Last updated: August 7, 2026
Terms of Service
These Terms of Service ("Terms") govern your use of StackShield's beta security scanning and remediation service (the "Service"), operated by Santa Singh Sehra ("StackShield," "we," "us"). By creating an account or connecting Supabase, GitHub, or Vercel to StackShield, you agree to these Terms.
1. Beta status
StackShield is currently in a limited beta, capped at 100 users. The Service is provided for evaluation purposes and:
- May contain bugs, incomplete features, or behavior that changes without notice.
- Has no guaranteed uptime or service-level agreement (SLA).
- May be modified, suspended, or discontinued at any time during the beta period.
- May have its beta cohort closed to new signups once capacity is reached.
We will make reasonable efforts to notify active beta users before making changes that materially affect their access or data.
2. What the Service does
StackShield connects to your Supabase, GitHub, and/or Vercel accounts (whichever you choose to authorize) to scan for common misconfigurations — including exposed keys, disabled Row Level Security, and open CORS policies — and to propose fixes for issues it finds. Fix analysis is performed using an AI provider you connect yourself under a Bring Your Own Key (BYOK) model (see Section 6). StackShield does not include AI usage costs in any plan.
3. Every fix requires your explicit approval
StackShield does not apply any change to your connected Supabase, GitHub, or Vercel account without you first reviewing the exact proposed change and explicitly confirming it. No fix is applied autonomously. If you use a feature that behaves differently from this description, that is a product bug, not intended behavior, and you should report it to us immediately at contact@stackshield.org.
4. Your responsibility
You are solely responsible for:
- Reviewing the exact change shown before confirming it.
- Testing fixes in a non-production or staging environment before applying to production where practical.
- Ensuring you have the legal authority to connect the Supabase, GitHub, and Vercel accounts/projects you authorize (e.g., you are the owner or have permission from the owner).
- Complying with the terms of service of Supabase, GitHub, Vercel, and any AI provider you connect.
5. Required third-party access
By connecting an account, you grant StackShield permission to access that account via the OAuth or API tokens you provide, solely to perform the scans and approved fixes you request. You may revoke this access at any time from your account settings or directly within the connected third-party service; revoking access will disable related functionality.
Our sub-processors (Supabase, Polar, Ollama Cloud, and our email provider) process data on our behalf under contractual obligations. A full sub-processor list and our Data Processing Addendum are available in our Privacy Policy (Sections 11 and 12). If you require a separately executed DPA for enterprise procurement, contact contact@stackshield.org.
6. Bring Your Own Key (BYOK)
Fix analysis uses an AI provider account you connect and pay for separately (currently Ollama Cloud). You are solely responsible for your own AI provider costs, usage limits, and compliance with that provider's terms. StackShield is not responsible for charges incurred on your connected API key and does not mark up or bill for AI usage.
6a. AI-generated outputs
Scan findings, proposed fixes, and remediation suggestions are generated by third-party AI models under your own BYOK credentials. While we design our prompts and validation logic to produce accurate, safe outputs, AI-generated content may be incomplete, inaccurate, or contain unintended side effects. You are solely responsible for reviewing every proposed fix before applying it. StackShield does not guarantee the correctness, completeness, or safety of any AI-generated output and disclaims liability for any harm caused by acting on such outputs without your own verification.
7. "As is" — no warranty
The Service is provided "as is" and "as available," without warranty of any kind, express or implied. We do not warrant that:
- All vulnerabilities will be detected.
- Every proposed fix will be correct, complete, or free of side effects.
- The Service will be uninterrupted, secure, or error-free.
No security tool can guarantee complete protection. StackShield is one layer of defense and should be combined with code review, manual security audits, and other controls.
8. Limitation of liability
To the maximum extent permitted by law:
- StackShield and its operators are not liable for any indirect, incidental, special, or consequential damages, including data loss, downtime, or security incidents, arising from your use of the Service.
- Our total liability for any claim arising from the Service is limited to the greater of (a) the amount you paid us in the 12 months before the claim, or (b) USD $100 — except where a fix you did not review and approve caused the harm, in which case this cap does not apply.
- Nothing in these Terms limits liability that cannot be limited under applicable law.
9. Indemnification
You agree to indemnify and hold StackShield harmless from claims, damages, or expenses arising from: (a) your misuse of the Service, (b) your violation of these Terms, or (c) your connecting accounts or projects you were not authorized to connect.
10. Subscriptions, billing, and refunds
Paid plans, if any during beta, are billed through our payment processor (Polar). Subscriptions renew automatically until cancelled. You may cancel at any time from your account settings; cancellation takes effect at the end of the current billing period, and you will retain access until then. Deleting your account also automatically cancels any active subscription (see our Privacy Policy, Section 5).
All sales are final. We do not offer refunds for subscription payments already processed, except where a refund or a right of withdrawal is required by applicable law — for example, consumers in the European Union and United Kingdom have a statutory 14-day right of withdrawal on most digital subscription purchases under EU/UK consumer protection law, unless that right has been expressly waived at the time of purchase (such as by acknowledging immediate access to the Service). Where such a legal right applies to you, we will honor it as required; nothing in this section limits any right you cannot lawfully waive.
Beta pricing and any "founding user" terms will be honored as stated at signup unless you're notified otherwise in advance.
11. Termination
We may suspend or terminate accounts that violate these Terms, abuse the Service, or attempt to compromise its integrity. You may close your account at any time. On termination, Section 8 (Limitation of Liability), Section 9 (Indemnification), and Section 10 (Refunds) survive.
12. Changes to these Terms
We may update these Terms as the beta evolves. We'll update the "Last updated" date above and, for material changes, notify active users by email or in-app notice before the changes take effect.
13. Governing law and disputes
These Terms are governed by the laws of the Republic of Kenya, without regard to conflict-of-law principles. Any dispute arising from these Terms or the Service will first be attempted to be resolved informally by contacting contact@stackshield.org; if unresolved, disputes will be subject to the exclusive jurisdiction of the courts of Nairobi, Kenya.
14. General
- Severability: if any provision of these Terms is found unenforceable, the rest remain in effect.
- Entire agreement: these Terms, together with the Privacy Policy, are the entire agreement between you and StackShield regarding the Service.
- Assignment: you may not assign these Terms without our consent; we may assign them in connection with a merger, acquisition, or sale of assets.
15. Contact
Questions about these Terms: contact@stackshield.org