1. Who these terms apply to

These terms apply to services provided by DefensiveAI (“we”, “us”) to a client (“you”). A specific engagement is defined by a written statement of work — an email or document that names the scope, the deliverables, the price, and the dates. Where a statement of work and these terms disagree, the statement of work governs for that engagement.

2. Services

We provide source-code security analysis and related work: Assessments, Continuous agreements, implemented Fixes, and, where separately authorized, stress testing. What each service delivers is described under Services and the process is described under Methodology.

3. What analysis does not establish

Security analysis reduces risk. It does not prove that your product is secure, and nothing does. We report what we find and we report our coverage honestly: where a part of the codebase was out of scope, inaccessible, or could not be analyzed, the report says so. We do not represent that a report is exhaustive, that it identifies every vulnerability, or that acting on it will prevent a compromise.

4. Your responsibilities

  • You confirm that you own the code you give us, or that you are authorized to have it analyzed.
  • You provide read-only access to the repository, or an archive, through a channel we agree on. We do not ask for production credentials for analysis, and you should not send them.
  • You identify any third-party code, systems, or data in scope where analysis requires someone else’s permission, and obtain that permission.
  • Remediation is yours to schedule unless you engage us for Fixes.

5. Access, handling, and retention

Analysis runs on infrastructure we control, isolated per client. Where a client requires it, analysis can run inside the client’s own environment.

Your code and all derived reports are deleted 30 days after delivery. Under a Continuous agreement, they are retained for the life of the agreement and deleted 30 days after it ends. You may request earlier deletion in writing at any time; we will confirm when it is done. Copies held in routine backups age out on the backup schedule.

Your code is never used to train models, ours or anyone else’s.

6. Confidentiality

Every engagement is confidential. Your code, your report, and the fact of the engagement are treated as your confidential information. Access is limited to the analysts assigned to your engagement.

We never name a client without written consent. When we describe past work publicly, it is anonymized to the point where the pattern is recognizable and the client is not. If you would prefer that an engagement never be described in any form, say so and we will record that.

These obligations survive the end of the engagement. They do not apply to information that is public through no act of ours, that you tell us is not confidential, or that we are legally compelled to disclose — in which case we will tell you before disclosing, unless we are prohibited from doing so.

7. Stress testing

Stress testing is performed only under a separate written authorization that names the targets, the window, and the stop conditions. It runs against a staging environment by default. We provide the authorization template. We stop when a stop condition is met, and we stop immediately if you ask us to.

8. Deliverables and intellectual property

The report and any code we write for you as part of Fixes are yours on payment. You may share them with your customers, auditors, insurers, and advisors.

Our methods, tooling, internal prompts, and the analysis system itself remain ours. Nothing in an engagement transfers a licence to them.

9. Fees and payment

Prices are published under Pricing and confirmed in the statement of work. Assessments are invoiced on delivery unless agreed otherwise. A Continuous agreement is billed monthly in advance; we do not hold funds on account against future work. Fixes are invoiced per finding at the price agreed in advance, or hourly. Invoices are due 14 days from issue. Prices exclude taxes, which are added where applicable.

10. Term and termination

A Continuous agreement runs month to month. Either party may end it with 30 days’ written notice. Either party may end any engagement immediately if the other is in material breach and has not fixed it within 14 days of being told. On termination we invoice for work delivered, delete your code and reports on the schedule in section 5, and return or destroy any material you ask us to.

11. Subcontractors and service providers

Analysts working on your engagement are bound by the same confidentiality obligations we are. Where infrastructure or model providers are used to run the analysis, they are selected on terms that prohibit training on the data submitted to them. We remain responsible for their handling of your code.

12. Liability

Neither party is liable for indirect or consequential loss, or for loss of profit, revenue, or data. Our total liability for any engagement is limited to the fees paid for that engagement, except for liability that cannot be limited by law, and except for breach of confidentiality, which is not capped by this clause.

13. Reporting a vulnerability in our own properties

Use the disclosure policy. It includes safe-harbor terms for good-faith research.

14. Changes to these terms

We may change these terms for future engagements. The version in force for your engagement is the one published on the date of your statement of work. We will not apply a change retroactively to an engagement already under way.

15. Governing law and notices

The governing law and venue are named in the statement of work. Notices under these terms are given by email to the addresses in the statement of work, or to [email protected] for notices to us.

Last updated 14 September 2026. Questions about this document: [email protected]. Related: Terms · Privacy · Disclosure policy.