1. Agreement

These Terms govern your use of SecureVault API ("the Service"), operated by DennisCreatives Data Solutions Ltd ("we", "us"). By registering an account or using an API key, you agree to these Terms.

2. The Service

SecureVault API provides envelope-encrypted storage of data you submit via our REST API, along with authentication, key rotation, and audit logging features. You are responsible for what you choose to store.

Early-stage service, read before storing anything critical. SecureVault API has not yet undergone independent third-party security audit or penetration testing. It is provided on an as-is, best-effort basis. Evaluate carefully before relying on it for regulated, highly sensitive, or business-critical data, and consider it alongside — not necessarily instead of — other safeguards you already use.

3. Your account

  • You're responsible for keeping your password and API keys confidential. Treat a leaked API key as a security incident — revoke it immediately via DELETE /v1/apikeys/{id}.
  • You must provide a valid email address and are responsible for activity that happens under your account.
  • We strongly recommend enabling multi-factor authentication (/v1/auth/mfa/enroll).

4. Acceptable use

You may not use the Service to:

  • Store or transmit unlawful content, malware, or material that infringes others' rights.
  • Attempt to circumvent rate limits, probe for vulnerabilities without authorization, or disrupt the Service for other users.
  • Use the Service in a way that violates applicable data protection law for the data you're storing (e.g. storing regulated health or financial data without appropriate safeguards on your end).

We reserve the right to suspend accounts that violate these terms.

5. Plans and billing

The Free tier is provided at no cost, subject to the request limits described on our pricing page. Paid tiers (Basic, Pro, Enterprise) are billed as arranged directly with us — currently by manual invoice pending completion of automated M-Pesa billing. Prices are quoted in Kenyan Shillings and may change with notice.

6. Availability

We aim for high availability but do not currently guarantee a specific uptime SLA outside of Enterprise agreements. Scheduled maintenance will be communicated where practical.

7. Limitation of liability

To the maximum extent permitted by law, the Service is provided "as is" without warranties of any kind, express or implied. DennisCreatives Data Solutions Ltd will not be liable for indirect, incidental, or consequential damages arising from use of the Service, including loss of data, except where such liability cannot be excluded under Kenyan law.

You remain responsible for maintaining your own backups of critical data stored through the Service.

8. Termination

You may close your account at any time by contacting us. We may suspend or terminate accounts that violate these Terms, with notice where reasonably possible. Upon termination, stored data may be deleted after a reasonable grace period.

9. Governing law

These Terms are governed by the laws of Kenya. Any disputes will be subject to the exclusive jurisdiction of the courts of Kenya.

10. Changes to these Terms

We may update these Terms from time to time. Material changes will be reflected by updating the date above. Continued use of the Service after a change constitutes acceptance.

11. Contact

DennisCreatives Data Solutions Ltd · Nairobi, Kenya
[email protected]

This document was drafted to be clear and reasonable, but it is not a substitute for advice from a Kenyan-qualified lawyer — particularly given this Service handles encrypted user data. Consider a legal review before relying on these Terms commercially.