VeritasChain Certified (VC-Certified)

Frequently Asked Questions (FAQ)

Encoding Trust in the Algorithmic Age

This FAQ section addresses key technical, legal, and ethical questions about the VC-Certified certification program governed by VeritasChain Standards Organization (VSO).

Purpose: To proactively address common questions and enhance trust by clarifying what VC-Certified does—and doesn't—guarantee.

Scope 1. Certification Scope & Limitations

A. No, this certification does NOT guarantee financial health or solvency.

VC-Certified certifies only that a system technically complies with the VeritasChain Protocol (VCP) specification.

Specifically, the CAB assessment verifies that the following are mathematically and cryptographically correct:

  • Trading data is tamper-evident (append-only)
  • Algorithm decision-making processes are recorded
  • Time synchronization and numerical precision meet specified Tier requirements

Important: VSO does NOT guarantee or endorse any company's:

  • • Solvency or ability to meet financial obligations
  • • Business continuity or long-term viability
  • • Investment product profitability or returns

A. No, VSO maintains a strict "Non-Endorsement Policy."

VSO is a neutral standards organization. Issuing a certification badge indicates only that a system meets transparency standards—it is NOT an endorsement of that company's products or services.

VSO maintains a vendor-neutral stance and aims to improve the health of the entire market ecosystem.

A. No. We have no affiliation, relationship, or connection of any kind with such entities.

VeritasChain Standards Organization (VSO) and VeritasChain Co., Ltd. are Japanese organizations dedicated to open technical standards for auditable AI and algorithmic systems, including the VeritasChain Protocol (VCP), an open technical standard for cryptographic auditability in algorithmic trading.

Important Distinction:

Some investor warning lists published by financial regulatory authorities include entities that operate under similarly spelled or confusingly similar names. Those entities are entirely separate from VSO and the VeritasChain standards initiative.

What VSO Does NOT Do:

  • • Financial products
  • • Investment services
  • • Brokerage activities
  • • Fund management

VSO's work is limited to standardization, technical specifications, and research; its operating company, VeritasChain Co., Ltd., additionally provides technical services, including conformity assessment under the VC-Certified scheme.

Privacy 2. Data Privacy & Security

A. It should not, if the system is implemented as specified — but that depends on the implementation, not on the certificate.

VCP's design philosophy balances "public truth (Veritas)" with "privacy protection."

Hashing

The external anchor holds only a signed Merkle root (a fingerprint of the batch), not the events. The audit log itself contains the events, in which the account identifier must be pseudonymized.

Crypto-shredding

Personal Identifiable Information (PII) is encrypted with unique per-user keys. For an erasure request under GDPR Article 17, destroying the decryption key makes the encrypted data unreadable in practice. Whether that amounts to erasure under the GDPR is a legal assessment for the controller (VCP v1.2 RC1 §3.2.2).

Therefore, where personal data is pseudonymized or encrypted under VCP-PRIVACY, VSO and third parties without the keys cannot read customer names or addresses from audit logs.

A. Only "data necessary for verification" is made transparent.

In VCP-compliant systems, the signed Merkle Root of each batch of event hashes is committed to an external anchor (depending on the tier: a public blockchain, an RFC 3161 timestamp authority, an attested database or a public timestamping service).

This allows users to verify "whether my trades were tampered with" using Explorer tools.

Protected Information: The specific logic of algorithms (intellectual property) and detailed trading information of others are NOT exposed.

VCP provides "verifiable transparency" that sits between "black box (opaque)" and "glass house (fully exposed)."

Tiers 3. Certification Tiers & Technical Value

A. Yes, within stated limits: it provides batch-level tamper evidence once each daily batch is anchored.

While Silver Tier doesn't require atomic-clock precision (PTPv2), it makes "retroactive fraud detectable."

UUID v7 Ordering

All events are assigned time-ordered IDs.

Retroactive Tampering Detection

A Merkle root is externally anchored every 24 hours (public timestamping service or attested database).

Fraud Types Made Detectable:

  • • "Deleting unfavorable trades after the fact"
  • • "Inserting fake data with past timestamps"

These typical frauds become detectable once the affected batch has been anchored—even when committed by database administrators.

Silver Tier is a powerful tool to resolve trust disputes ("he said, she said") while keeping costs low.

A. No, "sidecar" deployment is possible.

VCP defines a sidecar integration pattern (see the Sidecar Integration Guide and the SDK specification) in which adapters run alongside existing FIX engines and trading servers (MT4/MT5, etc.) to generate audit logs without modifying the existing infrastructure.

For Retail Brokers & Prop Firms:

VSO publishes vcp-sidecar-guide (written for VCP v1.0, Silver tier), which describes an integration that minimizes impact on existing environments. Certification against v1.1 additionally requires external anchoring and Policy Identification.

A. Silver Tier is not positioned as a regulatory-grade artifact.

It is intentionally designed as the "minimum viable transparency layer" for retail and prop-style environments where server-side privileges are limited.

Silver Tier provides:

  • Cryptographically tamper-evident logs
  • Transparent dispute resolution
  • Reliable verification for traders and platforms

It does not aim to satisfy MiFID II RTS 25 or equivalent regulatory-grade evidentiary requirements.

Gold and Platinum Tiers are intended for formal regulatory evidence, targeting exchanges, institutional brokers, and supervised market infrastructures.

In short:

Silver = Transparency & Fairness
Gold/Platinum = Evidence intended for regulatory use

A. To support regulatory clock-synchronization requirements—although the VCP Platinum figure is stricter than the regulation.

The EU clock-synchronization rules (Commission Delegated Regulation (EU) 2025/1155, Articles 11–16 and Annex IV, which replaced MiFID II RTS 25 — Delegated Regulation (EU) 2017/574 — on 2 March 2026) limit divergence from UTC to 100 microseconds for high-frequency algorithmic trading activity; for trading venues the limit is 100 microseconds or 1 millisecond, depending on gateway-to-gateway latency. They do not prescribe a synchronization technology. The VCP tiers specify:

Platinum

PTPv2, accuracy under 1 µs (stricter than the EU limit)

Gold

NTP/Chrony, accuracy under 1 ms (timestamps stored with microsecond precision)

The Platinum figure is a VCP design choice that goes beyond the regulation.

To reduce integration cost, VSO publishes:

  • A sidecar integration pattern (non-invasive attachment to existing systems; see the Sidecar Integration Guide)
  • The SDK specification and a VCP Explorer demo (SDK packages and the Explorer API are not yet published)
  • Standardized implementation guidance (Sidecar Integration Guide, Conformance Test Guide)

The aim is to turn "implementation cost" into a shared, standardized, reusable cost across the industry.

Governance 4. Governance & Future-Proofing

A. This is expected. VCP (v1.1 published; v1.2 Release Candidate RC1) is currently in its Day-0 to Day-1 adoption phase.

Current status: zero external implementations of VCP, and zero Evidence Packs accepted in any proceeding. VeritasChain Co., Ltd. (the operating base of VSO) holds ten paid service contracts with European organizations in regulatory technology, financial trading, and audit and assurance (client names withheld pending individual consent). The initial rollout plan targets:

Three pilot integrations

(planned — no date set)

Public Case Study #1

Planned — no date set

"First Production Deployment" announcement

Planned for a follow-up release

Early-stage standards typically gain momentum after the first 1–3 public integrations. The current phase reflects timing, not a structural issue.

A. No design can promise that. VCP is crypto-agile: the algorithm is identified in every record, so algorithms can be replaced.

NIST published the ML-DSA signature standard (FIPS 204) in August 2024. VCP v1.2 RC1 lists the identifiers DILITHIUM2 (ML-DSA) and FALCON512 (FN-DSA) as EXPERIMENTAL; they are not a certification requirement.

Current algorithms:

  • • Ed25519
  • • ECDSA
  • • RSA_2048 (deprecated)

Experimental in v1.2 RC1:

  • • DILITHIUM2 (ML-DSA, FIPS 204)
  • • FALCON512 (FN-DSA)

Migration of deployed systems and of already-signed records is a separate task; VCP v1.2 RC1 gives non-normative guidance on hybrid (classical + post-quantum) signatures in Appendix E.

This makes VCP safer, not weaker.

A. VCP is crypto-agile; post-quantum signatures are experimental in v1.2 RC1 and migration is not automatic.

Currently, we default to the fast Ed25519 signature algorithm, but the specification defines a migration path to Post-Quantum Cryptography (PQC).

Future Migration Path

Appendix E of the specification gives non-normative guidance: during a transition period implementations may carry dual signatures, Ed25519 plus a post-quantum signature (ML-DSA, identifier DILITHIUM2). Records signed only with Ed25519 are not upgraded by a later change of algorithm.

A. VCP-GOV records are relevant evidence where the Act applies; algorithmic trading is not itself listed as high-risk (Annex III), and the high-risk rules apply from 2 December 2027.

The VCP-GOV extension module includes fields for storing:

  • AI algorithm decision factors
  • Risk classification
  • Human oversight records

Evidence Support:

This produces evidence relevant to high-risk AI system requirements for transparency and record-keeping.

A. No. VeritasChain Standards Organization (VSO) operates as a distributed standards organization and does not maintain a permanent physical headquarters.

VSO does not store, process, or centrally manage certified systems, audit data, or operational records.

Any administrative or liaison offices that may be used are not security boundaries and do not perform core certification, audit, or data-custodial functions.

For clarity: Trust in VC-Certified is derived from verifiable technical processes, not from physical office locations.

Process 5. Certification Process & Compliance

A. No. VC-Certified is optional and is not required to implement the VeritasChain Protocol (VCP).

Organizations may deploy VCP freely under the open standard license, with or without certification.

Certification provides third-party validation of technical compliance, but is not a prerequisite for using the protocol.

A. No. VC-Certified evaluates only technical compliance with VCP.

It does NOT replace:

  • Statutory financial audits
  • Licensing requirements
  • Regulatory examinations

VC-Certified focuses exclusively on technical protocol compliance, not business or regulatory status.

A. The certification process is designed to be completed within 2–6 weeks.

Timeline depends on:

  • Integration depth — complexity of existing systems
  • Log volume — amount of trading data to verify
  • Technical readiness — current compliance posture

A. VC-Certified does NOT evaluate the following:

Financial soundness
Trading strategy
Profitability
Risk appetite
Business performance
AML/KYC compliance
Customer funds handling

A. A VSO-accredited Conformity Assessment Body (CAB) may revoke certification under specific conditions.

Note: VSO does not issue or revoke certifications directly. VSO is the scheme owner and maintains governance authority over the certification program. Certification decisions are made by VSO-accredited CABs.

Revocation conditions include:

  • Logs are manipulated
  • VCP-required modules are removed
  • AI governance metadata is falsified
  • Audit proofs fail verification
  • Material violations of VSO non-endorsement policy occur

These strict standards ensure the integrity and credibility of the certification program.

Tiers 6. Tier-Specific Questions

A. Yes. Silver Tier is designed for retail/prop environments where best-effort synchronization is acceptable.

Silver Tier provides tamper-evident records with indicative (best-effort) timestamps without requiring enterprise-grade time synchronization infrastructure.

A. Not strictly, but Platinum Tier is recommended for microsecond/nanosecond trading environments.

Platinum Tier is ideal for systems using PTP v2, SBE, or FIX engines requiring ultra-low latency verification.

A. VC-Certified currently has no formal international recognition. VSO seeks engagement with regulatory, academic, and technical communities to promote interoperability.

VC-Certified is not a regulatory license but may support compliance documentation for organizations operating across jurisdictions.

A certification report may be offered to an authority as supporting technical material; the scheme has no formal recognition by any authority.

Need More Information?

VeritasChain Standards Organization (VSO) supports building trust infrastructure for the algorithmic age.