OceanAltOceanAlt

Website and Services Terms

Document version V0.4Legal set V0.4Effective 2026-09-12business@oceanalt.com

This is the bilingual V0.4 publication copy of the OceanAlt legal documents. OceanAlt is at an early stage and has not yet designated a single formal legal operating entity; these documents use a transitional operating arrangement and do not fabricate any legal-entity details.

Core reminder: no risk signal found ≠ safe. Pre-payment screening does not replace your own authorisation, transaction monitoring, legal judgement or necessary human review.

These Terms apply to the OceanAlt website, research and media content, AI Security Lab, KYA, RAP, Registry, ratings, address and endpoint screening, APIs, MCP, SDKs, bots, embeds and other OceanAlt services. Read them before accessing the site, creating an account, calling an API, connecting a wallet or making any on-chain payment. By using the Services — and, where required, by actively checking an acceptance box — you agree to these Terms.

1. OceanAlt and operating arrangements

“OceanAlt”, “we” or “the platform” means the operating team currently maintaining, operating and providing the OceanAlt website, products, APIs, research and related services, and any operating entity that may take over the relevant business in future.

OceanAlt is at an early stage and has not designated or disclosed a single formal legal operating entity. Until one is designated, these Terms use a transitional arrangement and do not fabricate a legal company name, place of registration, registration number or registered address.

General, business, legal and privacy contact: business@oceanalt.com.

If a formal operating entity is designated, or different Services are provided by different entities, OceanAlt will update these Terms and related documents, and the new entity details will apply from the effective date of that version. At this stage “we” refers only to the actual operating team and the Services it provides, and must not be read as a statement about any entity not yet disclosed or established.

2. Scope of the Services

OceanAlt provides, for agentic payments and the agent economy: pre-payment address risk screening; payment URL/endpoint risk screening; payment decisions and payee decisions; KYA attribution, authorisation and revocable credential tools; the Agent Control Baseline, gateway and research-grade firewall; the RAP framework, conformance tests and public ratings; the trusted service registry; the incident archive, coverage statement, status page and output contract; APIs, MCP, SDKs, Telegram/Discord bots and embeds; and news, weekly and monthly briefings, research and other public content.

These Services may be in public beta, research, demonstration or staged roll-out; the current status is shown on the relevant product page. Public content and free tools are open to general visitors. Accounts, APIs, wallet connections, real mainnet payments and Agent features are intended mainly for businesses, professionals and developers aged 18 or over.

3. What we do not provide

Unless separately agreed in writing, OceanAlt: is not a wallet; does not custody user assets; does not sign or broadcast on-chain transactions on a user's behalf; is not a bank, payment institution, broker or stablecoin issuer; is not a licensed KYC/AML/sanctions certification body; does not provide legal, tax, investment, audit or sanctions legal advice; and does not guarantee that any address, URL, Agent, merchant, protocol or transaction is “safe”.

OceanAlt's screening and decisions are for service admission and pre-payment support only.

4. Decision semantics

The payment-decision interfaces (/api/decide, MCP payment_decision) return allow, review or decline.

allow means that, for that request, at that time, on the data and rules then available to OceanAlt, no risk signal sufficient to trigger a refusal was found. allow does not mean the address or transaction is safe, that the address carries no legal risk, that full KYC/KYB/AML has been completed, that any particular country's sanctions law is satisfied, or that OceanAlt guarantees the outcome or any third party's performance.

review means there is uncertainty, insufficient information, insufficient coverage, or a need for additional verification. You should decide whether to proceed using your own mandate, policy, human review or other evidence.

decline means OceanAlt refuses that service request, or returns a machine-executable do-not-proceed result to a system integrated with OceanAlt. It is not a final legal determination by any government, court or regulator.

Other interfaces use their own vocabulary at their own layer, with the same logic: address/endpoint screening (/api/risk, /api/endpoint) returns clear, caution, risky or uncertain, where uncertain means the screening could not complete and is never equivalent to clear; the payment gateway (/api/pay) returns allow, blocked or held (human approval required); payee decisions (/api/payee/decide) return accept, decline, hold_request_info or not_ready; RAP conformance returns PASS, FAIL or UNCERTAIN; probe verification (/api/probe/verify) returns release, hold or abort. A “pass” at any layer is not a guarantee of safety, legality or compliance, and a “could not check / incomplete” at any layer must never be read as a pass.

Every verdict carries evaluated_at (when the decision was computed, RFC 3339) and evidence_as_of (the date through which the underlying lists were covered, date-granular). They differ in precision and are not substitutes for each other; you should judge freshness from both.

5. Accounts, Agents and credentials

You must submit only information, addresses, domains, Agent identifiers and credentials you are authorised to use; safeguard your account, password, API credentials, wallets and Agent authentication material; never submit seed phrases, private keys or full signing keys; never impersonate a third-party Agent, business, merchant or developer; and remain responsible for your Agent's mandate scope, payment limits, allowlists and actual behaviour.

OceanAlt will never ask for a wallet seed phrase, private key or full authentication key; any such request purporting to come from OceanAlt should be treated as high-risk. Report unauthorised use, credential compromise or security incidents to business@oceanalt.com immediately.

KYA is used only for attribution, proof and authorisation-related capabilities. It is not government identity verification, KYC certification, or OceanAlt's endorsement of an Agent's safety.

6. RAP, ratings, Registry and public records

OceanAlt's RAP, self-assessments, public ratings, trusted service registry, incident archive and similar materials may rely on public sources, self-disclosed material and OceanAlt's methodology; are affected by data timing, evidence completeness and method version; are not legal, investment or compliance advice; are not a “certification”, “official recognition” or safety guarantee for any party; and the parties concerned may request corrections, supply evidence or respond under the Submission, Registry and Public Rating Terms.

Commercial relationships do not change public rating methods or results.

7. Third-party services and data

OceanAlt may use or link to third parties: sanctions and government notices; on-chain data; stablecoin issuer freeze information; malicious-domain/phishing databases; RPCs, blockchains, wallets; facilitators; Discord, Telegram and MCP platforms; and other data and infrastructure. Third-party services may be interrupted, delayed, updated, withdrawn or erroneous. OceanAlt does not thereby acquire ownership of third-party data.

Use and redistribution of third-party data is governed by its original licence and rights notices; see the Data Sources, Attribution and Licensing Statement.

8. Intellectual property and use of output

OceanAlt's original site and product design, research, methodology, code, API output structure, own labels, rules and copy, and marks are protected by applicable intellectual-property law.

You may use OceanAlt output as permitted by the product page, the API Terms or a written agreement, but you must not: rebuild OceanAlt's or a third party's underlying risk database through bulk scraping; remove mandatory attribution or third-party rights notices; repackage OceanAlt screening results as an “official certification”; imply that OceanAlt endorses you or your product; or breach any upstream data-source licence.

Where a third-party licence grants you broader rights, that licence prevails; these Terms do not reduce rights lawfully granted by it.

9. Prohibited conduct

You must not use OceanAlt for: money laundering, terrorist financing or sanctions evasion; fraud, theft, extortion or malware; unauthorised wallet or Agent operations; impersonation or credential theft; circumventing limits, allowlists or risk controls; manipulating, poisoning or mass-probing the risk system; unauthorised dataset reconstruction; interference, DoS or API abuse; infringement of privacy, intellectual property or other rights; or any unlawful activity.

Good-faith security research is governed by the Security Research and Vulnerability Disclosure Policy. See the Acceptable Use Policy for the full rules.

10. Availability

The Services are provided “as is” and “as available”. Unless a formal written SLA exists, OceanAlt does not promise 99.9% or any fixed availability, error-free operation, uninterrupted service, real-time or complete data across all chains, or suitability for your specific regulatory scenario.

Live availability and latency are published on the OceanAlt status page and are not fixed in these Terms.

11. Suspension and termination

OceanAlt may restrict, refuse, suspend or terminate the Services for security risk, compliance risk, abuse, third-party requirements, legal requirements, resource or capacity limits, or breach of these Terms. OceanAlt may decline to explain internal rules whose disclosure could help circumvent security or risk controls.

12. Limitation of liability

To the extent permitted by law, OceanAlt is not liable for indirect, incidental, special, punitive or consequential loss arising from: mistaken payments by a user or Agent; misconfigured payment mandates; direct on-chain actions that bypass OceanAlt; third-party service or data errors; on-chain finality; contract, wallet or private-key attacks; market, stablecoin or liquidity changes; non-performance by third-party merchants; or reading “no risk signal found” as “safe”.

Liability that cannot lawfully be excluded is not limited. Direct liability, refunds and disputes for paid APIs are governed by the API and x402 Pay-per-Call Terms.

13. Governing law and disputes

During the transitional period in which OceanAlt has not designated a single formal legal operating entity, disputes are handled on a principled basis: the parties should first attempt good-faith negotiation, with a suggested 30-day negotiation period before formal proceedings; mandatory consumer rights are not excluded by these Terms; where applicable law gives a particular court, arbitral body or consumer-protection mechanism mandatory jurisdiction, that law prevails; and once a formal operating entity is designated, this section will be updated with the governing law, jurisdiction or arbitration arrangement.

At this stage these Terms do not designate any country, region, court or arbitral institution, and do not imply that an entity not yet in existence has chosen a jurisdiction.

14. Contact

General, legal, privacy, complaint and security matters: business@oceanalt.com.

Other documents: Legal centre →