Terms
Terms of service
Last updated August 26, 2026. See our Privacy Policy for how we handle your data.
1. Acceptance of terms & eligibility
Welcome to Riskline ("Riskline", "we", "us", or "our"), an AI-assisted automated security scanning service. The Service is provided by Leontios Konstantinidis, an individual based in Greece, operating as Riskline (formal business-entity registration, if and when it occurs, will be reflected here without changing the substance of these Terms).
By accessing or using our website (riskline.co), API, GitHub App, or associated services (collectively, the "Service"), you agree to be bound by these Terms of Service ("Terms"). If you do not agree, you may not use the Service.
You must be at least 18 years old, or the age of majority in your jurisdiction, to use the Service on your own behalf. If you are between 16 and that age, you may only use the Service under the supervision of a parent or legal guardian who agrees to these Terms on your behalf. The Service is not directed at, and may not be used by, anyone under 16. We do not independently verify age; you are solely responsible for the accuracy of your eligibility representation. A parent or guardian who becomes aware that a child has created an account should contact support@riskline.co for prompt account closure.
If you are using the Service on behalf of an organization, you represent and warrant that you have the authority to bind that organization to these Terms, and "you" refers to that organization.
2. Description of service & crucial security disclaimer
Riskline provides automated static analysis and AI-interpretation tooling designed to identify common security misconfigurations, vulnerabilities, and exposed secrets in software repositories (for example, exposed API keys, OWASP Top 10 vulnerability patterns, and Supabase/Firestore access-rule gaps), using established third-party engines (including Semgrep, Gitleaks, and the OSV.dev advisory database) that Riskline orchestrates and interprets.
"AS-IS" disclaimer & limitations of scanning
Software security is complex and constantly changing. The Service is provided strictly on an "AS-IS" and "AS-AVAILABLE" basis. We expressly disclaim any warranty, express or implied, that the Service will:
- Identify 100% of bugs, vulnerabilities, or security flaws in your code;
- Protect you against zero-day exploits, sophisticated attacks, business-logic flaws, or issues outside the specific checks described in our Security Details page;
- Produce AI-generated explanations, fix-prompts, or automatically generated code changes and pull requests that are flawless or suited to your specific system architecture;
- Constitute a professional, human-led security audit, penetration test, or compliance certification of any kind (SOC 2, ISO 27001, PCI DSS, or otherwise). We do not hold, and do not claim to hold, any such certification.
Riskline is a supplementary developer tool. You are solely responsible for reviewing, testing, and verifying any finding, fix-prompt, or automatically generated pull request before relying on it or deploying it to production. A grade, "clean scan," or badge issued by Riskline reflects the specific automated checks described in our Security Details page at a specific point in time. It is not, and must never be treated as, a guarantee that a project is free of vulnerabilities.
Feature descriptions & fair use. Terms like "unlimited scans" or "priority support" describe the intended shape of a plan, not a guaranteed service level. All use of the Service, including on plans described as unlimited, remains subject to reasonable use and the rate and abuse limits described in Section 6, and "priority support" means faster average handling on a best-effort basis, not a guaranteed response time. Neither constitutes a service-level agreement (SLA) unless we separately agree to one with you in writing.
3. Authorized code uploads & your warranties
By uploading source code, configuration files, or any other materials (collectively, "Your Code") to Riskline, whether by direct upload or by connecting a repository, you represent and warrant that:
- You are the creator and legal owner of Your Code, or you hold all necessary legal authority, licenses, consents, and permissions to upload and scan it;
- Your Code does not infringe the intellectual property, privacy, or confidentiality rights of any third party;
- Your Code, and your use of the Service, does not violate any applicable law, including export control and sanctions law (see Section 12); and
- You will not use the Service to scan malware, ransomware, or code whose purpose is malicious, or to evade antivirus or security detection.
Uploading stolen, leaked, or unauthorized proprietary code belonging to a third party is a material breach of these Terms and grounds for immediate suspension or termination.
If Riskline opens a pull request on your behalf (a Guardian Pro feature), you remain solely responsible for reviewing, testing, and deciding whether to merge it. Riskline never merges a pull request automatically, and Riskline has no liability for any consequence of your decision to merge, deploy, or otherwise act on a suggested change without independent review.
4. Intellectual property rights
Your Code (you own 100%): You retain all rights, title, and interest in Your Code. Riskline claims no ownership or license over it beyond what is strictly necessary to operate the Service (extraction into an isolated sandbox, scanning, and immediate deletion on scan completion, as described in our Privacy Policy). We do not use Your Code to train or fine-tune any AI model.
Your Reports: You own the findings, explanations, grades, and PDF reports generated about your own projects, and you may freely use, reproduce, and share them, including the "Scanned & Secured" trust badge and any Audit Report you purchase.
Riskline's IP: We retain all right, title, and interest in the Riskline platform, detection rules, AI-prompt architecture, report design, website, and our brand and trademarks. You may not copy, modify, decompile, reverse-engineer, or distribute our proprietary software, rules, or interface, except as expressly permitted by law notwithstanding this restriction.
5. Subscriptions, payments, billing & chargebacks
Riskline offers a Free tier, paid subscriptions (Guardian at $19/month; Guardian Pro at $49/month), and one-time purchases scoped to a specific project or scan (Clean Bill at $17; Audit Report at $199).
- Payments: All payments are processed by Lemon Squeezy, our merchant of record and the seller of record for tax purposes. Lemon Squeezy, not Riskline, is responsible for collecting and remitting applicable sales tax and VAT on your purchase. By providing payment information, you authorize Riskline, via Lemon Squeezy, to charge the applicable fee.
- Automatic renewal: Paid subscriptions renew automatically at the end of each monthly billing cycle unless cancelled beforehand. One-time purchases do not renew.
- Cancellation: You may cancel at any time via the Lemon Squeezy billing portal in your account settings. Cancellation takes effect at the end of the current paid cycle; you keep access to paid features until then.
- Refunds: Fees are non-refundable, including for mid-cycle cancellations and for one-time purchases once the purchased feature has been used, except where required by applicable consumer-protection law. Nothing in this section limits any mandatory remedy available to you under the EU Digital Content and Digital Services Directive (2019/770) if the Service does not conform to its description; those remedies (repair, replacement, price reduction, or contract termination as applicable) are preserved and are in addition to, not instead of, this refund policy.
- Chargebacks & payment disputes: If you initiate a chargeback, dispute, or reversal of a payment without first contacting us to resolve the issue, we may immediately suspend or terminate your account and access to any data, reports, or features associated with the disputed payment, and may recover the disputed amount together with any reasonable fees we incur as a result (such as chargeback fees), in addition to any other remedy available to us. Repeated or bad-faith chargebacks are grounds for permanent termination.
6. Acceptable use policy
You agree not to:
- Reverse-engineer, decompile, or attempt to extract the source code of the Riskline application, workers, or detection rules;
- Create multiple accounts to evade rate limits, quotas, or the scope of the Free tier, or use automated means to scrape, probe, or bulk-test the Service in a manner designed to reconstruct our detection logic;
- Intentionally bypass, abuse, or overwhelm our API rate limits or infrastructure, including uploading "zip bomb" or "zip-slip" payloads;
- Use the Service to scan code you do not have the right to submit, or code whose purpose is malicious;
- Perform automated or manual penetration testing against Riskline's own infrastructure without our prior written consent (see Section 15 for how to report a vulnerability instead).
7. Trust badges, Audit Reports & no third-party reliance
The Trust Badge and any report or grade generated by the Service (including the Audit Report product) reflect the output of an automated scan at a specific point in time, scoped to the checks described in our Security Details page. They are not, and must not be represented as, an independent audit, a certification, or a warranty of security.
No third-party beneficiaries; no reliance by third parties. Reports, grades, and badges are prepared for your own use. No investor, acquirer, customer, regulator, or other third party may rely on a Riskline report, grade, or badge as a substitute for their own independent diligence, and Riskline accepts no liability to any such third party arising from their reliance on it, including where a report was shared or displayed at your direction (for example, in an investor update or procurement questionnaire).
8. Term, suspension & termination
These Terms remain in effect while you use the Service. You may stop using the Service and delete your account at any time from your account settings.
We may suspend or terminate your access to the Service, in whole or in part, immediately and without notice, if: (a) you materially breach these Terms, including the warranties in Sections 3 or 6; (b) your use poses a security, legal, or operational risk to Riskline or other users; (c) required by law or a competent authority; or (d) as described in Section 5 regarding chargebacks. We may otherwise suspend or terminate accounts, including free accounts, for any reason or no reason, with 30 days' notice where reasonably practicable.
On termination: your right to use the Service ends immediately; Your Code and associated scan data are deleted or scheduled for deletion in accordance with our Privacy Policy; fees already paid are not refunded except as required by law; and any provision of these Terms that by its nature should survive termination (including Sections 4, 7, 9, 10, 11, and 14) will survive.
9. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT WILL RISKLINE, ITS OPERATOR, EMPLOYEES, CONTRACTORS, OR AFFILIATES BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING LOSS OF PROFITS, REVENUE, DATA, OR GOODWILL, ARISING FROM OR RELATING TO:
- YOUR USE OF OR INABILITY TO USE THE SERVICE, INCLUDING ANY DOWNTIME OR UNAVAILABILITY OF THE SERVICE OR OF ANY THIRD-PARTY INFRASTRUCTURE WE RELY ON;
- ANY SECURITY BREACH, HACK, OR DATA COMPROMISE OF YOUR OWN SOFTWARE, EVEN IF RISKLINE SCANNED IT AND DID NOT DETECT THE VULNERABILITY;
- ANY ERROR, OMISSION, OR INACCURACY IN AN AI-GENERATED REPORT, FIX-PROMPT, OR AUTOMATICALLY GENERATED CODE CHANGE OR PULL REQUEST, THE ACT OF OPENING OR ATTEMPTING TO OPEN SUCH A PULL REQUEST ON A CONNECTED REPOSITORY, OR YOUR DECISION TO MERGE OR ACT ON ONE;
- ANY THIRD PARTY'S RELIANCE ON A REPORT, GRADE, OR BADGE YOU SHARED OR DISPLAYED.
LIABILITY CAP: Riskline's total aggregate liability for all claims relating to the Service will not exceed the greater of (a) the total amount you paid Riskline in the twelve months immediately preceding the event giving rise to the claim, or (b) one hundred euros (€100).
Carve-outs: Nothing in these Terms excludes or limits liability that cannot be excluded or limited under applicable law, including liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or gross negligence or willful misconduct.
What this carve-out is not: For clarity, none of the following, by themselves, constitute gross negligence or willful misconduct: a vulnerability that existed outside the specific checks described in our Security Details page and was not detected; an error, omission, or imprecision in an AI-generated explanation or fix-prompt; a good-faith security incident despite the measures described in our Security Details page; or downtime caused by a third-party infrastructure provider. This paragraph narrows what the carve-out means; it does not expand the exclusion above it.
10. Disclaimer of warranties
EXCEPT AS EXPRESSLY STATED IN THESE TERMS, THE SERVICE IS PROVIDED WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT, AND ANY WARRANTY ARISING FROM COURSE OF DEALING OR USAGE OF TRADE. WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, TIMELY, SECURE, OR ERROR-FREE, OR THAT ANY THIRD-PARTY TOOL WE RELY ON (INCLUDING SEMGREP, GITLEAKS, OSV.DEV, OR OUR AI SUB-PROCESSOR) IS FREE OF DEFECT. NOTHING IN THIS SECTION AFFECTS ANY STATUTORY RIGHTS YOU HAVE AS A CONSUMER THAT CANNOT BE WAIVED BY CONTRACT.
11. Indemnification
You agree to defend, indemnify, and hold harmless Riskline, its operator, and affiliates from any claim, damage, liability, cost, or expense (including reasonable attorneys' fees) arising from: (a) your use of the Service; (b) your breach of these Terms, including your warranties regarding Your Code; (c) your violation of any third-party right, including intellectual property or privacy rights; or (d) content you submit that is unlawful or that you were not authorized to submit.
12. Export control & sanctions compliance
You represent that you are not located in, and are not a national or resident of, any country or region subject to comprehensive sanctions, and that you are not listed on any applicable restricted-party or denied-persons list. You agree not to use the Service in violation of applicable export control or sanctions laws, including those of the European Union and the United States.
13. Force majeure
Neither party is liable for any failure or delay in performance to the extent caused by circumstances beyond its reasonable control, including natural disaster, war, act of terrorism, labor dispute, internet or telecommunications failure, or a widespread outage of a third-party infrastructure provider we rely on (such as our hosting, database, or payment providers). This section excuses delayed or prevented performance; it does not excuse your obligation to pay fees already incurred for a billing period that had already begun.
14. Governing law & dispute resolution
These Terms are governed by the laws of Greece and applicable European Union law, without regard to conflict-of-law provisions. Subject to the paragraph below, any dispute arising out of or relating to these Terms is subject to the exclusive jurisdiction of the courts of Athens, Greece.
If you are a consumer habitually resident elsewhere, including another European Union member state or the United Kingdom, this choice of law does not deprive you of any mandatory consumer-protection you are entitled to under the law of your country of residence, and, where applicable law entitles you to do so (for example, under the Brussels I Recast Regulation for EU consumers), you may bring or defend proceedings in the courts of your own country of residence.
15. Reporting a vulnerability
As a security company, we take reports of vulnerabilities in our own Service seriously. If you believe you have found a security issue in Riskline itself, please report it privately to support@riskline.co with enough detail to reproduce it, and give us a reasonable opportunity to investigate and remediate before any public disclosure. Do not access, modify, or exfiltrate another user's data while investigating an issue. Good-faith research conducted consistently with this policy will not be treated as a violation of Section 6.
16. Notice of claimed infringement
If you believe content processed through the Service infringes your intellectual property rights, send a notice to support@riskline.co identifying the material and the basis for your claim, together with your contact details. We will review and respond to good-faith notices, which may include removing access to the relevant scan or report and, where warranted, suspending the account that submitted it under Section 8.
17. General provisions
Severability: If any provision of these Terms is found unenforceable, the remaining provisions remain in full force, and the unenforceable provision will be enforced to the maximum extent permitted.
Entire agreement: These Terms, together with our Privacy Policy and Cookie Policy, constitute the entire agreement between you and Riskline regarding the Service, and supersede any prior agreement on the subject.
No waiver: Our failure to enforce any provision is not a waiver of our right to do so later.
Assignment: You may not assign these Terms without our prior written consent. We may assign these Terms without restriction, including in connection with a merger, acquisition, restructuring, or sale of assets.
No third-party beneficiaries: These Terms are for the benefit of you and Riskline only. No other person or entity, including your end users, customers, or investors, has any right to enforce these Terms or to bring a claim against Riskline arising from your use of the Service.
Relationship of the parties: Nothing in these Terms creates a partnership, joint venture, agency, or employment relationship between you and Riskline.
Notices: We may provide notices to you via email or a prominent notice on the Service. Notices to us should go to support@riskline.co.
18. Right of withdrawal (EU consumers)
If you are a consumer in the European Union, you generally have the right to withdraw from a distance contract within 14 days without giving a reason, under the EU Consumer Rights Directive (2011/83/EU). Because Riskline is a digital service that we begin performing as soon as you sign up or make a purchase (for example, by running a scan or generating a report), starting to use the Service, or requesting immediate access to a one-time product such as Clean Bill or an Audit Report, constitutes your express request that we begin performance immediately. You acknowledge that once we have fully performed a one-time digital service at your request, you lose your right of withdrawal for that purchase, consistent with Article 16(m) of the Directive. For a paid subscription, you may still cancel at any time as described in Section 5; the 14-day withdrawal right, where it still applies, entitles you to a refund only for the unused portion of a subscription you withdraw from within that window before making substantial use of it.
19. Data processing & sub-processor terms (business customers)
If personal data is incidentally contained in Your Code or account data, and you are a controller under GDPR engaging Riskline as a processor, the following terms apply between us in addition to the rest of these Terms, satisfying the substance of Article 28(3) GDPR without requiring a separate signed document:
- We will process personal data only on your documented instructions (namely, to provide the Service), unless required otherwise by law;
- Personnel authorized to process the data are bound by confidentiality;
- We implement the technical and organizational measures described in our Security Details page;
- We use the sub-processors listed in our Privacy Policy, and will notify you of material changes as described there, giving you an opportunity to object;
- We will assist you, to the extent reasonably possible, in responding to data subject rights requests and in meeting your own breach-notification and data protection impact assessment obligations relating to your use of the Service;
- At the end of our relationship, we will delete personal data in accordance with our Privacy Policy, or return it where we are able to and you request it before deletion; and
- We will make available information reasonably necessary to demonstrate compliance with this section.
If your own compliance program requires a separately signed, bespoke Data Processing Addendum, one is available on request at support@riskline.co; this section governs in the meantime and to the extent a bespoke addendum does not depart from it in writing.
20. Service discontinuation
If we ever decide to permanently discontinue the Service, we will provide reasonable advance notice where practicable (targeting at least 30 days, except where continuing to operate would itself create a legal or security risk), and a reasonable opportunity to export your account data and reports before shutdown. Discontinuation does not entitle you to a refund of fees already paid beyond what Section 5 or applicable law otherwise requires.
21. Changes to terms
We may modify these Terms at any time. For material changes, we will provide at least 30 days' notice via email or a prominent notice on the Service before the new terms take effect. Continued use of the Service after that point means you accept the revised Terms.
22. Contact information
If you have any questions, concerns, or legal inquiries regarding these Terms of Service, please contact us at support@riskline.co.
