Public issuer policy

Credential trust should be inspectable.

This policy describes how EduGator issues and maintains verifiable credentials. It does not establish accreditation, licensure, public funding eligibility, or recognition by a third party.

Credential criteria

A credential is issued only from an approved program assertion. For the FDE track, the assertion must show that the applicable time gate and mastery gate are both met and that required human review is complete. Program owners approve criteria; the credential service does not invent them.

Evidence and privacy

Credentials contain the minimum claims needed to describe the achievement. Confidential learner, reviewer, or partner artifacts must remain in access-controlled systems. Public evidence links require permission and must not expose protected records.

Verification and status

Verifiers should resolve the issuer DID, validate the Data Integrity proof, confirm the achievement criteria, and check the referenced Bitstring Status List. A successful signature check does not by itself establish that a credential is current or suitable for a particular decision.

Correction, revocation, and appeal

Holders may request correction of an issuer error or appeal an operational decision by contacting credential operations. Revocation is used when the credential should no longer be accepted. The program owner records the reason and approval in the private audit trail; the public list reveals only status.

Expiration and renewal

A credential is non-expiring unless its published terms include an expiration or renewal requirement. Specialization and continuing-education credentials may require renewal. The achievement definition and issued credential control; marketing copy does not change those terms.

Key rotation

New signing keys receive a new verification-method identifier. Prior public keys remain resolvable for credentials issued with them. A compromised key triggers the incident and rotation runbook; key replacement must not silently overwrite the identity of existing credentials.