and accelerometer attestation.
- SCIM v2 user and group provisioning for enterprise directory synchronization.
- Okta event hook integration for real-time identity lifecycle event consumption.
- Okta Identity Security Posture Management (ISPM)—automated auditing of Okta IdP configurations with 25 weighted security checks, phishing-resistant MFA enforcement validation, admin sprawl detection, and composite 0-100 Posture Score generation (Enterprise plan).
- Microsoft Entra ID Identity Security Posture Management (ISPM)—automated auditing of Entra ID (Azure AD) tenant configurations with 25 weighted security checks covering Conditional Access policy validation, Privileged Identity Management (PIM) hygiene, credential lifecycle auditing, and composite 0-100 Posture Score generation. Authenticates via OAuth 2.0 client credentials against the Microsoft Graph API (Enterprise plan).
- Google Workspace Identity Security Posture Management (ISPM)—automated auditing of Google Workspace configurations with 25 weighted security checks covering 2-Step Verification enforcement, super admin sprawl detection, OAuth app grant activity, mobile device management, stale account detection, and composite 0-100 Posture Score generation. Authenticates via service account JWT with domain-wide delegation against the Google Admin SDK Directory and Reports APIs (Enterprise plan).
- AWS IAM Identity Center Identity Security Posture Management (ISPM)—automated auditing of AWS IAM Identity Center (formerly AWS SSO) configurations with 25 weighted security checks covering MFA enforcement, permission set least-privilege analysis, account assignment hygiene, lifecycle provisioning, and composite 0-100 Posture Score generation. Authenticates via AWS Signature Version 4 against the SSO Admin, Identity Store, and IAM APIs (Enterprise plan).
- PingOne Identity Security Posture Management (ISPM)—automated auditing of PingOne (by Ping Identity) environment configurations with 25 weighted security checks covering MFA policy enforcement, population and role management, application and sign-on policy hygiene, lifecycle provisioning, and composite 0-100 Posture Score generation. Authenticates via OAuth 2.0 client credentials against the PingOne Management API (Enterprise plan).
- CyberArk Identity Security Posture Management (ISPM)—automated auditing of CyberArk Identity tenant configurations with 25 weighted security checks covering MFA profile enforcement, administrative privilege management, application SSO hygiene, lifecycle provisioning, PAM-adjacent posture checks (session recording, PSM policies), and composite 0-100 Posture Score generation. Authenticates via OAuth 2.0 client credentials against the CyberArk Identity Platform API (Enterprise plan).
- OneLogin Identity Security Posture Management (ISPM)—automated auditing of OneLogin (by One Identity) tenant configurations with 25 weighted security checks covering MFA policy enforcement, role and privilege management, application policy hygiene, directory sync lifecycle, and composite 0-100 Posture Score generation. Authenticates via OAuth 2.0 client credentials against the OneLogin Admin API v2 (Enterprise plan).
- AI Intelligence Layer providing asynchronous risk analysis with explainable outputs, behavioral clustering, and Human-in-the-Loop review workflows (Enterprise plan).
- Observability: structured metrics (JSON and Prometheus exposition), anomaly detection, and alerting pipelines (Slack, PagerDuty, webhooks) with cooldown enforcement (Enterprise plan).
- A2A Horizontal Trust Negotiation for autonomous inter-agent scoped transaction limiting (Patent 19/561,964).
- Hybrid Post-Quantum Cryptography (PQC) signatures aligned with NIST FIPS 204 (Enterprise plan).
- Quantum Random Number Generator (QRNG) seeded entropy for cryptographic key material (Enterprise plan).
- SSF/CAEP (OpenID Shared Signals Framework 1.0 + Continuous Access Evaluation Profile 1.0, both final August 29, 2025)—real-time cross-IdP session revocation, credential-change propagation, and device-compliance event ingestion via Security Event Tokens (RFC 8417). PasskeyBridge operates as both Transmitter and Receiver; inbound CAEP events dispatch directly into the in-process revocation cascade on the same request, with 24-hour
jtiidempotency caching. Stream URLs are discovered via/.well-known/ssf-configuration. Zero-PII subject hashing and AES-256-GCM SET forensic retention apply throughout (Enterprise plan). - DPoP (Demonstrating Proof of Possession, RFC 9449)—sender-constrained OAuth token binding via client-held asymmetric key pairs with JWK Thumbprint (RFC 7638) identification, seven supported algorithms (ES256, ES384, ES512, PS256, PS384, PS512, EdDSA), server nonce issuance (§8), one-time-use proof consumption, and an opt-in shadow-telemetry mode that captures DPoP coverage metrics through the
api-key-authchokepoint without rejecting unbound traffic, surfacing ashadow_degradedtier with 15-minute re-attestation cadence (Enterprise plan). - Bulk PII Migration tooling for encrypting legacy plaintext columns and permanently shredding plaintext after manual confirmation.
- Purpose-Bound PII Vault (PBPBV) with dual-path cryptographic storage (AES-256-GCM ciphertext + independent SHA-256 hashes), auditable purpose-coded decryption gates, and tenant-isolated Bring-Your-Own-Key management enabling cryptographic erasure via key deletion.
- Topological Virtual Authenticator (PBANCHOR)—browser-resident Manifest V3 extension implementing a virtual FIDO2 authenticator via topological braiding operations with Kinematic-Temporal Gate validation against LEO satellite Doppler telemetry.
- Supply Chain Provenance Guard—build artifact attestation with SLSA Level 1-3 verification, Sigstore Rekor transparency log integration, SBOM signing (CycloneDX/SPDX), and optional hybrid PQC provenance signatures (Enterprise plan).
- Client-Side SDK Integrity Attestation (RASP-lite)—runtime six-check self-verification pipeline detecting code tampering, DOM injection, AiTM/EvilGinx2 proxy signatures, and debugger attachment with threat classification and replay protection (Enterprise plan).
- Breakglass Emergency Access Protocol—multi-party approval workflow for emergency access bypass with severity-based approval thresholds, time-bounded sessions, five access scopes, self-approval prevention, and immutable audit trail. No breakglass session records are ever deleted (Enterprise plan).
- Cross-Tenant Threat Sharing—privacy-preserving collaborative threat intelligence via anonymized IOC exchange with k-anonymity thresholds (k ≥ 3), opt-in subscription model, and atomic contributor count tracking. All indicators are pre-hashed SHA-256 values—zero plaintext (Enterprise plan).
- Insider Threat Behavioral Analytics—27-category anomaly detection engine covering human administrator behavior (off-hours access, privilege escalation, data exfiltration, credential hoarding) and autonomous agent threats (scope creep, lateral movement, trust gaming, delegation chain abuse, exfiltration tunneling). Behavioral baselines, configurable thresholds, and investigation workflows (Enterprise plan).
- Asynchronous webhook delivery via queue-based architecture with SSRF validation, exponential backoff retries, and full delivery logging (all plans).
- Global health check endpoint for synthetic monitoring—validates database connectivity, encryption key availability, and billing integration status (all plans).
- Public component-level status page (/status) backed by sampled snapshots of nine independently checked components (carrier APIs, DPoP, SSF/CAEP relay, NTP, ingest, cascade, VC engine, A2A, observability) with a 30-day retention window (all plans).
- Per-tenant request quotas enforced at the edge with predictable per-tier ceilings (Starter, Growth, Enterprise, Dedicated) and an outbound egress allowlist via the
safeFetchhelper that blocks SSRF and unauthorized data-exfiltration paths from edge functions (all plans). - Platform-wide infrastructure anomaly scanner monitoring traffic, error-rate, latency, egress, cascade depth, and tenant-concentration anomalies; honeypot canary endpoint mesh recording probe attempts and dispatching SSRF-guarded alerts (all plans).
- P-256 ECDSA tenant signing keys (ES256) with 24-hour rotation grace periods preserving in-flight VC verification continuity, and asynchronous webhook delivery already covered above (all plans).
- Usage analytics, API key management, and administrative dashboard access.
3. Account Registration
You must provide accurate and complete information when creating an account. You are responsible for maintaining the confidentiality of your credentials, API keys, and callback signing secrets.
4. Acceptable Use
You agree not to:
- Use the Service for any unlawful purpose.
- Attempt to reverse-engineer, decompile, or extract source code from the Service.
- Transmit malicious code or denial-of-service attacks.
- Submit PII directly to the signal ingestion endpoint.
5. Data Processing and Zero-PII Architecture
Phone numbers and other low-entropy identifiers are hashed with keyed HMAC-SHA-256 under a server-held pepper before storage; raw values are never persisted. Identifiers supplied to the API already pre-hashed by you carry the guarantee of how you computed them. You remain the data controller for any data processed through the Service. We act as a data processor under GDPR and PIPEDA. AI Intelligence Layer analysis receives only hashed, anonymized signal metadata—no plaintext PII is ever transmitted to AI providers.
If you use the hosted passkey relying-party service, we process your end users' WebAuthn credential public keys, credential identifiers and related authenticator metadata, and a keyed digest of each user handle, as described in Privacy Policy section 5, on your documented instructions. You can delete a credential or a user at any time through the API, and we delete the remainder within 30 days of termination. If you request a carrier lookup on a phone-based signal, the phone number is sent to the carrier-data provider for that lookup and is not stored by us.
6. API Keys and Security
API keys are SHA-256 hashed before storage. The raw key value is displayed only once at generation time. Callback payloads are signed with HMAC-SHA256.
7. Subscription Plans and Billing
The Service is offered under tiered subscription plans (Starter, Pro, Enterprise) and seat-based licensing for Pillar II and Pillar III capabilities. All fees are non-refundable except as required by applicable law.
The Starter plan is free and is limited to one organization per account owner. A second organization under the same owner requires a paid plan for that organization; the limit is enforced when an organization is created.
8. Service Level
We target 99.9% uptime for the signal ingestion endpoint and dashboard. Scheduled maintenance windows will be communicated with 48 hours' notice.
9. Intellectual Property
The Service is the intellectual property of PasskeyBridge LLC. The PasskeyBridge™ identity orchestration methodology is the subject of sixteen (16) patent filings, anchored by U.S. Patent Application 19/553,357.
10. Data Processing Addendum (GDPR)
This section constitutes the Data Processing Addendum ("DPA") as required by GDPR Articles 28 and 29:
- Processing scope: We process personal data solely on your documented instructions and for the purpose of providing the Service.
- Confidentiality: All personnel with access to personal data are bound by confidentiality obligations.
- Security measures: TLS 1.3, AES-256-GCM encryption at rest (including vault-keyed encryption of SOC 2 evidence-request contact details), keyed HMAC-SHA-256 identifier hashing (server-held pepper) with plain SHA-256 for high-entropy secrets and content digests, RLS tenant isolation, column-level access controls, append-only audit logging, hybrid PQC signatures (ML-DSA-65, NIST FIPS 204), QRNG-seeded entropy, and BLAST Protocol encrypted tunnels (X25519 ECDH + AES-256-GCM) for Enterprise tenants.
- Sub-processors: Current sub-processors are listed in our Privacy Policy §10. We provide 30 days' notice before engaging new sub-processors.
- Data subject rights: We will assist you in fulfilling data subject access, rectification, erasure, and portability requests within 30 days.
- Data deletion: Upon termination, we delete all personal data within 30 days unless retention is required by law.
- International transfers: Transfers outside the EEA are governed by Standard Contractual Clauses (SCCs).
- Breach notification: We will notify you of a personal data breach without undue delay and within 72 hours of becoming aware.
- Audit rights: You may audit our processing activities upon reasonable written notice.
11. PIPEDA Compliance (Canada)
For users subject to Canada's Personal Information Protection and Electronic Documents Act:
- Accountability: PasskeyBridge LLC is responsible for personal information under our control. Our Data Protection Officer (dpo@passkeybridge.io) is accountable for compliance.
- Purpose limitation: Personal information is collected only for identified purposes: authentication, billing, and service provision.
- Consent: We obtain meaningful consent for collection of personal information. Consent can be withdrawn at any time by contacting dpo@passkeybridge.io.
- Limiting collection: Our zero-PII architecture ensures we collect only information necessary for the identified purposes.
- Safeguards: We protect personal information with security measures proportional to its sensitivity (see Privacy Policy §11).
- Openness: This Terms of Service and our Privacy Policy constitute our public documentation of privacy practices.
- Individual access: You may request access to your personal information by contacting dpo@passkeybridge.io. We respond within 30 days.
- Challenging compliance: You may challenge our compliance by contacting dpo@passkeybridge.io or filing a complaint with the Office of the Privacy Commissioner of Canada.
12. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, PASSKEYBRIDGE LLC SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES.
13. Indemnification
You agree to indemnify and hold harmless PasskeyBridge LLC from any claims arising from your use of the Service, including any failure to comply with data protection laws applicable to your use of orchestrated signal data.
14. Termination
Either party may terminate these Terms with 30 days' written notice. Upon termination, we will delete your data within 30 days unless retention is required by applicable law. You may export your data before termination via the API.
15. Governing Law and Dispute Resolution
These Terms are governed by the laws of the State of Wyoming, United States. Disputes will be resolved through binding arbitration under the rules of the American Arbitration Association, except where prohibited by applicable consumer protection law (including GDPR or PIPEDA).
16. Contact
PasskeyBridge LLC
5830 E 2nd St., Ste 7000 #33652, Casper, WY 82609
support@passkeybridge.io (General)
dpo@passkeybridge.io (Data Protection)
passkeybridge.io