API Terms of Service
Licence, credentials, integration, data use, security and enforcement
Provider: "WEB SOLUTIONS" LLC («ՎԵԲ ՍՈԼՅՈՒՇՆՍ» ՍՊԸ)
Legal address: 11/1, Apt. 14/1, Adonts Street, Arabkir, Yerevan, Republic of Armenia
Effective date: 5 August 2026
Version: 2.0
IMPORTANT: This document forms part of the binding agreement governing use of amlkyc.tech, its dashboard, reports, applications, bots, APIs and related services.
1. Scope and precedence
These API Terms govern access to AMLKYC APIs, SDKs, webhooks, documentation, sandbox and credentials. They supplement the Terms of Use. A signed enterprise agreement controls over these API Terms only to the extent of an express conflict.
2. Licence and credentials
Subject to payment and compliance, Provider grants a limited, non-exclusive, non-transferable, non-sublicensable, revocable licence to call the API and display or use results within Customer’s authorised internal product or workflow. API keys are confidential and may be used only by the assigned environment/account. Customer must use secret storage, least privilege, TLS, rotation and access logging and must never embed secret keys in public client code or repositories.
3. Integration requirements
- Follow current documentation, schemas, authentication, rate limits, idempotency and network requirements.
- Validate inputs and outputs, handle errors/timeouts safely, verify webhook signatures and prevent replay.
- Do not infer success from a timeout; use documented status/idempotency methods before retrying billable requests.
- Maintain human review and fallback procedures for material compliance decisions.
- Promptly install security or breaking-version updates within announced timelines.
4. Limits, metering and overages
Provider may enforce quotas, concurrency and rate limits and may throttle or reject excessive calls. Provider records are authoritative for billing absent manifest error. Retries, invalid requests and asynchronous processing may consume credits where documentation or pricing states. Customer must not split accounts, rotate keys or use proxies to evade limits.
5. Data and privacy
Customer is controller of personal data it submits and instructs Provider to process it to deliver and secure the API, unless the parties agree otherwise. Customer must provide notices, lawful bases and data-subject mechanisms and must minimise inputs. Customer must not send private keys, seed phrases, passwords, full payment-card data or unsupported special-category data.
6. Output restrictions
- Do not sell, publish, scrape, bulk-export or build a substitute/competing database from raw outputs.
- Do not expose scores or allegations publicly or to unauthorised persons.
- Do not remove proprietary notices or misrepresent an output as your own regulatory certification.
- Caching is allowed only as documented or reasonably necessary for the integrated workflow and must respect retention, security and deletion duties.
- Derived internal decisions may be retained as required by law, but underlying Provider data remains subject to licence limits.
7. Changes, versions and deprecation
Provider may add, change or deprecate endpoints. For planned breaking changes to generally available versions, Provider aims to give at least 30 days’ notice, and 90 days where reasonably practicable. Immediate changes may be made for security, legal requirements, third-party dependencies or abuse. Customer is responsible for monitoring notices and maintaining supported integrations.
8. Security and vulnerabilities
Customer must notify Provider immediately of leaked keys, unauthorised calls or vulnerabilities and cooperate in containment. Provider may rotate or revoke credentials without prior notice where necessary. Customer may conduct security testing only with written authorisation and must not access other users’ data, disrupt service or publicly disclose before coordinated remediation.
9. Audit and enforcement
Provider may review usage records and reasonably request information to verify compliance. Provider may throttle, suspend or terminate API access for abuse, security risk, prohibited use, sanctions/AML risk, non-payment or legal necessity. Customer remains liable for authorised and unauthorised usage resulting from failure to safeguard credentials until notice and reasonable revocation time.
10. Intellectual property and feedback
Provider retains all rights in the API, SDKs, documentation, models, taxonomies, datasets and improvements. Customer retains its application and submitted data. Feedback may be used without restriction. No licence is granted to Provider marks except a separate written brand permission.
11. Disclaimers, liability and termination
API data and outputs have the limitations stated in the AML Disclaimer and are provided “as is” and “as available”. The disclaimers, liability cap, indemnity, governing law and dispute provisions in the Terms of Use apply. On termination, Customer must stop calls, delete keys and cease use of restricted Provider data, subject to lawful archival records.
Contact and notices
support@amlkyc.tech
The AMLKYC app — checks at your fingertips
Check addresses and transactions from your phone: Telegram bot, RuStore and App Store.
Have a question? Write to us
Fill in the form and we will get back to you.