1. Acceptance of Terms
These Terms of Service ("Terms") constitute a legally binding agreement between you ("Customer", "you", or "your") and Cyfendo Inc. ("Cyfendo", "we", "us", or "our"), governing your access to and use of the Cyfendo web platform, CLI tooling, APIs, and automated security scanning services (collectively, the "Services").
By registering an account, connecting a repository, or using the Services, you represent that you have the authority to bind yourself or your organization to these Terms.
2. Description of Services
Cyfendo provides autonomous application security scanning, vulnerability discovery, taint-path analysis, and review-ready remediation patch generation for software codebases. The Services analyze codebases to identify potential security defects across standard Common Weakness Enumeration (CWE) categories.
3. Intellectual Property & Code Ownership
Customer Retains All Ownership: Customer exclusively owns all right, title, and interest in and to Customer's source code, repositories, configuration files, and software artifacts. Cyfendo claims no ownership rights over Customer code.
License to Process: Customer grants Cyfendo a limited, non-exclusive, non-transferable, revocable license solely to access, parse, and analyze Customer code as necessary to deliver the security scanning and remediation services requested by Customer.
4. Generated Patches & Developer-in-the-Loop Governance
Cyfendo may generate proposed code patches, unified diffs, and remediation suggestions to assist developers in resolving discovered vulnerabilities.
- Human Review Required: All generated code patches are recommendations intended for human developer review. Customer agrees that Customer developers retain sole responsibility for reviewing, testing, approving, and merging any code changes.
- No Direct Production Modification: Cyfendo does not unilaterally merge code or alter production runtime environments without authorized developer interaction.
5. Subscriptions, Pricing & Protected LOC
Paid plans are billed on a recurring subscription basis based on the volume of active protected Lines of Code (LOC) in Customer's monitored repositories.
- Protected LOC Calculation: Protected LOC represents non-generated, actively scanned application source code. Generated files, vendored dependencies, blank lines, and repeated scan executions do not consume additional LOC allowances.
- Scan Frequency & Allowances: Subscriptions include monthly security scan allowances designated by plan tier. Re-scans of unchanged codebase snapshots consume 0 scan credits. Fair-use provisions apply to prevent abnormal or abusive automated workloads.
6. Acceptable Use Policy
Customer agrees to use the Services only on source code and systems that Customer owns or is explicitly authorized to audit. Customer shall not use the Services to generate malicious exploits for unauthorized systems or conduct denial-of-service attacks against third parties.
7. Warranty Disclaimer & Limitation of Liability
While Cyfendo strives for high sensitivity and low false-positive rates, automated static and dynamic security analysis cannot guarantee the identification of 100% of all potential security vulnerabilities in arbitrary software codebases. The Services are provided "as is" and "as available" without warranties of any kind, whether express or implied.
To the maximum extent permitted by applicable law, neither party shall be liable for indirect, incidental, consequential, special, or punitive damages arising from the use of the Services.
8. Termination & Governing Law
Either party may terminate a subscription at the conclusion of the active billing period. Upon account closure, Customer repository metadata and cached scan records are purged in accordance with our data retention schedule.
These Terms shall be governed by and construed in accordance with the laws of the State of Delaware, without regard to conflict of law principles.
For questions regarding these Terms, please contact legal@cyfendo.com.