Legal

Terms of Service

These Terms govern your access to and use of AtRisk, including URL scanning, findings, fix prompts, GitHub repo audits, correlation, teams, MCP, CI deploy gate, free marketing tools, public or unlisted reports where offered, and billing.

Last updated: September 9, 2026 · Effective: September 9, 2026

1. Agreement to Terms

These Terms of Service ("Terms") are a legally binding agreement between you ("you," "User," or "Customer") and AtRisk ("AtRisk," "we," "us," or "our") regarding your use of atrisk.dev, app.atrisk.dev, free tools, documentation, APIs, MCP endpoints, emails, and related services (collectively, the "Services").

By accessing or using the Services, creating an account, submitting a URL for scanning, connecting a repository, inviting team members, starting a trial or subscription, generating or sharing a report, using MCP tokens, or submitting information through free tools, you agree to these Terms, our Privacy Policy, our Acceptable Use Policy, and our General Disclaimer. Business customers processing Customer Personal Data through the Services also accept our Data Processing Addendum unless a separately signed DPA controls. If you do not agree, do not use the Services.

If you use the Services on behalf of an organization, you represent that you have authority to bind that organization, and "you" includes that organization. You are responsible for Authorized Users (including teammates you invite) and their compliance with these Terms.

PLEASE NOTE THAT THESE TERMS INCLUDE IMPORTANT DISCLAIMERS, LIMITATIONS OF LIABILITY, INDEMNITY OBLIGATIONS, AND A GOVERNING-LAW CLAUSE. AI-GENERATED AND AUTOMATED SECURITY OUTPUTS ARE INFORMATIONAL ONLY AND ARE NOT A SUBSTITUTE FOR PROFESSIONAL SECURITY, LEGAL, OR ENGINEERING ADVICE.

2. Definitions

  • “AI Features” means generative AI, large language models, and related automated analysis used in the Services (including fix-prompt polish and optional finding judges).
  • “Authorized User” means a person you invite or authorize to access your account, apps, findings, or integrations (including team seats).
  • “Beta Features” means features labeled beta, preview, coming soon, limited release, or similar.
  • “Customer Content” means URLs, domains, repository contents and metadata you authorize us to access, scan evidence, finding notes, app names, team invite emails, free-tool inputs, support messages, and other materials you submit or connect.
  • “Findings” means automated or AI-assisted observations, severity labels, evidence snippets, correlation links, and related records produced by the Services.
  • “Outputs” means Findings, fix prompts, digests, report artifacts, SARIF or CI gate results, MCP responses, free-tool results, and similar generated content.
  • “Platform” means the AtRisk hosted application, APIs, workers, and related interfaces.
  • “Usage Parameters” means plan entitlements, credit allotments, rate limits, seat/app/repo/monitor caps, and other quantitative limits published for your plan.

3. Eligibility

You must be at least 16 years old to use the Services, and at least the age of majority in your jurisdiction to create a paid subscription. You may not use the Services if you are barred under applicable law, including sanctions or export-control restrictions, or if we previously suspended or terminated your access for cause.

4. Description of Services

AtRisk provides a maintenance and security-assurance layer for AI-built applications: standing URL audits, repository analysis, Findings, and fix prompts intended for AI coding agents. Depending on your plan and feature availability, the Services may include:

  • Public URL scanning with read-only retrieval of publicly reachable responses, headers, HTML/JS, DNS/TLS, and related signals
  • Free-tier previews (for example severity counts or blurred Finding detail) and paid unlock of full Findings and fix prompts
  • On-demand URL re-scans after you mark a finding fixed or run another scan
  • Optional GitHub App connection for read-oriented repository analysis within permissions you grant
  • Repo agents (for example security, dependencies/OSV, auth, and AI-surface packs) subject to credits and plan caps
  • Unified Findings inbox, status workflows (fixed / dismiss / reopen / false positive), verify-after-fix, trends, and wins surfaces
  • Cross-layer correlation between URL Findings and connected repository signals (for example secrets/source maps or CSP/headers ↔ config)
  • Multi-app organization of monitored properties, subject to plan caps
  • Team seats and email invites subject to plan caps
  • MCP (Model Context Protocol) tokens for Findings access from tools such as Cursor or Claude Code
  • Pro CI deploy gate (GitHub Action + SARIF) where offered and enabled on your plan
  • Unlisted or public report artifacts, claim flows, and domain proof where we offer those features
  • Free marketing-site tools (email-gated) that use third-party AI models
  • Account, billing, and entitlement management via Polar

AtRisk does not replace AI coding agents, hosting providers, or professional legal, security, or engineering advice. We do not claim to perform penetration testing, send exploit payloads, or automatically open pull requests unless a feature expressly states otherwise. Default scanning and repository analysis are read-only. We may modify, suspend, or discontinue features at any time, including Beta Features.

4.1 Plans and entitlements

Current packaging (subject to change and to what checkout displays at purchase) is generally:

  • Free - limited URL scan previews; no repo audits, MCP, or fix prompts
  • Starter - full URL Findings and fix prompts, 30 URL scans and 40 PR reviews per month, one connected repo, Findings inbox, correlation where available, MCP, Ship/Block and README badge
  • Pro - 250 URL scans and 100 PR reviews per month, up to 5 apps and 5 repos, team seats, and CI deploy gate where offered

Only features that are live for your account apply. Marketing copy labeled "Coming" or similar is not a contractual commitment until generally available and enabled for you.

4.2 Beta Features

Beta Features are provided AS IS, may be unsupported, may change or disappear without notice, and may be subject to additional limits. Direct competitors may not access Beta Features without our prior written approval.

5. Authorized scanning and read-only analysis

You may use the Services only to scan websites, applications, domains, and source repositories that you own or that you are expressly authorized to analyze. By submitting a URL, enabling a monitor, connecting a repository, or requesting a report, you represent and warrant on a continuing basis that:

  • You own the target or have obtained all rights and permissions needed for AtRisk to access and analyze it on your behalf
  • Your use does not violate anti-hacking, computer-misuse, unauthorized-access, telecommunications, or similar laws in any relevant jurisdiction
  • Your scanning does not breach the target’s terms, acceptable use policies, or other contractual restrictions applicable to you
  • You will not use Findings or Outputs to attack, exploit, or harm any system or person

Scans target publicly reachable resources associated with the URL or permissions you provide. We may refuse, rate-limit, or terminate scans that appear unauthorized, abusive, or legally risky. We have no obligation to independently verify your authority. You assume sole responsibility for authorization and for operational effects of scans you request (including alerts, blocks, or load on the target).

Findings and fix prompts are informational only. You remain responsible for verifying results and any changes you apply. Free scans may show limited detail; paid plans unlock fuller Findings and fix-prompt generation subject to then-current entitlements.

6. GitHub App, repository analysis, and third-party integrations

If you connect GitHub (or another source-control provider we support), you grant AtRisk access consistent with the permissions you approve in that provider's OAuth / App flow. Repository agents run only where your plan, credits, and feature availability allow. Analysis is intended to be read-oriented within those permissions. You may disconnect or revoke access at any time through the provider or in-product settings.

Dependency and vulnerability lookups may query third-party databases (for example OSV) using package names and versions derived from lockfiles or manifests you authorize us to read. Third-party integrations are optional; their terms and privacy practices apply to your use of those products. We are not responsible for third-party outages or policy changes beyond our reasonable control.

7. MCP tokens, CI deploy gate, and credentials

MCP tokens, API credentials, and similar secrets issued for your account are credentials for your account. You must keep them confidential, rotate or revoke them if compromised, and not share them beyond Authorized Users. Misuse may result in suspension.

Where offered, the CI deploy gate (including GitHub Action and SARIF output) evaluates Findings against configured severity thresholds. Gate results are informational automation aids; you remain responsible for CI policy, deployment decisions, and false positives/negatives.

8. Apps, teams, and Authorized Users

Paid plans may allow multiple apps and team seats subject to Usage Parameters. When you invite someone, you represent you are authorized to share Customer Content and Findings with them. You are responsible for permissions you grant, for invitees' conduct, and for promptly revoking access when appropriate. Leaving a team or revoking a seat does not automatically delete historical Findings retained under our retention practices.

9. Public, unlisted, and outbound reports

Where we offer public or unlisted report links, claim flows, domain proof, or operator intake for audits (including cold or unsolicited outreach by us or by you):

  • Report links may be secret/unlisted, time-limited, noindexed, or otherwise restricted; possession of a link does not grant ownership of the underlying account or target
  • Claiming a report or domain may require authentication and/or domain proof before monitors or paid unlocks
  • You must not use report sharing to harass, dox, extort, or publicly shame third parties
  • If you request or authorize outreach about a publicly reachable property, you remain responsible for complying with applicable marketing, anti-spam, and computer-misuse laws
  • We may remove, expire, or takedown reports for abuse, legal risk, or owner requests as described in-product or by contacting support

Features not yet generally available are not promised by these Terms until enabled for your account.

10. Accounts and security

10.1 Registration

Some features require an account (email/password and/or OAuth such as Google via our auth provider). You agree to:

  • Provide accurate and complete registration information
  • Keep credentials, MCP tokens, and session secrets confidential
  • Promptly update account information when it changes
  • Accept responsibility for activity under your account and Authorized Users
  • Notify us immediately of suspected unauthorized access

10.2 Suspension and termination

We may suspend or terminate access if you violate these Terms, create risk or legal exposure, fail to pay fees when due, abuse trials, scans, credits, reports, or invites, or if we discontinue the Services. You may stop using the Services and cancel your subscription as described in Section 12. Account deletion options in the product remove or deactivate in-app profile data as described in the Privacy Policy; residual copies may remain in backups for a limited period, and payment records may be retained as required by law or our processors.

11. Acceptable use

You agree to use the Services only for lawful purposes and in compliance with our Acceptable Use Policy, which is incorporated into these Terms. Without limiting that policy, you must not:

  • Violate any law, regulation, or third-party right
  • Submit URLs or repositories you are not authorized to scan
  • Use scans, Findings, or Outputs to attack, exploit, or harm third-party systems
  • Upload or generate unlawful, harmful, deceptive, or abusive content
  • Submit Prohibited Data (Section 14.5) into prompts, free tools, or unnecessary scan surfaces
  • Attempt to gain unauthorized access to systems, accounts, or data
  • Interfere with or disrupt the Services, including via malware or excessive automated traffic
  • Bypass rate limits, credit limits, trial limits, entitlements, paywalls, or security controls
  • Scrape, harvest, or systematically extract content or user data without permission
  • Reverse engineer or attempt to extract source code except where applicable law allows
  • Resell, sublicense, white-label, or commercially redistribute the Services or Outputs as a paid audit product without our written permission (agency/white-label offerings, if any, require a separate plan or agreement)
  • Misrepresent your identity or affiliation
  • Use the Services or Outputs to train, fine-tune, or improve competing AI/ML models, or to build a competing product by copying non-public features, prompts, detectors, or workflows in bad faith
  • Represent Outputs as human-vetted certification, penetration-test results, or approval by AtRisk or any model provider

12. Subscriptions, trials, credits, and payments

12.1 Plans and pricing

Paid plans (including Starter and Pro), included entitlements, and pricing are as published on our website and in the app at the time of purchase. Annual billing may be shown before yearly SKUs are live; checkout will state what is available. We may change plans or pricing prospectively; material changes affecting existing subscribers will be communicated with reasonable notice where required. Free-tier access is offered AS IS and may be modified or discontinued without liability.

12.2 Payment processor

Payments and subscriptions are processed by Polar. By completing checkout, you also agree to Polar's applicable terms and privacy policy. Polar may act as merchant of record. We do not store full payment card numbers on our servers. Fees are generally quoted exclusive of taxes; you are responsible for applicable taxes except taxes based on our net income.

12.3 Trials

Where offered, free trials provide limited access as described at signup:

  • Trial features and amounts are as stated at the time you start the trial
  • Unless you cancel before the trial ends, your paid subscription may begin automatically
  • Checkout may collect a payment method for billing after the trial, depending on the then-current flow
  • Only one free trial per user or organization is permitted unless we state otherwise

12.4 Credits and entitlements

Some features consume credits or are gated by plan entitlements (for example repo agent runs, monitors, seats, apps, MCP, or deploy gate). Credits are a usage measure, have no cash value, are non-transferable, and are not redeemable for money except where required by law. Unused credits typically do not roll over unless we expressly state otherwise. Entitlements refresh according to your plan and billing cycle.

12.5 Renewal, cancellation, and refunds

  • Subscriptions renew automatically until cancelled
  • Cancel through account billing settings or the Polar customer portal
  • Cancellation typically takes effect at the end of the current billing period
  • You retain paid access until the end of the paid period already purchased
  • Except where required by law or expressly stated by us, fees are non-refundable, including for unused credits or partial periods
  • Cancellation during an eligible free trial before conversion should not result in a charge
  • Chargebacks filed without first contacting support may result in suspension pending investigation

13. Free tools and communications

Free tools on atrisk.dev may require an email address and may send a transactional or product-related message. Tool Outputs are informational only and may use third-party AI providers. We may rate-limit, modify, or discontinue free tools at any time.

By creating an account or submitting an email for tools, you consent to receive transactional, security, billing, and service messages necessary to operate the Services (including regression alerts and digests you enable). Optional marketing emails, where sent, include an unsubscribe mechanism. You cannot opt out of essential transactional messages while your account remains active.

14. Intellectual property, Customer Content, and Outputs

14.1 Our IP

The Services - including software, detectors, workflows, UI, branding, documentation, and non-user content - are owned by AtRisk or its licensors and protected by intellectual property laws. Feedback you provide may be used by us without restriction or compensation.

14.2 License to you

Subject to these Terms and your subscription, we grant you a limited, non-exclusive, non-transferable, revocable license to access and use the Services for your internal personal or business purposes, within Usage Parameters.

14.3 Your content

You retain ownership of Customer Content. You grant us a worldwide, royalty-free license to host, process, transmit, display, and create derivative technical artifacts from Customer Content solely as needed to provide, secure, support, and improve the Services, including sending content to AI and infrastructure providers that process it to return Outputs.

14.4 Generated Outputs

As between you and AtRisk, and to the extent permitted by law and third-party model terms, you may use Outputs for your projects, including commercial projects, subject to Section 11. You are responsible for reviewing Outputs and ensuring they do not infringe others' rights or violate law. Due to the nature of machine learning and shared detectors, Outputs may not be unique to you.

14.5 Prohibited Data

Do not submit Prohibited Data into free tools, prompts, or unnecessary fields. We have no liability for Prohibited Data you choose to submit. "Prohibited Data" includes:

  • Government ID numbers (passport, national ID, driver’s license, and similar)
  • Full payment card numbers or bank account credentials (beyond what Polar collects at checkout)
  • Passwords or production secrets not required for a feature you intentionally connect
  • Health, genetic, biometric, or other special-category data under applicable privacy laws
  • Data you are not authorized to process or disclose

14.6 Usage and de-identified data

We may collect technical logs, metrics, and analytics about use of the Services ("Usage Data") and create aggregated or de-identified data that does not reasonably identify you. We may use Usage Data and de-identified data to operate, secure, and improve the Services.

15. AI Features and security disclaimer

Outputs are generated with automated analysis and/or third-party AI models (including providers such as Anthropic for in-app generation, and OpenRouter / underlying model providers for certain marketing free tools) and may contain errors, omissions, insecure recommendations, or outdated information. AtRisk does not guarantee that scans, Findings, or fix prompts are complete, accurate, or fit for any particular purpose.

We do not use Customer Content to train third-party foundation models except as necessary to generate the specific Output you requested, as required by law, or as disclosed in our Privacy Policy and provider terms. You remain solely responsible for decisions made using the Services and for any code, product, or business you build or operate. Your use of AI Features must also comply with applicable provider acceptable-use policies (for example Anthropic's).

16. Third-party services

The Services rely on or integrate with third parties, including:

  • Polar - payments and subscription management
  • Neon - authentication and database hosting
  • GitHub - when you connect a repository via the GitHub App or OAuth
  • Anthropic - in-app AI Features (for example fix-prompt polish; optional judges when enabled)
  • OpenRouter and underlying model providers - marketing free-tool AI
  • Cloudflare - hosting, CDN, Workers, Browser Rendering, Containers, KV, and related infrastructure
  • OSV and similar public vulnerability data sources - dependency lookups
  • Resend - transactional and tool-related email
  • Sentry - error monitoring and performance traces (session replay off by default)
  • PostHog - product analytics (no session recording in current configuration)

Your use of third-party services may be subject to their own terms. A current processor overview also appears in our Privacy Policy, Subprocessors page, and DPA.

17. Availability, support, and confidentiality

We aim to keep the Services available and reliable, but we do not guarantee uninterrupted or error-free operation. Maintenance, security incidents, vendor outages, and force majeure events may cause downtime. Support is provided via email and in-product channels; response times may vary by plan and issue severity. No formal SLA applies unless we execute a separate written agreement.

Non-public Customer Content and non-public aspects of the Platform are confidential to the disclosing party. Each party will protect the other's confidential information with reasonable care and use it only to perform under these Terms, except for information that is public, independently developed, or required to be disclosed by law.

18. Disclaimers

THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE SERVICES OR ANY OUTPUTS WILL MEET YOUR REQUIREMENTS OR BE ACCURATE, COMPLETE, SECURE, OR FREE OF VULNERABILITIES. ATRISK IS NOT A PENETRATION-TESTING FIRM AND DOES NOT CERTIFY COMPLIANCE WITH ANY SECURITY STANDARD. Additional plain-language disclaimers appear in our General Disclaimer.

19. Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, ATRISK AND ITS AFFILIATES, OFFICERS, EMPLOYEES, AND AGENTS WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS, REVENUE, DATA, GOODWILL, OR BUSINESS OPPORTUNITY, ARISING OUT OF OR RELATED TO THE SERVICES OR THESE TERMS, WHETHER BASED IN CONTRACT, TORT, OR OTHERWISE.

OUR TOTAL LIABILITY FOR ANY CLAIM ARISING OUT OF OR RELATING TO THE SERVICES OR THESE TERMS WILL NOT EXCEED THE AMOUNTS YOU PAID TO US FOR THE SERVICES IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM (OR, IF YOU HAVE NOT PAID, USD $50).

Some jurisdictions do not allow certain limitations; in those cases, our liability is limited to the fullest extent permitted by law.

20. Indemnification

You agree to defend, indemnify, and hold harmless AtRisk and its officers, directors, employees, and agents from and against claims, damages, losses, and expenses (including reasonable attorneys' fees) arising out of or related to:

  • Your use of the Services or Outputs
  • Your Customer Content and URLs or repositories you submit or connect
  • Unauthorized scanning or misuse of Findings
  • Your Authorized Users’ conduct
  • Your violation of these Terms
  • Your violation of any law or third-party right

21. Governing law and disputes

21.1 Governing law

These Terms are governed by the laws of the Kingdom of Saudi Arabia, without regard to conflict-of-law rules.

21.2 Dispute resolution

The parties will first attempt to resolve disputes in good faith through informal negotiation by contacting contact@atrisk.dev. If unresolved, disputes may be brought in the competent courts of the Kingdom of Saudi Arabia, unless mandatory consumer protections in your jurisdiction provide otherwise.

22. General

  • These Terms, together with the Privacy Policy, Acceptable Use Policy, General Disclaimer, Data Processing Addendum (where applicable), Cookie Policy, and any plan-specific or feature-specific notices presented at use, are the entire agreement between you and us regarding the Services
  • If any provision is unenforceable, the remaining provisions remain in effect
  • Failure to enforce a provision is not a waiver
  • You may not assign these Terms without our consent; we may assign them in connection with a reorganization, merger, or sale of assets
  • Headings are for convenience only
  • Export and sanctions laws may restrict use; you are responsible for compliance

23. Changes to these Terms

We may update these Terms from time to time. We will post the updated Terms on this page and update the "Last updated" date. For material changes, we may also provide additional notice (for example email or in-product notice). Continued use after the effective date constitutes acceptance of the updated Terms.

24. Contact

Questions about these Terms:

These Terms of Service are effective as of September 9, 2026 and apply to all users of AtRisk. This is product-aligned legal copy - have counsel review before relying on it for regulated or enterprise deals.