Last Updated: September 18, 2026
These Bitsight API and MCP Terms of Use (these "API Terms") are incorporated into and form part of the agreement between Bitsight and Customer that governs Customer's use of the Bitsight products and services (the "Agreement"). These API Terms apply to Customer's use of Bitsight's API and any MCP functionality as further described below, in connection with the Agreement and the applicable Order. Capitalized terms used but not defined in these API Terms have the meanings given to them in the Agreement.
By clicking to accept these API Terms, or by otherwise indicating acceptance or accessing or using the API or any Customer MCP Integrations, the individual doing so represents and warrants that: (a) they have all authority, rights, consents, and permissions necessary to accept these API Terms and to legally bind Customer to them; and (b) Customer is bound by these API Terms as a result. If the individual accepting does not have such authority, or Customer does not agree to these API Terms, the individual must not accept these API Terms and neither the individual nor Customer may access or use the API or any Customer MCP Integrations.
1. DEFINITIONS
1.1 In these API Terms, the following definitions apply:
"Access Credentials" means any credentials, API keys, tokens, secrets, certificates, or other authentication mechanisms issued to Customer for use of the API;
"API" means Bitsight-provided programmatic web APIs, software, interface definitions, generated code libraries, technical documentation, and associated functionalities made available by Bitsight that enable Customer to access or interact with certain Bitsight Data, datasets, information, content, systems, or integrations made available through the Services;
"Breaking Change" means a backwards incompatible update that materially disrupts Customer's existing integration or materially removes previously available functionality;
"Customer MCP Integrations" means any customer-created or customer-operated Model Context Protocol ("MCP") servers, MCP clients, connectors, artificial intelligence ("AI") agents, orchestration frameworks, prompts, workflows, vector databases, retrieval systems, automation tools, external AI platforms or inference solutions, such as large language model ("LLM") vendors, or related integrations that interact with the API or Bitsight Data;
"Material Action" means any operation initiated through the API or any Customer MCP Integration that: (a) writes to, modifies, deletes, or otherwise changes any data or configuration within Customer systems or third-party systems connected by Customer; (b) invokes credentialed actions (including use of Customer or third-party access tokens, secrets, or service principals); (c) triggers transactions, notifications to external parties, or system changes that are not easily reversible; or (d) accesses or transmits Customer Confidential Information to any third-party system outside Customer's controlled tenant. For avoidance of doubt, read-only retrieval of Bitsight Data is not a Material Action;
"Non-Breaking Change" means any update, modification, enhancement, security update, or operational change that does not materially disrupt existing functionality;
"Security Incident" means the loss or unauthorized destruction, alteration, disclosure of, access to, or control of Customer's systems, operational technology systems, networks, internet-enabled applications, or the data contained within such systems that affects the Services;
"Service Telemetry" means telemetry, logs, and operational metadata generated by Customer's use of the API and Customer MCP Integrations, including but not limited to: request and response timestamps, authentication method and pseudonymous identifier, endpoint and method invoked, scope and tool identifiers, request size and rate-limit signals, execution status and error codes, and performance metrics.
2. API AND MCP SCOPE
2.1 API Scope: Customer's use of the API and any Customer MCP Integrations must comply with the Documentation. Bitsight may monitor Customer's use of the API and Customer MCP Integrations to ensure compliance with the Agreement (including these API Terms), maintain security and integrity of the Services, prevent misuse, and protect Bitsight Data and systems.
2.2 Customer-Controlled MCP Environments: Customer acknowledges that any Customer MCP Integrations are solely controlled by Customer and not by Bitsight. Customer is solely responsible for the design, configuration, operation, monitoring, security, legality, and outputs of any Customer MCP Integrations and for ensuring that such systems comply with applicable law and the Agreement. Bitsight is not responsible for outages, changes, or security events originating from Customer MCP Integrations or third-party providers.
2.3 Unless expressly authorized in writing by Bitsight, Customer MCP Integrations may access Bitsight Data solely on a read-only basis and may not modify Bitsight systems, alter Bitsight Data, execute transactions, or initiate actions within Bitsight environments.
3. ACCESS CREDENTIALS AND AUTHENTICATION
3.1 Customer shall:
- (a) maintain industry-standard administrative, technical, and physical safeguards to protect Access Credentials;
- (b) implement per-user or dedicated service principal authentication for all API and Customer MCP Integrations, ensuring that (i) human users authenticate exclusively via individual flows and may not share credentials or authenticate on behalf of automated systems and (ii) non-human and automated callers authenticate exclusively via scoped service principals and may not utilize human user credentials;
- (c) use multi-factor authentication where supported;
- (d) restrict Access Credentials to authorized personnel and approved systems solely for purposes authorized under the Agreement and prohibit the sharing of API keys or tokens across users or systems;
- (e) maintain attribution to an identified user or service identity for each request;
- (f) immediately revoke or rotate compromised credentials;
- (g) promptly notify Bitsight of any actual or reasonably suspected unauthorized access, misuse, compromise, or Security Incident involving the API, Customer MCP Integrations, or Access Credentials; and
- (h) not embed, store, log, or transmit Access Credentials within AI prompts, model context windows, training datasets, vector databases, or retrieval-augmented generation ("RAG") systems.
3.2 Customer may not sell, sublicense, disclose, distribute, or otherwise make Access Credentials available to any third party except authorized contractors operating on Customer's behalf that are not competitors of Bitsight and subject to written confidentiality and security obligations no less protective than those contained herein.
3.3 Bitsight may require the use of specific supported authentication methods as described in the Documentation.
3.4 Customer is fully responsible for all activities conducted using its Access Credentials, including activities conducted by AI agents, automation tools, subprocessors, contractors, Managed Security Service Providers ("MSSPs"), or integrated systems.
4. MCP-SPECIFIC SECURITY AND GOVERNANCE REQUIREMENTS
4.1 Customer Responsibilities: Customer acknowledges that Customer MCP Integrations may enable AI systems, applications, or agents to retrieve, process, generate, or act upon data dynamically. Accordingly, Customer shall:
- (a) ensure that any Material Actions initiated through Customer MCP Integrations is approval-gated by a human reviewer designated by Customer prior to execution, and that approval workflows, including approver identity, timestamp, requested scope, and executed scope, are recorded in audit logs;
- (b) ensure that read operations are logically and technically separated from write-capable operations;
- (c) validate outputs before use in operational, legal, compliance, investigative, or security decisions;
- (d) maintain commercially reasonable safeguards consistent with industry security standards against prompt injection attacks, privilege escalation, unauthorized tool execution, hallucinated outputs, and data exfiltration, and any additional safeguards that may be required by the Documentation;
- (e) ensure connected AI systems are configured to follow least-privilege access principles;
- (f) maintain audit logs sufficient to identify actions taken through Customer MCP Integrations and make such logs available to Bitsight upon reasonable written request in connection with a security incident or compliance investigation; and
- (g) ensure that any third party, MSSP, contractor, AI provider, or downstream system accessing the API or Bitsight Data through Customer MCP Integrations is bound by written obligations no less protective than those contained herein.
4.2 AI Outputs: Customer acknowledges that AI-generated outputs may be probabilistic and may contain inaccuracies. Customer remains solely responsible for verifying the accuracy, legality, appropriateness, and security of any outputs, recommendation, workflow, or action generated through Customer MCP Integrations. Customer may not use Bitsight Data to create or share AI-generated outputs that violate these API Terms, the Agreement, or any third-party agreement or policies. Bitsight does not develop, control, monitor, or validate Customer-created AI models, prompts, workflows, or outputs and disclaims responsibility for Customer AI-generated outputs, decisions, actions, or downstream processing activities.
4.3 Automated Decision Making: Customer shall comply with all applicable laws and regulations governing automated decision-making, profiling, and AI systems in connection with any use of Bitsight Data in Customer MCP Integrations. Customer shall not use Bitsight Data as a factor in any automated decision that has a legal or similarly significant effect on any individual or entity without implementing appropriate human review, fairness assessment, and disclosure obligations required by applicable law. Customer shall promptly notify Bitsight of any regulatory inquiry, investigation, or enforcement action relating to Customer's use of Bitsight Data in AI or automated decision-making systems.
5. API MODIFICATIONS
5.1 API Modifications: Bitsight reserves the right to modify the Services, API, technical specifications, security requirements, and Documentation. Customer may be required to use the most current version of the API to continue using the Services. Bitsight will use commercially reasonable efforts to provide at least thirty (30) days' notice of Breaking Changes to generally available API endpoints, together with migration guidance where applicable. Non-Breaking Changes may be implemented with or without notice.
5.2 Emergency Changes: Bitsight may implement immediate changes without prior notice where necessary to:
- (a) maintain security or integrity of the Services;
- (b) respond to legal or regulatory requirements;
- (c) address vulnerabilities, abuse, or threats; or
- (d) prevent harm to Bitsight, customers, third parties, or systems.
5.3 Bitsight will provide notice as soon as practicable thereafter.
6. USAGE LIMITATIONS
6.1 Usage Limits: Customer's use of the API, Customer MCP Integrations, and related Services is subject to the usage limits, technical restrictions, and security requirements specified in the Documentation or applicable Order Form, including any rate limits, token limits, concurrency limits, or monthly usage quotas established by Bitsight from time to time. Bitsight may monitor Customer's use of the API and Customer MCP Integrations to ensure compliance with the Agreement, maintain platform security and integrity, prevent abuse, and protect Bitsight Data and systems.
6.2 Prohibited Activities: In addition to any restrictions contained in the Agreement, Customer shall not, and shall not permit any third party (e.g. MSSP, AI provider), AI agent, automated process, downstream system, directly or indirectly to:
- (a) exceed, circumvent, disable, or otherwise interfere with usage limitations, authentication controls, monitoring mechanisms, or security protections applicable to the API;
- (b) use the API in a manner that generates excessive, abusive, disruptive, or unreasonable request volumes or otherwise adversely impacts the availability, performance, integrity, or security of the Services;
- (c) scrape, harvest, replicate, or systematically extract Bitsight Data except as expressly authorized by Bitsight;
- (d) use the API, Customer MCP Integrations, or Bitsight Data to train, fine-tune, improve, benchmark, or otherwise develop any generalized, shared, or multi-tenant artificial intelligence or machine learning models without Bitsight's prior written consent;
- (e) incorporate Bitsight Data into shared or multi-tenant AI systems, reusable training datasets, cross-customer retrieval environments, or generalized AI knowledge bases (e.g., use Bitsight Data in a non-enterprise LLM);
- (f) operate autonomous or unsupervised agents that execute Material Actions without human approval;
- (g) permit unauthorized retrieval, retention, caching, indexing, scraping, replication, exfiltration, or downstream redistribution of Bitsight Data;
- (h) use the API or Customer MCP Integrations in connection with autonomous or unsupervised actions that could reasonably create legal, operational, cybersecurity, or compliance risk;
- (i) introduce malicious code, prompt injection attacks, adversarial inputs, unauthorized tool execution, or other harmful or disruptive activity into the Services or connected systems; and
- (j) persist, store, or retain Bitsight Data — whether in raw form, as vector embeddings, in RAG index stores, in AI model fine-tuning datasets, or in any other derived form — beyond the term of the applicable Order or the period necessary for the authorized purpose for which it was retrieved, whichever is shorter, except as required by law.
6.3 Suspension Rights: Bitsight may suspend, throttle, restrict, or terminate access to the API where Bitsight reasonably determines that Customer's use violates the Agreement, involves prohibited automated activity or unsafe AI behavior, poses a security risk, threatens the integrity or availability of the Services, or could expose Bitsight Data, systems, customers, or third parties to harm.
7. BITSIGHT OBLIGATIONS
7.1 Use of Service Telemetry: Bitsight may collect and process Service Telemetry. Service Telemetry will not include Customer Confidential Information other than incidental inclusion in technical headers or fields necessary for routing and security, which Bitsight will minimize and not use for model training. Bitsight may use Service Telemetry solely to provide, secure, support, monitor, and improve the reliability and performance of the Services, to enforce usage limits and security controls, and to comply with law. Bitsight may use aggregated, de-identified Service Telemetry to operate, secure, prevent abuse of, and improve the reliability and performance of the Services. Service Telemetry used for service improvement will be aggregated and de-identified so it does not identify Customer, a User, or Customer Confidential Information. Customer shall maintain its own audit logs sufficient to trace actions executed via Customer MCP Integrations for at least 90 days.
7.2 Limitations on Training: Bitsight will not use Customer Confidential Information or Customer-provided content accessed through the API to train, retrain, or improve any generalized or multi-tenant AI or machine learning models without Customer's prior written agreement.
8. SECURITY INCIDENTS AND COOPERATION
8.1 Customer shall notify Bitsight without any undue delay, and no later than 24 hours after discovery, in the event of any:
- (a) actual unauthorized access to or use of the API, Bitsight Data, or Customer MCP Integrations;
- (b) Security Incident involving Customer systems that could impact the Services;
- (c) misuse of Customer MCP Integrations; and
- (d) AI-related safety issue, prompt injection attack, or unauthorized automated action involving the API or Bitsight Data.
8.2 Customer shall: (a) preserve all logs, forensic evidence, and records relating to the incident for a minimum of 12 months; (b) to the extent possible, include known indicators, affected credentials or scopes, preliminary root cause, and containment steps in any notice; (c) implement reasonable containment measures promptly upon discovery; (d) cooperate fully with Bitsight's investigation, including providing access to relevant audit logs and system records upon request; and (e) not make any public statement regarding the incident that references Bitsight without Bitsight's prior written approval.
9. AUDIT
9.1 Upon reasonable written notice, Bitsight may, by itself or through an independent third party, audit Customer's use of the Services to verify compliance with these API Terms. Customer shall maintain complete and accurate books, logs, and other records with respect to Customer's use of the Services sufficient to verify compliance with these API Terms and provide reasonable access to such records for the purpose of conducting these audits.
10. INDEMNIFICATION
10.1 Customer Indemnity: Customer shall defend, indemnify, and hold harmless Bitsight and its affiliates, officers, directors, employees, and agents from and against any third-party claims, damages, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of or relating to: (a) Customer's operation, configuration, or outputs of any Customer MCP Integration; (b) Customer's use of Bitsight Data in any AI, automated decision-making, or machine learning system; (c) Customer's breach of these API Terms; or (d) any legal or regulatory violation arising from Customer's AI use of Bitsight Data. Customer's indemnity under these API Terms is subject to the Agreement's limitation of liability provisions.