Legal
Read this before relying on any AtRisk scan result, Finding, fix prompt, monitor alert, MCP response, CI gate output, or free-tool result.
Last updated: September 9, 2026 · Effective: September 9, 2026
AtRisk is an automated informational service. Scan results, Findings, severity labels, evidence snippets, fix prompts, digests, report artifacts, SARIF/CI gate results, MCP responses, and free-tool Outputs are not a substitute for professional security, legal, compliance, or engineering advice.
Your use of the Services does not create an attorney-client, consultant, cybersecurity- professional, fiduciary, or other professional relationship with AtRisk. Communications with support are operational, not advisory engagements.
We use commercially reasonable efforts to provide useful, up-to-date information. The Services rely on automated software, third-party data, AI models, and heuristics that may be incomplete, outdated, or wrong. False positives and false negatives occur. You are solely responsible for independently verifying any information before relying on it.
AtRisk is an automated remote scanner and repository analysis layer. It does not perform exhaustive manual review, business-logic testing, authenticated deep penetration testing, formal compliance audits, or certification against SOC 2, ISO 27001, PCI DSS, or similar standards unless a feature expressly states otherwise.
Nothing on the Services constitutes legal advice, regulatory guidance, or an opinion on the legality, suitability, or compliance of any system, product, or practice. Consult qualified counsel for legal or compliance decisions.
AtRisk does not authorize you to scan any system you do not own or for which you lack explicit authorization. You are solely responsible for ensuring every scan you initiate is lawful. See our Acceptable Use Policy and Terms of Service.
Portions of the Services use large language models and other AI systems to polish fix prompts, summarize Findings, or generate free-tool results. AI output may hallucinate, omit context, or suggest insecure changes. Review all Outputs before applying them.
The Services may incorporate or link to third-party sources (for example OSV, GitHub, model providers, Polar checkout). We do not control and are not responsible for third-party content, availability, or practices.
Any decision, code change, configuration change, remediation, deployment, client report, or other action based on the Services is made entirely by you. Suggested fixes may introduce defects, break functionality, or create new security issues. You remain responsible for testing, rollback, and production impact.
A scan is a limited point-in-time automated observation. Monitors, where enabled, re-run configured checks on a schedule but are not continuous 24/7 surveillance and do not create a duty to discover every vulnerability, regression, or incident. We have no duty to warn you about issues outside the configured Service features you use.
Nothing on the Services constitutes investment, tax, accounting, financial-planning, or valuation advice. Pricing and refund information is operational, not financial-advisory.
This Disclaimer is in addition to, and not in limitation of, the disclaimers of warranty and limitations of liability in our Terms of Service, which apply fully.
Contact: contact@atrisk.dev
See also: Terms· Privacy· Acceptable Use.