bedoBox.eSignVerification

Terms of Service

bedoBox.eSignVerification — electronic signature verification

Effective: 2026-08-14 · Provider: SPOCONT Ltd. · Contact: hello@spocont.com

1. What this covers

These terms govern the service at esign.spocont.com across all of its surfaces: the web interface, the REST API, the MCP server and the A2A endpoint. By using the service you accept them.

2. What we promise — and precisely what we do not

What we promise: we run the examination on the PDF you submit and report the result of that examination on the basis of the data available to us. That is the whole of it.

The service produces a technical finding. It is not legal advice, not certification, not attestation and not evidence. It does not replace a lawyer, a notary, or a qualified trust service provider.

2.1 Known limits of the examination

The service does not examine, and makes no statement about:

  • whether a certificate has been revoked — there is no CRL and no OCSP check;
  • whether the trust service provider was trusted at the time of signing; the examination uses the trusted list available at the moment of the request;
  • the cryptographic validity of any timestamp;
  • certificate chains passing through an intermediate CA;
  • the signatures on the trusted lists themselves;
  • the authenticity, lawfulness or meaning of the document's content.

Where a signature covers only part of a document we report that as a fact. It is not in itself evidence of tampering: incremental update is a normal feature of PDF.

2.2 Source and limits of the data

The examination relies on publicly published data from the European Union trusted lists (the LOTL and the member state lists). We refresh these regularly, but we are not responsible for their content, availability or currency — they are produced by third parties. The state of the data in use (anchor count, number of member state lists, publication time) is shown in the interface and can be queried at any time via esign_trusted_list, and it is your responsibility to judge whether it is current enough for your purpose.

3. Exclusion of liability

The service is provided "as is". We do not warrant that the result of an examination is correct, complete, error-free or fit for any particular purpose.

We expressly exclude liability for any loss arising from:

  • a result that was wrong, incomplete or open to misreading;
  • a valid signature reported as invalid, or an invalid signature reported as valid;
  • a qualification (QESig / AdESig / Unknown) that did not match reality or the view of an authority;
  • trusted list data that was incomplete, out of date or incorrect;
  • the service being suspended, slow or unavailable;
  • any decision, transaction or legal act you based on a result.

You acknowledge that evaluating and acting on a result is your own responsibility. Where the stakes warrant it, obtain an independent qualified verification.

Where liability cannot be excluded, it is limited to the fees you actually paid for the service in the twelve months preceding the claim. We are not liable for lost profit or for indirect or consequential loss.

Nothing here limits liability for intent, for death or personal injury, or for anything that mandatory law does not permit to be excluded.

4. Fees and credit

The service is credit-based. The current price and package size are shown in the interface; at present 99 EUR / 1,000 verifications.

  • One processed document consumes one credit, whatever the examination turns out to say. An invalid signature is a real answer.
  • A document that cannot be processed consumes nothing.
  • Purchased credit is usable for 90 days from purchase; unused credit expires and is not refundable.
  • Credit is consumed from the batch closest to expiry first.
  • An API key does not expire and is not withdrawn; it can run out, and a top-up restores the same key.

5. Data handling

We do not store submitted documents. Processing happens in memory, and once the answer has been returned the document is not retained in any form. Results returned to agents over A2A are likewise not placed in the task cache, because a result contains personal data — the signer's name and certificate details.

In the web interface your verification history is stored only by your own browser (localStorage) for 30 days. It never reaches a server.

For billing we log that a call happened: the user identifier, the API key identifier, the time, the credit consumed and the number of signatures found. We do not log document content, filenames or signer names.

6. Availability and changes

We give no availability guarantee. The service may be suspended at any time for maintenance, for a fault in a third-party dependency, or for any other reason.

We may change these terms. A change takes effect on publication, and the effective date appears at the top of this document. Credit already purchased is governed by the terms in force at the time of purchase.

7. Permitted use

You warrant that you are entitled to have the documents you submit examined. Use that breaks the law, infringes the rights of others, or interferes with the operation of the service is prohibited. We may restrict access without notice in case of abuse.

8. Governing law

These terms are governed by Hungarian law. The parties will seek to settle disputes by discussion; failing that, the Hungarian courts have jurisdiction. Where the user is a consumer, mandatory consumer protection rules are unaffected.

9. Contact

Questions, complaints, security reports: hello@spocont.com

© 2026 SPOCONT Ltd. All rights reserved. EU servers · GDPR compliant