These Terms and Conditions (“Terms”) form a binding agreement between Secure Code LLC, located at 417 Staunton Dr, Leander, Texas 78641 (“Secure Code,” “Company,” “we,” “us,” or “our”), and the entity or person accepting them (“Customer,” “you,” or “your”). The Terms govern Zyloch, including its web application, APIs, GitHub App, scanning engine, dashboards, reports, Software Bills of Materials, and related services (collectively, the “Services”).
By creating an account, installing or authorizing the Zyloch GitHub App, starting a trial, purchasing a Subscription, clicking to accept, or otherwise using the Services, you agree to these Terms. A person accepting the Terms for an organization represents that the person is authorized to bind that organization. A person without such authority must not accept the Terms or use the Services for that organization.
1. Eligibility and Business Use
1.1The Services are intended for business-to-business use by software-development, DevOps, platform-engineering, compliance, and security teams. You must be at least 18 years old and legally capable of entering into a binding agreement.
1.2You may use the Services only for lawful business purposes and only in connection with repositories, systems, configurations, and data that you own or are authorized to access and scan.
1.3Customer is responsible for ensuring that every User acting through its account complies with these Terms. Any act or omission by a User is treated as an act or omission of Customer.
2. Definitions
2.1“Authorized User” or “User” means an individual whom Customer permits to access the Services under Customer’s account.
2.2“Customer Data” means data, files, configurations, repository content, metadata, workspace information, policy settings, comments, support communications, and other content submitted to or processed through the Services on Customer’s behalf.
2.3“Documentation” means technical, operational, or usage materials supplied by Secure Code for the Services.
2.4“Findings” means security, configuration, policy, vulnerability, compliance, or other results generated through the Services.
2.5“Subscription” means a paid monthly or annual right to access a selected Service plan.
2.6“Third-Party Service” means a service, platform, database, integration, infrastructure provider, payment provider, or data source operated by a third party.
3. The Services
3.1Zyloch is a multi-tenant developer-security SaaS platform that scans infrastructure-as-code and software-delivery configurations, including Docker files, Kubernetes configurations, GitHub Actions workflows, and repository metadata.
3.2The Services may evaluate submitted materials against security or policy rules, identify potential issues, generate SBOMs, and display ranked Findings through a dashboard or API.
3.3Secure Code grants Customer a limited, non-exclusive, non-transferable, and non-sublicensable right to access and use the Services during the applicable trial or Subscription term, solely for Customer’s internal business operations, subject to the selected plan’s usage limits and to suspension or termination only as provided in these Terms.
3.4Features, repository limits, scan frequency, policy capabilities, storage, support, and other entitlements may vary by plan. Current plan details displayed at purchase or recorded in an order form form part of these Terms.
3.5The Services provide automated technical analysis. Findings may contain false positives, false negatives, incomplete information, or results affected by repository structure, available permissions, third-party data, policy configuration, or technical limitations. Customer remains responsible for evaluating Findings, testing remediation, and deciding whether and how to act.
3.6The Services do not constitute a legal opinion, regulatory certification, penetration test, guarantee of compliance, or guarantee that software, infrastructure, or pipelines are secure or free from vulnerabilities.
4. Accounts, Organizations, and Access
4.1Users may register using an email address and credentials or authenticate through GitHub where available. Customer must provide accurate account information and keep it current.
4.2Accounts may belong to an organization or tenant. Tenant administrators may invite or remove Users, assign roles, connect repositories, configure policies, access Customer Data, and manage the Subscription.
4.3Customer is responsible for controlling administrator permissions, maintaining the confidentiality of credentials and authentication tokens, and preventing unauthorized access.
4.4Customer must promptly notify Secure Code at privacy@secure-code.dev after discovering suspected account compromise, credential theft, unauthorized repository access, or misuse of the Services. 4.5Secure Code may rely on instructions submitted through an authenticated account. We are not responsible for losses caused by Customer’s failure to secure credentials, integrations, or administrator access, except to the extent caused by our breach or applicable law.
5. GitHub Integration and Repository Access
5.1Customer may authorize the Zyloch GitHub App and related authentication functions to access selected repositories. The integration is designed to use read-only repository access unless a separately described feature requires additional permission and Customer expressly authorizes it.
5.2By connecting a repository, Customer instructs Secure Code to receive relevant webhooks, retrieve repository and branch details, access supported configuration files, temporarily clone repository content when required for a scan, and process associated metadata.
5.3Metadata may include GitHub username, name, email address, repository name, branch information, commit identifier, commit message, and commit author information.
5.4Temporary repository clones used for scanning are deleted after the applicable scan has completed. Scan results, SBOMs, Findings, policy records, and limited repository or commit metadata may remain available within Customer’s account according to the Services, selected settings, and applicable retention practices.
5.5Customer represents that it has all rights, permissions, notices, and authorizations required to connect each repository and permit the processing described in these Terms.
5.6Removing the GitHub App or revoking permissions may stop future scans and limit Service functionality. Revocation does not automatically delete Customer Data already retained within the Services.
6. Customer Data
6.1Customer retains all ownership rights in Customer Data. No ownership interest in Customer Data transfers to Secure Code.
6.2Customer grants Secure Code and its contracted service providers a worldwide, limited, non-exclusive right to host, copy, transmit, access, use, and process Customer Data only as reasonably necessary to provide, secure, maintain, and support the Services, comply with Customer’s documented instructions, prevent misuse, and satisfy applicable legal obligations. Secure Code may use aggregated or de-identified technical and usage information to analyze and improve the Services, provided that such information does not identify Customer, any User, repository content, or another person.
6.3Customer is responsible for the legality, accuracy, quality, and integrity of Customer Data and for maintaining independent copies of any data needed for business continuity, recordkeeping, or compliance.
6.4Customer must not submit special-category, highly sensitive, regulated, or consumer data unless the Services expressly support it and Secure Code has agreed in writing. Prohibited data includes protected health information, payment-card data, government identification numbers, and personal data unrelated to Zyloch’s intended developer-security use.
6.5Secure Code may remove or restrict access to Customer Data that reasonably appears unlawful, malicious, infringing, or likely to threaten the Services or third parties. Where lawful and practicable, we will notify Customer before or promptly after taking action.
7. Free Trial
7.1Secure Code may offer a 14-day free trial. No payment details are required to begin any such trial.
7.2Trial features, usage, storage, and support may be limited. Secure Code may end a trial where Customer abuses the offer, creates duplicate accounts, or violates these Terms.
7.3A trial does not convert into a paid Subscription unless Customer affirmatively selects a paid plan and provides an accepted payment method through the designated payment provider.
7.4Trial Customer Data may become unavailable after the trial expires. Customer must export any required information before expiration.
8. Subscriptions, Fees, and Billing
8.1Paid access is offered through monthly or annual Subscriptions. Prices, plan limits, billing intervals, and applicable charges are disclosed during checkout or in an order form.
8.2Customer authorizes Secure Code and its payment provider to charge the selected payment method for all fees, applicable taxes, and approved charges. Secure Code does not store full payment-card details.
8.3Subscriptions renew automatically for successive periods equal to the initial billing period unless Customer cancels before the renewal date. Customer may cancel through available account controls or by contacting Secure Code using the contact details in Section 24.
8.4Cancellation stops future renewal charges but does not terminate access before the end of the paid period, unless the cancellation qualifies for an annual-plan refund under Section 9 or Secure Code confirms an earlier termination.
8.5Upgrades take effect immediately and may result in a prorated or immediate charge. Downgrades take effect at the next renewal date unless otherwise shown at the time of change.
8.6Fees are due in the currency and on the schedule shown at purchase. Customer is responsible for applicable transaction taxes, excluding taxes based on Secure Code’s net income.
8.7Failed, disputed, reversed, or overdue payments may result in restricted access or suspension. Customer remains responsible for undisputed amounts accrued before suspension or termination.
8.8Secure Code may change Subscription prices by giving advance notice before the change applies. A price change will ordinarily take effect at the next renewal, unless Customer agrees to an earlier change.
9. Cancellation and Refunds
9.1Monthly Subscriptions are non-refundable. Cancellation of a monthly Subscription prevents the next renewal charge, and access continues until the end of the current paid month unless the account is terminated earlier for breach.
9.2A Customer purchasing an annual Subscription may cancel within three calendar days after the applicable annual purchase. Secure Code will retain a cancellation fee equal to 15% of the amount paid and refund the remaining 85%.
9.3An annual cancellation request received after the three-day period is not eligible for a refund, except where applicable law requires otherwise.
9.4Refund requests must identify the account, organization, charge, and reason for cancellation. Approved refunds will be returned through the original payment method where practicable.
9.5Fees for usage already incurred, separately purchased professional services, or third-party charges are non-refundable unless Secure Code agrees otherwise in writing or applicable law requires a refund.
10. Acceptable Use
10.1Customer and Users must not:
10.1.1access or scan repositories, systems, accounts, or data without authorization;
10.1.2use the Services to attack, exploit, disrupt, damage, or gain unauthorized access to any system;
10.1.3upload malware, destructive code, unlawful content, or material designed to evade or compromise security controls;
10.1.4reverse engineer, decompile, disassemble, copy, modify, or create derivative works from the Services, except where a restriction is prohibited by law;
10.1.5bypass plan limits, rate limits, authentication, access controls, or technical restrictions;
10.1.6resell, sublicense, rent, time-share, or provide the Services as a service bureau without Secure Code’s written authorization;
10.1.7interfere with the operation, integrity, or performance of the Services or Third-Party Services;
10.1.8use automated means to scrape or extract data from the Services except through an authorized API;
10.1.9use the Services or their output to develop or train a substantially competing security-scanning product, except with Secure Code’s written permission;
10.1.10misrepresent Findings, reports, or SBOMs as an endorsement, certification, or warranty issued by Secure Code; or
10.1.11use the Services in violation of applicable export-control, sanctions, privacy, intellectual-property, cybersecurity, or other laws.
10.2Secure Code may investigate suspected misuse and cooperate with lawful requests from competent authorities.
11. Security and Confidentiality
11.1Secure Code will maintain reasonable administrative, technical, and organizational safeguards designed to protect Customer Data against unauthorized access, use, alteration, or disclosure.
11.2Each party may receive non-public information identified as confidential or reasonably understood to be confidential, including source code, repository content, security Findings, credentials, pricing, and business information (“Confidential Information”).
11.3The receiving party must use Confidential Information only to perform or receive the Services, protect it using reasonable care, and disclose it only to personnel and contractors who need access and are bound by confidentiality obligations.
11.4Confidential Information does not include information that the receiving party can document was lawfully known without restriction, independently developed without use of the other party’s information, lawfully obtained from a third party, or publicly available without breach.
11.5A receiving party may disclose Confidential Information where required by law, subpoena, or court order. Where legally permitted, the receiving party will provide prompt notice and reasonable assistance so the disclosing party may seek protective treatment.
12. Intellectual Property
12.1Secure Code and its licensors own all rights in the Services, Documentation, interfaces, software, policy engines, rules, designs, trademarks, APIs, workflows, and related technology, excluding Customer Data.
12.2No rights are granted except the limited access rights expressly stated in these Terms. Secure Code reserves all rights not expressly granted.
12.3Findings and SBOMs generated specifically from Customer Data may be used by Customer for its internal business purposes during and after the Subscription, subject to any third-party rights and data-source restrictions identified in the Services.
12.4Customer must not remove proprietary notices from the Services or Documentation.
12.5Customer may provide suggestions or feedback. Customer grants Secure Code a perpetual, worldwide, irrevocable, royalty-free right to use that feedback without restriction or obligation, provided Secure Code does not identify Customer publicly as the source without permission.
13. Third-Party Services
13.1The Services may interact with GitHub, cloud-infrastructure providers, MongoDB Atlas, payment providers, vulnerability or SBOM intelligence sources, and error-monitoring services.
13.2Third-Party Services are governed by their own terms and privacy practices. Secure Code does not control their availability, changes, security, or acts, except where applicable law provides otherwise.
13.3Customer authorizes Secure Code to transmit Customer Data to Third-Party Services where reasonably necessary to provide the requested functionality.
13.4Changes, outages, permission restrictions, or discontinued features affecting a Third-Party Service may impair the Services. Secure Code may replace, modify, or discontinue an affected integration.
14. Privacy and Data Processing
14.1Secure Code will process personal data in accordance with its Privacy Policy and applicable data-protection law.
14.2Where Secure Code processes personal data on Customer’s behalf as a service provider, processor, or equivalent regulated role, the parties will comply with any data-processing terms required by applicable law and agreed in writing.
14.3Customer is responsible for providing legally required notices, obtaining valid permissions, responding to relevant requests concerning Customer-controlled data, and establishing a lawful basis for connecting repositories and submitting personal data to the Services.
14.4Regional data storage or processing options, where available, are governed by the selected plan, product configuration, Documentation, or a written order form. Customer acknowledges that authorized support, security, payment, and infrastructure operations may involve cross-border access or processing subject to applicable safeguards.
15. Service Availability and Changes
15.1Secure Code may perform maintenance, apply security patches, modify features, update policies, or change technical components. We will use reasonable efforts to avoid material disruption where practicable.
15.2No service-level commitment applies unless stated in a separate written service-level agreement.
15.3Secure Code may discontinue a material paid feature or the Services by giving reasonable advance notice where practicable. Customer’s sole remedy for a prepaid period materially affected by permanent discontinuation is a prorated refund for the unused portion, unless replacement functionality is provided.
15.4Emergency maintenance, security incidents, legal requirements, provider outages, and events outside reasonable control may require immediate action without advance notice.
16. Warranties and Disclaimers
16.1Each party represents that it has authority to enter into these Terms.
16.2Secure Code warrants that it will provide the paid Services with reasonable skill and care. Customer’s exclusive remedy for a verified breach of that warranty is re-performance of the affected Services or, where re-performance is not reasonably possible, termination and a prorated refund for the affected unused prepaid period.
16.3EXCEPT FOR THE EXPRESS WARRANTY IN SECTION 16.2, THE SERVICES, FINDINGS, SBOMS, DOCUMENTATION, TRIALS, AND INTEGRATIONS ARE PROVIDED “AS IS” AND “AS AVAILABLE.” TO THE FULLEST EXTENT PERMITTED BY LAW, SECURE CODE DISCLAIMS IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, AVAILABILITY, AND ERROR-FREE OPERATION.
16.4SECURE CODE DOES NOT WARRANT THAT EVERY VULNERABILITY, MISCONFIGURATION, POLICY VIOLATION, DEPENDENCY, OR COMPLIANCE ISSUE WILL BE DETECTED, THAT EVERY FINDING IS CORRECT, OR THAT USE OF THE SERVICES WILL PREVENT SECURITY INCIDENTS OR ESTABLISH COMPLIANCE.
16.5Customer is responsible for security decisions, code review, testing, remediation, backups, access controls, regulatory analysis, and professional advice appropriate to its operations.
17. Limitation of Liability
17.1TO THE FULLEST EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, PUNITIVE, OR CONSEQUENTIAL DAMAGES, OR FOR LOST PROFITS, REVENUE, BUSINESS, GOODWILL, DATA, OR ANTICIPATED SAVINGS, ARISING FROM OR RELATED TO THE SERVICES OR THESE TERMS, EVEN IF ADVISED THAT SUCH LOSS WAS POSSIBLE.
17.2TO THE FULLEST EXTENT PERMITTED BY LAW, SECURE CODE’S TOTAL AGGREGATE LIABILITY ARISING FROM OR RELATED TO THE SERVICES OR THESE TERMS WILL NOT EXCEED THE FEES PAID OR PAYABLE BY CUSTOMER FOR THE SERVICES DURING THE 12 MONTHS BEFORE THE EVENT GIVING RISE TO LIABILITY. FOR A FREE TRIAL OR FREE PLAN, SECURE CODE’S TOTAL AGGREGATE LIABILITY WILL NOT EXCEED USD 100.
17.3The limitations do not apply to liability that cannot lawfully be excluded or limited. Applicable mandatory rights remain unaffected.
17.4Each limitation applies regardless of the legal theory asserted and applies collectively to Secure Code and its personnel, suppliers, licensors, and contractors.
18. Indemnification
18.1Customer will defend, indemnify, and hold harmless Secure Code and its affiliates, officers, employees, contractors, and licensors from third-party claims, damages, judgments, penalties, costs, and reasonable legal fees arising from:
18.1.1Customer Data or Customer’s repositories;
18.1.2Customer’s lack of authority to access, connect, submit, or scan data or systems;
18.1.3Customer’s unlawful, infringing, or unauthorized use of the Services;
18.1.4Customer’s violation of Section 10; or
18.1.5Customer’s breach of applicable law or third-party rights.
18.2Secure Code will promptly notify Customer of an indemnified claim, permit reasonable control of the defense, and cooperate at Customer’s expense. Customer may not settle in a manner that admits wrongdoing by, imposes obligations on, or fails to release Secure Code without written consent.
19. Suspension
19.1Secure Code may suspend access where reasonably necessary to:
19.1.1prevent or address a security threat, unlawful activity, or material risk to the Services or another customer;
19.1.2respond to unauthorized use or a material breach of these Terms;
19.1.3comply with law or a binding governmental request;
19.1.4address overdue payment; or
19.1.5protect Customer Data, systems, or third parties.
19.2Where lawful and practicable, Secure Code will notify Customer of the reason for suspension and restore access after the underlying issue is resolved.
20. Term and Termination
20.1The Terms begin when Customer first accepts them or uses the Services and continue until all accounts, trials, and Subscriptions governed by them have ended.
20.2Customer may terminate by cancelling its Subscription, disconnecting integrations, and closing its account. Fees remain subject to Sections 8 and 9.
20.3Either party may terminate for material breach if the breach is not cured within 15 days after written notice. Secure Code may terminate immediately where a breach is unlawful, threatens security, cannot reasonably be cured, or involves repeated violations.
20.4Upon termination, Customer’s right to use the Services ends. Customer must stop using Secure Code software, credentials, APIs, and Documentation, except for retained copies lawfully required for recordkeeping.
20.5Customer may export available Customer Data through the download functionality before termination. If Customer selected post-cancellation retention during installation or account configuration, applicable account data, repository metadata, scan results, support communications, and other available Customer Data may remain accessible for up to 15 days after cancellation and will then be deleted from active systems, subject to Section 20.6. If Customer did not select post-cancellation retention, Secure Code will begin deleting such data from active systems promptly after termination, subject to Section 20.6.
20.6Secure Code may retain billing, security, dispute, and legal records for a longer period where permitted or required by law. Customer Data remaining in protected backups will be deleted or overwritten no later than 15 days after cancellation, unless a longer period is required by applicable law. Backup data will not be restored for ordinary business use after the applicable deletion deadline.
20.7Sections concerning accrued payment obligations, confidentiality, intellectual property, disclaimers, liability, indemnification, governing law, and any provisions intended by their nature to survive will remain effective after termination.
21. Changes to These Terms
21.1Secure Code may update these Terms to reflect Service changes, legal requirements, security needs, or business practices.
21.2Material changes will be communicated through the Services, by email, or by another reasonable method before taking effect. The notice will state the effective date.
21.3Continued use after an updated version takes effect constitutes acceptance. Where applicable law requires affirmative consent, Secure Code will request it. Customer may stop using the Services and cancel before the updated Terms become effective.
22. Governing Law and Disputes
22.1The laws of the State of Texas govern these Terms and any dispute arising from them, without regard to conflict-of-law principles.
22.2Each party submits to the exclusive jurisdiction of the state and federal courts having jurisdiction in Texas. Each party waives objections based on venue or inconvenient forum to the extent permitted by law.
22.3Before filing a claim, the complaining party must provide written notice describing the dispute and requested resolution. The parties will attempt in good faith to resolve the dispute for 30 days after receipt, except where urgent injunctive or equitable relief is reasonably necessary.
22.4The United Nations Convention on Contracts for the International Sale of Goods does not apply.
22.5Mandatory rights and forums that cannot lawfully be waived remain unaffected.
23. General Provisions
23.1Neither party is liable for delay or failure caused by events beyond its reasonable control, including natural disasters, war, terrorism, civil unrest, labor disputes, internet or utility failures, governmental action, widespread cyberattacks, or failures of essential Third-Party Services.
23.2Customer may not assign these Terms without Secure Code’s prior written consent, except as part of a merger, reorganization, or sale of substantially all relevant assets, provided the assignee agrees to be bound. Secure Code may assign the Terms in connection with a merger, financing, corporate reorganization, sale of assets, or transfer of the Services.
23.3The parties are independent contractors. The Terms do not create a partnership, franchise, fiduciary relationship, employment relationship, or agency.
23.4Failure to enforce a provision is not a waiver. A waiver must be in writing and applies only to the stated instance.
23.5If a provision is held unenforceable, it will be modified to the minimum extent necessary to make it enforceable, and the remaining provisions will continue in effect.
23.6Electronic acceptance, communications, records, and signatures may satisfy writing and signature requirements to the extent permitted by applicable law, including Chapter 322 of the Texas Business and Commerce Code.
23.7These Terms, the Privacy Policy, any accepted order form, and any written addenda form the entire agreement concerning the Services and replace prior or contemporaneous discussions on the same subject. An executed order form controls over conflicting provisions only for the specific commercial terms it expressly addresses.
23.8Headings do not affect interpretation. “Including” means “including without limitation.”
24. Contact and Notices
24.1Legal notices and questions concerning these Terms may be sent to:
Secure Code LLC
417 Staunton Dr
Leander, Texas 78641
Email: privacy@secure-code.dev
24.2Notices to Customer may be delivered to the account email address, through the Services, or through another contact method Customer has provided.
24.3Email notices are deemed received when sent, unless the sender receives a delivery-failure message. Notices by tracked mail are deemed received upon documented delivery.