---
title: "Terms of Service | ShipSafe"
description: "Terms and conditions for using ShipSafe security scanning service."
doc_version: 2026-10-05
last_updated: 2026-10-05T02:22:48.585Z
canonical: https://ship-safe.co/terms
---

# Terms of Service | ShipSafe

Last updated: September 24, 2026

Terms used here are defined in the [glossary](https://ship-safe.co/glossary).

# Terms of Service

Please read these terms carefully before using ShipSafe. By accessing or using our service, you agree to be bound by these terms.

## 1\. Acceptance of Terms

By accessing or using ShipSafe ([ship-safe.co](https://ship-safe.co)), operated by Tomer Goldstein d/b/a ShipSafe, Reut 12B, Hod HaSharon 4529614, Israel, including our web application, CLI tool, MCP servers, and API, you agree to be bound by these Terms of Service. If you do not agree to all of these terms, you may not access or use the service. Our MCP servers are the ShipSafe MCP server you install and run on your own machine and the hosted MCP endpoint we operate; these terms cover anything you run through either of them exactly as they cover a scan started from the dashboard.

These terms apply to all visitors, users, and others who access or use the service, whether on a free or paid plan.

## 2\. Description of Service

ShipSafe is a SaaS security scanner designed for applications built with AI-assisted coding tools such as Cursor, Lovable, Bolt, and v0\. The service allows you to:

- Submit a GitHub repository URL for automated security analysis
- Receive plain-English security reports identifying vulnerabilities, misconfigurations, and risks
- Run scans from the web dashboard, the ShipSafe CLI, or an AI coding tool connected to a ShipSafe MCP server
- Submit the URL of a live, deployed web application you own or are authorized to test, for read-only runtime analysis (security headers, content security policy, exposed files, and secrets shipped to the browser in client-side code)
- Track scan history and compare results over time
- On a subscription plan, ask ShipSafe to write fixes for the findings of a scan and send them to your GitHub repository as a pull request — GitHub’s page for approving a change — for you to approve, subject to Section 8b

ShipSafe performs automated code analysis and provides recommendations. It is not a substitute for professional security audits or penetration testing.

### Scheduled re-scanning

On the Growth and Shield plans, ShipSafe re-scans your code on a schedule, without you starting anything. **How often depends on your plan: Growth ($49/month) re-scans every week; Shield ($29/month) re-scans every two weeks.** That is the fastest cadence your plan runs at, and it is what applies if you never change the setting. You may choose a slower one in Settings — Growth can be set to every week or every two weeks, and Shield can be set to every two weeks. Choosing a cadence faster than your plan’s does not make it run faster — re-scans still run at your plan’s cadence — and no plan re-scans daily.

Each run re-scans the GitHub repositories you have already scanned with ShipSafe, using the access you granted when you connected GitHub. If you have scanned a live URL, each run also re-checks that URL from our servers, relying on the ownership confirmation you gave the first time you submitted it.

We do not email you a full report after every run. We email you when a re-scan finds a critical or high issue that was not in the previous scan of that repository, and we send a digest when a re-scan shows your findings changed. If several of your repositories change in the same run, those alerts are combined into one email rather than one per repository. You can turn both off under Notifications. Turning them off stops the emails, not the scans.

Scheduled re-scanning is part of a subscription. It is not included on the Free, Solo or Pro Audit plans, and it stops when your subscription ends. Scheduled re-scans can use the AI scan credits on your account, including overage credits you have already purchased. They never create a new charge on their own. If your allowance is used up, a scheduled re-scan still runs its AI pass at our cost rather than billing you; it drops to the pattern-based checks only when a service-wide daily limit has been reached. You can stop scheduled re-scanning entirely by setting the cadence to off in Settings. If you want scheduled re-scanning switched off while keeping your plan, email support@ship-safe.co and we will switch it off for your account.

## 3\. Account Terms

- Authentication is managed through Clerk. You may sign in using your email, GitHub account, or other supported providers.
- Each account is intended for use by a single individual. Sharing account credentials is not permitted.
- You are responsible for maintaining the security of your account and any activity that occurs under it.
- You must provide accurate and complete information when creating your account.
- You must be at least 16 years old to use ShipSafe. By creating an account, you confirm that you are at least 16 years of age.
- ShipSafe reserves the right to suspend or terminate accounts that violate these terms.

## 4\. Acceptable Use

You agree not to:

- Use ShipSafe to scan repositories you do not own or have explicit authorization to scan
- Use the live-URL scan on any URL or deployed application you do not own or are not explicitly authorized to security-test
- Submit URLs that resolve to private, internal, loopback, or cloud-metadata addresses to a scan that runs on ShipSafe's servers, or submit any URL designed to attack, mislead, or overload ShipSafe's infrastructure. This restriction is about our servers, and they refuse such addresses in any case (see 5b). It does not apply to the owner-local tools described in 5c: the ShipSafe CLI and the ShipSafe MCP server run on your own computer, and you may point them at a development server on a loopback or private address that you own or operate.
- Use the live-URL scan to test, probe, or enumerate systems belonging to third parties
- Attempt to reverse-engineer, decompile, or disassemble any part of the ShipSafe platform, scanning engine, or CLI tool
- Abuse the service by submitting an excessive number of scans designed to overload or disrupt our infrastructure
- Use scan results to exploit vulnerabilities in third-party applications
- Circumvent or attempt to circumvent scan limits, rate limits, or other usage restrictions
- Resell, redistribute, or sublicense access to ShipSafe or its scan reports without written permission
- Use automated scripts or bots to interact with the service outside of the official CLI tool, MCP servers, and API

**Authorization is your responsibility.** Each time you start a live-URL scan you confirm that you own the target or are authorized by its owner to security-test it. We record that confirmation (your account, the target host, the authorization basis, and the time) so it can be verified if it is ever questioned. You are solely responsible for that confirmation, and you agree to indemnify ShipSafe for any claim arising from a scan you were not authorized to run (see Indemnification below).

**Checks that send real requests to a live target.** Some checks do more than read your code: the runtime probe of a live app, the deployed-app scan, and the API authorization test all send real HTTP requests to the address you name, and the git-history scan reads past commits from a repository on your disk. Because those requests reach a running system, we only make them where authorization is established, and there are exactly two ways that happens. First, from your own machine: run them through the ShipSafe CLI or MCP server and you confirm, each time, that you own or are authorized to security-test the target; that confirmation and the results stay on your machine unless you choose to send them to us. Second, from our servers, but only against an address you have proven to us that you control. Proving it means we give you a single-use token, you publish it at a fixed path on that exact address, and we fetch it back over HTTPS without following a redirect anywhere else. A proof covers only that one address, only your account, and lapses after thirty days, so we re-check rather than assume. Until you complete that proof, a scan you start on our site runs the reading-only checks: your home page, your published JavaScript, your headers and your security policy. We do not go looking for files like /.env or /admin on an address nobody has proven. The API authorization test also uses two test-account tokens you supply: they are sent only to the API you named, and never to ShipSafe. You are responsible for anything an AI agent or script does through a ShipSafe MCP server on your behalf, exactly as if you had run it yourself.

**Takedown and removal.** If you believe ShipSafe scanned a system you control without your authorization, or you want a public verification receipt for your app taken down, email [security@ship-safe.co](mailto:security@ship-safe.co) and we will investigate and act promptly. You do not need to email us to take down a page you published yourself: every public receipt, report and badge can be unpublished from the scan it belongs to in your dashboard, and unpublishing takes effect immediately. The receipt and proof pages stop resolving, and so does our badge verification API. The badge image itself keeps loading so that an embed on your site does not break, but it stops making any claim: it turns grey and reads EXPIRED wherever it is still embedded. For requests you do send us, we will acknowledge within 3 business days and, where the request is well-founded, unpublish the page within 5 business days. Unpublishing removes the page from ShipSafe; it does not reach copies, screenshots or third-party caches already made.

## 5\. GitHub Integration

ShipSafe integrates with GitHub to read repository source code for security analysis. By using this feature:

- You grant ShipSafe read access to the repositories you explicitly submit for scanning. ShipSafe writes to a repository in three cases only: when you send fixes to GitHub from a scan, it commits them to a new branch it creates for that purpose and opens a pull request from it (see Section 8b); when you approve that pull request in ShipSafe rather than on GitHub yourself, it merges that one pull request into your default branch using the GitHub access you granted — the only case where it writes to your default branch, and only after that approval (Section 8b); and, if you install the ShipSafe GitHub App, it writes pull request comments and check runs in the repositories you select for it, as described in Section 5a
- ShipSafe accesses repository content only for scans you started or set up: a scan you submit in the app, from the CLI, or through the MCP server; a scheduled re-scan on a paid plan, at the cadence you set in Settings; and a pull request in a repository where you installed the ShipSafe GitHub App, where we review the changed files. We do not browse, index, or access any other repositories in your account
- Repository code is processed for the purpose of generating security reports; no copy of your repository is kept after a scan completes, though each finding stores a short excerpt of the flagged code, with any detected secret value redacted, as described in the Privacy Policy
- You represent that you have the necessary rights and permissions to submit each repository for scanning
- You may revoke GitHub access at any time through your GitHub account settings
- Fix pull requests are AI-generated and unverified; ShipSafe writes the patch, you review it, and nothing reaches your default branch unless you approve it — in ShipSafe, where ShipSafe then merges that one pull request for you with the GitHub access you granted, or by merging it yourself on GitHub
- ShipSafe does not build or test the patched code, and does not warrant that a patch fixes the finding
- Every finding ShipSafe could not fix is counted and named in the receipt in your signed-in account (and in the email we send when the run finishes, unless you have turned email notifications off). On a private repository the pull request names them too (counted, where the list is long); on a public repository the pull request description carries only the three counts and a link to that receipt. A fix pull request is never a claim that every finding was fixed
- The re-scan receipt re-checks rule findings with the same rules and AI-found findings with the AI pass; a finding is counted as “fixed and re-checked” only when the re-check no longer detects it, as “still there” when it still does, and as “could not be re-checked; re-scan after you approve” when the re-check did not run or did not finish
- You can stop the standing triggers at any time: scheduled and push-triggered re-scans stop when your plan ends or when you switch them off

## 5a. The ShipSafe GitHub App

Separately from the GitHub connection described above, you can install the ShipSafe GitHub App on your GitHub account or organization and give it access to the repositories you choose. Once installed, it reviews pull requests in those repositories automatically. By installing it:

- The App runs on pull request events only — when a pull request is opened, reopened, or updated with new commits in a repository you gave it access to. It does not run on a schedule, and it does not look at repositories or branches you did not include.
- The App acts under its own GitHub installation credential, issued by GitHub to the App. It does not use your personal access token, your OAuth token, or any other credential of yours.
- It reads the list of files the pull request changes, and the contents of those changed source files at the commit under review, up to a bounded number of files. It does not read the rest of the repository.
- It writes two things back, and only to that pull request: review comments on lines the pull request added, and a check run reporting whether new critical or high-severity issues were introduced. It never commits, pushes, merges, closes a pull request, or changes any repository setting.
- A ShipSafe account is required. An installation that is not linked to a ShipSafe account is refused before anything else happens: no credential is issued, nothing is read, and nothing is written.
- You can remove the App at any time from your GitHub settings, under Applications, Installed GitHub Apps, or narrow it by removing individual repositories from its access. Uninstalling stops all future reviews immediately.

The representations in Acceptable Use above apply to the App as well: install it only on repositories you own or are authorized to have reviewed.

## 5b. Live-URL & Deployed-App Scanning

ShipSafe can scan a live, deployed application by URL. When you submit a URL, our servers make read-only HTTP GET requests to that URL and to the public assets it references (such as JavaScript bundles), comparable to what a web browser loads when visiting the page. By using this feature:

- You confirm that you own, operate, or are explicitly authorized to security-test the application at the URL you submit
- ShipSafe does not log in, submit forms, modify data, or send any request intended to change the application's state; the number and rate of requests are bounded
- ShipSafe analyzes the retrieved content for security issues and retains only the resulting findings, not the raw page or bundle content
- You accept that the target server will receive and may log these requests, including ShipSafe's IP address and User-Agent
- Requests to private, internal, loopback, or cloud-metadata addresses are refused

## 5c. Owner-Local Active Scanning

Section 5b describes the hosted scan, which runs on our servers. ShipSafe also publishes a local tool — the ShipSafe MCP server, which you install and run on your own computer alongside your AI coding assistant. These terms apply to it as they do to the web application and the CLI. The local tool goes further than the hosted scan, and it is the only place the deeper checks ever run. Because it runs on your computer, it is also the only place a loopback or private address can be a target: you may point it at your own development server (for example http://localhost:3000) or another host on your own network that you own or operate. In the MCP server this is off unless you turn it on in your own client configuration, so an instruction hidden inside scanned code cannot enable it for you; the CLI, which you invoke yourself and which already requires an explicit ownership flag, accepts such addresses directly.

Against a target you confirm you own or operate, the local tool can:

- Request paths your application never linked to, to see whether they are publicly readable — for example /.env, /.git/config, /admin, /config.json, /backup.sql and /server-status, plus any additional paths you name. These are guesses at addresses your app never served, so they are not browser-equivalent requests.
- Take a credential your application already publishes in its browser bundle and send it to that provider (for example OpenAI, Stripe, GitHub, GitLab, SendGrid or Slack) to establish whether the exposed key still works, and make unauthenticated requests to your own Supabase or Firebase back end to establish what an anonymous visitor can read.
- Test your API for broken object-level authorization using two disposable test accounts you supply, by checking whether one account can read the other's records. Use test accounts on a non-production environment; the tokens you provide are used for the test and are not stored.

These checks are read-only. Nothing is sent that is intended to create, change, or delete data, the number of requests is bounded, and requests are paced. They are not GET-only in every case — a few providers expose their read-only status check over POST.

Two boundaries apply to all of it, and both are permanent:

- **Requesting a path your application never linked to normally runs on your own machine, not ours.** The one exception is described in Acceptable Use (§4): for an origin you have proven you control, our servers may make this kind of request too, as part of the Live-URL scan in 5b. Outside that proof, ShipSafe's servers never make this kind of request, whatever you attest to. Live key validation — taking a credential found in your application and sending it to its provider to check whether it still works — is never performed by ShipSafe's servers under any circumstance, proven origin or not; that check runs only on your own machine, as described above.
- You must confirm ownership each time you invoke it. That confirmation is yours, on the same terms as in Acceptable Use above, including the indemnity.

## 6\. Subscription & Billing

ShipSafe offers both free and paid plans:

- **Free plan:** Includes 1 AI-powered security scan for the life of the account, only the 3 most severe findings from that scan — the remaining findings, and the exact line and suggested fix for all of them, stay locked until you pay. Every scan you run after it — including a re-scan to refresh a verification — runs pattern-only, using our rule and secret checks without the AI pass. Pattern-only scans are not metered per month; they are subject to a fair-use limit of 10 scans per hour, and live-URL scans are limited to 5 per day on the free plan. Free plan limits are subject to change with reasonable notice.
- **Pro Audit ($9 one-time):** Includes 1 AI-powered security scan for the life of the purchase, no AI fix prompts — a fix prompt is a separate one-time purchase, and no verified security badge.
- **Solo ($19/month or $190/year):** Includes 4 AI-powered security scans per calendar month, no automatic re-scanning — scans run when you ask for them, up to 999 AI fix prompts per calendar month, and no verified security badge.
- **Shield ($29/month or $290/year):** Includes 10 AI-powered security scans per calendar month, scheduled re-scanning of up to 2 repositories every two weeks, with an alert email when a re-scan finds something new, up to 999 AI fix prompts per calendar month, and a verified security badge with a public proof page. You may request a slower cadence in Settings; a request faster than your plan provides is applied at your plan's cadence. The badge states what the most recent scan of that repository found, and it is valid for 45 days from that verification; each re-scan that completes its AI pass re-states it and extends the window; a re-scan that runs pattern-only does not.
- **Growth ($49/month or $490/year):** Includes 20 AI-powered security scans per calendar month, scheduled re-scanning of up to 4 repositories every week, with an alert email when a re-scan finds something new, up to 999 AI fix prompts per calendar month, and a verified security badge with a public proof page. You may request a slower cadence in Settings; a request faster than your plan provides is applied at your plan's cadence. The badge states what the most recent scan of that repository found, and it is valid for 45 days from that verification; each re-scan that completes its AI pass re-states it and extends the window, so it lapses on its own face if the re-checks stop. A re-scan that runs pattern-only does not extend it. Includes priority support, as described in Section 9b.
- **AI Fix Prompt ($4.99 one-time):** A copy-pasteable fix prompt tailored to your AI coding tool.
- **Unlock a scan’s findings ($9 one-time):** A free scan shows the 3 most severe findings — each with its title, its severity, the file it is in and what is at stake in plain English — but not the exact line, the code excerpt, or the fix, and not the findings beyond those 3. This unlocks all of them for one specific scan, permanently, for the life of that scan. It is per scan and does not carry to other scans or to later re-scans of the same repository.

**When the AI pass does not run.** A scan you start yourself runs pattern-only — our rule and secret checks, without the AI pass — if your AI scan allowance is used up or a service-wide daily limit has been reached, and we flag that in the scan result. A scheduled re-scan behaves differently: once your allowance is used it still runs its AI pass at our cost, and drops to pattern-only only when the service-wide limit is reached. A scan that runs pattern-only for either reason does not deduct an AI scan from your allowance, and we return the AI scan a failed scan had reserved. Our AI provider can also be slow or unavailable, in which case a scan may return partial results, with any findings we could not translate shown in their raw form. A pattern-only re-scan does not extend a verification badge’s freshness window. We reserve the right to apply these limits so the service stays affordable at a fixed price.

**Overage Scans:** When you exhaust your plan's included AI scans, you may purchase additional scans individually at $4.99 per scan. Overage purchases are one-time charges processed through Polar and are non-refundable. AI scan allowances. Each plan includes a set number of AI-powered scans: Free, 1 scan for the life of the account; Pro Audit, 1 scan for the life of the purchase; Solo, 4 scans per calendar month; Shield, 10 scans per calendar month; Growth, 20 scans per calendar month. Monthly allowances reset at the start of each calendar month and do not carry over. Solo, Shield and Growth also include up to 999 AI fix prompts per calendar month.  Alongside these allowances we apply cost-control limits: we currently allow at most 20 AI scans and 40 AI fix prompts per account per day, we apply a service-wide daily ceiling on AI scans across all accounts, and we limit repository scans to 10 per account per hour, live-URL scans to 5 per day on the free plan or 40 per day on a paid plan, and fix runs (Section 8b) to 5 starts per account per hour, 10 starts per account per day, with 1 run in flight per account at a time and one run at a time on a scan. These operational limits sit well above normal use and we may adjust them; if we reduce a plan allowance stated above, we will give notice under Section 17.

**Who is charged for a scan.** A scan is charged to the ShipSafe account that submitted it. Where a scan runs automatically — a scheduled re-scan, or a scan triggered by a change to a repository — it is charged to the account that most recently scanned that repository on a paid plan, and it uses that account’s allowance and scan authorisation. Repositories you scan are added to your monitored set automatically, up to your plan’s project limit, most recently scanned first; older repositories drop out as you scan new ones. You can stop scheduled re-scanning at any time by setting the cadence to off in Settings.

All payments are processed securely through Polar. ShipSafe does not store your payment card details directly. Purchase confirmations are provided by our payment processor, Polar.

**Merchant of Record.** Polar acts as the merchant of record (reseller) for purchases of ShipSafe. This means Polar is responsible for charging you, issuing invoices, and collecting and remitting any applicable sales tax, VAT, or GST as the seller of record in its own name — not as our agent and not on our behalf. The price you pay may include such taxes depending on your location.

**Automatic renewal:** Paid subscriptions renew automatically at the end of each billing period (monthly or annual) at the then-current price for your plan, charged to your payment method on file, until you cancel. By selecting a paid plan at checkout you provide affirmative consent to this automatic renewal. If you are on an annual plan, we will email you a reminder between 45 and 15 days before each renewal, showing the renewal date, the amount, and a link to cancel. Month-to-month plans do not receive a separate advance renewal notice. Your renewal date, plan and price are shown in Settings, under Plan and Billing, where you can cancel at any time and the change takes effect without contacting us.

**Cancellation:** You may cancel at any time, with no cancellation fee, from Settings, under Plan and Billing. Select Manage subscription; this opens the customer portal run by Polar, our payment processor, where you cancel yourself. You do not need to contact us and you do not need to give a reason. Cancellation stops the next charge immediately and takes effect at the end of your current billing cycle, during which you retain access to paid features. Where required by applicable law, including the California Automatic Renewal Law and applicable FTC rules on negative-option marketing, cancellation is at least as simple as the method of enrollment.

**Refund policy:** New subscriptions are eligible for a full refund within 14 days of purchase, in accordance with the EU Consumer Rights Directive. After the 14-day period, no refunds are issued for partial billing periods. Overage charges ($4.99/scan) are non-refundable once incurred.

**EU users:** You have the right to withdraw from your subscription within 14 days of purchase without giving any reason. By using the service during this withdrawal period, you acknowledge that you have requested the service begin immediately and that you understand your right of withdrawal.

**Israeli users:** Under the Israeli Consumer Protection Law (Section 14C(4)(a)), you have the right to cancel a remote transaction for a digital service within 14 days of purchase, provided the service has not been fully performed. A cancellation fee of up to 5% of the transaction price or 100 NIS (whichever is lower) may apply. To exercise this right, contact support@ship-safe.co.

For billing inquiries, contact [support@ship-safe.co](mailto:support@ship-safe.co).

## 7\. Intellectual Property

- **ShipSafe platform:** The ShipSafe service, including its scanning engine, web application, CLI tool, documentation, and branding, is the intellectual property of ShipSafe. All rights are reserved.
- **Your code:** You retain full ownership of all source code you submit for scanning. ShipSafe claims no ownership rights over your code.
- **Scan reports:** ShipSafe retains ownership of all scan reports, including their format, structure, and analysis methodology. We grant you a perpetual, non-exclusive, royalty-free license to use, copy, and share scan reports generated during your subscription for your internal business purposes, including compliance documentation and sharing with auditors or clients. You may not resell scan reports as a standalone product. This license survives termination of your account for reports generated during your active subscription.
- **Third-party trademarks:** Product and company names referenced on this site are trademarks of their respective owners. ShipSafe uses them solely for nominative and comparative purposes to identify the products discussed; such use does not imply any affiliation with, endorsement by, or sponsorship from those owners. Any comparative statements reflect ShipSafe’s good-faith understanding of publicly available information as of the date shown and may not reflect the referenced products’ current features or pricing.
- **ShipSafe Verified badge:** The badge image, the ShipSafe wordmark it carries, and the layout of the public proof page it links to are ShipSafe's intellectual property. While a badge is live for one of your repositories, we grant you a limited, worldwide, non-exclusive, royalty-free, revocable licence to display it by hot-linking the image we serve at ship-safe.co/badge/... and linking that image to its proof page at ship-safe.co/report/..., in the form we give you on the Badges page. The same licence covers the "Scanned by ShipSafe" badge at ship-safe.co/badge/generic, which every plan may display. You may not copy the image and serve it from your own domain, alter its wording, colours or the verdict it shows, or display a badge for a repository it was not issued for: we generate the image on each request so it always shows the current state, and a stored copy would keep asserting something we no longer stand behind. What a badge asserts and how long it stays valid are described in section 6\. The licence ends when you unpublish the badge, when your account closes, or if we withdraw the badge because it is being displayed in breach of this clause, and on ending you must remove the embed. You can unpublish at any time yourself, from the scan the badge belongs to (see section 4).

## 8\. AI Analysis Disclaimer

ShipSafe uses AI-powered scanning to analyze source code for potential security vulnerabilities. This section covers ShipSafe's analysis and the reports it produces. AI-generated code that ShipSafe commits to your repository is covered separately in Section 8b. While we strive for accuracy, AI analysis has inherent limitations that you should be aware of:

- AI-generated results may contain **false positives** — flagging code as vulnerable when it is not.
- AI-generated results may contain **false negatives** — failing to detect actual vulnerabilities present in your code.
- AI models may produce inaccurate or fabricated findings (commonly referred to as "hallucinations").

Scan results are **informational only** and should not be solely relied upon for security assurance, compliance certification, or as a substitute for professional security audits and penetration testing.

Scans of deployed applications may surface secrets, API keys, or tokens that were unintentionally included in production client-side code. Treat any such finding as potentially compromised: rotate the credential and remove it from the deployed build. ShipSafe reports these findings on a best-effort basis and does not guarantee that all exposed secrets are detected.

You are responsible for independently verifying scan findings and making your own security decisions. ShipSafe does not guarantee that your application is free of vulnerabilities based on scan results.

## 8b. AI-Generated Fixes and Pull Requests

On a subscription plan (Solo, Shield and Growth — not a one-time purchase), you can ask ShipSafe to write fixes for the findings of a scan and send them to your GitHub repository. This happens only when you ask for it, from the scan, and each request is one run: ShipSafe attempts every finding it can, re-checks each file it changed, and, when it has at least one change to send, opens one pull request on a new branch; a run that reaches the end of its files with no change to send — every change refused, or nothing it could change — opens no pull request, and the receipt says so. Nothing is scheduled: no fix run starts on its own, and a scheduled re-scan does not start one. The pull request is a proposal and nothing else. Opening it changes no running code, and approving it is always your decision, made by you — in ShipSafe or on GitHub. This section governs that feature.

The patch is machine-generated. An AI model proposes edits to each affected file, ShipSafe applies them and commits the result to a new branch using the GitHub access you granted; where a fix can be computed without a model (for example an integrity hash for a script served from a public CDN), ShipSafe computes it. No person at ShipSafe reads, runs, builds, or tests the change before it is committed. ShipSafe's checks are automated: a patch that comes back empty or unchanged is refused, an automated review refuses a patch that does not address the finding or looks likely to break behaviour, and each changed file is re-scanned. None of this establishes that the change is correct. A later run on the same scan or repository starts from what the previous run recorded — which findings it left open and why — as described in the Privacy Policy.

The change lands on a new branch that ShipSafe creates for it, never directly on your default branch, and ShipSafe opens a pull request from that branch. Nothing reaches your default branch unless you approve it, and there are two ways to do that, both your own act. You can approve it in ShipSafe, signed in: ShipSafe then merges that one pull request on your behalf, using the GitHub access you granted, so the change appears under your own GitHub account, pinned to the exact change the receipt describes. Or you can merge the pull request yourself on GitHub. Each approval covers one pull request. There is no setting, no schedule and no email that lets ShipSafe merge without you, and an email from us never approves anything. ShipSafe does not build or test the change before applying it. If GitHub refuses the merge — because the repository requires a review or a status check, or because your code changed since the pull request was opened — ShipSafe tells you in plain words, and you can still approve it on GitHub yourself. Where ShipSafe cannot tie your approval to the exact change the receipt covered, it declines the same way and asks you to re-scan and send the fixes again; you can still approve it on GitHub. You can decline a fix on GitHub, and you can ignore it. A fix you ignore keeps waiting for your decision, and a later request on that scan is refused and points you to it. A fix you declined stays on its branch in your repository until you delete it, or until you start another run on that scan: that run moves ShipSafe's own branch back to your default branch's head and starts over, so an earlier fix you declined is replaced, never merged. ShipSafe moves and removes only the branch it created; it never deletes anything else in your repository.

Reviewing and testing the patch before you approve it is your responsibility. AI-generated code may be incorrect or incomplete, may fail to fix the finding it was written for, may break behavior that previously worked, and may introduce new defects or new security issues. ShipSafe does not warrant that a fix resolves the underlying issue, and does not warrant that the patched code builds, passes your tests, or behaves as your application did before.

The re-check receipt ShipSafe produces for a run — shown in your signed-in account and, unless you have turned email notifications off in Settings, sent in the email when the run finishes, which carries the counts and every list but the fixed one — is a limited check, not a clean bill of health. ShipSafe re-scans only the files it changed. Rule findings are re-checked by the same rules; findings originally identified by AI are re-checked by the AI pass. A finding is counted as “fixed and re-checked” only when the re-check no longer detects it, as “still there” when it still does, and as “could not be re-checked; re-scan after you approve” when the re-check did not run or did not finish. “Fixed and re-checked” means the re-check no longer detects it in that file; it does not establish that the underlying vulnerability is gone, and it says nothing about the rest of your codebase.

Findings ShipSafe did not fix are counted and named in that receipt, so that you can address them yourself. On a private repository the pull request names them too (counted, where the list is long), with the automated review's reasons; on a public repository the pull request description carries only the three counts and a link to the scan page, and the full receipt stays in your signed-in account (and, every list but the fixed one, in the email, when notifications are on). Everyone who can see the repository can read the pull request — the changed code and whatever its description carries — and on a public repository that is anyone. A fix pull request is never a complete remediation of a scan.

ShipSafe claims no ownership of the code in the patch. Once you approve it, it is your code, and you are responsible for it as you are for anything else in your repository. You may revoke ShipSafe's GitHub access at any time from your GitHub account settings.

## 9\. Disclaimer of Warranties

ShipSafe is provided on an “as is” and “as available” basis without warranties of any kind, either express or implied.

Security scans are performed on a best-effort basis using automated analysis. ShipSafe does not guarantee that all vulnerabilities will be detected, nor that your application is secure after receiving a clean scan report.

ShipSafe does not warrant that the service will be uninterrupted, error-free, or free of harmful components. You use the service at your own risk.

**Consumer rights:** Nothing in this section excludes or limits any statutory guarantee, warranty, or right that cannot be excluded under the law applicable to you as a consumer — including the EU/UK consumer guarantee of conformity and the consumer guarantees under the Australian Consumer Law. Those rights apply in addition to, and prevail over, the disclaimers above where they conflict.

## 9b. Support

Support is provided by email at [support@ship-safe.co](mailto:support@ship-safe.co) and through the contact form on this site. There is no telephone, chat, or ticketing channel. ShipSafe is operated by one person, and support is answered during ordinary working hours in Israel.

**Response times are not guaranteed.** Where a plan is described as including priority support, that means we answer messages from that plan ahead of other messages. It is an ordering, not a service-level agreement: no response time is promised, no uptime or resolution target applies, and nothing in this section creates a remedy or a refund entitlement if a reply is slow. If you need a contractual service level, contact us before subscribing and we will tell you whether we can offer one.

Support covers using ShipSafe: what a finding means, how to run a scan, and questions about your plan or billing. It does not include writing, reviewing, or fixing your application code for you, and nothing said in support is security advice you should rely on without your own review — see Section 9.

## 10\. Limitation of Liability

To the maximum extent permitted by applicable law, ShipSafe and its officers, directors, employees, and agents shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including but not limited to loss of profits, data, or goodwill, arising out of or in connection with your use of the service.

In no event shall ShipSafe's total liability to you exceed the amount you have paid to ShipSafe in the twelve (12) months preceding the event giving rise to the claim, or one hundred dollars ($100), whichever is greater.

**AI-generated fixes.** ShipSafe is not liable for loss or damage arising from code that ShipSafe generated and you approved into your repository, including defects, outages, data loss, and security issues introduced by that code. The pull request is a proposal; the decision to approve it is yours, and reviewing and testing the change before you approve it is your responsibility under Section 8b. This paragraph does not apply where the loss was caused by our fraud or by our failure to operate the feature as described in these terms, and it is subject to the consumer protections set out below.

**Consumers in the EU, UK, and Switzerland:** The exclusions and the cap above do not limit our liability for (a) death or personal injury caused by our negligence, (b) fraud or fraudulent misrepresentation, (c) failure to perform the core scanning service we agreed to provide, or (d) any other liability that cannot be limited or excluded under the mandatory consumer law applicable to you. For such consumers, we remain liable for foreseeable loss arising from a material breach of the service in accordance with applicable law; the cap continues to apply to indirect or unforeseeable losses to the fullest extent permitted.

## 11\. Termination

Either party may terminate this agreement at any time. You may stop using the service and delete your account through your account settings or by contacting support.

ShipSafe may suspend or terminate your account if you (a) breach these terms, (b) engage in abusive, fraudulent, or unlawful use, or (c) create security or legal risk to the service or others. Except where immediate action is needed to stop abuse, illegal activity, or a security threat, we will give you reasonable advance notice.

**Consumers in the EU, UK, and Switzerland:** If we terminate or suspend your paid subscription for reasons not caused by your breach, we will give you at least 30 days' notice (except where immediate action is legally required) and refund the unused, pro-rata portion of your current billing period. You may cancel at any time without penalty.

Upon termination, you may request deletion of your data by contacting [support@ship-safe.co](mailto:support@ship-safe.co). We will process data deletion requests within 30 days.

## 12\. Indemnification

You agree to indemnify, defend, and hold harmless ShipSafe and its officers, directors, employees, and agents from and against any claims, liabilities, damages, losses, and expenses (including reasonable attorneys' fees) arising out of or in connection with:

1. Your violation of these Terms of Service
2. Your unauthorized scanning of repositories, URLs, or deployed applications that you do not own or do not have explicit permission to scan
3. Your misuse of scan results, including using findings to exploit vulnerabilities in third-party systems
4. Your code, applications, or content
5. Your violation of any applicable law or third-party rights

## 13\. Dispute Resolution

**Informal resolution first:** Before filing any formal claim or proceeding, you agree to contact us at [support@ship-safe.co](mailto:support@ship-safe.co) and attempt to resolve the dispute informally for at least 30 days.

**Where disputes are heard:** If informal resolution does not settle the matter, disputes are heard by the courts identified in Section 14 (Governing Law), subject to the consumer exceptions below.

**Class action waiver:** You agree to resolve disputes with ShipSafe only on an individual basis and waive any right to participate in a class action or representative action, to the extent such a waiver is permitted by the law that applies to you.

**Small claims exception:** Either party may bring qualifying claims in a small claims court of competent jurisdiction.

**EU / UK / EEA / Switzerland users exception:** If you are a consumer in the European Union, the United Kingdom, the EEA, or Switzerland, the class action waiver above and the forum selection in Section 14 do not apply to you. You may bring claims in the courts of your country of residence in accordance with applicable consumer protection laws, and the mandatory consumer law of your country applies.

**Other consumers (including Singapore, India, Australia, Japan, and South Korea):** Nothing in this section deprives you of the protection of mandatory consumer-protection laws of your country of residence, or of any right you have to bring proceedings in your local courts where such laws so provide. Where those laws conflict with this clause, they prevail.

**Israeli users exception:** If you are a consumer in Israel, the mandatory consumer-protection provisions of Israeli law (including the Consumer Protection Law, 5741-1981 and the Protection of Privacy Law, 5741-1981) apply to you. You may bring claims in the competent courts in Israel, and nothing in this section limits your statutory rights under Israeli law, including any right to bring or join a class action under the Class Actions Law, 5766-2006.

## 14\. Governing Law

These terms are governed by the laws of the State of Israel, where ShipSafe is operated from, without regard to its conflict of law provisions. Disputes arising under these terms are subject to the jurisdiction of the competent courts of Tel Aviv-Yafo, Israel.

**Consumer override:** If you use ShipSafe as a consumer, this choice of law and forum does not override the mandatory consumer-protection laws of your country of residence. Where the law of your country grants you rights that cannot be waived by contract (including in the EU, UK, EEA, Switzerland, Australia, Singapore, India, Japan, and South Korea), those rights continue to apply to you and prevail over this clause to the extent of any conflict.

For users who are consumers residing in Israel, the mandatory provisions of Israeli law, including the Consumer Protection Law, 5741-1981 and the Protection of Privacy Law, 5741-1981, shall apply to the extent they cannot be derogated from by agreement. ShipSafe is operated by Tomer Goldstein, registered as an Osek Patur (exempt dealer) with the Israel Tax Authority.

## 15\. Force Majeure

Neither party shall be liable for any failure or delay in performing its obligations under these terms where such failure or delay results from events beyond the reasonable control of the affected party, including but not limited to: natural disasters, acts of war or terrorism, pandemics, epidemics, government actions or orders, labor disputes, internet or infrastructure failures, cyberattacks, third-party service outages, or power failures. The affected party shall use commercially reasonable efforts to mitigate the impact of such events and resume performance as soon as practicable.

## 16\. Severability

If any provision of these Terms of Service is found to be invalid, illegal, or unenforceable by a court of competent jurisdiction, such provision shall be modified to the minimum extent necessary to make it valid and enforceable, or if modification is not possible, shall be severed from these terms. The remaining provisions shall continue in full force and effect.

## 16b. General

**Entire agreement.** These Terms, together with the Privacy Policy and any Data Processing Addendum you have entered into with us, are the whole agreement between you and ShipSafe about the service, and replace any earlier understanding about it. This does not limit any right you have under consumer protection law that cannot be excluded by agreement, and it does not affect our responsibility for statements we have made about what the service does.

**Assignment.** You may not transfer your rights or obligations under these Terms without our written consent. We may transfer ours to a successor in connection with a merger, acquisition, or sale of all or substantially all of our assets, provided the successor is bound by these Terms and by the Privacy Policy. We will tell you if that happens, and it does not reduce any right you already have.

**No waiver.** If we do not enforce a right under these Terms straight away, that is not a waiver of it, and we may still enforce it later. A waiver of one breach is not a waiver of any other.

## 17\. Changes to Terms

ShipSafe reserves the right to modify these terms at any time. For material changes, we will provide at least 30 days' notice via email or a prominent notice on the service before the changes take effect.

Your continued use of the service after the effective date of any changes constitutes your acceptance of the updated terms. If you do not agree to the revised terms, you must stop using the service.

---

## 18\. DMCA / Copyright Policy

DMCA policy last updated: March 2026

### Overview

ShipSafe respects the intellectual property rights of others and expects its users to do the same. In accordance with the Digital Millennium Copyright Act of 1998 ("DMCA"), we will respond expeditiously to claims of copyright infringement committed using the ShipSafe service.

### Submitting a DMCA Takedown Notice

If you believe that your copyrighted work has been copied or made available through ShipSafe in a way that constitutes copyright infringement, please submit a written notice to our designated agent (see below) containing the following information:

1. **Identification of the copyrighted work** — a description of the copyrighted work that you claim has been infringed.
2. **Identification of the infringing material** — the URL(s) or other specific identification of the material that you claim is infringing, with enough detail for us to locate it.
3. **Your contact information** — your name, mailing address, telephone number, and email address.
4. **Good faith statement** — a statement that you have a good faith belief that the use of the material in the manner complained of is not authorized by the copyright owner, its agent, or the law.
5. **Accuracy statement** — a statement that the information in the notification is accurate, and under penalty of perjury, that you are authorized to act on behalf of the owner of an exclusive right that is allegedly infringed.
6. **Signature** — a physical or electronic signature of the copyright owner or a person authorized to act on their behalf.

### Counter-Notification Process

If you believe that your content was removed or disabled as a result of a mistake or misidentification, you may submit a counter-notification to our designated agent containing:

1. Your physical or electronic signature.
2. Identification of the material that has been removed or disabled, and the location at which the material appeared before it was removed or disabled.
3. A statement under penalty of perjury that you have a good faith belief that the material was removed or disabled as a result of mistake or misidentification.
4. Your name, address, and telephone number, and a statement that you consent to the jurisdiction of the federal court in your district (or, if outside the United States, any judicial district in which ShipSafe may be found), and that you will accept service of process from the person who provided the original takedown notification or an agent of such person.

Upon receipt of a valid counter-notification, we will forward it to the complaining party and restore the removed material within 10–14 business days, unless the complaining party notifies us that they have filed a court action seeking to restrain you from engaging in infringing activity.

### Repeat Infringers

In accordance with the DMCA and other applicable law, ShipSafe has adopted a policy of terminating, in appropriate circumstances, the accounts of users who are deemed to be repeat infringers. ShipSafe may also, in its sole discretion, limit access to the service or terminate the accounts of any users who infringe any intellectual property rights of others, whether or not there is any repeat infringement.

### Designated Agent

DMCA notices and counter-notifications should be sent to our designated agent:

DMCA Designated Agent

Tomer Goldstein

Reut 12B, Hod HaSharon 4529614, Israel

Email: [support@ship-safe.co](mailto:support@ship-safe.co)

## 19\. Contact

ShipSafe is operated by Tomer Goldstein, a sole proprietor doing business as ShipSafe.

Legal Contact

Tomer Goldstein d/b/a ShipSafe

Reut 12B, Hod HaSharon 4529614, Israel

Email: [support@ship-safe.co](mailto:support@ship-safe.co)

[← Back to ShipSafe](https://ship-safe.co/)

## Sitemap

Every page of this site, in markdown: [https://ship-safe.co/sitemap.md](https://ship-safe.co/sitemap.md)
