Draft - under legal review
This document is published in draft form so users can read our intent. It has not yet been reviewed by counsel and is not yet binding on KeyVault Edge or its customers. A final version will replace this page and supersede any draft language. Last updated: 2026-04-23
Terms of Service
These are the terms between you and KeyVault Edge when you use the service. Written in plain English where we can; precise where we must be.
1. Acceptance
By creating an account, signing in, or sending a request through our service, you agree to these Terms. If you are accepting on behalf of an organisation, you represent that you have authority to bind it.
If you do not agree, do not use the service.
2. The service
KeyVault Edge provides an edge proxy that accepts host-bound tokens from your applications, validates them, injects your third-party API keys, and forwards the request to the upstream provider. The technical details are described in our documentation and threat model.
We offer a free tier with limitations and paid plans described on our pricing page. Plan limits and features may change with notice.
3. Your account
You must be at least the age of majority in your jurisdiction to use the service. You are responsible for everything that happens under your account, including the actions of anyone you invite.
Keep your credentials safe. Use a unique password. Enable the security features we offer. Tell us immediately if you suspect compromise - email security@keyvaultedge.com.
We may suspend or terminate accounts that violate these Terms or that we reasonably believe are being used to harm the service or other customers.
4. Acceptable use
You agree not to:
- Upload or proxy API keys that do not belong to you or that you are not authorised to use.
- Use the service to transmit malware, phishing content, or material that is illegal in your jurisdiction or ours.
- Attempt to reverse-engineer, decompile, or otherwise circumvent the security features of the service, except as expressly permitted by law or by our responsible disclosure policy.
- Attempt to overwhelm the service (volumetric attack, resource exhaustion) or to bypass rate limits, quotas, or billing.
- Use the service to scrape, spam, or otherwise violate the terms of the upstream API provider whose key you are proxying.
- Resell or sublicense access to the service without our written permission.
We reserve the right to investigate and take appropriate action, including suspension, termination, and cooperation with law enforcement, against any account that violates this section.
5. Customer data and keys
You own your data. Nothing in these Terms transfers ownership of your data or your API keys to KeyVault Edge.
You grant us a limited licence to host, process, and transmit your data solely as needed to operate the service you asked for. That licence ends when you delete the data or close your account.
You are responsible for what you put into the service. If a third party claims that your content infringes their rights, that claim is yours to resolve.
If you process personal data of your own users through KeyVault Edge, our Data Processing Agreement (DPA) applies. Paid customers can countersign the DPA on request at privacy@keyvaultedge.com.
6. Fees and billing
Paid plans are billed monthly or annually in advance via Stripe. Prices are shown in US dollars unless otherwise stated and exclude taxes, which are your responsibility where applicable.
Subscriptions renew automatically until cancelled. You can cancel at any time from the billing portal; your plan remains active until the end of the current billing period. We do not refund partial periods except where required by law.
Usage-based overages are billed at the rates published on the pricing page. If your payment fails, we will email you and attempt to retry; persistent failure may lead to suspension.
7. Intellectual property
We own the service, the software that runs it, and the marketing materials that describe it. You receive a non-exclusive, non-transferable right to use the service as described in these Terms.
Any feedback, bug reports, or suggestions you send us may be used by us without obligation. We will not publicly attribute feedback to you without your permission.
8. Third-party providers
When you proxy a request through us, it goes to a third-party API provider whose terms you are independently bound by. KeyVault Edge is not responsible for the third-party provider's service, outages, policy changes, billing, or terms.
We use sub-processors to deliver the service, listed on the Trust Center. Their role and the data they touch is described there.
9. Warranties and disclaimers
The service is provided “as is” and “as available.” To the fullest extent permitted by law, we disclaim all warranties, express or implied, including fitness for a particular purpose, merchantability, and non-infringement.
We do not warrant that the service will be uninterrupted, error-free, or perfectly secure. We do make best-effort availability commitments on paid plans, described on the pricing page and credited as service credits where we fall short.
10. Limitation of liability
To the fullest extent permitted by law, neither party is liable to the other for indirect, incidental, consequential, special, exemplary, or punitive damages, or for lost profits, revenues, or data, even if advised of the possibility.
Our total aggregate liability to you for any claim arising out of or relating to these Terms or the service is capped at the greater of (a) the amounts you paid us in the 12 months preceding the claim, or (b) one hundred US dollars (US$100).
These limits do not apply to liability that cannot be excluded under applicable law, including gross negligence, wilful misconduct, or personal injury.
11. Indemnification
You will defend, indemnify, and hold harmless KeyVault Edge, its officers, employees, and sub-processors from any third-party claim arising out of (a) your content or data, (b) your use of the service in violation of these Terms or applicable law, or (c) your violation of the rights of a third party.
12. Termination
You can close your account at any time. We can terminate or suspend your account for material breach of these Terms, for non-payment, or where we reasonably believe your use is harming the service or other users. We will give you notice where practical.
On termination, your right to use the service ends immediately. We will delete your data as described in the Privacy Policy. Sections that by their nature should survive (IP, liability, indemnification, governing law) will survive.
13. Changes to these Terms
We may update these Terms as the service evolves. Material changes will be announced by email to the account owner and by a notice on the dashboard at least 14 days before they take effect. The date at the top of the page always reflects the current version.
If you do not accept a material change, you may close your account before the effective date. Continued use after the effective date constitutes acceptance.
14. Governing law and disputes
These Terms are governed by the laws of the jurisdiction in which KeyVault Edge is incorporated, without regard to its conflict-of-law rules. The governing jurisdiction will be stated here before general availability.
The parties will first attempt to resolve any dispute informally by contacting legal@keyvaultedge.com. Nothing in this section limits either party's right to seek injunctive relief for intellectual-property or security matters.
15. Contact
Legal notices: legal@keyvaultedge.com. Other contacts are listed on the Trust Center.