Last updated: draft, not yet published.
By creating an account or using Hakscan (“the Service”), you agree to these Terms. If you do not agree, do not use the Service. We may update these Terms from time to time; continued use after an update means you accept the revised Terms.
Hakscan runs automated security scans (Semgrep, Gitleaks, and a passive OWASP ZAP baseline) against GitHub repositories and live websites you add as targets, then uses the OpenAI API to explain the findings in plain language and suggest fixes. It is a detection aid, not a guarantee of security. A clean scan does not mean a target has no vulnerabilities, and we make no warranty that the Service will find every issue.
You must be able to form a binding contract to use the Service. You are responsible for the security of your account credentials and for all activity that happens under your account.
You may only add a target (a GitHub repository or a live site) that you own or are explicitly authorized to test. Before any scan can run, you must verify ownership (GitHub OAuth admin access for repos; a DNS TXT record or meta tag for sites) and attest, per-target, that you have authorization to scan it. Scanning a target you do not own or control is a violation of these Terms and may be unlawful under computer-misuse laws in your jurisdiction. We enforce this at the API layer, not just in the interface, and we log every verification attempt and scan trigger for audit purposes.
Live-site scans run in passive and baseline mode only. We do not perform active exploitation, denial-of-service style payloads, or data modification against your target. We reserve the right to rate-limit or suspend scanning for any account we reasonably believe is using the Service to scan targets it doesn't control, or as an unauthorized scanning proxy against third-party systems.
In addition to unauthorized scanning, you agree not to: attempt to bypass or disable the ownership-verification gate; interfere with the Service's infrastructure or other users' access to it; resell or provide the Service to third parties without our consent; or use the Service in a way that violates applicable law.
Operating the Service means sending data to third-party providers: Supabase (database, authentication), OpenAI (the OpenAI API, to analyze and explain scan findings), GitHub (OAuth and repository access for repos you add), Resend (transactional email), and PayPal (payment processing for paid plans). Each processes data under its own terms and privacy policy. We send only what each integration needs to function, not your full account data.
The free plan is limited to one target and manual scans. Paid plans are billed on a recurring basis through PayPal and grant unlimited targets, scheduled scans, priority scanning, and full PDF reports and email alerts. You can cancel at any time; cancellation takes effect immediately and ends paid features right away rather than at the end of the billing period. We do not currently offer refunds for partial billing periods.
We retain your targets, scan history, and findings for as long as your account is active, so you can track security posture over time. You can delete a target at any time from the dashboard. If you delete your account, we will delete or anonymize your data within a reasonable period, except where we are required to retain it (for example, billing records).
The Service is provided “as is” without warranties of any kind, express or implied, including fitness for a particular purpose. Scan results, AI-generated explanations, and fix suggestions may be incomplete or inaccurate. You are responsible for independently verifying and remediating any security issue before relying on the Service's output.
To the maximum extent permitted by law, Hakscan will not be liable for indirect, incidental, or consequential damages arising from your use of the Service, including damages resulting from a vulnerability the Service did not detect, or from a scan you triggered against a target you were not actually authorized to test.
We may suspend or terminate your access to the Service if you violate these Terms, including the scan-authorization requirement. You may stop using the Service and delete your account at any time.
Governing law and jurisdiction to be finalized during legal review.
Contact details to be added.