# BRD-230 — Identity-plus vetting is for public companies only

> An Authentication+ vet must not be ordered for a brand that is not PUBLIC_PROFIT.

- **Rule ID:** BRD-230
- **Layer:** Brand (`BRAND`)
- **Checks:** `the vet order + brand.entity_type`
- **Severity:** BLOCKING — Breaking this rule gets the submission rejected outright.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** Deterministic (settled in code from the submitted values)
- **Fix type:** Fix the field — a better value in the form clears it
- **Required by:** TCR
- **Applies:** Applies when the brand is NOT a public company.
- **Canonical URL:** https://ekas.io/rules/10dlc/brand/brd-230/

## Why this rule exists

Authentication+ is the two-factor confirmation designed for listed companies, and the registry refuses the order for any other entity type rather than downgrading it to something available. Teams order it because it is the strongest-sounding option on the list, and the fee is taken before the refusal.

## How to fix it

Order a standard vet instead — it is the one that raises throughput for a private, non-profit or government brand. Authentication+ is not a higher tier of the same thing; it is a different verification for a different entity type.

## Example of a compliant value

```text
vetting class: STANDARD for a PRIVATE_PROFIT brand — not AUTHPLUS
```

## Provider rejection codes

| Provider | Code | Resubmission allowed |
| --- | --- | --- |
| TCR | `592` | yes |
