Legal
These Terms govern your access to and use of AtRisk, including URL scanning, findings, fix prompts, GitHub repo audits, correlation, teams, MCP, CI deploy gate, free marketing tools, public or unlisted reports where offered, and billing.
Last updated: September 9, 2026 · Effective: September 9, 2026
These Terms of Service ("Terms") are a legally binding agreement between you ("you," "User," or "Customer") and AtRisk ("AtRisk," "we," "us," or "our") regarding your use of atrisk.dev, app.atrisk.dev, free tools, documentation, APIs, MCP endpoints, emails, and related services (collectively, the "Services").
By accessing or using the Services, creating an account, submitting a URL for scanning, connecting a repository, inviting team members, starting a trial or subscription, generating or sharing a report, using MCP tokens, or submitting information through free tools, you agree to these Terms, our Privacy Policy, our Acceptable Use Policy, and our General Disclaimer. Business customers processing Customer Personal Data through the Services also accept our Data Processing Addendum unless a separately signed DPA controls. If you do not agree, do not use the Services.
If you use the Services on behalf of an organization, you represent that you have authority to bind that organization, and "you" includes that organization. You are responsible for Authorized Users (including teammates you invite) and their compliance with these Terms.
PLEASE NOTE THAT THESE TERMS INCLUDE IMPORTANT DISCLAIMERS, LIMITATIONS OF LIABILITY, INDEMNITY OBLIGATIONS, AND A GOVERNING-LAW CLAUSE. AI-GENERATED AND AUTOMATED SECURITY OUTPUTS ARE INFORMATIONAL ONLY AND ARE NOT A SUBSTITUTE FOR PROFESSIONAL SECURITY, LEGAL, OR ENGINEERING ADVICE.
You must be at least 16 years old to use the Services, and at least the age of majority in your jurisdiction to create a paid subscription. You may not use the Services if you are barred under applicable law, including sanctions or export-control restrictions, or if we previously suspended or terminated your access for cause.
AtRisk provides a maintenance and security-assurance layer for AI-built applications: standing URL audits, repository analysis, Findings, and fix prompts intended for AI coding agents. Depending on your plan and feature availability, the Services may include:
AtRisk does not replace AI coding agents, hosting providers, or professional legal, security, or engineering advice. We do not claim to perform penetration testing, send exploit payloads, or automatically open pull requests unless a feature expressly states otherwise. Default scanning and repository analysis are read-only. We may modify, suspend, or discontinue features at any time, including Beta Features.
Current packaging (subject to change and to what checkout displays at purchase) is generally:
Only features that are live for your account apply. Marketing copy labeled "Coming" or similar is not a contractual commitment until generally available and enabled for you.
Beta Features are provided AS IS, may be unsupported, may change or disappear without notice, and may be subject to additional limits. Direct competitors may not access Beta Features without our prior written approval.
You may use the Services only to scan websites, applications, domains, and source repositories that you own or that you are expressly authorized to analyze. By submitting a URL, enabling a monitor, connecting a repository, or requesting a report, you represent and warrant on a continuing basis that:
Scans target publicly reachable resources associated with the URL or permissions you provide. We may refuse, rate-limit, or terminate scans that appear unauthorized, abusive, or legally risky. We have no obligation to independently verify your authority. You assume sole responsibility for authorization and for operational effects of scans you request (including alerts, blocks, or load on the target).
Findings and fix prompts are informational only. You remain responsible for verifying results and any changes you apply. Free scans may show limited detail; paid plans unlock fuller Findings and fix-prompt generation subject to then-current entitlements.
If you connect GitHub (or another source-control provider we support), you grant AtRisk access consistent with the permissions you approve in that provider's OAuth / App flow. Repository agents run only where your plan, credits, and feature availability allow. Analysis is intended to be read-oriented within those permissions. You may disconnect or revoke access at any time through the provider or in-product settings.
Dependency and vulnerability lookups may query third-party databases (for example OSV) using package names and versions derived from lockfiles or manifests you authorize us to read. Third-party integrations are optional; their terms and privacy practices apply to your use of those products. We are not responsible for third-party outages or policy changes beyond our reasonable control.
MCP tokens, API credentials, and similar secrets issued for your account are credentials for your account. You must keep them confidential, rotate or revoke them if compromised, and not share them beyond Authorized Users. Misuse may result in suspension.
Where offered, the CI deploy gate (including GitHub Action and SARIF output) evaluates Findings against configured severity thresholds. Gate results are informational automation aids; you remain responsible for CI policy, deployment decisions, and false positives/negatives.
Paid plans may allow multiple apps and team seats subject to Usage Parameters. When you invite someone, you represent you are authorized to share Customer Content and Findings with them. You are responsible for permissions you grant, for invitees' conduct, and for promptly revoking access when appropriate. Leaving a team or revoking a seat does not automatically delete historical Findings retained under our retention practices.
Where we offer public or unlisted report links, claim flows, domain proof, or operator intake for audits (including cold or unsolicited outreach by us or by you):
Features not yet generally available are not promised by these Terms until enabled for your account.
Some features require an account (email/password and/or OAuth such as Google via our auth provider). You agree to:
We may suspend or terminate access if you violate these Terms, create risk or legal exposure, fail to pay fees when due, abuse trials, scans, credits, reports, or invites, or if we discontinue the Services. You may stop using the Services and cancel your subscription as described in Section 12. Account deletion options in the product remove or deactivate in-app profile data as described in the Privacy Policy; residual copies may remain in backups for a limited period, and payment records may be retained as required by law or our processors.
You agree to use the Services only for lawful purposes and in compliance with our Acceptable Use Policy, which is incorporated into these Terms. Without limiting that policy, you must not:
Paid plans (including Starter and Pro), included entitlements, and pricing are as published on our website and in the app at the time of purchase. Annual billing may be shown before yearly SKUs are live; checkout will state what is available. We may change plans or pricing prospectively; material changes affecting existing subscribers will be communicated with reasonable notice where required. Free-tier access is offered AS IS and may be modified or discontinued without liability.
Payments and subscriptions are processed by Polar. By completing checkout, you also agree to Polar's applicable terms and privacy policy. Polar may act as merchant of record. We do not store full payment card numbers on our servers. Fees are generally quoted exclusive of taxes; you are responsible for applicable taxes except taxes based on our net income.
Where offered, free trials provide limited access as described at signup:
Some features consume credits or are gated by plan entitlements (for example repo agent runs, monitors, seats, apps, MCP, or deploy gate). Credits are a usage measure, have no cash value, are non-transferable, and are not redeemable for money except where required by law. Unused credits typically do not roll over unless we expressly state otherwise. Entitlements refresh according to your plan and billing cycle.
Free tools on atrisk.dev may require an email address and may send a transactional or product-related message. Tool Outputs are informational only and may use third-party AI providers. We may rate-limit, modify, or discontinue free tools at any time.
By creating an account or submitting an email for tools, you consent to receive transactional, security, billing, and service messages necessary to operate the Services (including regression alerts and digests you enable). Optional marketing emails, where sent, include an unsubscribe mechanism. You cannot opt out of essential transactional messages while your account remains active.
The Services - including software, detectors, workflows, UI, branding, documentation, and non-user content - are owned by AtRisk or its licensors and protected by intellectual property laws. Feedback you provide may be used by us without restriction or compensation.
Subject to these Terms and your subscription, we grant you a limited, non-exclusive, non-transferable, revocable license to access and use the Services for your internal personal or business purposes, within Usage Parameters.
You retain ownership of Customer Content. You grant us a worldwide, royalty-free license to host, process, transmit, display, and create derivative technical artifacts from Customer Content solely as needed to provide, secure, support, and improve the Services, including sending content to AI and infrastructure providers that process it to return Outputs.
As between you and AtRisk, and to the extent permitted by law and third-party model terms, you may use Outputs for your projects, including commercial projects, subject to Section 11. You are responsible for reviewing Outputs and ensuring they do not infringe others' rights or violate law. Due to the nature of machine learning and shared detectors, Outputs may not be unique to you.
Do not submit Prohibited Data into free tools, prompts, or unnecessary fields. We have no liability for Prohibited Data you choose to submit. "Prohibited Data" includes:
We may collect technical logs, metrics, and analytics about use of the Services ("Usage Data") and create aggregated or de-identified data that does not reasonably identify you. We may use Usage Data and de-identified data to operate, secure, and improve the Services.
Outputs are generated with automated analysis and/or third-party AI models (including providers such as Anthropic for in-app generation, and OpenRouter / underlying model providers for certain marketing free tools) and may contain errors, omissions, insecure recommendations, or outdated information. AtRisk does not guarantee that scans, Findings, or fix prompts are complete, accurate, or fit for any particular purpose.
We do not use Customer Content to train third-party foundation models except as necessary to generate the specific Output you requested, as required by law, or as disclosed in our Privacy Policy and provider terms. You remain solely responsible for decisions made using the Services and for any code, product, or business you build or operate. Your use of AI Features must also comply with applicable provider acceptable-use policies (for example Anthropic's).
The Services rely on or integrate with third parties, including:
Your use of third-party services may be subject to their own terms. A current processor overview also appears in our Privacy Policy, Subprocessors page, and DPA.
We aim to keep the Services available and reliable, but we do not guarantee uninterrupted or error-free operation. Maintenance, security incidents, vendor outages, and force majeure events may cause downtime. Support is provided via email and in-product channels; response times may vary by plan and issue severity. No formal SLA applies unless we execute a separate written agreement.
Non-public Customer Content and non-public aspects of the Platform are confidential to the disclosing party. Each party will protect the other's confidential information with reasonable care and use it only to perform under these Terms, except for information that is public, independently developed, or required to be disclosed by law.
THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE SERVICES OR ANY OUTPUTS WILL MEET YOUR REQUIREMENTS OR BE ACCURATE, COMPLETE, SECURE, OR FREE OF VULNERABILITIES. ATRISK IS NOT A PENETRATION-TESTING FIRM AND DOES NOT CERTIFY COMPLIANCE WITH ANY SECURITY STANDARD. Additional plain-language disclaimers appear in our General Disclaimer.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, ATRISK AND ITS AFFILIATES, OFFICERS, EMPLOYEES, AND AGENTS WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS, REVENUE, DATA, GOODWILL, OR BUSINESS OPPORTUNITY, ARISING OUT OF OR RELATED TO THE SERVICES OR THESE TERMS, WHETHER BASED IN CONTRACT, TORT, OR OTHERWISE.
OUR TOTAL LIABILITY FOR ANY CLAIM ARISING OUT OF OR RELATING TO THE SERVICES OR THESE TERMS WILL NOT EXCEED THE AMOUNTS YOU PAID TO US FOR THE SERVICES IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM (OR, IF YOU HAVE NOT PAID, USD $50).
Some jurisdictions do not allow certain limitations; in those cases, our liability is limited to the fullest extent permitted by law.
You agree to defend, indemnify, and hold harmless AtRisk and its officers, directors, employees, and agents from and against claims, damages, losses, and expenses (including reasonable attorneys' fees) arising out of or related to:
These Terms are governed by the laws of the Kingdom of Saudi Arabia, without regard to conflict-of-law rules.
The parties will first attempt to resolve disputes in good faith through informal negotiation by contacting contact@atrisk.dev. If unresolved, disputes may be brought in the competent courts of the Kingdom of Saudi Arabia, unless mandatory consumer protections in your jurisdiction provide otherwise.
We may update these Terms from time to time. We will post the updated Terms on this page and update the "Last updated" date. For material changes, we may also provide additional notice (for example email or in-product notice). Continued use after the effective date constitutes acceptance of the updated Terms.
Questions about these Terms:
Contact: contact@atrisk.dev