Back to Home

Terms of Service

Last Updated: August 25, 2026

Plain-English summary

This summary is provided for convenience only. It is not part of the agreement, and where it differs from the sections below, the sections below govern.

  • What you get. An AI security pipeline — an agent investigator reads your code and traces data flows, a verify subagent generates and runs local exploit tests to prove findings, the Fixer proposes patches and re-verifies them, Attacker Mode stress-tests fixes — plus a dashboard, a VS Code extension, and an MCP server for AI coding assistants.
  • What you own. Your code stays yours. The fixes we generate for you are yours. We claim neither.
  • What we need from you. Only submit code you have the right to submit, keep production data out of the sandbox, and only point Attacker Mode at systems you are authorised to test.
  • What we do not promise. We do not promise to find every vulnerability, and we do not promise that a patch is safe to ship without your review. We are a second pair of eyes, not a certification.
  • Where responsibility sits. We do not run your systems, so we are not the cause of an incident in them. A scan describes your code at one moment; change it afterwards and that result no longer applies. You review every finding and every patch before anything ships, so the decision to deploy, and what follows from it, is yours.
  • Money. Cancel any time and it takes effect at the end of your billing period. New subscribers get 30 days to change their mind — and you can still claim it after heavy use, we just take the credits you spent off the refund. We give 30 days' notice before raising a price, and founding-member pricing is honoured.
  • If something goes wrong. Talk to us first — most things get resolved in an email. If they do not, disputes go to arbitration in Cairo, and our financial liability is capped.

1. The agreement between us

These Terms of Service ("Terms") are a binding agreement between you and SecureCode ("SecureCode", "we", "our" or "us"), an independently operated software product run from Egypt, governing your access to and use of the SecureCode service.

By creating an account, installing our VS Code extension, or otherwise accessing or using the Service, you agree to these Terms. If you do not agree, do not use the Service.

Eligibility. You must be at least 18 years old to use the Service. The Service is a professional developer tool and is not directed to anyone under 18.

Acting for an organisation. If you use the Service on behalf of a company or other organisation, you confirm that you have authority to bind that organisation to these Terms, and "you" refers to both you and that organisation.

2. Definitions

  • "Service" — the SecureCode website at usesecurecode.tech, the web dashboard, the VS Code extension, the standalone MCP server, our APIs, and any documentation, reports or output they produce.
  • "Your Code" — source code, configuration, file paths, dependency information, HTTP response excerpts and any other content from your environment that you submit to the Service or instruct the Service to process.
  • "Output" — findings, verification verdicts, confidence scores, reports, generated patches and other results the Service returns to you.
  • "Findings Data" — the metadata a scan produces: vulnerability class, file path, line number, severity, confidence score, verification outcome and timestamps. This is the same term used in section 2 of the Privacy Policy.
  • "Privacy Policy" — our privacy policy at usesecurecode.tech/privacy, as updated from time to time.

3. What the Service does

SecureCode is an AI-assisted security review pipeline. It currently provides:

  • Agent scan (investigation). An AI investigator reads your files, traces data flows, checks guards, and compares endpoint policies to find vulnerabilities. It is informed by a Project Map of your endpoints, middleware and authentication paths that is built locally on your machine using Tree-sitter.
  • Verify subagent (exploit verification). For each high-confidence finding, a verify subagent generates a local exploit test, runs it in a sandbox on your machine, and analyzes the output to return a PROVEN, UNPROVEN, or INCONCLUSIVE verdict. The sandbox supports Node.js, Bun, Deno, and Python projects.
  • Fixer. Automated patch generation. Before a patch is returned, the model reviews it against a checklist of eight common bypass techniques. This review is model reasoning about the patch; it is not execution or testing of the patch against your application.
  • Fix re-verification. After a fix is generated, the pipeline re-runs the original exploit test against the merged fixed code to determine whether the fix actually closed the vulnerability — reporting fix-verified-closed, fix-still-vulnerable, or fix-verification-inconclusive.
  • Finding review queue. When the verify subagent cannot prove or disprove a finding (INCONCLUSIVE), the finding is added to a non-blocking local review queue so you can later adjudicate it as confirmed, rejected, or deferred.
  • Attacker Mode (optional). Builds endpoint-specific attack scenarios against a proposed fix. With the local sandbox enabled, payloads are replayed against a temporary copy of your own application so that the model's verdict can be checked against real behaviour. Sandbox replay supports Node.js, Bun, Deno, and Python projects.
  • Reporting, analytics, VS Code integration, and MCP server.

We may add, change, or discontinue features. Section 11 explains how.

4. What the Service is not

This section matters more than any other for both of us, so it is written plainly rather than in capitals.

  • It is not a penetration test, a security audit, or a certification. Output from the Service does not certify that your application is secure, and it does not demonstrate compliance with any law, standard or framework — including SOC 2, ISO 27001, PCI DSS, HIPAA, the GDPR, or the OWASP Top 10.
  • It is not a guarantee of detection. No automated tool finds every vulnerability. The Service will miss issues, and it will sometimes report issues that turn out not to be exploitable.
  • It is not a substitute for your own review. Every patch the Fixer produces is a suggestion. You must read, test and take responsibility for any code you ship, whether or not the Service generated it.
  • It is not continuous monitoring. A scan describes your code at the moment it ran, and nothing more. Change your project afterwards and the earlier result no longer describes it. Keeping your code scanned is your call, not something that happens in the background.
  • It is not legal, regulatory or professional advice.
  • It does not transfer your responsibility for your own applications. You remain solely responsible for the security of your systems and for your obligations to your own users and customers.

5. Your account

5.1 Registration

Some features require an account. You agree to provide accurate information and to keep it current.

5.2 Your responsibility for your account

You are responsible for keeping your credentials confidential, for all activity that occurs under your account, and for notifying us promptly at support@usesecurecode.tech if you suspect unauthorised use. Accounts are for a single user and may not be shared, except where your plan expressly provides for additional seats. We recommend enabling every account-security option we make available to you.

5.3 Accuracy of usage

You must not circumvent, or attempt to circumvent, plan limits, quotas, rate limits or metering.

6. Plans, fees and billing

6.1 Plans

We offer a free plan and one or more paid plans. The features and limits of each plan are as published on our website at the time you subscribe.

6.2 Billing

Paid plans are billed in advance on a recurring basis, monthly or annually as you select, and renew automatically until cancelled. You authorise us and our payment processor to charge your payment method for all fees as they fall due. If a payment fails, we may retry it and may suspend paid features until payment succeeds.

6.3 Taxes

Fees are exclusive of taxes. You are responsible for all value-added tax, sales tax, and similar taxes and duties arising from your subscription, other than taxes on our income. If you are required to withhold any amount, you will gross up the payment so that we receive the full amount invoiced.

6.4 Price changes

We may change our prices. For an existing paid subscriber, a price change takes effect no earlier than 30 days after we notify you, and applies from your next renewal. If you do not accept a price change, you may cancel before it takes effect. Founding-member pricing, where we have granted it, is honoured for as long as your subscription remains continuously active on that plan.

6.5 Cancellation and refunds

You may cancel at any time from your account. Cancellation takes effect at the end of the current billing period, and you keep access until then. Fees are non-refundable and we do not provide refunds or credits for partial periods, unused capacity, or downgrades, except under the thirty-day guarantee below, under sections 11.2, 15.4 and 17, or as required by applicable law.

Thirty-day guarantee. If you are a new subscriber, you may request a refund of your first subscription payment within 30 days of that payment by emailing support@usesecurecode.tech. The guarantee applies once per customer and to a first paid subscription only, and does not apply to renewals.

Credits you have already used are deducted. Heavy use before a refund request is consumption, not evaluation, so we treat the first 15 scan credits as evaluation and account for the rest:

  • 15 credits or fewer used — you receive a full refund of your first subscription payment.
  • More than 15 credits used — you can still request the refund. We deduct the value of every credit you have consumed, not only those above the first 15, and refund the balance.

How a credit is valued. At the rate you obtained it at: for credits included in a subscription, the subscription price divided by the number of credits it includes; for credits bought separately, the price you paid for that pack. If the resulting deduction equals or exceeds your payment, no refund is due.

Attacker Mode runs and any other usage-based charges already incurred are not refundable and are not covered by the guarantee.

6.6 Trials and promotional plans

Where we offer a trial or promotional plan, the terms stated at sign-up apply. Unless we say otherwise, a trial converts to a paid subscription at the end of the trial period unless you cancel first.

7. Acceptable use

7.1 Permitted use

You may use the Service to scan and analyse code that you own or have permission to modify, and to generate and apply fixes to that code.

7.2 Authorisation to test

This is a condition of use, not a formality. You represent and warrant that, for every system you scan and every system against which you run Attacker Mode, you either own that system or hold authorisation from its owner to perform automated security testing against it. Replaying attack payloads against a system you do not own or are not authorised to test may be a criminal offence in many jurisdictions. Obtaining authorisation is entirely your responsibility.

7.3 Sandbox and production environments

The local sandbox runs on your machine against a temporary copy of your application, and running it may create, alter or delete data in that copy. You must not run the sandbox or Attacker Mode against a production environment, or against any environment containing live personal data of real individuals.

7.4 Restrictions on data you submit

You must not submit to the Service any special categories of personal data, payment card data subject to PCI DSS, government identification numbers, protected health information, or data subject to sector-specific regulatory regimes, unless we have agreed in writing in advance to receive it. Section 12 of the Privacy Policy sets out your representations about the data you submit in full, and they apply as terms of this agreement.

7.5 Prohibited activities

You must not:

  • scan, analyse or attack code or systems you do not have the rights or authorisation to access;
  • attempt to reverse engineer, extract or reconstruct our models, prompts, orchestration logic or scoring algorithms, including by prompt injection or other jailbreaking techniques;
  • use the Service, or any Output, to build, train or market a product or service that competes with the Service;
  • resell, sublicense, or provide the Service to third parties as a service bureau, except as expressly permitted by your plan;
  • circumvent security features, access controls, quotas, rate limits or metering;
  • use automated systems to access the API in excess of your plan limits, or in a manner that degrades the Service for others;
  • upload code or payloads designed to compromise our infrastructure, other than as permitted under section 7.6;
  • use the Service in violation of applicable law, or in breach of any confidentiality obligation you owe to a third party.

7.6 Responsible disclosure

Nothing in section 7.5 prohibits good-faith security research into the Service itself, provided you report what you find to contact@usesecurecode.tech, do not access or exfiltrate data belonging to other users, do not degrade the Service, and give us a reasonable opportunity to remediate before any public disclosure. We will not pursue claims against researchers who act in accordance with this section.

7.7 Enforcement

We may investigate suspected breaches of this section and may suspend or limit access as described in section 15.

8. Your Code, our Service, and who owns what

8.1 Your Code stays yours

You retain all right, title and interest in Your Code. You grant us a worldwide, non-exclusive, royalty-free licence to host, copy, transmit, display and process Your Code, and to transmit it to the third-party AI providers described in section 9, in each case for the limited purposes of (a) providing, maintaining and securing the Service for you, (b) preventing abuse and enforcing these Terms, and (c) creating aggregated and de-identified data as described in section 7 of the Privacy Policy. This licence exists only to let us run the Service and ends when we delete the relevant data in accordance with the Privacy Policy.

8.2 We do not train on Your Code

We do not use Your Code to train, fine-tune or evaluate any machine-learning model, and we do not use it to build internal classifiers. Section 8 of the Privacy Policy describes this commitment, and the limits of our control over third-party providers, in detail.

8.3 Output is yours

As between you and us, you own the Output, including generated patches, and you may use it without restriction. We claim no ownership of the code you write or the fixes we generate for you.

8.4 Output is not exclusive

The Service is generative and other users submit similar code. Output provided to you may be similar or identical to Output provided to other users, and nothing in section 8.3 restricts us from providing similar or identical Output to anyone else. You are responsible for satisfying yourself that any Output you incorporate is suitable for your use and does not infringe a third party's rights.

8.5 Our Service

The Service — including its software, models, prompts, orchestration logic, scoring methodology, documentation, and the SecureCode name, logo and branding — is owned by us and protected by intellectual property law. These Terms grant you a limited, revocable, non-exclusive, non-transferable right to use the Service in accordance with your plan, and nothing more.

8.6 Feedback

If you send us ideas, suggestions or feedback about the Service, you grant us a perpetual, irrevocable, royalty-free licence to use it for any purpose without obligation or attribution to you. We will not identify you as the source without your permission.

8.7 Third-party and open-source components

The Service includes third-party and open-source components licensed under their own terms, which apply to those components to the extent they conflict with these Terms.

9. Third-party AI providers

The Service depends on third-party large language model providers, currently Vultr Inference and OpenRouter. By using the Service you acknowledge and instruct that Your Code and related context will be transmitted to those providers so that the Service can produce the Output you requested. Section 8 of the Privacy Policy describes our commitments regarding their handling of that data, including the limited retention they apply for abuse monitoring and the fact that we cannot independently audit their infrastructure.

We may change providers. We are not responsible for the acts, omissions, availability or performance of a third-party provider, and their outages may affect the Service as described in section 11.

10. Privacy and data protection

Our Privacy Policy explains what information we collect and how we handle it, and it is incorporated into these Terms by reference for the purpose of describing our information-handling practices.

The Privacy Policy is a description of practice, not a warranty. It does not create any contractual right, representation, warranty or obligation beyond those set out in these Terms, and if there is any inconsistency between the Privacy Policy and these Terms concerning warranties, disclaimers, indemnities or limitations of liability, these Terms govern. Nothing in either document limits a right you have that cannot be limited or waived under applicable law.

Where we process personal data contained in Your Code, we do so as your processor and you act as controller, as described in section 3 of the Privacy Policy. If you require a data processing agreement, email contact@usesecurecode.tech and we will provide our standard DPA, which on execution forms part of these Terms for that processing.

11. Availability, changes and early-access features

11.1 Availability

We aim for high availability but we do not commit to an uptime level unless we have agreed one with you in a separate written order. The Service may be unavailable because of maintenance, updates, network problems, or outages at an upstream AI provider or infrastructure vendor.

11.2 Changes to the Service

We may add, modify, or discontinue features. If we discontinue a feature that is material to a paid plan, or make a change that materially reduces the core functionality of a paid plan, we will give you at least 30 days' notice where practicable, and you may cancel and receive a pro-rata refund of prepaid fees for the remainder of the then-current term.

11.3 Beta and early-access features

Features we identify as beta, preview, experimental or early access are provided for evaluation, may not work as described, may change or be withdrawn at any time without notice, and are excluded from any commitment in section 11.2. They are provided "as is" and your use of them is at your own risk.

12. Disclaimers

12.1 General disclaimer

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE SERVICE AND ALL OUTPUT ARE PROVIDED "AS IS" AND "AS AVAILABLE", WITHOUT WARRANTY OF ANY KIND, WHETHER EXPRESS, IMPLIED OR STATUTORY. WE SPECIFICALLY DISCLAIM ALL IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, AND ANY WARRANTY ARISING FROM COURSE OF DEALING OR USAGE OF TRADE. WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, TIMELY, SECURE OR ERROR-FREE, OR THAT ANY DEFECT WILL BE CORRECTED.

12.2 Security and AI disclaimer

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, WE DO NOT WARRANT THAT:

  • THE SERVICE WILL IDENTIFY ALL OR ANY PARTICULAR VULNERABILITIES IN YOUR CODE;
  • ANY FINDING IS ACCURATE, COMPLETE, CORRECTLY PRIORITISED, OR ACTUALLY EXPLOITABLE;
  • ANY CONFIDENCE SCORE IS AN ACCURATE PREDICTION OF RISK;
  • ANY GENERATED PATCH WILL REMEDIATE A VULNERABILITY, OR WILL DO SO WITHOUT INTRODUCING A DEFECT, REGRESSION OR NEW VULNERABILITY;
  • ANY ATTACKER MODE OR SANDBOX RESULT REFLECTS HOW YOUR APPLICATION WILL BEHAVE IN PRODUCTION; OR
  • USE OF THE SERVICE WILL RESULT IN COMPLIANCE WITH ANY LAW, REGULATION, STANDARD OR FRAMEWORK.

YOU MUST REVIEW AND TEST ALL AUTOMATED FIXES BEFORE DEPLOYMENT. We are not responsible for defects, outages, data loss or security issues arising from code you deploy, whether or not that code originated as Output. Your review is the control that stands between a finding and a shipped change, and section 13.2 sets out what that means for responsibility.

12.3 Local execution

The Project Map and the local sandbox run on your machine and consume your resources. You are responsible for your development environment and for any effect running them has on it.

12.4 Statutory rights

Some jurisdictions do not allow the exclusion of certain warranties. Where that is the case, the exclusions in this section apply only to the extent permitted, and nothing here affects a consumer right that cannot be excluded under the law of your country of residence.

13. Limitation of liability

13.1 Excluded losses

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, BUSINESS, GOODWILL, ANTICIPATED SAVINGS, OR LOSS OR CORRUPTION OF DATA, ARISING OUT OF OR RELATING TO THESE TERMS OR THE SERVICE, WHETHER IN CONTRACT, TORT OR OTHERWISE, AND EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

13.2 Security outcomes and where responsibility sits

Securing software is shared work with a clear division of labour, and this section records it. You acknowledge and agree that:

  • (a) We do not operate your systems. We do not host, deploy, configure or administer your applications, infrastructure or data, and we have no access to your production environment. A security incident in your systems arises from your code, your configuration, your dependencies, your operational choices or the act of a third party, and not from our analysis of them.
  • (b) The Service carries a residual error rate. Automated and AI-assisted analysis is probabilistic: it will miss vulnerabilities, and it will raise findings that prove not to be exploitable. Our multi-layer pipeline is built to reduce that rate, and no tool can eliminate it. You do not rely on the Service as your only security control.
  • (c) The decision to ship is yours. Every finding and every patch is presented to you before anything is applied. Your review, your testing and your decision to deploy are independent acts, and they are the last link in the causal chain between our analysis and whatever follows from it.
  • (d) A scan describes one version of your code, at one moment. Any change you make afterwards, however small and whether or not it touches the file that was scanned, may introduce a vulnerability that no earlier scan could have covered. We do not monitor your code continuously, and we have no obligation to re-scan it, to revisit an earlier result, or to warn you. A result showing nothing wrong says nothing about any version other than the one scanned.

What follows from that. To the maximum extent permitted by applicable law, we are not liable for any loss, damage, regulatory penalty, breach-notification cost, reputational harm or third-party claim arising from a vulnerability the Service did not detect, misclassified or scored incorrectly; from a patch that did not hold; from a result that became stale when your code changed; from a security incident affecting your systems, your data or your users; or from your deployment of any Output.

Section 13.5 still applies: nothing here limits liability that cannot lawfully be limited.

13.3 Cap

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, OUR TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THESE TERMS OR THE SERVICE WILL NOT EXCEED THE GREATER OF (A) THE TOTAL FEES YOU PAID US IN THE TWELVE MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM, OR (B) ONE HUNDRED UNITED STATES DOLLARS (US$100). MULTIPLE CLAIMS DO NOT ENLARGE THIS CAP.

13.4 Basis of the bargain

The disclaimers and limitations in sections 12 and 13 are a fundamental basis of the agreement between us and reflect an allocation of risk that is proportionate to the fees charged. They apply even if a limited remedy is found to have failed of its essential purpose.

13.5 Exceptions

Nothing in these Terms excludes or limits liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, for your obligation to pay fees due, for a party's indemnification obligations under section 14, or for any other liability that cannot lawfully be excluded or limited. Where applicable law does not permit some of the exclusions or limitations above, they apply to the fullest extent permitted.

14. Indemnification

14.1 Your indemnity

You will defend, indemnify and hold harmless SecureCode and its owners, officers, employees, contractors and agents from and against any third-party claim, and any resulting liability, damages, settlement, penalty, and reasonable legal fees, arising out of or relating to:

  • your use of the Service, or any Output you deploy;
  • a security incident, data breach or vulnerability in your applications, infrastructure or data, including any claim brought by your own users, customers or a regulator, whether or not you had scanned the affected code;
  • Your Code, including any claim that Your Code or your submission of it infringes a third party's rights or breaches a confidentiality obligation;
  • personal data you submitted to the Service, including any claim that you lacked a lawful basis to submit it or that you submitted data restricted under section 7.4;
  • your scanning of, or running Attacker Mode against, any system you did not own or were not authorised to test; or
  • your breach of these Terms or of applicable law.

14.2 Procedure

We will notify you promptly of a claim for which we seek indemnity, give you control of the defence and settlement (except that you may not settle in a way that imposes an obligation or admission on us without our written consent), and cooperate at your reasonable expense. Our failure to notify promptly reduces your obligation only to the extent you are prejudiced by the delay.

15. Suspension and termination

15.1 By you

You may stop using the Service at any time, and may cancel a paid subscription as described in section 6.5. You may request deletion of your account by emailing support@usesecurecode.tech.

15.2 Suspension for cause

We may suspend or limit your access, in whole or in part, immediately and without prior notice, where we reasonably believe it is necessary because of: a breach of section 7; fraudulent, abusive or unlawful activity; non-payment of fees that remain overdue after we have notified you; a risk to the security, integrity or availability of the Service or to other users; or a requirement of law. Where practicable we will tell you what has happened and what is needed to restore access.

15.3 Termination for cause

We may terminate these Terms and your account on notice if you materially breach these Terms and, where the breach is capable of remedy, you do not remedy it within 14 days of our notice. We may terminate immediately for a breach of section 7.2, 7.3 or 7.4, or for unlawful activity.

15.4 Termination for convenience

We may terminate these Terms or discontinue the Service for convenience by giving you at least 30 days' notice. If we do, we will refund the prepaid fees covering the unused remainder of your then-current subscription term. We may discontinue the free plan at any time without a refund obligation.

15.5 Effect of termination

On termination your right to use the Service ends immediately. We will handle deletion of your data as described in section 10 of the Privacy Policy. Export any Findings Data you want to keep before terminating.

15.6 Survival

Sections 2, 4, 8, 10, 12, 13, 14, 15.5, 15.6, 16 and 18 survive termination, as does any payment obligation that accrued before termination, together with any other provision that by its nature should survive.

16. Disputes

16.1 Talk to us first

Before starting a formal proceeding, you agree to email us at contact@usesecurecode.tech with a written description of the dispute and the relief you seek, and to allow us 30 days to try to resolve it informally. Most disputes are resolved at this stage. This step is a condition of commencing arbitration, but it does not prevent either party from seeking urgent injunctive relief.

16.2 Governing law and venue

These Terms and any dispute arising out of them are governed by the laws of the Arab Republic of Egypt, without regard to its conflict of laws rules. For any claim that is not subject to arbitration under section 16.3 — including a claim falling within section 16.4 or severed under section 16.6 — the competent courts of Cairo, Egypt have exclusive jurisdiction, except where a small-claims court elsewhere has jurisdiction under section 16.4. This section is without prejudice to section 16.5.

16.3 Arbitration

Subject to sections 16.4 and 16.5, any dispute that is not resolved under section 16.1 will be finally settled by arbitration administered by the Cairo Regional Centre for International Commercial Arbitration (CRCICA) under its rules in force at the time. The seat of arbitration is Cairo, Egypt; there will be one arbitrator; and the language of the arbitration is English. Judgment on the award may be entered in any court of competent jurisdiction.

16.4 Carve-outs

Either party may bring an individual claim in a small-claims or equivalent court that has jurisdiction, and either party may seek injunctive or other equitable relief in any court of competent jurisdiction to protect its intellectual property or confidential information, or to stop unauthorised access to the Service.

16.5 Consumers and mandatory rights

If you use the Service as a consumer and the law of your country of residence gives you a right to bring proceedings in your local courts, or gives you the benefit of mandatory consumer protections, sections 16.2 and 16.3 do not deprive you of that right or those protections.

16.6 No class actions

To the extent permitted by applicable law, each party waives any right to bring or participate in a class, collective, consolidated or representative action, and an arbitrator may not consolidate claims or preside over any form of representative proceeding. If this section 16.6 is found unenforceable in relation to a particular claim, that claim is severed from arbitration and heard in the courts identified in section 16.2, and the remainder of section 16 continues to apply.

16.7 Regulatory complaints preserved

Nothing in this section prevents you from lodging a complaint with a data protection or consumer protection authority, or from reporting a matter to any regulator or law enforcement body.

16.8 Time limit

To the extent permitted by applicable law, any claim arising out of these Terms or the Service must be brought within one year after it arises, or it is permanently barred.

17. Changes to these Terms

We may update these Terms. If a change is material, we will notify you at least 30 days before it takes effect, by email to the address on your account or by a prominent notice in the Service. Changes are not retroactive and do not affect a dispute that arose before they took effect.

If you continue to use the Service after a change takes effect, you accept the updated Terms. If you do not accept them, stop using the Service before the effective date and cancel your subscription; if a material change disadvantages you and you cancel for that reason, we will refund the prepaid fees covering the unused remainder of your then-current term.

18. General

18.1 Entire agreement

These Terms, together with the Privacy Policy and any order or written agreement we sign with you, are the entire agreement between us about the Service and supersede any prior discussions. Where a signed written agreement conflicts with these Terms, that agreement governs.

18.2 Severability

If a provision is held unenforceable, it will be modified to the minimum extent necessary to make it enforceable, or severed if it cannot be, and the remaining provisions stay in force.

18.3 No waiver

A failure or delay in enforcing a right is not a waiver of it.

18.4 Assignment

You may not assign or transfer these Terms without our prior written consent, except to a successor of your business by merger or acquisition that is not a competitor of ours. We may assign these Terms to an affiliate or in connection with a merger, acquisition, financing or sale of assets.

18.5 Notices

We may give notice by email to the address on your account, or by a notice in the Service or on our website. You must give notice to contact@usesecurecode.tech. Notice is effective when sent, and you are responsible for keeping your email address current.

18.6 Force majeure

Neither party is liable for a failure or delay in performance (other than payment of fees) caused by an event beyond its reasonable control, including natural disaster, war, civil unrest, epidemic, labour action, failure of a utility or telecommunications provider, government action, or the failure or discontinuation of a third-party AI provider or infrastructure vendor.

18.7 Export control and sanctions

You must comply with all applicable export control and sanctions laws. You may not use the Service if you are located in, ordinarily resident in, or organised under the laws of a comprehensively sanctioned jurisdiction, or if you are named on an applicable restricted-party list.

18.8 No third-party beneficiaries

These Terms do not give rights to anyone other than you and us.

18.9 Relationship

Nothing in these Terms creates a partnership, joint venture, agency or employment relationship between us.

18.10 Interpretation

Headings are for convenience only. "Including" means "including without limitation". If we publish these Terms in another language and there is a discrepancy, the English version governs to the extent permitted by law.

19. Contact

Legal, contractual, privacy and security reports: contact@usesecurecode.tech

Support, billing and cancellations: support@usesecurecode.tech

Anything else: hello@usesecurecode.tech

By using SecureCode you acknowledge that you have read and understood these Terms and agree to be bound by them.