Apova Developer Preview Terms
Version: developer-preview-v1
Effective date: September 15, 2026.
1. Parties and scope
These terms govern your use of the Apova developer portal, Agent Atlas ("Atlas") identity API and MCP interfaces, and any Developer Kit made available to you (together, the “Preview”). The Developer Kit consists of approved SDK code, documentation, references, and samples.
The provider is Apova Inc., incorporated in Delaware, at 1259 El Camino Real, Unit #1120, Menlo Park, CA 94025 (“Apova,” “we,” or “us”). “You” means the individual accepting these terms or the organization that individual is authorized to represent. You must be at least 18 and have authority to bind any organization on whose behalf you use the Preview.
Independent developers may apply in their individual capacity; representing an organization is not required. The input, credential, acceptable-use and integration responsibilities in these terms apply equally to individual and organizational users. Access remains subject to approval.
A later agreement signed by you and Apova, including a pilot agreement, data-processing agreement, master services agreement, order form or production agreement, governs the subject matter it expressly covers and controls over conflicting Preview Terms. These terms continue only for Preview activities not superseded by that agreement. Production use requires its own express agreement and provisioning; originating an account through the Preview does not make these terms the agreement for production execution. Product demonstrations or sales inquiries alone do not create developer access rights.
2. Accounts, approval and permitted access
Provide accurate account and organization information and keep it current. Verify your email before submitting an access request. Signup, email verification and acceptance of these terms do not guarantee approval or grant API access. Access begins only after Apova approves your request and completes provisioning. Legal assent, account/access approval, Atlas policy authorization and downstream execution authority are distinct; none alone confers the others.
Your permitted use is limited to the project, scopes, data mode, quotas and features assigned to your account. You are responsible for users you authorize, protecting credentials, and promptly reporting suspected compromise to legal@apova.ai. Do not share credentials with unauthorized people, place secrets in public code or model prompts, or use another project's resources.
3. Sandbox access and evaluation stages
The initial Preview is free, subject to enforced per-minute request budgets. Honor rate-limit responses and documented retry instructions. Do not evade limits by creating additional accounts, rotating identities, or distributing traffic across interfaces. API and MCP calls may share a budget.
The Developer Preview provides sandbox access for testing, integration and experimentation. The sandbox is non-production and does not authorize live business actions. Unless Apova separately approves a controlled real-data evaluation under the applicable agreement and required privacy controls, use synthetic test data only.
Sandbox describes the environment and permitted-use boundary; synthetic describes the default data rule. The service evaluates representative scenarios against accepted context and configured policy. The documented simulation mode governs execution; it does not mean that evaluation responses are canned.
The progression is:
- Sandbox evaluation: approved developers test representative scenarios using synthetic test data within assigned policies, scopes and budgets under these terms.
- Controlled real-data evaluation: separate approval of the testing scope, applicable agreement, privacy controls and success criteria. This does not automatically grant production access.
- Production: a separate contract, integration review and explicit production provisioning. That engagement defines its own execution responsibilities and controls.
Changes to supported interfaces and behavior are subject to the versioned contract and change process described here. Apova will identify versioned contract changes and provide migration guidance where practicable; this clause does not make undocumented breaking changes a normal integration practice. It is not a production service-level commitment. Apova may change limits or features with reasonable notice where practicable; urgent security or abuse controls may take effect immediately.
Paid service requires a separate affirmative agreement to pricing and applicable terms. Free access will not automatically create a paid subscription or authorize charges.
4. Evaluation and execution boundaries
The initial Preview evaluates scenarios within its documented simulation execution mode. It is not authorization to perform a live transaction or change a real account. Use only supported operations and follow their documented meanings and next steps.
The Atlas Sandbox Normative Reference, version atlas-sandbox-reference-v1, sections 1–4, is incorporated into these terms and defines the applicable Preview use, execution semantics, limits and required response handling. Tutorials, examples, marketing pages, changelogs and other explanatory material are informational unless expressly identified as incorporated. Linking to a page does not incorporate the entire developer website.
ALLOW is Atlas's policy determination that the evaluated action is permitted under the applicable configured policy and accepted context, subject to the documented evidence, mode, validity and execution-time checks. Within this simulation-only access, it does not authorize live execution or warrant the lawfulness, safety or outcome of a downstream transaction. You must satisfy the documented verification or review requirements associated with VERIFY or REVIEW; RESTRICT, DENY and pending results must not be treated as permission to execute the requested action. These legal boundaries preserve the versioned reference's meaning and do not expand access beyond the assigned mode.
An API credential authenticates a calling application or principal; it does not establish the end user's identity. Behavioral signals and generated output do not confer authority. You remain responsible for authenticating your users, checking the proposed target, protecting signing credentials, and enforcing authorization at your execution boundary.
You are responsible for the accuracy, completeness and lawful provenance of the context you supply, and for selecting or configuring policy and context where those choices are within your control. Submitted assertions must satisfy the documented evidence and verification requirements; an assertion does not become verified evidence merely because it appears in a request.
You are responsible for the application code, configuration, credentials, user access, submitted inputs and third-party dependencies you control; for interpreting responses according to the documented contract; and for downstream execution in your environment. Validate the integration, handle errors and retries, and enforce the applicable authorization, verification and human-review requirements before any consequential action. These operational responsibilities do not exclude Apova’s obligations for its own service or override the liability provisions below.
No Preview response alone authorizes a live transfer of funds, credential change, credit approval, account modification or other consequential action. This execution boundary does not change the documented meaning of ALLOW as permission under the configured policy and applicable mode; sandbox access remains non-production, with synthetic test data required unless controlled real-data evaluation is separately approved.
A trusted issuer's signature establishes attribution and binding, not the truth of assertions made by a compromised issuer. Do not rely on Atlas to independently cure that trust failure. Results may include false positives or false negatives because of incomplete context, evaluation variability, third-party system behavior or service interruptions. A result is not a guarantee that an identity, request or action is legitimate or safe. Apply controls appropriate to the consequences, including the documented execution-time checks. Results are not legal, financial, regulatory, or other professional advice.
5. Test data and permitted processing
Use synthetic API/MCP test data in the sandbox by default. Unless separately authorized under the controlled real-data evaluation arrangements described below, do not submit actual customer records, personal or regulated information (including Social Security numbers, protected health information, biometric templates, payment credentials or production bank data), passwords, private keys, access tokens, or confidential third-party material in test payloads. Account and contact information used to operate the portal is handled separately under the Privacy Notice.
Real-client testing requires Apova's separate written approval, applicable data-processing terms, and enabled privacy controls. A request flag cannot authorize that mode. You are responsible for having the rights, permissions and lawful basis needed to submit any approved data, including any necessary notices to affected people.
You retain your rights in data you submit. You authorize Apova and its contracted service providers to process that data only as needed to provide, secure, support and administer the agreed service, and as otherwise specifically authorized or legally required. This permission does not grant a general right to train on your data or to reuse payloads for unrelated product research. Operational debugging and abuse investigation must be limited to the service purpose and applicable retention window; they do not create an indefinite dataset license. Processing purposes, recipients and retention are described in the applicable privacy notice and any signed data-processing agreement.
6. Training and feedback
Ordinary API/MCP use and acceptance of these terms do not authorize Atlas training on your data. Categorical outcome feedback is not automatic training consent.
Any training participation requires a separate, explicit enrollment specifying the purpose, immutable dataset/version, provenance, privacy review, authorized retention period and approval. Changing the dataset or purpose requires new authorization. You may revoke a grant for future use through legal@apova.ai. Revocation does not promise that influence can be removed from models already trained; any treatment of derived artifacts must be specified in the separate enrollment before training starts.
General suggestions about the product may be used to improve it without compensation, excluding your confidential information, submitted payloads and personal data. A suggestion is not permission to repurpose an API dataset.
7. Acceptable use and security testing
Do not use the Preview unlawfully, impersonate others without authorization, attempt unauthorized access, extract another user's information, distribute malicious software, interfere with service availability, or circumvent technical controls. Do not use it to make live consequential decisions about individuals under this simulation access.
Synthetic adversarial prompts and security scenarios within your assigned test project are permitted for evaluating documented behavior. Infrastructure exploitation, denial-of-service testing, third-party targeting and attempts to extract secrets require a separately agreed testing scope. Report suspected vulnerabilities privately to legal@apova.ai.
8. Developer Kit license and intellectual property
Subject to these terms and your approved access, Apova grants you a limited, nonexclusive, nontransferable, non-sublicensable and revocable license during your authorized Preview access to download, reproduce internally, execute and modify the approved SDK and samples solely to evaluate and integrate the Preview for yourself or the organization you represent. You may not redistribute or publish the SDK or samples, sublicense them, or provide them as a service without Apova's separate written permission. Preserve applicable notices.
You retain ownership of your independently created application and integration code and your original modifications, subject to Apova's ownership of the underlying SDK, samples and other Apova technology. Interfacing with the Preview or modifying sample code does not by itself transfer your integration intellectual property to Apova. Ownership of modifications does not expand the permitted use or distribution of underlying Apova code.
Third-party components remain subject to their own licenses, which govern those components in the event of conflict. Apova retains rights in its service, software and documentation except for the express license above. No model weights, trademarks or unpublished interfaces are licensed by implication.
9. Confidentiality and publicity
Each party must protect the other's nonpublic information identified as confidential or reasonably understood to be confidential, using at least reasonable care and no less than the care used for its own comparable confidential information. Use it only for the Preview relationship and disclose it only to personnel and advisers who need it and are bound to protect it.
These obligations do not cover information already lawfully known without a confidentiality duty, public through no breach, independently developed, or rightfully received from another source without restriction. Legally compelled disclosures are permitted, with advance notice and reasonable assistance seeking protection where lawful and practicable.
The confidentiality obligations continue during this agreement and for three years after its termination. Trade secrets remain protected for as long as they qualify as trade secrets under applicable law.
Neither party may use the other's name or logo as an endorsement or announce a customer relationship without permission. Internal evaluation and benchmarking are permitted. Publishing benchmark results that identify Apova or Atlas, or publicly compare their performance, requires Apova's prior written consent, except where such a restriction is prohibited by applicable law. This does not prohibit otherwise permitted private security testing or protected disclosures.
10. Suspension, termination and data requests
You may stop using the Preview and request account closure through legal@apova.ai. Apova may immediately suspend, restrict or terminate affected access for security risk, suspected abuse, unauthorized use, legal or regulatory requirements, material breach, risk to Apova or others, or discontinuation of the Preview. Where appropriate and practicable, Apova will give notice and an opportunity to resolve remediable issues; prior notice is not required when immediate action is reasonably necessary.
Suspension or termination withdraws the affected API and download entitlements. Stop using affected credentials and, on termination, licensed Preview materials, except copies required by law or permitted by third-party licenses. Credential revocation cannot recall files already downloaded. Account closure and deletion requests are handled under the Privacy Notice and applicable agreements. Suspension or termination does not restart or extend data-retention periods.
11. Warranties, liability and indemnity
Apova is responsible for applying its documented service logic to the accepted inputs and applicable policy received by its service, subject to the Preview limitations and this section. An Apova-side policy application failure is not reclassified as a developer integration error. This allocation is not a warranty of error-free service or of any downstream transaction. Apova's express service, privacy and credential-handling commitments remain subject to their terms and applicable law.
To the extent permitted by law, the Preview is provided “as is” and “as available,” without warranties of accuracy, uninterrupted service, fitness for a particular purpose, merchantability or noninfringement. Preview risks include false positives and negatives, incomplete context, evaluation/model variability, third-party dependencies, interruptions and integration errors.
To the fullest extent permitted by applicable law, Apova is not liable for losses to the extent caused by your integration or use errors, including inaccurate or unauthorized inputs, mishandling credentials, misinterpreting documented responses, or failure to follow documented API, evidence, verification, authorization or execution requirements. This does not assign an Apova service failure to you.
To the maximum extent permitted by applicable law, Apova will not be liable for indirect, incidental, special, consequential, exemplary or punitive damages, or loss of profits, revenue, goodwill, business opportunity or data, arising from or relating to the Preview or these terms, regardless of the theory of liability and even if advised of the possibility of such loss.
To the maximum extent permitted by applicable law, Apova's aggregate liability arising from or relating to the Preview or these terms will not exceed the greater of (a) the fees you paid Apova for the Preview during the twelve months preceding the first event giving rise to the claims, or (b) US$100. This is an aggregate limit, not a separate allowance for each claim. No provision excludes or limits liability that cannot lawfully be excluded or limited. Free Preview access does not authorize future charges; any paid evaluation requires a separate agreement, subject to section 1.
You will defend Apova against third-party claims and indemnify it for resulting damages, settlements approved under this paragraph, and reasonable costs, to the extent caused by your submitted content or materials infringing third-party rights, your unlawful or unauthorized use of the Preview, or your application or integration violating law or another party's rights. This obligation excludes claims to the extent caused by the SDK or service itself, Apova's breach, or other conduct attributable to Apova.
Apova must promptly notify you of the claim and reasonably cooperate at your expense. A delay in notice relieves your obligation only to the extent it materially prejudices the defense. You control the defense using reasonably qualified counsel. You may not settle a claim in a way that requires an admission, obligation or non-monetary restriction from Apova without Apova's prior written consent.
12. Changes, disputes and general terms
Material changes to these terms or incorporated normative provisions require a new version, appropriate notice and reacceptance where required before continued use. Non-material documentation corrections may be made without reacceptance only if they do not change contractual rights, responsibilities or execution semantics. Apova will preserve accepted versions. A terms update does not retroactively enroll data in training or expand existing data permission.
California law governs these terms, without regard to conflict-of-law principles, subject to rights and laws that cannot be displaced by agreement. The parties consent to the exclusive jurisdiction of the state courts located in San Mateo County, California, and, where federal jurisdiction exists, the U.S. District Court for the Northern District of California, except where applicable law requires otherwise.
Before litigation, a party will give written notice of the dispute and the parties will attempt in good faith to resolve it for thirty days after receipt. Either party may seek urgent injunctive or equitable relief when appropriate, or file a proceeding needed to preserve a claim before a legal deadline. These terms do not impose arbitration or a class-action waiver.
Neither party may assign this agreement without the other's consent, except in connection with a merger, acquisition, corporate reorganization or sale of substantially all relevant assets to a successor that assumes the agreement. An individual developer has no corporate-successor exception. Any other attempted assignment without required consent is ineffective.
Send contractual notices to Apova at legal@apova.ai and, where formal mailed notice is required, Apova Inc., 1259 El Camino Real, Unit #1120, Menlo Park, CA 94025. Apova will send notices to your designated account/legal contact. Contractual notices take effect upon receipt. Routine product messages are not formal contractual notices unless expressly identified as such. Keep your designated contact information current.
Neither party is responsible for delay or failure caused by events beyond its reasonable control, provided it takes reasonable steps to mitigate the effect. This does not excuse obligations that remain performable or liabilities that cannot lawfully be excused.
Accrued obligations, ownership and continuing license restrictions, confidentiality for its stated duration, responsibility allocation, disclaimers, liability limitations, indemnity for pre-termination conduct, dispute provisions and provisions expressly stated to survive continue after termination to the extent relevant to their purpose. No right to continue using the Preview or Apova materials survives solely because a limitation or ownership provision survives.
These terms and their expressly incorporated provisions form the agreement for the Preview, subject to section 1's later-agreement precedence. If a provision is unenforceable, the remainder continues to the extent permitted by law. Failure to enforce a provision is not a waiver.
You will comply with applicable export-control and sanctions laws and will not use or provide access to the Preview where prohibited. Apova's access approval is not a representation that sanctions or export screening has occurred.
