Terms
Short, and specific about the one thing that matters most: a clean scan is not a certificate. It is a report on what twenty-two checks could reach.
Last updated 4 September 2026
What you are agreeing to
By running a scan you confirm that you own the repository, or that you have permission from whoever does. Scanning code you have no right to read is not something we can check for you, and it is not something we will defend.
What the scan is
Twenty-two checks run against your code history, your delivered files and — when you supply them — your live site and your database. A review pass then removes findings it judges to be false positives and writes the rest in plain English. You get a grade derived from the confirmed findings by a published formula.
What the scan is not
It is not a penetration test, an audit, a certification, or a guarantee. Two limits are worth stating plainly:
- A check that could not run is reported as not assessed. It is never counted as a pass, and you should not read it as one.
- Twenty-two checks are twenty-two checks. A grade of A means those twenty-two found nothing they could confirm — not that your application is secure.
Read-only by default
We clone and read. Nothing is written back to your repository unless you explicitly use the pull request option and supply your own write token. Even then we only push a new branch and open a pull request: we never push to your default branch, never force-push, and never merge. You review and merge, or you do not.
What we charge
The scan, the grade, the counts and one full critical finding are free. The full report is a one-time $35. There is no subscription and no renewal. [[REAL PROOF NEEDED: the refund policy and its window]]
Fixes
Where we generate a fix, it is applied to our own clone and the originating check is re-run against it. A fix is marked verified only by that re-run, never by the thing that wrote it. Verified means the check no longer fires. It does not mean the change is right for your application, and you are expected to read a patch before you merge it.
Availability and liability
The service is provided as it is, without warranty. We will not be liable for a vulnerability we did not find, for one we found and you did not fix, or for anything arising from a change you merged. [[REAL PROOF NEEDED: the liability cap and the governing law]]
The rest
How we handle what we read is set out in full on the privacy page. [[REAL PROOF NEEDED: the contracting legal entity and its registered address]]
Questions about anything on this page: start a scan or write to the address in the footer.