IIC TSA

IIC TSA terms of use

Terms of use of the time-stamping service at tsa.internetidentitycard.com
Last updated: 10 October 2026

1. The service and the provider

These terms govern the use of the IIC TSA time-stamping service (the "Service"), reachable at https://tsa.internetidentitycard.com/tsa and described on the IIC TSA page. The Service is provided by HTTPS CARD — INTERNET IDENTITY CARD LIMITED, a company registered in England and Wales under number 09168431, registered office 124 City Road, London EC1V 2NX, United Kingdom ("we", "us", "the operator").

The Service is operated under the IIC TSA Timestamp Policy v1.0 (policy OID 1.3.6.1.4.1.67100.1.1.1.1) and the IIC TSA Practice Statement v1.0, both published on the IIC TSA page. In case of conflict on a technical point, the Timestamp Policy prevails; on a legal point, these terms prevail.

2. Acceptance

By sending a request to the Service, or by relying on a token it issued, you accept these terms. If you do not accept them, do not use the Service. Use on behalf of an organisation binds that organisation.

3. Nature of the Service

The Service is designed to RFC 3161, as updated by RFC 5816. It is not a qualified trust service under Regulation (EU) No 910/2014 (eIDAS) or under UK eIDAS, it has not been audited against ETSI EN 319 421 or any other standard, it is not listed in any trust list, and neither the Service nor its signing key is certified, accredited or FIPS-validated. The signing key is protected by Google Cloud KMS at the SOFTWARE protection level, not by a hardware security module. The Service has a single operator and no separation of duties.

A token issued by the Service proves that the Service signed a given hash value at the time stated in the token, with a declared accuracy of one second. It proves nothing about the document from which the hash was computed, its author, its content, its accuracy or its lawfulness. It is not a signature of the document.

4. Free of charge, no commitment of availability

The Service is provided free of charge, as is and as available. We give no commitment on availability, response time or continuity. The Service refuses to issue a token whenever its time sources disagree, whenever its key is unavailable, during key rotations and during incidents; such refusals are a design feature, not a defect.

We may modify, suspend or terminate the Service, in whole or in part, at any time. Where practicable, a notice is published in advance on the status page ↗ and on the IIC TSA page. Termination does not invalidate tokens issued before it; the root certificate, the TSA certificates and the archived CRLs remain published so that existing tokens can still be verified.

5. Permitted use and limits

We may block, without notice, any client address or pattern of requests that breaches these limits.

6. Your responsibilities as a relying party

Verification is your responsibility. Before relying on a token, verify its signature, verify that the signing certificate chains to the published root (compare its SHA-256 fingerprint with the one published on the IIC TSA page), that it carries the time-stamping extended key usage and was valid and not revoked at the token's time, that the policy OID is the production policy and not a test policy, and that the message imprint matches your data. Keep each token with the certificate chain and a CRL issued after the token's time; before the algorithms of a token weaken, protect it with a fresh time-stamp as long-term validation formats do.

A failure to retrieve the current CRL does not make a token valid or invalid: it makes the result undetermined.

7. Related party: VerifBox

VerifBox (verifbox.com ↗), a file time-stamping website, is operated by the same company and has been a client of the Service since 10 October 2026. For VerifBox users, the Service is not an independent third party. Where independent evidence is needed, it must come from a source that does not depend on this company (for example a third-party time-stamp authority, or an anchor in the Bitcoin blockchain through OpenTimestamps, which VerifBox adds to each proof). VerifBox has its own terms and privacy information, published on its site.

8. Privacy

The Service receives the hash of your data and, if you send one, a nonce; it never receives your document. It keeps an issuance log for 12 years containing the serial number, time, key generation, clock state and signature digest of each token, but not the hash submitted, the nonce, the request body or your IP address. Your IP address is held in memory for at most one minute, solely for rate limiting, and is not written to any log we keep. Details are in the privacy policy, section on the IIC TSA service. The data controller is the operator (ICO registration ZA457585).

9. Intellectual property

The name IIC TSA, the Internet Identity Card trademark (UK00003166480), the website and the documentation remain our property or that of our licensors. The Timestamp Policy and the Practice Statement may be copied and redistributed unchanged, with their source stated. Tokens issued to you are yours to keep, share and present as evidence.

10. No warranty

To the fullest extent permitted by law, the Service is provided without any warranty, express or implied, including warranties of availability, accuracy beyond the declared accuracy, fitness for a particular purpose, legal effect or admissibility of a token as evidence in any jurisdiction. The evidential value of a token is assessed by the competent court or authority.

11. Limitation of liability

Because the Service is free of charge and relied upon at your own risk, we shall not be liable, in contract, tort (including negligence), breach of statutory duty or otherwise, for any loss of profit, loss of business, loss of data, loss of evidence, or any indirect or consequential loss arising from the use of, reliance on, or inability to use the Service or a token. Our total liability for all claims relating to the Service in any twelve-month period shall not exceed one hundred pounds sterling (£100).

Nothing in these terms excludes or limits liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any liability that cannot be excluded or limited by law. If you are a consumer, nothing in these terms affects your statutory rights, including, where you are resident in the European Union, the mandatory provisions of the law of your country of residence.

12. Changes to these terms

We may update these terms. The date at the top of this page states the current version; continued use of the Service after a change constitutes acceptance of the revised terms. A change to the Timestamp Policy produces a new policy version with a new OID, and tokens always name the policy under which they were issued.

13. Governing law and jurisdiction

These terms and any dispute arising from the Service are governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, except that if you are a consumer resident in the European Union you may also bring proceedings in the courts of your country of residence and benefit from its mandatory consumer protection rules.

If any provision of these terms is found invalid or unenforceable, the remaining provisions remain in force.

14. Contact

HTTPS CARD — INTERNET IDENTITY CARD LIMITED
124 City Road
London EC1V 2NX
United Kingdom

Email: contact@internetidentitycard.com · Security reports: security@internetidentitycard.com