API Terms of Use

UM-AI API Terms of Use

Effective date: May 26, 2026(Version 1.0)

These terms apply to all API integrations with the UM-AI platform (umgpt.ai). By accessing or using the API you confirm that you have read, understood, and agreed to be bound by these terms on behalf of your organization. Trust Center

1. Parties and Scope

This API Terms of Use ("Terms") is entered into between SSP Development LLC d/b/a UM-AI ("UM-AI," "we," "us") and the organization that has been issued API credentials ("Client," "you"). These Terms govern programmatic access to the UM-AI platform via its REST API (the "API") and supplement any executed API Integration Agreement or Master Services Agreement between the parties.

2. Permitted Use

The API may be used solely for healthcare-related utilization management (UM) workflows within the Client's own systems. Specifically permitted uses include:

  • Submitting medical referral requests and receiving AI-generated UM determinations.
  • Submitting imaging orders for prior authorization evaluation.
  • Integrating UM-AI follow-up intelligence into clinical workflow tools.
  • Building internal dashboards or EHR-embedded panels that surface UM-AI results.

Any use outside the foregoing — including resale of raw API output to third parties, training competing AI models on UM-AI responses, or using the API for non-clinical automation — requires prior written approval from UM-AI.

3. Credentials & Security

Clients are issued an asymmetric Ed25519 credential pair. The private key is displayed once at issuance and must be stored securely by the Client.

  • Credentials must not be shared, embedded in public repositories, or transmitted in plaintext.
  • Each credential is tied to a single Client account; sharing across accounts is prohibited.
  • Compromised credentials must be reported to api-support@umgpt.ai immediately. UM-AI will revoke and reissue upon verification.
  • UM-AI reserves the right to revoke credentials without notice upon evidence of misuse, abuse, or security risk.

4. Rate Limits & Quotas

Each Client account is subject to per-minute and monthly call limits established at account creation. These limits are displayed in the onboarding pack and the API portal.

  • Requests exceeding the per-minute limit will receive HTTP 429 responses.
  • Requests exceeding the monthly quota will be blocked until the quota resets or is upgraded.
  • Attempts to circumvent limits through multiple accounts or credential rotation are prohibited.
  • Quota increases may be requested via api-support@umgpt.ai.

5. Protected Health Information (PHI) & HIPAA

UM-AI operates as a HIPAA Business Associate where applicable. If Client submits PHI through the API:

  • A signed Business Associate Agreement (BAA) must be in place prior to transmitting PHI. Contact privacy@umgpt.ai to execute a BAA.
  • PHI must be limited to the minimum necessary for the clinical service requested.
  • UM-AI does not store raw request bodies in audit logs. Only request metadata (timestamps, endpoint, status code, latency) is retained.
  • Audit logs are retained for a minimum of seven (7) years per 45 CFR §164.316(b)(2)(i).
  • Client is responsible for ensuring their integration complies with applicable HIPAA requirements on the Client side.

6. Webhooks

UM-AI may deliver asynchronous event notifications to a Client-provided HTTPS webhook URL. Webhook payloads are signed with HMAC-SHA256 using a per-client signing secret. Clients must:

  • Verify the X-UMAI-Signature-256 header before processing any payload.
  • Respond to webhook deliveries with HTTP 2xx within 10 seconds.
  • Ensure their webhook endpoint is accessible via HTTPS with a valid TLS certificate.

UM-AI will retry failed webhook deliveries up to five (5) times with exponential back-off. Persistent failures may result in webhook suspension.

7. Clinical Disclaimer

UM-AI's AI-generated utilization management determinations are advisory only. They are not a substitute for independent clinical judgment by a licensed healthcare professional. Specifically:

  • Final authorization, denial, or modification decisions must be made by appropriately licensed clinicians in accordance with applicable law and payer guidelines.
  • UM-AI makes no warranty, express or implied, that any particular determination is medically correct, compliant with payer contracts, or appropriate for any specific patient.
  • Client assumes full responsibility for the clinical and administrative consequences of all decisions made using UM-AI output.

8. Service Level Agreement

  • Uptime target: 99.5% monthly API availability (excluding scheduled maintenance).
  • Response time target: p95 < 4 seconds for synchronous evaluation endpoints.
  • Status page: https://umgpt.ai/status
  • Scheduled maintenance: notified at least 24 hours in advance via email and status page.
  • Service credits are available for significant uptime failures; contact api-support@umgpt.ai within 30 days of the incident.

9. Billing

API usage is billed on a metered basis per successful API call, at the rates specified in the Client's pricing agreement. Unless otherwise agreed:

  • Billing occurs monthly via the Stripe payment method on file.
  • Invoices are available in the API portal under Billing → Invoices.
  • Disputed charges must be raised within 60 days of the invoice date.
  • Past-due accounts may have API access suspended after 15 days.

10. Intellectual Property

UM-AI retains all intellectual property rights in the API, its responses, models, and documentation. Client receives a limited, non-exclusive, non-transferable license to use the API solely as described in these Terms. No rights to UM-AI's AI models, training data, or underlying systems are conveyed.

11. Limitation of Liability

To the fullest extent permitted by applicable law, UM-AI's aggregate liability arising from or relating to this Agreement — regardless of the form of action — shall not exceed the total fees paid by Client in the three (3) months preceding the claim. UM-AI shall not be liable for indirect, incidental, special, consequential, or punitive damages, even if advised of the possibility of such damages.

12. Term & Termination

  • These Terms are effective from the date of credential issuance and continue until terminated.
  • Either party may terminate with 30 days' written notice.
  • UM-AI may suspend or terminate access immediately for: material breach, non-payment, security incident caused by Client, or violation of prohibited uses.
  • Sections 5, 7, 10, 11, and 13 survive termination.

13. Governing Law

These Terms are governed by the laws of the State of Florida, United States, without regard to conflicts-of-law principles. Disputes not resolved within 30 days of written notice shall be submitted to binding arbitration under the AAA Commercial Arbitration Rules, conducted in English in Miami, Florida.

14. Contact

API Portal & Documentation

Existing API clients can access credentials, usage metrics, invoices, and full documentation in the API portal.

umgpt.ai/api-portal