API Terms
Contractual and security requirements for Aeltrix APIs, SDKs, webhooks, developer credentials, and automated integrations.
1. Scope and Incorporation
These API Terms apply to APIs, SDKs, webhooks, developer consoles, machine credentials, integration endpoints, and related documentation made available by Aeltrix Technologies LLC for a covered Service. They supplement the Terms of Service and Acceptable Use Policy.
2. Credentials and Authentication
API keys, client secrets, signing secrets, certificates, tokens, service-account credentials, and webhook secrets are confidential authentication material. Customer must store them securely, apply least privilege, rotate them when appropriate, and revoke them promptly after suspected compromise. Credentials may not be embedded in public source code, client-side code, public repositories, or other locations accessible to unauthorized users.
3. Authorized Use
Customer may access an API only for the applications, organizations, accounts, and purposes authorized by its plan, documentation, or order. Customer may not use another customer's credential or access resources outside its authorization scope.
4. Rate Limits and Fair Use
Customer must comply with documented rate limits, concurrency limits, payload limits, pagination limits, timeouts, quotas, and retry requirements. Aeltrix may throttle, queue, reject, or temporarily block requests that exceed limits or threaten service stability. Customer must implement reasonable exponential backoff and idempotency where documented.
5. Prohibited API Conduct
- circumventing quotas, access controls, or tenant isolation;
- enumerating identifiers to discover non-public resources;
- scraping or extracting data beyond authorized scopes;
- using undocumented endpoints in a manner that creates security or stability risk;
- replaying signed requests or webhooks without authorization;
- fabricating events, headers, signatures, or authentication context;
- using the API to conduct activity prohibited by the Acceptable Use Policy; or
- attempting to reverse engineer private protocols or bypass intended authorization boundaries.
6. Webhooks
Customer is responsible for securing webhook endpoints, validating signatures where provided, protecting replay windows, returning appropriate response codes, and handling duplicate or delayed events. Unless expressly stated otherwise, webhook delivery is at-least-once rather than exactly-once, and Customer should design idempotent handlers.
7. Data Handling
Customer must process personal information and confidential information obtained through an API only for authorized purposes and in compliance with applicable privacy law, the Privacy Policy, and where applicable the Data Processing Addendum. API access does not grant rights to repurpose data beyond the applicable agreement.
8. Security
Customer must use current TLS, validate certificates, protect secrets, restrict source networks where appropriate, monitor credential use, and maintain secure software-development practices. Aeltrix may revoke or rotate credentials, require additional authentication, block abusive traffic, or disable vulnerable integrations where reasonably necessary.
9. Versioning and Changes
Aeltrix may release new API versions and deprecate old versions. For materially used stable APIs, Aeltrix will use commercially reasonable efforts to publish deprecation information or migration guidance where practicable. Security fixes, emergency changes, undocumented interfaces, previews, and beta APIs may change more rapidly.
10. Availability
Unless an executed order includes an API-specific SLA, APIs are provided subject to the availability commitments of the underlying Service and may be affected by maintenance, rate limits, third-party dependencies, network conditions, or security events.
11. Developer Applications
Customer is responsible for applications it builds using the APIs, including user notices, consents, permissions, security, regulatory compliance, support, and downstream terms. Customer must not represent that Aeltrix endorses or certifies a third-party application unless Aeltrix has provided written authorization.
12. Monitoring and Audit
Aeltrix may log API requests, authentication events, response metadata, errors, rate-limit events, security signals, and administrative activity for operational, security, support, compliance, and abuse-prevention purposes. Customer may be required to provide information reasonably necessary to investigate suspected API abuse.
13. Suspension and Revocation
Aeltrix may suspend or revoke API access for credential compromise, material breach, excessive load, abuse, non-payment, legal restriction, or security risk. Where appropriate and lawful, Aeltrix will provide notice and a reasonable opportunity to remediate.
14. Open Source and Third-Party Components
SDKs or examples may include open-source components governed by their applicable licenses. These API Terms do not override third-party open-source licenses.
Questions about this legal document?
For legal notices, compliance questions, or requests relating to this document, contact Aeltrix Technologies LLC through the legal channel below.
