Legal
Terms of service
Six terms in this document are not yet settled. They are commercial and legal decisions that are recorded nowhere in this service — the operating entity, its address, the refund policy, the liability cap, the governing law and the support commitment. They are marked [LIKE THIS] rather than invented, and must be settled before this page is final.
Everything else here describes how the deployed service actually behaves and what the committed price catalog actually says.
- Who these terms are with
- Accepting them
- What the service is
- Accounts and API keys
- The free tier
- Paid plans, quota, overage and the spend cap
- Payment
- Cancellation and refunds
- Acceptable use
- Your data
- Availability and support
- Changes to the API
- Suspension and termination
- Disclaimer of warranties
- Limitation of liability
- Governing law
- Changes to these terms
- Contact
1. Who these terms are with
These terms are an agreement between you and [LEGAL ENTITY NAME], at [REGISTERED POSTAL ADDRESS], which operates the Vendor Evidence Drift API and this website. “We” and “us” mean that entity. “You” means the person or organisation using the service; if you are using it for an employer, you confirm you may accept these terms for them.
2. Accepting them
You accept these terms when you request an API key, call the API, or buy a plan — whichever happens first. If you do not accept them, do not do any of those things.
3. What the service is
Monitor vendor security, privacy, subprocessor, certification and SLA evidence, and map changes to controls and risk.
It is a computation over the data you send it. It does not gather data on your behalf, and it returns results derived from your input.
4. Accounts and API keys
- Your account is identified by your email address. A key is issued only after you prove control of that mailbox by spending a token we email to it, so that nobody can mint a key on your account or spend your allowance.
- A key's secret is shown once, when it is issued. We store only a hash of it and cannot recover, resend or read it back. Keeping it secret is your responsibility, and anything done with your key is metered and billed to your account.
- You may hold up to five active keys per account on this API. Rotating a key replaces it rather than adding one, so rotation is never blocked by that limit.
- If a key leaks, revoke it. Revoke, rotate, list and usage all cost no quota, so they keep working while a leaked key is being hammered through its ceiling.
- A key works only on this API. It is not a browser credential and must not be embedded in front-end code.
5. The free tier
The free tier is 150 evidence checks/month, with no card. It exists so you can build an integration and decide, and it is enforced by the same quota machinery as a paid plan — the figure published on this site is the figure the backend refuses beyond. We may change or withdraw the free tier; if we do, you are never billed for it retrospectively.
6. Paid plans, quota, overage and the spend cap
Plans are monthly, in US dollars, and bought through a Square-hosted checkout. Every plan is a flat monthly fee plus an included allowance of evidence checks. Beyond that allowance you pay a stated per-unit overage, and the overage for a billing period is hard-capped. Your worst case for a period is the base fee plus that cap, and never more.
The fee, the allowance, the per-unit overage and the cap for each plan are on the pricing section, and are deliberately not restated here. Those figures are projected from the product catalog into one committed file and rendered from it; a second copy in this document would be a second copy to keep correct, and the one that drifts is always the one nobody is looking at. What this clause fixes is the shape of the bill, not the numbers in it.
Two windows, and they are not the same window. The quota period is the calendar month in UTC and
resets at 00:00 UTC on the 1st. Your invoice window is anchored to the day you subscribed.
GET /v1/usage reports the allowance actually being enforced against your key, what you
have consumed, and when it resets; it costs no quota, so it still answers once you are being refused.
The Enterprise plan is arranged with us rather than bought self-serve.
Prices may change. A change takes effect from your next billing period, never the one you are in.
7. Payment
Payments are processed by Square. You enter your card on Square's own hosted page; card numbers, expiry dates and security codes never reach this service. We store the identifiers Square issues for your customer record and your stored card, and the amounts, periods and status of each charge.
If a payment fails we retry it. If it keeps failing, your plan may be suspended and your keys may fall back to the free allowance until it is settled.
8. Cancellation and refunds
There is no self-serve cancellation button yet, and we will not pretend otherwise: to cancel, email contact@nerveplusinc.com from the address the account is keyed to. Cancellation stops the next renewal; your plan keeps working to the end of the period you have already paid for, after which keys fall back to the free allowance rather than stopping dead.
Refunds: [REFUND POLICY]
9. Acceptable use
You must not:
- use the service unlawfully, or to do something unlawful to someone else;
- send us data you have no right to send — you are responsible for having the rights and, where the law requires it, the consent to submit what you submit;
- attempt to reach another account's data, or to test whether a given email address has an account;
- work around quota, rate limits, authentication or the account scoping of a key, or use several accounts to do what one account's plan would not allow;
- resell or sublicense raw access to a key as if it were your own API;
- put a key in browser JavaScript, a mobile app or any other place a third party can read it.
If you find a security problem, tell us at contact@nerveplusinc.com before telling anyone else, and we will not treat a good-faith report as a breach of this section.
10. Your data
What you send stays yours. You grant us only the permission needed to run the service for you: to receive your request, compute the response and return it, and to meter the call for billing. We do not use it to train models and we do not use it to build another product. What we store, and for how long, is set out in the privacy policy.
11. Availability and support
We publish no uptime commitment and offer no service-level agreement. This service is newly launched and has no operating history to base one on; saying otherwise would be a number we made up. The status page reports the service's state live, from the service's own health endpoint, at the moment you load it.
Support is by email at contact@nerveplusinc.com. Quote the
requestId from the response you are asking about — it appears on every response,
success or failure, and it is what lets us find the exact request. Our response commitment is
[SUPPORT RESPONSE COMMITMENT].
12. Changes to the API
The public contract is everything under /v1/, and the machine-readable version of it is
openapi.json, generated from the deployed route table rather than
written by hand. Every published change is recorded in the changelog, which is
generated from that contract's own history. We will add to /v1/; we will not silently
change the meaning of what is already there. A breaking change gets a new version prefix, so an
integration you have already shipped is not renumbered underneath you.
13. Suspension and termination
We may suspend or terminate access if payment fails persistently, if section 9 is breached, or if we are required to by law. Where the situation allows it we will tell you first and give you a chance to fix it. You may stop using the service at any time; see section 8 for a paid plan.
14. Disclaimer of warranties
To the fullest extent the law allows, the service is provided “as is” and “as available”, without warranties of any kind, whether express or implied, including any implied warranty of merchantability, fitness for a particular purpose or non-infringement. The output is arithmetic over the data you supply. It is information for you to act on, not advice, and not a decision made on your behalf.
15. Limitation of liability
[LIABILITY CAP AND EXCLUSIONS]
Nothing in these terms excludes liability that cannot lawfully be excluded.
16. Governing law
These terms are governed by, and disputes under them are resolved in, [GOVERNING LAW AND VENUE].
17. Changes to these terms
If these terms change, the date at the top of this page changes with them. Continuing to use the service after that is acceptance of the new version. A change to price, allowance or overage takes effect from your next billing period, never the one you are already in.
18. Contact
contact@nerveplusinc.com. See also the privacy policy.