Legal
Terms of Use
Effective date: July 12, 2026.
1. Parties and Service Provider Information
These Terms of Use govern the use of the agentbouncer.io website, the AgentBouncer software service, its API, SDK, documentation, dashboard, analytics, and other related features, hereinafter collectively referred to as the “Service.”
The owner and provider of the Service is individual entrepreneur Alexey Sharapov, Primary State Registration Number of Individual Entrepreneur (OGRNIP) 325774600322644, Taxpayer Identification Number (IN) 773001860255, hereinafter referred to as the “Provider,” “we,” “us,” or “our.” Email: hello@agentbouncer.io.
An individual or legal entity using the Service is hereinafter referred to as the “User” or the “Client.” If the Service is used on behalf of an organization or an individual entrepreneur, the person accepting these Terms confirms that they have the appropriate authority to do so.
2. Acceptance of the Terms
By registering an account, creating an API key, connecting an SDK or API, submitting requests to the Service, or using its results, the User confirms that they have read and accepted these Terms.
If the User does not agree to these Terms, they must not register for or use the Service.
The use of certain features may be governed by additional documentation, technical limitations, or a separate agreement. In the event of a conflict, the terms of a separate written agreement shall prevail.
3. Definitions
“Verification” means the automated processing of a submitted request to verify a cryptographic signature, time parameters, key identifier, information about the purported provider or agent, and other technical attributes.
“Decision” means a technical result generated by the Service that may contain verified, allowed, or trusted indicators, a risk level, the reason for the decision, information about the matched rule, and other parameters.
“Access Policy” means rules configured by the Client or provided by the Service and used to generate a recommendation to allow or reject a request.
“API Key” means a secret identifier that enables access to the Service API on behalf of the Client’s account or project.
4. Purpose and Features of the Service
AgentBouncer is intended for the technical verification of requests from AI agents, bots, and other automated clients, including the verification of HTTP message signatures, identification of the purported sender, and application of access policies.
The Service may provide a REST API, SDKs, a dashboard, an event log, statistics, and tools for configuring projects, keys, and access rules.
The Service may use public key directories, JWKS, provider information, technical signals, request frequency, event history, and other parameters for verification and risk assessment.
The available features may change during development. The description of a feature in the documentation does not guarantee its continued availability.
5. Public Beta
As of the effective date of these Terms, the Service is provided as a public beta and, unless otherwise separately agreed, free of charge.
The beta version may contain errors, incomplete features, limitations, inaccurate results, and changes that break backward compatibility.
We may introduce request limits, restrict the number of projects and API keys, temporarily disable certain features, and modify the API, SDKs, and response formats, while endeavoring to reflect material changes in the documentation where reasonably possible.
The User must not use the beta version as the sole protection mechanism for systems in which an error could result in substantial damage, unauthorized payments, data loss, or a breach of mandatory requirements.
6. User Account
Account registration is required to use certain features.
The User must provide accurate information and keep it up to date.
The User is responsible for actions performed through their account, except where such actions occurred due to the Provider’s fault.
If the User suspects that their account has been compromised, they must change their credentials and notify us at hello@agentbouncer.io.
7. API Keys and Credentials
API keys, tokens, and other secret data must be kept confidential and must not be placed in public repositories, client-side JavaScript, mobile applications, or other publicly accessible locations.
The User is responsible for requests made using an API key issued to them unless the key was compromised due to the Provider’s fault.
Upon discovering a leak, the User must immediately revoke or replace the relevant key.
We may block an API key if we suspect a leak, abuse, exceeded limits, a security threat, or a breach of these Terms.
8. Integration and Operation
The Client is solely responsible for integrating the Service with its website, API, MCP server, application, or other information system.
Before using the Service in a production environment, the Client must test the integration, error handling, timeouts, Service unavailability, and ambiguous results.
The Client must ensure that its system behaves securely when AgentBouncer is unavailable and independently determine whether, in such a case, a request should be allowed, rejected, or referred for additional review.
The Client is responsible for the correctness of its own access rules, endpoint configuration, key storage, result verification, and any subsequent actions taken by its system.
9. Verifications, Assessments, and Decisions
Verified, allowed, trusted, risk score, reputation, and similar results are technical assessments based on the data available to the Service and the configured rules.
A positive result does not guarantee that a request is safe, useful, lawful, or genuinely reflects the intent of a particular individual or legal entity.
A negative result does not guarantee that a request is malicious or fraudulent. False-positive and false-negative results are possible.
The final decision regarding granting access, performing an operation, transferring data, making a payment, or invoking a tool is made by the Client and its information system.
10. Technical Analytics
The Service may log verification events, including the request time, project, endpoint, IP address, signature headers, keyid, purported provider or agent, action, tool, verification result, rule, risk level, and technical errors.
The Client must minimize the data transmitted and must not submit request content, personal data, or confidential information to the API unless such data is required for the relevant verification.
Event statistics and classifications may be incomplete or inaccurate and are provided for informational and technical purposes.
11. Acceptable Use
The User must use the Service lawfully, in good faith, and in accordance with the documentation.
The Service must not be used for unauthorized access, attacks, circumvention of restrictions, creation of malicious payloads, testing of stolen keys, phishing, distribution of malicious code, or infringement of third-party rights.
Users must not interfere with the operation of the Service, investigate its vulnerabilities without written permission, circumvent limits, resell access without prior approval, or attempt to access other clients’ data.
We may restrict or terminate access in the event of a breach of this section, a threat to the infrastructure, or the need to prevent harm.
12. Third-Party Sources and Providers
The Service may use third-party providers of hosting, databases, monitoring, email, authentication, infrastructure protection, and other technology services.
Verification may depend on the availability and accuracy of public key directories, JWKS, and other resources controlled by third parties.
We are not responsible for the unavailability, errors, format changes, or inaccuracy of information received from independent third-party sources, but we take reasonable measures to maintain the reliable operation of the Service.
13. Security
We implement reasonable technical and organizational measures to protect the Service, accounts, and processed data.
No internet service or cryptographic mechanism provides absolute protection against all possible threats.
The Client is solely responsible for protecting its servers, APIs, MCP tools, databases, secrets, API keys, and backup authentication mechanisms.
Suspected vulnerabilities or incidents should be reported to hello@agentbouncer.io without publicly disclosing the relevant information until a reasonable period has been provided to resolve the issue.
14. Personal Data
The rules governing the processing of personal data are described in the Personal Data Processing Policy published on the website.
With respect to account and agentbouncer.io visitor data, the Provider generally acts as the personal data controller.
If the Client transmits third parties’ personal data through an integration, the Client is responsible for having a lawful basis for such transmission, informing the data subjects, and complying with applicable law.
The User must not transmit special categories of personal data, biometric data, payment details, passwords, or other sensitive information unless this is expressly provided for by a specific feature and a written agreement.
15. Possible Introduction of Paid Features
As of the effective date of these Terms, the publicly available beta version is provided free of charge unless otherwise separately agreed with a specific Client.
In the future, we may introduce paid plans, subscriptions, limits, usage-based charges, and additional services.
The introduction of a paid model does not require the User to make any payment without separately accepting a plan or placing an order.
The currency, price, taxes, payment procedure, currency conversion, and refund terms will be specified in the plans, payment interface, invoice, offer, or separate agreement. Until payments are enabled, provisions concerning exchange rates do not apply.
16. Intellectual Property
Exclusive rights to the Service, software code, design, documentation, texts, logos, and other materials belong to the Provider or the respective rights holders.
The User is granted a limited, non-exclusive, and non-transferable right to use the Service in accordance with these Terms.
Rights to the Client’s data, software, rules, and materials remain with the Client or the respective rights holders.
The terms of use for SDKs and other open-source components may additionally be governed by the license published in the relevant repository.
17. Confidentiality
Each party agrees to take reasonable measures to protect the other party’s non-public information.
Confidential information may be used to provide the Service, deliver support, maintain security, perform contractual obligations, and comply with the law.
Information is not considered confidential if it was lawfully known to the recipient, became publicly available without a breach, or was independently developed without using the other party’s information.
18. Disclaimer of Warranties
The Service, particularly during beta testing, is provided “as is” and “as available.”
We do not guarantee uninterrupted operation, freedom from errors, preservation of backward compatibility, absolute verification accuracy, or detection of all fraudulent and malicious requests.
The Service does not replace a comprehensive authentication, authorization, antifraud, rate-limiting, or WAF system, security audits, or the Client’s internal procedures.
Information and results provided by the Service do not constitute legal, financial, or professional advice.
19. Limitation of Liability
To the extent permitted by law, the Provider is not liable for indirect damages, loss of profits, loss of data, downtime, erroneous approval or rejection of a request, or actions of third parties.
For the free beta version, the Provider’s aggregate liability is limited to documented actual damages not exceeding RUB 10,000, unless mandatory provisions of law require otherwise.
The limitations in this section do not apply where liability cannot be limited by agreement between the parties. The rights of individuals using the Service for personal purposes are also governed by mandatory consumer protection laws.
20. Suspension and Termination of Access
The User may stop using the Service at any time.
We may suspend access in the event of a breach of these Terms, a security threat, abuse, exceeded limits, technical necessity, or a requirement from a competent authority.
We may discontinue beta testing or the operation of the Service, in whole or in part, by notifying users in a reasonable manner where such notification is possible.
After access is terminated, data will be deleted or anonymized in accordance with the Personal Data Processing Policy and mandatory legal requirements.
21. Governing Law
These Terms are governed by the laws of the Russian Federation unless mandatory provisions of applicable law require otherwise.
Nothing in these Terms limits any rights that cannot be limited by contract.
22. Dispute Resolution
Before initiating court proceedings, the parties will endeavor to resolve the dispute through negotiations and the submission of a written claim.
The response period for a claim is 30 calendar days unless a different period is established by mandatory provisions of law.
Disputes shall be considered by a court of competent jurisdiction in accordance with applicable law. The jurisdiction provision does not restrict a consumer’s right to bring a claim before a court at a location permitted under consumer protection law.
23. Changes to the Terms
We may update these Terms as the Service develops and legislation changes.
The current version and its effective date will be published on agentbouncer.io.
If a change materially affects the rights of registered users, we may additionally notify them through the Service interface or by email.
24. Contact Information
For questions regarding these Terms, please contact us at hello@agentbouncer.io.