VERAHELMAPI TERMSAPI ↗

API TERMS / EFFECTIVE JULY 22, 2026 / VERSION 2026-07-22-US-NC-B2B-v1

Verahelm API terms.

These API Terms supplement the Verahelm Terms and Conditions. By creating, receiving, or using an API key, Customer accepts both.

1. Eligibility and acceptance

API access is only for United States business or professional users age 18 or older who have authority to bind themselves or their business. Before key creation or activation, Customer must affirm authority, absence of prohibited data and uses, the preliminary nature of results, no certification or professional advice, and no sole or determinative consequential reliance. Verahelm records the accepted document version, purpose, and time.

2. Revocable entitlement

Access is a limited service entitlement, not ownership of a permanent key. Each plan or testing issuance may set operation scopes, monthly or lifetime units, request size, rate, concurrency, expiration, project-key count, and other hard ceilings. No automatic overage billing applies. Verahelm may suspend a key, customer, plan, operation, or the service for security, abuse, prohibited use, nonpayment, refund, dispute, legal risk, provider loss, or compromise.

3. Authorized integration

Keys may be used only from Customer-controlled server-side systems and only for the documented API contract. Customer must validate its integration in a non-production environment, handle machine-readable errors, observe idempotency and retry guidance, enforce least privilege, and maintain its own qualified human review. Testing keys are strictly non-production.

4. Input boundary

The API accepts only bounded, structured JSON matching the published schema. It does not accept files, binaries, archives, repositories, source code, arbitrary HTML, credentials, datasets, user-supplied remote URLs, webhooks containing evaluation content, streams, or bulk jobs. Unexpected fields, unsupported media types, oversized bodies, prohibited patterns, and out-of-bound requests are rejected. Pattern screening reduces obvious misuse but does not guarantee detection.

5. Restricted data and uses

Customer must not submit personal, confidential, regulated, privileged, payment, credential, government-identifier, health, child, controlled, safety-critical, malicious, or third-party trade-secret material. The API may not be used for medical, legal, financial, credit, insurance, employment, housing, education, criminal-justice, immigration, biometric, infrastructure-control, physical-safety, weapons, surveillance, child-directed, certification, compliance, or autonomous high-consequence decisions, or as the sole or determinative basis for a consequential decision.

6. Nature of outputs

Outputs are compact preliminary automated signals, triage, bounded comparisons, stability classifications, evidence-readiness maps, or improvement codes based on Customer-supplied summaries. Outputs are not an automated audit, independent verification, complete reproduction, certification, professional advice, compliance or safety approval, production authorization, guaranteed winner, or guaranteed result. Customer is responsible for interpretation, independent validation, deployment decisions, monitoring, and compliance.

7. Key security

Keys are secrets. Customer must not share, resell, email, publish, expose, log, screenshot, place in URLs or browser storage, or embed keys in distributed client software. Full keys are displayed only once and cannot be recovered. Customer must promptly rotate or revoke a suspected compromised key and notify security@verahelm.com without including the key. Verahelm may apply immediate compromise controls.

8. Metering, quota, and retries

Requests consume configured evaluation units based on operation and bounded resource use. Quota reservation and finalization are authoritative server-side. Customer must use supported idempotency controls for safe retries. Requests may fail closed when authentication, entitlement, quota, private processing, or security state is unavailable. Units are not automatically exceeded or billed as overage. Metadata-only usage totals are controlling absent manifest error.

9. Privacy and retention

API input and full output are processed in active-request memory and are not persistently retained by default. Verahelm retains limited reference, operation, unit, latency, token, cost, status, error, entitlement, key, consent, and security metadata as described in the retention notice. Customer-specific payloads and outputs are not cached for reuse, placed in background jobs, or made available as run history. Essential infrastructure may transiently process requests to deliver and secure the service.

10. Manual escalation

Manual escalation transfers only the public run reference, result and reason codes, suggested service, and the exact non-confidential summary Customer separately reviews and approves. The original API input is not retained or silently transferred. Confidential evidence requires a separate signed manual scope and approved transfer route.

11. Proprietary protections

Customer receives only the documented public result contract. Probing, extraction, reverse engineering, reconstruction, competitive replication, benchmark manipulation, circumvention, or attempted inference of prompts, thresholds, formulas, weights, stress variations, feature contributions, intermediate values, internal scores, routing, architecture, evaluation order, or proprietary methods is prohibited. Customer may not use the API or outputs to train a competing evaluation system or resell Verahelm access or outputs.

12. Changes and deprecation

Breaking public-contract changes use a new API version. Verahelm intends reasonable advance notice for ordinary deprecation but may immediately suspend or modify access required for security, law, abuse prevention, provider loss, or service integrity. Continued use after a required terms-version update requires renewed acceptance.

13. Fees and paid access

When checkout is enabled, the displayed plan, units, term, price, and renewal disclosure control. Hosted checkout collects payment credentials; a browser redirect never activates access. Refund, dispute, cancellation, expiration, upgrade, and downgrade state are server-confirmed and may change entitlement and quota. Customer remains responsible for applicable taxes. Current checkout status is shown before any purchase action.

14. Disclaimers and liability

The warranty disclaimers, limitations of liability, indemnity, North Carolina governing law, arbitration, jury and class-action waiver, and other provisions in the Verahelm Terms and Conditions apply to API access. Nothing in these API Terms limits a right or liability that cannot lawfully be limited.

15. Contact

Security: security@verahelm.com. Privacy: privacy@verahelm.com. Legal: legal@verahelm.com. Never send an API key, payload, credential, restricted data, or complete output by ordinary email.