← Public Policy Library

Public procedures

Certification Mark and Badge Usage Policy

Controls who may display Clause5afe certification marks, what the mark may represent, and what happens when status expires, is suspended, is withdrawn, or is revoked.

Controlling public principle

The rule an outsider should be able to rely on

A Clause5afe certification mark may represent only the certified AI system, version, scope, organization, and active status shown by the authoritative Registry record.

License

Limited, revocable, and scope-specific

The mark and badge remain Clause5afe intellectual property. A certified organization receives a non-exclusive, non-transferable, revocable license for the certified system and only while the applicable certification remains active.

Permitted use

Every claim must resolve to the certified scope

Website use should employ the Registry-linked digital badge. Interface, proposal, press, and marketing use must identify the certified system, include the certification reference, and state the scope accurately.

  • A system-level certification may not be presented as certification of the entire organization.
  • Regulatory and framework references must describe mapping or alignment accurately and must not imply external accreditation or regulatory approval.
  • The certification is not a warranty, endorsement, guarantee of safety, guarantee of performance, or blanket guarantee of compliance.

Prohibited use

No scope expansion, redesign, transfer, or stale claim

The mark may not be used for an uncertified system, altered into another logo, transferred to another entity, displayed outside the certified scope, or used after the relevant license ends. It may not imply that Clause5afe endorses the organization's products or commercial activity.

Status controls

Display rights follow the live Registry record

A current Registry status may permit controlled display with the exact designation shown in the public record. Display permission ends when suspension, withdrawal, revocation, expiration, or another terminating status action takes effect.

The Registry must reflect the effective status without waiting for administrative badge cleanup. Source-policy removal deadlines are maximum cleanup windows and do not extend certification status or authorize continued distribution of a stale mark.

Verification

A copied badge is not proof

The Registry is the authoritative source for current status. The digital badge and future QR-enabled certificate experience must resolve to the current public record, including scope, validity, limitations, and status history where publishable.

Enforcement

Misuse receives a controlled response

The source policy uses graduated enforcement for correctable misuse and accelerated action for egregious or unauthorized use. Available actions include corrective notice, formal warning, mark-license suspension, certification-impact review, and legal protection of Clause5afe intellectual property.

Authority boundary

What this policy does not authorize

The mark communicates a controlled certification claim. It cannot enlarge scope, freeze an outdated status, replace the Registry record, or create an endorsement that Clause5afe did not issue.

Controlled information

What remains outside the public layer

  • Internal investigation strategy
  • Privileged enforcement advice
  • Security controls for badge issuance and signing keys

Connected governance

Follow the policy into the institution.