Legal

General Disclaimer

Read this before relying on any AtRisk scan result, Finding, fix prompt, monitor alert, MCP response, CI gate output, or free-tool result.

Last updated: September 9, 2026 · Effective: September 9, 2026

1. Informational purpose only

AtRisk is an automated informational service. Scan results, Findings, severity labels, evidence snippets, fix prompts, digests, report artifacts, SARIF/CI gate results, MCP responses, and free-tool Outputs are not a substitute for professional security, legal, compliance, or engineering advice.

2. No professional relationship

Your use of the Services does not create an attorney-client, consultant, cybersecurity- professional, fiduciary, or other professional relationship with AtRisk. Communications with support are operational, not advisory engagements.

3. Accuracy & completeness

We use commercially reasonable efforts to provide useful, up-to-date information. The Services rely on automated software, third-party data, AI models, and heuristics that may be incomplete, outdated, or wrong. False positives and false negatives occur. You are solely responsible for independently verifying any information before relying on it.

4. Not a penetration test, audit, or legal review

AtRisk is an automated remote scanner and repository analysis layer. It does not perform exhaustive manual review, business-logic testing, authenticated deep penetration testing, formal compliance audits, or certification against SOC 2, ISO 27001, PCI DSS, or similar standards unless a feature expressly states otherwise.

5. No legal, regulatory, or compliance advice

Nothing on the Services constitutes legal advice, regulatory guidance, or an opinion on the legality, suitability, or compliance of any system, product, or practice. Consult qualified counsel for legal or compliance decisions.

6. No authorization to scan

AtRisk does not authorize you to scan any system you do not own or for which you lack explicit authorization. You are solely responsible for ensuring every scan you initiate is lawful. See our Acceptable Use Policy and Terms of Service.

7. AI-generated output

Portions of the Services use large language models and other AI systems to polish fix prompts, summarize Findings, or generate free-tool results. AI output may hallucinate, omit context, or suggest insecure changes. Review all Outputs before applying them.

8. Third-party content & links

The Services may incorporate or link to third-party sources (for example OSV, GitHub, model providers, Polar checkout). We do not control and are not responsible for third-party content, availability, or practices.

9. Customer decisions, fixes & deployments

Any decision, code change, configuration change, remediation, deployment, client report, or other action based on the Services is made entirely by you. Suggested fixes may introduce defects, break functionality, or create new security issues. You remain responsible for testing, rollback, and production impact.

10. Monitoring & duty to warn

A scan is a limited point-in-time automated observation. Monitors, where enabled, re-run configured checks on a schedule but are not continuous 24/7 surveillance and do not create a duty to discover every vulnerability, regression, or incident. We have no duty to warn you about issues outside the configured Service features you use.

11. No investment, tax, or financial advice

Nothing on the Services constitutes investment, tax, accounting, financial-planning, or valuation advice. Pricing and refund information is operational, not financial-advisory.

12. No warranty; limitation of liability

This Disclaimer is in addition to, and not in limitation of, the disclaimers of warranty and limitations of liability in our Terms of Service, which apply fully.

13. Contact

This Disclaimer is effective as of September 9, 2026 and supplements the Terms of Service. Product-aligned legal copy - have counsel review before relying on it for regulated or enterprise deals.