Terms
What the service is
CodexMotiveShield connects to git repositories you nominate — on GitHub, GitLab, Azure DevOps or Bitbucket — clones them onto a temporary, isolated worker, and runs static analysis over the files. The worker is destroyed once the scan finishes. Nothing you scan is intentionally built, installed, or executed; the scanners read files, they don't run them.
On a paid Security Check, AI Review reads the finished scan's findings automatically and returns false-positive analysis, risk order and a combined fix prompt — see "AI Review" below for exactly what that does and doesn't involve.
It is an aid to your judgement, not a substitute for it. You remain responsible for what you ship — see "What we do not promise" and "Your responsibilities" below.
Accounts
You sign in through GitHub or Google. Today, an account belongs to one person, and that's who's responsible for what happens under it — keeping your sign-in secure, and everything done through your account whether or not you personally did it.
If you use the service for a business, the business is responsible for the account alongside the individual who controls it, and for making sure anyone it lets use that account follows these Terms.
We don't yet offer a self-serve plan with multiple seats or roles under one organisation — see the Team plan on the pricing page. When we do, this section will describe how responsibility is shared between an organisation and the people it authorises to use its account; until then, "your account" means the one person signed into it.
The free Security Check and any plan limit are counted the way the pricing page describes them: the free check per repository, a plan's monthly allowance per account. Using more than one account to get around either is a breach of "Acceptable use" below, not a separate rule here.
What you authorise
By connecting a repository, you represent and warrant that you're authorised to do all of the following, and that doing so doesn't violate any agreement, policy or law that applies to you:
- connect that repository to the service;
- give us the credential or token we need to access it;
- authorise us to access, clone and scan it;
- authorise the processing described in these Terms and the Privacy Policy of whatever information the repository contains — including sending a finished scan's findings for AI Review, when a paid plan bundles one in.
This matters most when a repository isn't entirely yours to give. If it belongs to an employer or client, contains a colleague's or a third party's proprietary code, or holds confidential or personal information you didn't put there yourself, you need whatever permission that situation requires before you connect it — an employer's policy allowing security tooling, a client engagement letter, a data-processing agreement, or similar. We don't ask to see that permission before a scan runs; connecting the repository is you telling us it exists, and you're responsible for that being true.
You may not connect a repository you're not authorised to submit. Running a Security Check against a repository, system, or organisation you don't have the right to test is also a breach of "Acceptable use" below.
This warranty is about your authority to hand us the repository. It isn't a warranty that we'll get everything right on our end once you have — that's what the rest of these Terms, and the Privacy Policy, commit to instead.
Your content
You keep every right you have in your source code, repository content, and anything else you submit to the service, including any prompts you write for it. Nothing in these Terms transfers ownership of any of it to us.
You grant us a limited licence — to access, copy, store and analyse what you submit, and to process it as needed — solely to run the scans and other features you've asked for, show you the results, and operate and improve the service. That licence ends when the corresponding project or account is deleted, subject to the backup handling described in the Privacy Policy.
We do not use your code, your findings, or your prompts to train any model of ours, and we do not sell them.
AI Review
AI Review is an optional capability bundled with certain paid Security Checks and plans — never with the free first check. When your plan includes it, it runs automatically once a scan finishes; there's nothing separate to turn on or pay for again.
It works from your scan's findings, not from your repository. We send the findings a completed Security Check already produced — not your source code — to Anthropic, our AI provider, so it can return false-positive analysis, a risk order, and a combined fix prompt. Because a finding has to point at something to be useful, a finding can include a short excerpt or identifier drawn from your repository; if one does, that fragment travels with it. A Security Check on its own, without AI Review, never reaches an AI provider.
It's a judgement, not a certainty. AI Review is probabilistic: it can misjudge which findings are real, order risk in a way you'd disagree with, or write a fix prompt that's incomplete, wrong for your codebase, or unsafe to apply as-is. You are responsible for reviewing and testing anything it suggests before you rely on it — see "What we do not promise" below.
What Anthropic does with the findings we send it is governed by Anthropic's own Commercial Terms of Service and Data Processing Addendum, not ours. As published today, Anthropic may not train its models on what we send it, and commits to deleting it within 30 days of that agreement ending. See the Privacy Policy for the complete picture, including what isn't yet confirmed about exactly where Anthropic processes it.
Reports, AI output and our intellectual property
Scan reports and findings
A report belongs to the scan that produced it, and you can use it the way you'd use any other output of your own development process: in your own security and development work, in an internal review, in a client engagement you're authorised to run, or as part of your own compliance documentation. Using a report that way, including sharing it with people who need it for that work, isn't something these Terms restrict.
What a report doesn't do is hand you rights in the thing that produced it. The scanners, detection rules, scoring, and the AI Review pipeline that generated the report stay entirely ours — see "Our intellectual property" below. You can use the output without owning, or acquiring any licence to, the system that made it.
AI-generated output
Fix prompts, risk ordering and false-positive analysis from AI Review are generated content, not a hand-authored work, and who owns AI-generated output is an unsettled question under Canadian and most other copyright law — we're not claiming a right we may not have, or promising you one we can't guarantee.
What we do give you: a non-exclusive, worldwide, royalty-free right to use AI Review's output for your own development, security and client work, the same way you'd use a report — subject to applicable law and to any rights a third party, including Anthropic, may hold in the underlying technology that generated it. That's a licence to use it, not a claim that you own it outright.
Our intellectual property
Everything that makes the service work — the scanners, detection rules, scoring and risk logic, the AI Review pipeline and prompts, the application, its interface, our documentation, our brand, and the infrastructure running all of it — is ours, or licensed to us. Using the service gives you a right to use it as intended; it doesn't give you any ownership or licence in the technology itself, beyond what this section and the two above already grant.
Confidentiality
Both sides can end up holding information the other doesn't want spread around — your repository and its contents on one side; how the service actually works, and anything we tell you about it that isn't public, on the other. This section covers that, on top of — not instead of — the Privacy Policy's rules for personal information.
Confidential information is anything either of us shares with the other that a reasonable person would understand to be non-public and sensitive, including your repository content and reports, and our product, security and business information. It doesn't include information that is or becomes public without breach of this section, that the receiving side already lawfully had, that it develops independently without using the other's confidential information, or that it lawfully receives from someone else with no duty of confidence.
Each of us will use the other's confidential information only to do what these Terms require or permit, protect it with reasonable care, and not disclose it except: to our own service providers who need it to help run the service, bound by confidentiality obligations at least as protective as this section; where a law, court or regulator requires it, giving notice first where we're legally allowed to; or with the other side's consent.
This section survives for as long as the information stays confidential, and in any case for 3 years after your account closes.
Acceptable use
Do not:
- scan a repository, system, or organisation you're not authorised to scan or test;
- attempt to access a repository, credential, or account you have no right to access;
- use the service to test systems that aren't yours and you have no clear authorisation to test;
- attempt to make the scanning environment build, install dependencies for, or execute code from a scanned repository — it's built not to, and trying to defeat that is a breach on its own;
- interfere with, overload, or attempt to bypass the limits, rate limits, or metering of the scanning infrastructure;
- share, sell, or use another person's or account's credentials, or create or use additional accounts for the purpose of circumventing plan limits, usage restrictions, promotional restrictions, or other controls;
- attempt to gain unauthorised access to our infrastructure, probe it for vulnerabilities without our prior written permission, or otherwise act in a way that threatens the security or availability of the service;
- reverse engineer the service, except to the extent applicable law gives you that right despite this restriction;
- resell, white-label, or offer the service or its output as a competing scanning or security-review service, or otherwise use it to build a product that competes with it.
That last one is about competing with us, not about using what you're entitled to. Nothing here stops you from using a report or AI Review output in your own development process, an internal security review, a client engagement you're authorised to run, or your own compliance work — see "Reports, AI output and our intellectual property" above.
We may suspend or terminate access for breaking this section — see "Suspension and termination" below.
Fees and subscriptions
Current prices, what each plan and pack includes, and exactly how many Security Checks and AI Reviews you get are on the pricing page, kept current there rather than restated here. If this section and the pricing page ever disagree about what a purchase included, the pricing page as it read when you paid controls — that's what you actually bought.
Stripe processes every payment. Checkout happens on Stripe's own hosted page, not ours — we receive confirmation of what you paid and what for, but never your card number itself. Stripe's own privacy policy and terms govern what it does with your payment details directly. Where sales tax, GST/HST, VAT or a similar tax applies, it's added at checkout before you pay.
One-off packs (Scan Pack, Fix Pack, Pro top-up) are single purchases — you're charged once, for what you bought. Pro is a subscription: it renews automatically every month, at the then-current price for your plan, until you cancel. Cancel any time, self-serve, from your account's billing portal — that stops future renewal charges; your Pro access, and any allowance already granted for the period you paid for, continues until that period ends. See "Refunds and cancellation" for what happens to money already paid.
If a renewal payment fails, we'll retry it automatically. Your access continues for 7 days from the failed charge while we do; if payment still hasn't gone through by then, your account is restricted to the free tier until it's resolved.
We may change prices for future purchases and future renewals. If a price change affects your Pro subscription, we'll tell you before it applies to your next renewal, so you have the chance to cancel first; it won't change what you already paid for a period or pack you already bought.
A payment reversed through a chargeback voids the credit it bought — see "Refunds and cancellation".
Refunds and cancellation
Security Checks and AI Reviews you bought and haven't used — Scan Pack, Fix Pack, or Pro top-up — are refundable for the unused portion if you ask within 14 days of that purchase. The free first check is never refundable; no money changed hands for it.
If applicable consumer-protection law gives you a right to withdraw from an online purchase within 14 days regardless of how much you've used, and you didn't validly give that right up at checkout, that fuller statutory right applies instead — a full refund of that purchase within the 14 days, whatever you've used. At checkout for a one-off pack, we ask you to expressly confirm you want immediate access and are giving up that 14-day withdrawal right for the units you use; where that confirmation is properly captured, the "unused portion" rule above applies. Where it isn't, or the law doesn't let you give the right up, the fuller statutory refund applies instead.
Pro subscription. Cancelling stops future renewal charges and your access continues to the end of the period you already paid for.
- Your first subscription period only: cancel within 14 days of your very first Pro charge, and we refund the smaller of (a) a day-based share of what you paid for the unused remainder of that period, or (b) the value of the Security Checks and AI Reviews you haven't used yet, priced at Pro's per-unit rate. We use the smaller of the two so this can't be used to keep most of a period's value by spending it fast and cancelling — see the boundary case this closes in the next paragraph.
- Renewal periods after that: not refunded unit by unit. If a renewal period was used for nothing at all, ask within 14 days of that renewal charge and we refund it in full. Use any part of it — even one Security Check — and that period isn't refunded, though cancelling still stops every charge after it.
- A monthly allowance itself never carries a per-unit refund or carry-over value — it's granted, not purchased, and doesn't roll over into the next period.
Unused Security Checks and AI Reviews you've paid for don't expire while your account stays open — that's true regardless of how long ago you bought them.
Closing your account refunds unused purchased credit bought in roughly the last 180 days; credit older than that is forfeited on closure, because our payment processor generally can't return a charge that old — this bound tracks what it can actually execute, not an arbitrary cutoff. The free check and any monthly Pro allowance have no cash value and are simply extinguished on closure either way. "Never expires" describes how long your credit works while your account is open; it isn't a promise about what closing that account gets you back, which is this paragraph instead.
A scan that fails for our reasons — our infrastructure, our scanner, or a bug on our side — doesn't consume a Security Check, and one already taken is returned. You don't pay for our outages. See "Scans that fail" below for what counts as ours versus yours.
Refund requests go through support, reviewed and actioned by a person rather than an automatic button, so it may take a short time to process. Filing a chargeback voids the credit tied to the disputed charge; it doesn't create a refund on top of the chargeback itself.
Nothing in this section limits any refund, cancellation, or cooling-off right that applies to you under mandatory law where you live. Where that law gives you more than this section does, it governs instead.
Service availability
The service is provided on an "as is" and "as available" basis. We don't promise it will be uninterrupted, error-free, or available at any particular time, and we don't currently offer a formal service-level agreement.
Availability can be affected by planned maintenance, an outage on our side, an outage at a provider we depend on — our hosting provider, your git provider, Anthropic, or Stripe — a scanner failing on a particular repository, rate limits (ours or a provider's), and changes we make to features as the product evolves. We'll fix what's in our control as quickly as we reasonably can; we're not responsible for an outage that starts on someone else's infrastructure.
Scans that fail
A scan that fails for our reasons doesn't consume a Security Check, and one already taken is returned — you don't pay for our outages. "Our reasons" means a failure caused by our infrastructure, our scanner, or a bug on our side.
It doesn't mean a scan that fails because your repository was unreachable or had been removed, your credentials were invalid, expired, or lacked the access the scan needed, your repository was too large or in a form we don't support, your repository was malformed in a way that broke the scan, or some other configuration issue on your side. Those consume the Security Check, because running the scan used real processing time regardless of the outcome — the same way a completed scan does.
Your responsibilities
- make sure you're authorised to connect and scan every repository you give us — see "What you authorise";
- keep your git provider account, and the credentials you give us, in good order — we can't scan a repository we can't reach;
- keep your own backups; we're not a backup service, for your repository or anything else;
- read what a report and AI Review actually say, rather than treating a clean result as a guarantee — see "What we do not promise";
- test any fix, prompt, or recommendation before you rely on it;
- decide, using your own judgement, whether your software is safe to deploy — that decision is always yours, not the service's;
- meet whatever laws, regulations and standards apply to the software you build, deploy and operate, independent of anything a scan says;
- treat CodexMotiveShield as one input to that judgement, not the only one.
What we do not promise
A clean report means nothing blocking was found, by these tools, on that commit. It is not a guarantee that your application is secure, and we will never describe it as one.
Static analysis finds what it has rules for. Our scanners cover a defined, and growing, set of vulnerability classes, credential formats and dependency ecosystems — see the pricing page for what's covered today — and anything outside that coverage isn't something a Security Check can find, by design, not by mistake. Every scanner also makes mistakes inside its coverage: it can flag something that isn't actually a problem (a false positive) and it can miss something that is (a false negative). Neither is a defect in the service; both are inherent to static analysis.
AI Review adds judgement, not certainty. It can misjudge which findings are real, get risk order wrong, or write a fix prompt that's incomplete or wrong for your specific code. Treat it as a second opinion, not a verdict.
You're responsible for independently reviewing every finding and recommendation, testing any fix before you rely on it, and deciding whether your software is safe to ship. We're not responsible for a vulnerability the service didn't detect, or for a decision you make based on a report or AI Review output without doing that review yourself.
The service is provided as-is — see "Service availability" above and "Liability" below.
Liability
To the extent the law allows, our total liability arising out of or related to these Terms or the service — however the claim is framed — is limited to what you paid us in the twelve months before the claim arose, and we are not liable for indirect, incidental, special or consequential loss, including lost profits, lost data, or a breach of your own application that a scan did not surface.
That cap and that exclusion do not apply to:
- amounts you owe us — this clause limits our liability to you, not your obligation to pay for what you've used;
- either side's breach of "Confidentiality" above, which is capped separately at the greater of $10,000 CAD or three times the fees you paid in the twelve months before the claim;
- your indemnification obligations under "Indemnification" below;
- fraud or fraudulent misrepresentation by either side;
- gross negligence or wilful misconduct by either side;
- death or personal injury caused by either side's negligence;
- anything else that cannot lawfully be excluded or limited where you're located.
If you're a consumer under mandatory law that gives you rights or remedies this section can't limit, this section doesn't limit them — it applies only to the extent that law allows.
Indemnification
You'll indemnify and hold us harmless from a third-party claim, and the reasonable costs of defending it, arising from: connecting or authorising a repository you weren't entitled to submit; your violation of a law that applies to you; your breach of these Terms, including "Acceptable use"; your infringement of a third party's intellectual property or other rights through content you submitted or authorised us to process; or your misuse of the service.
This doesn't cover a claim arising from our breach of these Terms, or our gross negligence or wilful misconduct — that's on us, and "Liability" above addresses it instead.
Suspension and termination
We may suspend your access immediately, without prior notice, where necessary to protect the service, other customers, or us — for example, a security threat, active abuse of the scanning infrastructure, payment fraud, or conduct that risks another customer's data or access. Where the issue doesn't require immediate action, we'll tell you what's wrong and give you a reasonable chance to fix it before suspending.
We may suspend or terminate an account for breaking "Acceptable use", illegal activity, a security threat to the service or another customer, payment fraud or persistent non-payment, or an attempt to compromise our infrastructure. We'll tell you why, except where doing so would itself create a security or legal problem.
You can close your account at any time from Settings. Closing it, or our terminating it, deletes your projects, scan history, and stored repository credentials from our active systems, as described in the Privacy Policy — that's not reversible.
Terminating for a breach on your side doesn't, on its own, entitle you to a refund of what you've already paid beyond what "Refunds and cancellation" already gives you — a breach on your part isn't the account-closure scenario that section describes. Nothing here overrides a refund right the law gives you regardless of why the account closed.
If we ever discontinue the service entirely, we'll give at least 30 days' notice where we reasonably can, so you have a chance to get your reports and history before it shuts down.
Data and privacy
Personal information is handled the way the Privacy Policy describes, not this document — read it for what we collect, why, how long we keep it, and your rights over it.
Your repository can contain personal information — about your users, or people named in code, commits, or issues — as well as your own or someone else's confidential or proprietary information. Connecting it authorises the processing described in the Privacy Policy and in "What you authorise" above; the Privacy Policy is where we describe what actually happens to that information once it reaches us.
Governing law and disputes
These Terms are governed by the laws of Ontario, Canada, without regard to its conflict-of-law rules, and any claim not resolved informally may be brought in the courts of Ontario, Canada, which each of us accepts as an appropriate venue.
If you're a consumer and the mandatory law of the country, state or province where you live gives you rights, protections, or a choice of forum that this section can't override, this section applies only to the extent that law allows, and those protections still apply.
General terms
Entire agreement. These Terms, the Privacy Policy, and what the pricing page says about a specific plan or pack are the whole agreement between us about the service; they replace any earlier understanding about it.
Order of precedence. Where these Terms and the Privacy Policy conflict about handling personal information, the Privacy Policy controls. Where these Terms and the pricing page conflict about what a plan or pack includes, the pricing page as it read when you bought it controls. Anywhere else these documents conflict, these Terms control.
Severability. If a court finds part of these Terms unenforceable, the rest stays in effect, and that part is read to be enforceable to the narrowest extent the court will allow.
No waiver. Not enforcing part of these Terms once doesn't give up our right to enforce it later.
Assignment. We may assign or transfer these Terms in connection with a merger, acquisition, or sale of all or substantially all of our assets. You may not assign these Terms without our consent, except to a successor of your business in a similar transaction.
Force majeure. Neither of us is liable for a delay or failure caused by something reasonably beyond our control — including an outage at a provider we depend on, a natural disaster, war, or a change in law.
Relationship of the parties. We're independent parties dealing with each other at arm's length. Nothing here creates a partnership, joint venture, agency, or employment relationship between us.
Notices. We'll send notices to the email address on your account, or post them in the product or on this page. You can reach us at info@codexmotive.com or through support.
Survival. Sections that by their nature should outlast these Terms — including "Your content", "Reports, AI output and our intellectual property", "Confidentiality", "Liability", "Indemnification", "Governing law and disputes", and this section — survive termination or account closure.
Electronic acceptance. Creating an account, or otherwise using the service, means you've read and agreed to these Terms.
Changes to these terms
We may update these Terms as the service changes. If a change is material, we'll tell you before it takes effect — by posting a notice on this page and, where practical, by email or an in-product notice. The date at the top always reflects the current version.
If you keep using the service after a change takes effect, that use means you accept it. If you're a Pro subscriber and don't agree with a material change, we won't apply it to your subscription until your next renewal, so you have a real chance to cancel first rather than being bound the moment we post it.
Contact
CodexMotive Digital Solutions, registered in Ontario, Canada, at 206 Candlewood Cres. Unit 1, Waterloo, ON N2L 5Y9. Enquiries: info@codexmotive.com, or through support.