Skip to content
hack(inspect)
How it works Coverage Pricing
Sign in Get started ↗

Legal

Terms of Service

Effective September 10, 2026

These Terms govern your access to and use of HackInspect’s websites, application-security checks, reports, generated prompts, and related services (the “Service”). By using the Service, you agree to these Terms.

Use a separate test copy of your app

We strongly recommend that you do not connect a production website or production repository. Clone your repository, deploy a separate staging or test copy of your application, and use test accounts and test data. Security checks can create traffic, logs, alerts, rate-limit events, or unexpected behavior. You are responsible for backing up your systems and protecting production data.

The ServiceAuthorized useResults and AIYour contentPlansLegal terms

1. The Service

HackInspect performs supported checks against the application and code repository you connect. Coverage is organized around the OWASP Top 10, but the Service does not test every category, weakness, route, role, configuration, dependency, or possible attack. The coverage page and each report describe the checks currently available and their limits.

The Service may provide findings, evidence, suggested next steps, generated explanations, and prompts for developers or AI coding assistants. Features may be experimental, incomplete, changed, suspended, or discontinued.

2. Authorized and safe use

You may use HackInspect only on applications, repositories, accounts, and data that you own or have explicit permission to test. This rule applies to systems owned by another person, organization, or company and to systems within your own employer or organization. Access to a system, a work account, or a repository does not by itself mean you have permission to perform security testing. You must obtain explicit authorization from someone with authority to grant it and stay within its scope.

You agree to:

  • use a cloned repository and a separate staging, development, lab, or test deployment whenever possible;
  • use dedicated test accounts and artificial test data rather than customer accounts or real personal information;
  • remove secrets and information that HackInspect does not need;
  • confirm that backups, monitoring, rate limits, and incident contacts are appropriate before a check; and
  • stop a check if it creates unexpected effects.

You must not use HackInspect for illegal, harmful, deceptive, abusive, or otherwise malicious purposes. You may not use the Service to access or test systems without explicit permission, disrupt a service, evade access controls, spread malware, steal data or credentials, perform denial-of-service activity, test outside an authorized scope, surveil another person, or violate another person’s rights. You may not misrepresent a HackInspect report as a certification, audit, warranty, or proof that an application is secure.

We may preserve evidence, suspend access, and report suspected criminal or seriously harmful activity to the appropriate organization, service provider, or law-enforcement authority—including the United States Federal Bureau of Investigation—when we reasonably believe a report is warranted or when required by law.

3. Accounts and access

You must be at least 18 years old and able to enter into a binding agreement. Keep your account credentials secure and provide accurate information. You are responsible for activity performed through your account and must notify us if you believe it has been compromised.

If you connect a third-party service such as GitHub, you authorize HackInspect to access the repositories and related information you select, subject to the permissions shown by that provider. You remain responsible for your third-party accounts and their terms.

4. No security guarantee; AI can make mistakes

HackInspect does not guarantee, certify, or state that your application is secure. A report with no findings means only that the checks shown in that report did not identify an issue. It does not mean that no vulnerability exists.

Findings can include false positives, false negatives, incomplete evidence, or incorrect severity and remediation guidance. Changes to your application, infrastructure, dependencies, accounts, configuration, or data can make earlier results outdated.

HackInspect uses automated systems and artificial intelligence to assist with analysis, explanations, suggestions, and generated prompts. AI output can be incomplete, misleading, or wrong. Do not apply a suggested change without reviewing and testing it.

For greater confidence, always review HackInspect findings, generated prompts, and proposed fixes with qualified professional developers and, where appropriate, a security professional or security team. You remain responsible for security decisions, code changes, testing, deployment, incident response, and compliance.

5. Your content and permission to process it

You keep ownership of the application, repository, credentials, data, and other materials you provide (“Customer Content”). You give HackInspect a limited permission to access, copy, transmit, analyze, and store Customer Content only as needed to provide, secure, maintain, and improve the Service, comply with law, and enforce these Terms.

You represent that you have all rights and permissions needed to provide Customer Content and authorize this processing. Do not provide production secrets, regulated data, or personal information that is unnecessary for testing.

We own the Service, its software, design, documentation, and branding. You may use reports and generated prompts for your own authorized business and development purposes. If you give feedback, you allow us to use it without restriction or payment.

6. Plans, scans, rescans, and payment

Paid plan details, prices, scan allowances, rescan allowances, billing periods, and renewal terms will be shown before purchase. A rescan checks whether previously reported issues are still detected and runs the supported checks available at that time to look for new issues that may have appeared since the last report. It does not guarantee that every old or new vulnerability will be found.

Scheduled scans and delivery times are targets rather than guaranteed execution times. A scan or rescan may be delayed, blocked, or incomplete because of target availability, authorization, credentials, third-party services, safety limits, or technical failure.

Unless checkout terms say otherwise, subscriptions renew automatically until canceled. Fees are charged through the payment method presented at checkout. Taxes may apply. Included usage expires at the end of the applicable billing period unless the plan expressly says it rolls over. Separately purchased rescans are governed by the terms shown at purchase.

7. Availability and termination

The Service is provided on an “as available” basis. We may impose safety or usage limits, block a target, refuse a check, suspend an account, or terminate access when reasonably necessary to protect users, third parties, or the Service; respond to legal requirements; address nonpayment; or enforce these Terms.

You may stop using the Service at any time and can delete projects or close your account using the available account controls. Some information may remain temporarily in backups or be retained where reasonably necessary for security, fraud prevention, dispute resolution, or legal obligations.

8. Disclaimers and limits on liability

To the maximum extent permitted by law, the Service is provided “as is” and “as available,” without warranties of merchantability, fitness for a particular purpose, noninfringement, uninterrupted availability, accuracy, or security. We do not warrant that the Service will find, prevent, or fix any vulnerability or incident.

To the maximum extent permitted by law, HackInspect and its owners, personnel, contractors, and service providers will not be liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for financial losses, lost revenue, profits, data, goodwill, business opportunities, security incidents, business interruption, or the cost of repairing or restoring systems arising from the Service, a report, a recommendation, generated content, or any action taken or not taken in reliance on them. Our total liability for claims relating to the Service will not exceed the greater of $100 or the amount you paid HackInspect during the 12 months before the event giving rise to the claim.

Some jurisdictions do not allow certain warranty exclusions or liability limits, so portions of this section may not apply to you. Nothing in these Terms excludes rights or liability that cannot lawfully be excluded.

9. Responsibility for misuse

To the extent permitted by law, you will defend and indemnify HackInspect against third-party claims, losses, and reasonable costs arising from your unauthorized testing, Customer Content, violation of law, infringement of another person’s rights, or material breach of these Terms.

10. General terms

These Terms and any plan-specific terms form the agreement between you and HackInspect concerning the Service. If a provision is unenforceable, the remaining provisions continue in effect. A failure to enforce a provision is not a waiver. You may not transfer these Terms without our consent; we may transfer them as part of a merger, financing, reorganization, or sale of the Service.

Applicable law governs these Terms. Any mandatory consumer protections in your place of residence remain available to you. Before bringing a formal dispute, please contact us and give us a reasonable opportunity to resolve it.

We may update these Terms as the Service changes. We will post the revised version and update the effective date, and will provide additional notice when required by law. Continued use after the updated Terms take effect means you accept them.

11. Contact

Questions about these Terms may be sent through the contact method provided in the Service. Operator identity, mailing address, and a dedicated legal email should be added here before commercial launch.

hack(inspect)

Get your app checked. See what needs attention.

Made in the USA 🇺🇸

Security coverage · Terms · Privacy · Account & data
HackInspect provides automated security insights. It does not certify, guarantee, or make your application secure.