This Application Programming Interface and Software Development Kit Supplement (“API and SDK Supplement”) is attached to and incorporated into the Proof General Terms (“General Terms”). Capitalized terms not otherwise defined have the meanings given in the General Terms, the Proof Glossary, or the Order Form. This API and SDK Supplement replaces the API Supplement. Any reference to the API Supplement in the Order Form or elsewhere in the Agreement shall be read to refer to this API and SDK Supplement.

  1. General. This API and SDK Supplement applies to Subscriber, if Subscriber uses Proof’s APIs. If Subscriber does not accept this API Supplement, Subscriber may not access or use the API.
  2. License Grant. Subject to and conditioned on Subscriber’s compliance with all terms and conditions set forth in the Agreement, Proof hereby grants Subscriber a limited, revocable, non-exclusive, non-transferable, non-sublicensable license during the term of the Agreement to use the API solely for developing an integration with Subscriber’s application(s) that will communicate and interoperate with the Services for the benefit of a User (“Applications”). Subscriber acknowledges that there are no implied licenses granted under the Agreement. Proof reserves all rights that are not expressly granted. Subscriber may not use the API for any other purpose without Proof’s prior written consent. In order to use and access the API, Subscriber must purchase Proof Services that include Proof’s APIs or Subscriber’s use must be approved by Proof. Subscriber will gain access to the API Key on the Proof Platform. Subscriber may not share Subscriber’s API Key with any third party, must keep Subscriber’s API Key and all log-in information secure, and must use the API Key as Subscriber’s sole means of accessing the API. Subscriber’s API Key may be revoked at any time by Proof.
  3. SDK Terms.
    3.1 Open-Source License.  The SDK is licensed under the open-source license identified in the applicable SDK repository, which governs Subscriber’s rights to use, reproduce, modify, and distribute the SDK code. Nothing in this API and SDK Supplement limits the rights, or enlarges the obligations, granted to Subscriber under that open-source license with respect to the SDK code, and to the extent of any conflict between this API and SDK Supplement and that open-source license as to the SDK code, the open-source license controls.

    3.2 Scope; Credentials.  This API and SDK Supplement governs Subscriber's access to and use of the API, Proof's related endpoints and interfaces, Subscriber's access credentials, the Proof Marks, and Subscriber's reliance on any output, in each case whether accessed directly or through the SDK. Any website, application, or integration through which Subscriber deploys or uses the SDK is an Application for purposes of this API and SDK Supplement. To access Proof's endpoints in production, Subscriber must obtain the access credentials Proof issues through the Proof Platform, must keep those production credentials and all related log-in information secure, may not share them with any third party, and must use them as Subscriber's sole means of accessing Proof's endpoints through the SDK; Proof may revoke Subscriber's production credentials at any time. Any sandbox or development credentials are provided for testing only, are not confidential, and the sandbox environment is provided "as is" without service levels or warranties.

    3.3 Verification; Trusted Root; Reliance.  The SDK may be used to (a) request a verifiable-credential presentation, in which case the User is directed to Proof’s platform to complete the presentation, and that presentation and any resulting transaction are governed by the General Terms and the Supplement(s) applicable to the Service used; and (b) verify credentials issued by Proof, which Subscriber may perform in its own environment using Proof’s published root certificate(s) and keys (“Trusted Root”). Subscriber is responsible for using the then-current Trusted Root and for validating each presentation, including any nonce, revocation status, and transaction-data binding. Any credential, attribute (such as an age or similar indicator), verification result, or Trusted Root is provided for Subscriber’s own risk-based decisions; Proof does not warrant that any of them is accurate, complete, current, or fit for a particular purpose, and Proof has no liability for Subscriber’s reliance on them. Subscriber’s use of Proof’s certificates is also subject to the Proof Certificate Policy and Certification Practice Statement.

    3.4 Proof Marks.  The Proof name, logos, the verification button, and other Proof brand elements are not licensed under the SDK’s open-source license. Subscriber may display them only in the form Proof provides and in accordance with any brand, style, or implementation guidelines Proof makes available, and will not modify, obscure, or interfere with any Proof-implemented consent, disclosure, warning, or other communication presented to Users.
  4. Personal Data. The API may provide Subscriber with access to certain personal information of Users, or other individuals, including but not limited to: (a) homeowner names and other homeowner information; and (b) certain financial information, including mortgage details, individual net worth, or home worth details (collectively, “API Personal Data”). Subscriber’s use of API Personal Data is strictly limited to the uses specifically requested through opt-in consent by Users. Subscriber agrees to keep the API Personal Data confidential. Subscriber will not disclose, reproduce, summarize or distribute the API Personal Data to any third party or otherwise display API Personal Data to anyone other than the User to whom theAPI Personal Data belongs and Subscriber’s employees who are bound by thisAgreement on a need-to-know basis. Subscriber will take reasonable security precautions, at least as great as the precautions Subscriber takes to protect Subscriber’s confidential information, but no less than reasonable care, to keep confidential API Personal Data.
  5. Use Restrictions.
    5.1
    Restrictions. In this Section, references to the API include Proof's endpoints and Services accessed through the SDK; they do not limit Subscriber's rights in the SDK code under its open-source license. Except as expressly authorized under this Agreement, Subscriber may not:

    (a)
    copy, modify, or create derivative works of the API, in whole or in part;
    (b) share Subscriber's access credentials with any third party, or allow any third party to use Subscriber's access credentials on Subscriber's behalf;
    (c) rent, lease, lend, sell, license, sublicense, assign, distribute, publish, transfer, or otherwise make available the API;
    (d) reverse engineer, disassemble, decompile, decode, adapt, or otherwise attempt to derive or gain access to any software component of the API, in whole or in part;
    (e) remove any proprietary notices from the API;
    (f) use the API in any manner or for any purpose that infringes, misappropriates, or otherwise violates any intellectual property right or other right of any person, or that violates any applicable law;
    (g) use any data or materials accessible through the API for any purpose other than for providing the Application to Users;
    (h) access the API or use any data or materials available through the API for competitive or benchmarking purposes;
    (i) combine or integrate the API with any software, technology, services, or materials not authorized by Proof;
    (j) design or permit Subscriber's Application(s) to disable, override, or otherwise interfere with any Proof-implemented communications to end users, consent screens, user settings, alerts, warning, or the like;
    (k) use the API in any of Subscriber's Application(s) to replicate or attempt to replace the user experience of the Proof Services, including any Proof or User forms or data; or
    (l) attempt to cloak or conceal Subscriber's identity or the identity of Subscriber's Application(s) when requesting authorization to use the API.

    5.2
    Acceptable Use. Subscriber and Subscriber's Applications shall comply with all terms and conditions of this Agreement, all applicable laws, rules, and regulations, and all guidelines, standards. In addition, Subscriber will not use the API or SDK in connection with or to promote any products, services, or materials that constitute, promote, or are used primarily for the purpose of dealing in spyware, adware, or other malicious programs or code, counterfeit goods, items subject to U.S. embargo, unsolicited mass distribution of email (“spam”), multi-level marketing proposals, hate materials, hacking, surveillance, interception, or descrambling equipment, libelous, defamatory, obscene, pornographic, abusive, or otherwise offensive content, stolen products, and items used for theft, hazardous materials, or any illegal activities. If Subscriber becomes aware of any access to the API that violates the Agreement, or any User activity that violates the Agreement, Subscriber agrees to immediately notify Proof of such breach by email to legal@proof.com.
  6. Applications.  Subscriber agrees to monitor the use of Applications for any activity that violates applicable laws, rules and regulation or any terms and conditions of theAgreement, including any fraudulent, inappropriate, or potentially harmful behavior, and promptly restrict any offending users of Applications from further use of Applications. Subscriber agrees to provide a resource for users of Applications to report abuse of Applications. As between Subscriber and Proof, Subscriber is responsible for all acts and omissions of Subscriber’s end users in connection with Subscriber’s Application and their use of the API or SDK, if any. Subscriber agrees that Subscriber is solely responsible for posting any privacy notices and obtaining any consents from Subscriber’s end users required under applicable laws, rules, and regulations for their use of Applications. If the number of requests that Applications make to the Platform are unreasonably large, Proof reserves the right, in its sole discretion, to limit the number of requests.
  7. No Fees. Subscriber agrees that no license fees or other payments will be due under this API and SDK Supplement in exchange for the rights granted under this API and SDK Supplement. Subscriber acknowledges and agrees that this fee arrangement is made in consideration of the mutual covenants set forth in this agreement, including, without limitation, the disclaimers, exclusions, and limitations of liability set forth herein. Notwithstanding the foregoing, Proof reserve the right to start charging for access to and use of the API or SDK at any time.
  8. Intellectual Property Ownership. Subscriber acknowledges that, as between Subscriber and Proof: (a) Proof owns all right, title, and interest, including all intellectual property rights, in and to the API (including all data or other materials accessible through the API), and theServices; and (b) Subscriber owns all right, title, and interest, including all intellectual property rights, in and to Subscriber’s Application(s), excluding the aforementioned rights. Subscriber will use commercially reasonable efforts to safeguard the API (including all copies thereof) from infringement, misappropriation, theft, misuse, or unauthorized access. Subscriber will promptly notify Proof if Subscriber becomes aware of any infringement of any intellectual property rights in the API and will fully cooperate with Proof, in any legal action taken by Proof to enforce Proof’s intellectual property rights. The SDK is provided under the open-source license identified in Section 3 (Open-Source License); as between Subscriber and Proof, Proof retains all right, title, and interest in the SDK not expressly granted under that license, and Proof’s names, logos, and marks are not licensed under it.
  9. Indemnification. Subscriber agrees to indemnify, defend, and hold harmless Proof and its officers, directors, employees, agents, affiliates, successors, and assigns from and against any and all losses, damages, liabilities, deficiencies, claims, actions, judgments, settlements, interest, awards, penalties, fines, costs, or expenses of whatever kind, including attorneys’ fees, arising from or relating to: (a) Subscriber’s use or misuse of the API or the SDK; and (b) Applications, including any User’s use of Applications. Subscriber’s obligations under this Section 9 are conditioned on Proof: (a) giving prompt notice of the claim to Subscriber,(b) granting sole control of the defense or settlement of the claim to Subscriber, and (c) providing reasonable cooperation to the Subscriber at Subscriber's request and expense. Proof may participate in the claim’s defense at its sole cost and expense. Subscriber will not enter into any settlement that adversely affects Proof’s interests without prior written approval, not to be unreasonably withheld. Subscriber is not responsible for any settlement it does not approve in writing.
  10. Term and Termination. Proof may immediately terminate or suspend any rights granted herein, and/or Subscriber’s licenses under the Agreement, in Proof’s sole discretion at any time and for any reason, by providing notice to Subscriber or revoking access to the API or Subscriber’s production credentials. In addition, Proof may suspend access to the API immediately without any notice, if Subscriber violates any of the terms and conditions of the Agreement. Upon termination of the Agreement for any reason, all licenses and rights granted toSubscriber under the Agreement will also terminate and Subscriber must cease using, destroy, and permanently erase from all devices and systems Subscriber directly or indirectly controls all copies of the API and any related materials and API documentation. Notwithstanding the foregoing, Subscriber’s rights in the SDK code will continue to be governed by its open-source license; upon termination Subscriber must cease using the API, Proof’s endpoints, its production credentials, and the Proof Marks. Any terms that by their nature are intended to continue beyond the termination or expiration of the Agreement, will survive termination. Termination will not limit any of Proof’s rights or remedies at law or in equity.