VaultProof

Terms of Service

Terms for using VaultProof.

These Terms explain how you may use VaultProof's website, hosted init, dashboard, scanner, API key protection, and provider routing services.

Effective date
  1. 1Last updated August 10, 2026.
  2. 2Use only keys and accounts you are authorized to use.
  3. 3Rotate leaked provider keys at the provider.
  4. 4Contact [email protected] with questions.

1. Agreement

By using VaultProof, you agree to these Terms.

These Terms of Service are an agreement between you and VaultProof Inc. They apply when you access or use VaultProof's website, hosted init installer, downloads, scanner, dashboard, API, Model Context Protocol (MCP) connection, provider routing, and related services.

If you use VaultProof for a company or other organization, you represent that you have authority to bind that organization to these Terms.

Age and guardian requirements You must be at least 13 years old and located in a region where VaultProof makes the Service available. If you are under the age of majority where you live, your parent or legal guardian must review these Terms and authorize your account before you use the Service. Your parent or legal guardian is responsible for supervising your use and may request account closure or withdraw authorization by contacting [email protected]. The account may be restricted or closed if required guardian authorization is withdrawn.

2. Service

VaultProof helps reduce raw provider-key exposure.

VaultProof is an API key protection and routing service. It helps users move provider keys out of source code, hosted environment files, CI logs, and AI coding context by using VaultProof-managed values and provider-compatible routes.

Hosted init

The init tool can detect supported provider keys, protect them, and write VaultProof values and base URLs into your app environment.

Dashboard

The app provides key management, activity, alerts, usage, settings, and billing-related workflows.

Provider routing

VaultProof routes supported provider calls through compatible endpoints and authenticates upstream on your behalf.

Security boundary VaultProof does not eliminate every key risk. During a provider request, VaultProof must use the credential required to authenticate upstream. You remain responsible for provider-side permissions, rotation, billing controls, and application security.
MCP connection The VaultProof MCP currently exposes narrowly scoped, read-only credential metadata and server-side integration placement guidance to an approved client after OAuth consent. It does not authorize the client to retrieve raw provider keys, scan repositories, modify applications, execute provider requests, or initiate purchases or upgrades. You may review or revoke an MCP grant through VaultProof.

3. Accounts

You are responsible for your account and configuration.

You must provide accurate account information and keep your login credentials secure. You are responsible for all activity under your account, including activity by users, teammates, applications, agents, CI jobs, or workloads that use your VaultProof values.

  • Use strong authentication and protect access to your email and dashboard account.
  • Only add provider keys that you own or are authorized to use.
  • Remove raw provider keys from old environments, logs, repos, and hosting settings after setup.
  • Notify us promptly if you believe your account or VaultProof values were accessed without authorization.
  • If you are under the age of majority, keep your parent or legal guardian informed about your account and comply with their supervision.

4. Customer Data

You keep ownership of your data and provider accounts.

"Customer Data" means information you submit to VaultProof, including account information, configuration, provider key material, VaultProof-generated values, activity records, and metadata related to your use of the Service.

You grant VaultProof a limited right to process Customer Data only as needed to provide, secure, operate, troubleshoot, and improve the Service; comply with law; and enforce these Terms. We handle personal data as described in the Privacy Policy.

Provider keys You are responsible for creating, scoping, rotating, revoking, and monitoring provider keys with the underlying providers such as OpenAI, Anthropic, Stripe, Google, and similar services.

5. Acceptable Use

Do not abuse VaultProof or other services through VaultProof.

You may not use VaultProof for illegal, harmful, abusive, or unauthorized activity.

  • Do not store or route keys you stole, found, scraped, bought without authorization, or are not allowed to use.
  • Do not use VaultProof to hide the origin of compromised provider keys or fraudulent provider usage.
  • Do not attack, overload, scan, scrape, reverse engineer, or bypass rate limits or security controls.
  • Do not use the proxy to conduct denial-of-service activity, credential stuffing, spam, malware distribution, fraud, or unlawful surveillance.
  • Do not create multiple accounts or projects to avoid plan limits, abuse controls, or enforcement.

We may suspend, limit, or terminate access if we reasonably believe your use violates these Terms, threatens the Service, creates legal risk, or harms VaultProof, users, providers, or third parties.

6. Billing

Paid plans are billed through our payment processor.

Some VaultProof features may require a paid plan. Prices, plan limits, included usage, trial terms, and the billing cycle are shown before purchase or in the dashboard. Paid plans may be billed monthly, annually, or on another stated cycle through a third-party payment processor.

Eligible accounts may receive one 30-day trial without providing a payment method. The trial does not automatically convert to a paid subscription. When it ends, the account returns to the then-current Free limits unless you separately choose a paid plan. Existing protected data may be preserved while creation or usage above the current plan limit is restricted. If you choose a paid plan, you authorize us and our payment processor to charge the displayed fees, applicable taxes, and allowed usage-based charges. We may provide a courtesy reminder before a trial ends or a recurring charge, but you remain responsible for managing a paid subscription before its stated renewal date. Fees are non-refundable except as required by law or expressly stated in a separate written agreement. If payment fails or usage exceeds allowed limits, we may throttle, limit, downgrade, or suspend access.

Billing authorization for minors An approved account may use the no-card trial because it creates no automatic charge. A user under the age of majority may not purchase a paid subscription or paid-plan upgrade unless their parent or legal guardian separately authorizes billing. Guardian approval of an account does not authorize charges. The adult authorizing billing represents that they are authorized to use the payment method and accepts the displayed renewal, cancellation, and refund terms.

7. Availability

The Service is provided with practical operational care, not a blanket uptime promise.

We work to keep VaultProof available, secure, and reliable. Unless you have a separate written agreement that includes a specific service level, VaultProof is provided without a guaranteed uptime, response-time, support-time, or recovery-time commitment.

The Service may be unavailable or degraded because of maintenance, provider outages, internet conditions, security events, third-party dependencies, abuse mitigation, or other events beyond our reasonable control.

8. Termination

You can stop using VaultProof, and we can suspend unsafe use.

You may stop using the Service at any time. You may delete or request deletion of account data where supported by the dashboard, support process, or applicable law.

We may suspend or terminate access if you violate these Terms, create risk for the Service or others, fail to pay fees, or use VaultProof in a way that could expose us, providers, or users to harm or liability. After termination, your right to use the Service ends, but sections that by their nature should continue will continue.

10. Contact

Questions about these Terms?

Contact [email protected] or visit VaultProof Support. For security issues, use [email protected].