Registry disclosure
A public credential record is a verification surface, not a dossier. This page says what we publish, what we keep off the record, and how a business can fix or remove a listing.
What appears on a public credential record
Only these fields render on a public record:
- Business name
- City / region
- Trust Badge tier (Bronze, Silver, or Gold)
- Credential ID in the LC-XXXXX format
- Standard version the credential was assessed against
- Issue date
- Expiry date
- Status: Active or Expired
Status is one of those two labels. Expired shows the expiry date and nothing further. Alignment language, where it appears, is exactly: Aligned with NIST CSF 2.0 + CIS Controls v8. Legacy Core is not affiliated with, endorsed by, or accredited by NIST, CIS, or any government agency.
What never appears on a public credential record
We do not publish:
- Owner or staff names, emails, phone numbers, or home addresses
- Vendor names, product names, or control-level detail
- Partial scores, per-area results, findings, notes, or remediation items
- The name of any attesting Alliance Partner
- Status labels other than Active or Expired — including failed, denied, revoked, suspended, or under review — and no reason text
If a partner attested to the evidence, the record may show a neutral marker such as “Partner-attested.” A partner's name on a public record is a bug. Tell us.
How evidence submitted during the Readiness Assessment is handled
The 15-part Readiness Assessment is how a business earns Bronze. Answers and supporting evidence are used to review readiness against the current Standards Release. They are not copied onto the public record. Public verification checks live registry status. It does not replay the assessment.
Reviewers see what they need to decide a credential. Alliance Partners do not receive another business's raw uploads through the public registry.
Retention: what we keep, for how long, and what we delete
We keep the minimum needed to issue, renew, and verify a credential, to answer a dispute, and to meet legal record-keeping duties. When a listing is withdrawn or a retention period ends, we delete or de-identify what we no longer need.
Exact retention periods are in our Privacy Policy. If a period is not listed there yet, we keep the record only as long as the purpose that created it still applies.
How to correct or dispute a listing
If a public field is wrong — name, city, dates, tier, or credential ID — email verify@legacycore.com from an address we can match to the listing. We will not argue a finding in public copy. We will correct facts that are wrong.
We will reply once we can match the request to the listing.
How to withdraw a listing
A credentialed business can ask us to take the listing down. Withdrawal means removal. We do not leave a public “withdrawn” marker, a tombstone, or a reason on the registry. After removal, a lookup of that credential ID does not show a record.
Withdrawal does not by itself cancel a paid credentialing pathway or a renewal invoice. Ask if you also need billing stopped.
How to report a security issue
If you think a listing is leaking data it shouldn't, or you found a problem in the registry itself, use our security disclosure process. Do not post exploit details on the public record.