Legal
Terms of Service
These Terms of Service govern access to and use of Fromenance, the communication provenance service operated by Many Software Enterprises LLC. Institutions that sign an order form or pilot agreement are bound by these terms as incorporated there; visitors to fromenance.com are bound by sections 1, 2, 12, and 14 through 17.
- Effective date:
- Provider:
- Many Software Enterprises LLC, a Delaware limited liability company (manyent.com)
1. Parties and agreement
"Provider", "we", or "us" means Many Software Enterprises LLC, a Delaware limited liability company. "Customer" or "you" means the institution identified on an order form, pilot agreement, or account registration. "Service" means the Fromenance platform: the API, the admin application, the verify inbox and verify page components, the documentation, and related support. These terms, the applicable order form, and theData Processing Addendum together form the agreement. If they conflict, the order form controls, then the DPA, then these terms.
2. The service
The service lets Customer register outbound communications at send time and lets Customer's own customers ("End Users") ask whether a communication came from Customer by forwarding it to a Customer controlled address or submitting it on a Customer controlled page. The service returns one of three verdicts: Verified, Not verified, or Known fraud, as defined in the documentation. We may improve or modify the service, and we will not materially reduce its core functionality during a paid term without notice.
3. Accounts and access
Customer is responsible for the users it invites, the roles it assigns, the API keys and site keys it issues, and all activity under its account. Customer must keep credentials confidential, use the roles the service provides to limit access, and notify us at security@fromenance.com promptly of any unauthorized use. Test API keys write to a sandbox partition and never send replies to real End User addresses.
4. Customer obligations
Customer will:
- Own or control every domain it adds to the service and publish the DNS trust record for it;
- Configure its verify address to redirect messages to the service in a way that preserves the End User as sender, and keep that configuration working;
- Register only communications it actually sent, and not register communications on behalf of third parties without authority;
- Compute recipient hashes with the secret we issue and never transmit raw recipient addresses on the registration API;
- Provide End Users the privacy notices required by law for the verification feature, using the descriptions in our Privacy Policy and DPA as needed;
- Use reply templates that keep the locked verdict block intact;
- Review analyst overrides and fraud list entries with reasonable care, since they change verdicts for later End Users.
5. Verdicts and verdict language
A verdict is a statement about Customer's registry: that a registered communication matches the submission, that no registered communication matches, or that the submission matches fraud Customer's analysts confirmed. A verdict is not a representation that a communication is harmless, and the service never describes a message in those terms. "Not verified" means no record and does not assert fraud. Customer acknowledges that verdict accuracy depends on the completeness of Customer's registration ("coverage"), and that the "we did not send this" wording (Authoritative Mode) is enabled by us only after coverage review and may be disabled by us if coverage falls. Customer is responsible for what it tells End Users beyond the locked verdict block.
6. Acceptable use
Customer will not, and will not permit anyone to:
- Use the service to send unsolicited mail, to harvest addresses, or to register communications the recipient did not agree to receive;
- Submit messages to another tenant's verify address or page in an attempt to manipulate that tenant's fraud list or intelligence;
- Probe, scan, or test the service for vulnerabilities except under our responsible disclosure terms, and never against tenant data;
- Reverse engineer the service, resell it, or use it to build a competing communication provenance service;
- Circumvent rate limits, origin checks, or bot protection on the public verify endpoint;
- Use the service in violation of law, including privacy, anti spam, and financial regulation applicable to Customer.
We may suspend access that we reasonably believe violates this section, with notice where practicable.
7. Customer data
Customer owns Customer Data: registrations, submissions, verdicts, indicators, fraud list entries, templates, configuration, and exports. Customer grants us a license to process Customer Data to provide, secure, and improve the service and as described in the DPA. We may derive and use indicators (such as domains, URLs, and phone numbers extracted from suspicious messages) and aggregate, de-identified statistics across tenants to detect campaigns and improve the service, provided that submissions, message content, End User identifiers, and tenant identities are never disclosed to other tenants. Customer may export Customer Data at any time through the admin application and the API, and we delete it within 30 days after termination except as retained in backups for a further limited period or as required by law.
8. Fees and payment
Fees are stated on the order form: an annual fee banded by protected customers, an optional intelligence tier, and, for pilots, a fixed pilot fee credited to the first annual contract. Fees are invoiced through Stripe annually or quarterly as stated on the order form, are due within 30 days of invoice, and are non refundable except as expressly stated. Registrations and verifications are metered for reporting and fair use, not billed per unit. Taxes are Customer's responsibility except taxes on our income. We may charge interest on late amounts at 1 percent per month or the maximum lawful rate, whichever is lower, and may suspend the service after 15 days' written notice of non payment.
9. Term and termination
The agreement runs for the term on the order form and renews for successive one year terms unless either party gives 60 days' notice before renewal. Either party may terminate for material breach uncured 30 days after written notice, or immediately if the other party becomes insolvent. On termination Customer's access ends, Customer may export Customer Data during a 30 day wind down, and sections 5, 7, 10 through 12, and 14 through 17 survive.
10. Confidentiality
Each party will protect the other's non public information with at least reasonable care, use it only for the agreement, and disclose it only to personnel and contractors who need it and are bound by similar obligations, or as required by law with notice where permitted. Customer Data is Customer's confidential information. The service's non public design, pricing, and security details are ours.
11. Intellectual property
We own the service, the documentation, the SDK, and all improvements. Customer receives a non exclusive, non transferable right to use them during the term for its own institution. Feedback may be used by us without obligation. Customer's names and marks stay Customer's; we will not use them publicly without written consent.
12. Warranties and disclaimers
We warrant that the service will perform materially as described in the documentation and that we will provide it with reasonable skill and care. Customer's exclusive remedy for breach of this warranty is for us to correct the non conformity or, if we cannot, to refund prepaid fees for the affected period. EXCEPT AS EXPRESSLY STATED, THE SERVICE IS PROVIDED "AS IS" AND WE DISCLAIM ALL OTHER WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON INFRINGEMENT. WE DO NOT WARRANT THAT THE SERVICE WILL DETECT EVERY IMPERSONATION, THAT EVERY LEGITIMATE COMMUNICATION WILL VERIFY, OR THAT END USERS WILL ACT ON VERDICTS. Verdicts depend on Customer's registration coverage and End Users' forwarding behavior, which we do not control.
13. Indemnification
We will defend Customer against third party claims that the service, used as permitted, infringes a United States patent, copyright, or trademark, and pay resulting damages and costs finally awarded, provided Customer notifies us promptly and gives us control of the defense. We may modify or replace the service to avoid infringement or terminate and refund prepaid fees for the remaining term. Customer will defend us against third party claims arising from Customer Data, Customer's communications to End Users, or Customer's breach of section 4 or 6, on the same conditions.
14. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, OR DATA, ARISING OUT OF THE AGREEMENT, EVEN IF ADVISED OF THEIR POSSIBILITY. EACH PARTY'S TOTAL LIABILITY ARISING OUT OF THE AGREEMENT WILL NOT EXCEED THE FEES PAID OR PAYABLE BY CUSTOMER IN THE TWELVE MONTHS BEFORE THE EVENT GIVING RISE TO THE CLAIM. THESE LIMITS DO NOT APPLY TO A PARTY'S INDEMNIFICATION OBLIGATIONS, BREACH OF CONFIDENTIALITY, OR LIABILITY THAT CANNOT BE LIMITED BY LAW. For clarity, we are not liable for losses an End User suffers by acting on a message, whether or not it was submitted for verification, except to the extent caused by our breach of the agreement.
15. Governing law and disputes
The agreement is governed by the laws of the State of Delaware without regard to its conflict of laws rules. The state and federal courts located in Delaware have exclusive jurisdiction, and each party consents to that jurisdiction and venue. Before filing suit, the parties will attempt in good faith to resolve any dispute through discussion between executives for 30 days. Nothing prevents either party from seeking injunctive relief for misuse of its confidential information or intellectual property.
16. Changes to these terms
We may update these terms by posting a new version with a new effective date. For Customers under a paid term, changes take effect at the next renewal unless required sooner by law, and we will notify tenant administrators by email at least 30 days before. Continued use of fromenance.com after a change means acceptance for website visitors.
17. General
The agreement is the entire agreement on its subject. Neither party may assign it without consent except to a successor of substantially all its business. Notices to us go to legal@fromenance.com; notices to Customer go to the tenant owner's email. Neither party is liable for delays caused by events beyond its reasonable control. If a provision is unenforceable it is modified to the minimum extent necessary and the rest remains in effect. The parties are independent contractors. Waivers must be in writing.
18. Contact
Legal: legal@fromenance.com. Privacy: privacy@fromenance.com. Security: security@fromenance.com.