01Why this policy exists
A false flag on a genuine bank statement does not inconvenience someone. It denies a real person credit — a medical bill unpaid, stock unbought, school fees late. Our output is powerful enough to do that at scale, quickly, to people who will never know why.
So there are conditions on using it. This policy forms part of the terms of service, and breaching it is one of the few things that gets an account suspended without a cure period.
02What Vepiom is for
Assessing the integrity of financial documents that a person has submitted to you, for your own credit, leasing, rental, insurance or onboarding decision, as an input to a process that includes human judgement.
That is the whole permitted purpose. The three emphasised parts each matter.
03What you must do
- Keep a human in the loop. No adverse action against an applicant on the basis of a Vepiom score alone. A person with authority to overrule the flag must review the evidence before a decline, cancellation, or reduction of terms.
- Give the applicant a way to answer. Anyone refused on document-integrity grounds must be able to respond. Provenance verification — asking them to forward the bank's original email — resolves most legitimate cases in minutes, without a branch visit.
- Tell applicants their documents are checked. Whatever notice or consent your law requires, before you send us anything.
- Set thresholds deliberately. Using a default cut-off you have never tuned against your own portfolio is how false positives get systematic.
- Watch your own outcomes for bias. Scanned and older-format documents correlate with lower-income and rural applicants. If your flag rate diverges by submission channel, issuing bank or region, treat it as a defect. Ask us and we will help you look.
- Investigate, do not accuse. A signal is evidence to examine, not a finding of fraud against a named person.
04What you must not do
With people
- Automatically reject, blacklist or report an applicant on a score alone, with no human review and no appeal.
- Use a fingerprint network match as grounds to refuse someone across institutions. A match means a document has been seen elsewhere. It says nothing about the person holding it.
- Build or contribute to a shared list of individuals denied credit, using our output.
- Publish, share or report an accusation of fraud against a named person on the strength of a Vepiom signal alone.
- Discriminate on any protected characteristic, or use our output as cover for doing so.
With documents
- Submit documents you have no lawful basis to process, or that were not given to you for the purpose you are using them for.
- Submit documents belonging to people who are not your applicants, customers or counterparties.
- Use the service for surveillance, investigation of private individuals, or any purpose unrelated to a decision you are making about someone who applied to you.
With the service
- Resell, sublicense or expose the API to third parties without a written reseller agreement.
- Reverse-engineer the detection engine, or probe it to develop or refine document manipulation techniques.
- Use the service to test whether a forgery you or anyone else produced would evade detection.
- Scrape, replicate or extract the issuer template library, reason-code logic or fingerprint data.
- Circumvent rate limits, quotas or metering.
05What we will not build, whoever asks
- We will not add an approve or decline field to the API.
- We will not expose the identity of an applicant or an institution behind a fingerprint match.
- We will not operate, host or supply data to a cross-lender blacklist of individuals.
- We will not sell document data or extracted financial data to anyone.
- We will not suppress a published false-positive rate because it moved the wrong way.
These are not negotiable at any contract value. A customer who needs one of them needs a different supplier, and we will say so plainly.
06How we enforce this
Where we have reason to believe this policy is being breached we will normally contact you first and try to resolve it, because most breaches are configuration mistakes rather than intent.
Where applicants are at risk of harm, we may suspend access immediately and without a cure period. Repeated or deliberate breach ends the agreement.
We do not monitor the substance of your credit decisions and we cannot see your review process. This policy works because it is contractual and because you have as much interest in not wrongly refusing good borrowers as we do.
07Reporting a concern
If you believe Vepiom output has been used to deny you credit unfairly, contact the lender first — they hold the decision and the evidence, and they are the only party who can revisit it. Asking them to accept a bank-forwarded original of your statement will settle most legitimate cases.
If you believe a customer of ours is breaching this policy, tell us at info@vepiom.com. We will look into it. We will not identify you to that customer without your agreement.