Trust & Safety DMCA Designated Agent Registered

The infrastructure of legitimate licensing.

LicenseOS is built on a single invariant: a license token can never carry more authority than the rights the issuing party claims to hold. Today that claim is self-attested by the rights holder; independent ownership verification (eKYC, registry checks, perceptual-hash and famous-mark screening) is on our roadmap. This page explains what we enforce today, and what is coming.

LicenseOS provides operational compliance tooling, not legal advice.

All allow / warn / review / block decisions reflect the rights holder's own published policy applied to the parameters you provided. They are not independent legal judgments by LicenseOS, do not constitute legal advice, and do not create an attorney-client relationship. The machine-readable policy JSON is subordinate to the authoritative, attorney-reviewed legal text associated with each license. Engage qualified IP counsel before relying on any decision for high-stakes uses, before onboarding IP in any jurisdiction outside the United States, and before entering into licensing arrangements with real-person likenesses, famous marks, or large commercial volumes.

We tell you what the license permits, not what the law permits.

The Evidence Spine

Every decision LicenseOS issues is wrapped in a chain engineered for one thing: so that the record is independently checkable and we cannot forge our own evidence. The chain is honest about what each layer proves — and what it does not.

1 · Sign
Sole-control signature

Proves LicenseOS issued this exact record and it hasn’t been altered. Does not prove the use is lawful.

ES256 today (verifiable against the public key). KMS/HSM sole-control is the next upgrade.

2 · Timestamp
Trusted time

Records when the decision was made. Strongest when a third party attests the time, not us.

Self-attested server clock today, honestly labeled. An RFC-3161 qualified timestamp authority drops in next.

3 · Hash-chained log
Tamper-evident audit trail

Any edit or reorder of a past entry breaks every later hash, so tampering is detectable. Does not prove a use was permitted.

Live: each entry hash-links to the previous one, with an independent head witness against truncation.

4 · Public verify
Verify without us

Anyone can re-check the signature against the published public key — no LicenseOS access. We can’t forge our own evidence.

Live: a public verify endpoint + a published JWKS public key set.

5 · Evidence bundle
Court-credible package

One self-contained file an insurer, regulator, or court can re-verify independently — receipt, key, timestamp, hashes, and an explicit “proves / does not prove.”

Live: downloadable signed bundle + human-readable summary + an FRE 902(13) certificate template.

What a receipt is — and isn’t.

this receipt is evidence of a documented generation-time process — not proof of compliance, admissibility, or non-infringement.

Anti-infringement-laundering and rights-holder KYC

The platform's most dangerous failure mode is a fraudulent listing of third-party IP that issues a clean-looking token. We call this infringement laundering and treat it as a critical risk. The verification ladder below is the design we are building toward; today, the first rung ships and the rest are on the roadmap.

What ships today vs. what's on the roadmap.

Today: IP ownership is self-attested by the rights holder at listing (a sworn attestation they accept). A platform admin can mark a listing as “reviewed” before it earns a registry badge, and real-person likeness/voice IP is hard-blocked from publishing until an admin signs off. On the roadmap (not yet shipping): automated eKYC/KYB identity checks, a live USPTO TSDR registry lookup, perceptual-hash collision detection against a known-IP corpus, and a famous-mark denylist. We label these as “coming” below so no one mistakes the planned ladder for what is enforced today.

TierWhoVerification (planned ladder)Status
Tier 0 — IdentityEvery listerPlanned: eKYC / KYB — government-ID liveness check; ultimate beneficial owner (UBO) disclosure for entities; phone, email, and device/IP fingerprint. Today: account email and a legal-name attestation.Roadmap (today: self-attested)
Tier 1 — Original worksIndie creatorsSworn attestation that the lister owns or controls the IP (accepted at listing). Planned: provenance evidence (dated creation files, prior-publication links) and a perceptual-hash check against the LicenseOS corpus and a known-IP denylist.Live: self-attestation
Tier 2 — Registered marksTrademark ownersPlanned: trademark registration number verified live against the USPTO TSDR API, with a confirmation code sent to the IP office's address-of-record (not applicant-supplied), mirroring Amazon Brand Registry. Today: manual admin review before a registry badge.Roadmap (today: admin review)
Tier 3 — Famous / high-risk IPMajor studios, sports leagues, globally famous marksDefault-deny. No token minted without enterprise onboarding of the actual rights holder, manual legal review, and a signed contract. A solo account cannot self-publish famous IP. Planned: an automated famous-mark denylist that escalates suspected hits here regardless of stated tier.Manual gate (denylist on roadmap)

Perceptual-hash collision detection

Coming

Planned: hash every asset on listing and check it against a growing corpus of known IP, so near-duplicates halt the listing and trigger manual review before any token is issued. Not yet shipping.

Famous-IP denylist

Coming

Planned: a curated denylist of high-risk marks and character names checked on every listing via fuzzy matching, escalating suspected hits to Tier 3 regardless of stated tier. Not yet shipping.

Payout holdbacks during disputes

Revenue is escrowed during any active dispute window, removing the profit motive for squatting or fraudulent listings. Funds are released only after the dispute period clears.

Demos use fictional IP only.

All LicenseOS documentation, demos, sandboxes, and marketing materials use fictional intellectual property (e.g., “Moonberry Grove,” “Momo the Moon Fox”). No real third-party IP is used in any example without verified rights-holder onboarding.

Staying a neutral intermediary

The structural design of LicenseOS keeps the platform a neutral conduit between rights holder and licensee. Enforcement decisions are the rights holder's own published rules applied to the stated facts — not independent editorial judgments by LicenseOS. Platform revenue is structured as a transaction fee, never a share of proceeds that would create a financial incentive to look the other way on infringement.

DMCA Section 512 safe-harbor compliance

LicenseOS maintains a registered DMCA designated agent with the U.S. Copyright Office (renewed on a three-year calendar). The agent's name, address, phone, and email are published below and on our DMCA policy page.

  • Designated agent registration current and publicly disclosed
  • Notice-and-takedown workflow active: notices actioned within 1 – 3 business days
  • Affected users notified of takedown with counter-notice instructions
  • Counter-notices processed per §512(g)(3); material restored in 10–14 days unless suit filed
  • Repeat-infringer policy enforced in code, not only in ToS: warn → restrict → terminate
  • §512(f) misrepresentation warning shown to every notice and counter-notice filer

Repeat-infringer policy

Having a repeat-infringer policy on paper while not enforcing it has been fatal to DMCA safe harbor — as the Cox v. Sony ruling illustrated when 150,000+ notices produced almost no account terminations. LicenseOS enforces escalation in code:

1st noticeWarning issued; logged against account
2nd noticeToken issuance suspended; review required
3rd+ noticeAccount terminated; re-registration blocked

All notices, escalations, and terminations are logged immutably. Revenue is never weighed against enforcement.

License flow: rights holder to licensee

LicenseOS does not grant rights it does not hold. The flow is:

  1. 1Rights holder self-attests ownership of the IP (KYC at the tier appropriate for their IP is on the roadmap).
  2. 2Rights holder publishes machine-readable rules and authoritative legal text for the license.
  3. 3Developer applies; LicenseOS evaluates the application against the rights holder's own rules.
  4. 4If approved, LicenseOS issues a cryptographically-scoped token binding the grant to a specific asset hash, use class, volume cap, territory, and expiry.
  5. 5Every API call is validated against the current policy; revocation flips the response to block immediately platform-wide.

Human review for high-risk decisions

A deterministic policy engine handles hard rules first — expiry, channel restrictions, volume caps, content category hard-blocks. An AI classifier runs brand-safety evaluation on top. Anything that returns a confidence below threshold, involves a use class with significant legal sensitivity (right of publicity, commercial use of real-person likeness, derivative-work requests), or is flagged by the rights holder's own review mode is routed to a human reviewer before a grant is issued.

Always auto-block
  • Minors in any adult-oriented context (hard-block, no override)
  • Real-person likeness in jurisdictions where consent is not on file
  • Famous / Tier-3 IP without verified enterprise onboarding
  • Uses that violate the rights holder's explicit denylist
Always human-reviewed
  • Commercial use of a real person's voice, face, or likeness
  • Derivative-work requests above stated volume thresholds
  • AI-classifier confidence below threshold on brand-safety check
  • Second or subsequent infringement notice against the applicant account

Revocation and the kill switch

Licenses on LicenseOS are online-revalidated with short TTLs. Revocation is not a scheduled job — it is immediate. The moment a rights holder revokes a token, every subsequent API call returns block. There is no grace period for continued infringing use.

Rights-holder-initiated revocation

Rights holders can revoke any token at any time from the dashboard or via the revocation API. Effect is immediate across all regions.

Platform-initiated revocation

LicenseOS will revoke tokens on receipt of a valid DMCA notice, a court order, a credible rights-holder dispute, or a repeat-infringer escalation to the termination threshold.

Automatic expiry

Every token carries a hard expiry. Applications must request renewal explicitly; renewal is subject to the same policy evaluation as an initial grant.

Post-revocation audit

Post-revocation use is provably outside the grant boundary. The immutable log provides evidence of both the grant period and the revocation timestamp.

Reproducible and audited decisions

Every allow / warn / review / block decision is reproducible from the immutable policy version, the exact input parameters, and the model version at evaluation time. The log is tamper-evident and covers the full lifecycle of every grant.

What is logged per decision

  • Account / API key ID
  • Asset hash (sha256 of licensed content)
  • Policy version + content hash of accepted legal text
  • Input parameters: use class, territory, volume cap, channel
  • Decision: allow / warn / review / block
  • Policy-engine version + AI classifier version
  • Precise UTC timestamp

Acceptance record per grant

  • Clickwrap button label text at time of acceptance
  • Rendered screenshot of the acceptance screen
  • Content hash of the license version accepted
  • E-SIGN / UETA attribution: account ID + device fingerprint
  • Bound parameters the user accepted (asset, use, expiry)

License version immutability

  • Each policy version is content-addressed and frozen on publish
  • Changing rules requires the rights holder to publish a new version
  • Existing grants remain bound to the version accepted at grant time
  • New applications evaluate against the current version
  • Retroactive rule changes cannot affect past grants

AI output ownership disclosure

Per the U.S. Copyright Office (Part 2, January 2025), works generated entirely by AI without meaningful human authorship may not be copyrightable. LicenseOS surfaces this notice in every allow response for AI-output use cases: the licensee's right to use the output flows from the LicenseOS license, not from copyright ownership of the output itself.

Reporting misuse and submitting takedown notices

If you believe a listing, token, or licensed use on LicenseOS infringes your intellectual property rights, or if you have evidence of infringement laundering (a party listing IP they do not own), you may submit a notice to our designated DMCA agent. We will act expeditiously — within 1 – 3 business days of receiving a complete notice.

How to submit a DMCA takedown notice

Your notice must include the following elements under 17 U.S.C. §512(c)(3)(A). Incomplete notices will be returned with a request for the missing information.

  1. 1Your physical or electronic signature (or that of an authorized agent)
  2. 2Identification of the copyrighted work you believe is infringed
  3. 3The URL or other specific location of the allegedly infringing material on LicenseOS
  4. 4Your name, address, telephone number, and email address
  5. 5A statement that you have a good-faith belief the use is not authorized by the rights owner, their agent, or the law
  6. 6A statement under penalty of perjury that the information in the notice is accurate and that you are the rights owner or authorized to act on their behalf

Warning: Under §512(f), knowingly materially misrepresenting that material is infringing may expose you to liability for damages, including attorney fees.

Designated DMCA Agent

LicenseOS, Inc. — Copyright Agent

dmca@licenseos.com

Physical address and agent name on file with the U.S. Copyright Office. Agent registration renewed on a three-year calendar per 17 U.S.C. §512(c)(2).

Counter-notice

If your content or token was removed and you believe this was a mistake, you may submit a counter-notice under 17 U.S.C. §512(g)(3). Your counter-notice must include: your signature; identification of the removed material and its prior location; a good-faith belief statement; your name, address, and phone number; and consent to the jurisdiction of the federal court for your district. We will forward the counter-notice to the complainant and restore material within 10 – 14 business days unless we receive notice that the complainant has filed an action in court.

Reporting non-DMCA misuse

For infringement laundering reports, suspected Tier-3 IP bypass, right-of-publicity violations, or other platform-safety concerns that are not copyright takedowns, email trust@licenseos.com. Include a description of the concern, the relevant listing URL or token ID, and your contact details. We respond to all substantive reports within 2 business days.

Built for serious licensing.

LicenseOS is designed from the ground up for rights holders and developers who need defensible, audited, revocable permission — not a fig leaf. If you have questions about our trust-and-safety program or want to discuss enterprise onboarding, speak with our team.