Vailar AI
Developers · API

API Terms of Service

Rules of engagement for developers building on the Vailar AI API.

Version · v1.0.0Last updated · May 2026Effective · May 2026REST · GraphQLEnterprise-grade
01

Scope

These API Terms govern your use of Vailar AI's REST and GraphQL APIs, SDKs, webhooks and developer documentation. They are in addition to the main Terms of Service and any applicable Enterprise Agreement.

02

Authentication

  • Use API keys or OAuth credentials issued through the developer dashboard
  • Keep credentials secret and never embed them in public client code
  • Rotate credentials promptly on suspected compromise
  • Scope keys to minimum required permissions and environments
03

Rate limits

API usage is subject to per-key and per-account rate limits to protect platform stability. Limits are returned in standard response headers and may be increased for enterprise customers via order form.

  • Respect rate-limit headers and back off on 429 responses
  • Use exponential backoff with jitter on retries
  • Cache responses where appropriate
04

Prohibited automation

  • No scraping or bulk extraction beyond your authorized account data
  • No use to train, distill or replicate Vailar AI models
  • No circumvention of rate limits, quotas or platform safeguards
  • No use to facilitate spam, phishing, fraud or abuse
  • No use that violates applicable laws or third-party rights
05

Developer responsibilities

  • Implement strong authentication and access controls in your application
  • Validate and sanitize all input passed to the API
  • Disclose your data practices clearly to your end users
  • Honor end-user deletion and access requests routed through your application
06

Security requirements

  • Use TLS 1.2+ for all API requests
  • Store credentials and tokens in secure secret management
  • Log only the minimum necessary metadata; never log raw secrets or PHI
  • Promptly report suspected security issues to security@vailarai.com
07

Usage monitoring

Vailar AI monitors API usage for abuse, fraud, security threats and platform stability. Aggregated and de-identified telemetry may be used to improve the service.

08

Suspension and termination

Vailar AI may throttle, suspend or revoke API access at any time to protect the platform or other users, with notice where reasonably possible. Material or repeated violations may result in termination of API access and the underlying account.

09

API changes

We aim to evolve the API responsibly. Breaking changes are versioned and announced in advance via the developer changelog. Beta endpoints are provided as-is and may change without notice.

Get in touch

For questions about this document, reach our legal team.

developers@vailarai.com

Revision history

Every update to this document is logged to support compliance and audit needs.

VersionDateSummary of changes
v1.0.0May 2026Initial publication of this document.

Current version v1.0.0 · Effective May 2026 · Last updated May 2026

Ready to elevate every consultation?

See how Vailar AI runs in real clinics — request a tailored walkthrough.