Skip to main content

Terms and Conditions

By using SECUTIX APIs, you implicitly agree to the following terms and conditions.

Fair Usage​

Integrators and third parties must use the SECUTIX APIs responsibly and within the limits defined in this documentation — in particular the rate limits and usage plans applicable to your integration. Usage must not negatively impact the performance, security, or availability of the SECUTIX platform.

Security Testing​

Integrators and third parties must not perform load testing, stress testing, or security penetration testing against any SECUTIX environment — production or non-production — unless they have both:

  1. Notified SECUTIX at least 10 business days in advance, and
  2. Received explicit written approval.

Approved testing is limited to the environment, scope, and time window set out in that approval. Testing of your own systems is unaffected, provided the resulting traffic to SECUTIX environments stays within your normal usage limits.

Reporting a Security Vulnerability​

The restriction above targets active, unsolicited testing. It does not prohibit the good-faith reporting of security vulnerabilities that are passively observed or incidentally discovered in the normal course of integration.

Report such findings through our customer portal, or by email to api@secutix.com, as soon as you become aware of them and before disclosing them to anyone else.

Where a vulnerability is reported in good faith, SECUTIX will not treat the discovery or the report as a breach of these terms, and will not pursue legal action or restrict your API access on that basis, provided that you:

  • Stop as soon as you identify the issue, and do not probe further to establish its extent
  • Do not access, modify, delete, or retain data belonging to any other party, and do not use any personal data you encounter
  • Do not degrade the availability or integrity of any SECUTIX environment
  • Keep the finding confidential until SECUTIX has had a reasonable opportunity to remediate it

These protections cover the conduct described above; they do not otherwise limit the consequences set out under Compliance.

Data Privacy and Security​

SECUTIX APIs must not be used to store, process, or transmit sensitive personal data beyond what is strictly required for the supported use cases. Integrators are responsible for ensuring that all data exchanged with the platform complies with applicable legal and regulatory requirements.

Cookies​

Once you are granted access to the documentation, we set a cookie in your browser to track which pages you visit. This helps us understand which parts of the documentation are most useful to our users, so we can improve it. This cookie is not used for advertising or any other purpose, and we do not share it with third parties.

By submitting the access request form, you consent to this cookie.

API Evolution and Decommissioning​

SECUTIX reserves the right to evolve its APIs at any time as part of ongoing product improvement with respect to the versioning policies explained on this website.

SECUTIX may decommission any version of any API with a minimum 6-month prior notice, except in cases where earlier decommissioning is required for urgent security or compliance reasons.

Compliance​

Failure to comply with these terms may result in throttling, access restrictions, or suspension of API credentials — subject to the protections described under Reporting a Security Vulnerability.