Terms and policies
Learn more about Chainguard policies and our legal documents.
Code Analysis Terms
Last Update: October 6, 2026
These Code Analysis Terms (“Terms”) govern Customer’s use of any Products, Services, or Technical Previews that reference or are otherwise identified as subject to these Terms (collectively, “Code Analysis Offerings”), including any optional features, add-ons, or supplemental capabilities made available or as part of or alongside the Code Analysis Offerings (“Optional Features”). Optional Features will be identified and made available to Customers in the Code Analysis Offerings product documentation, located here: https://edu.chainguard.dev/. Chainguard, Inc. (“Chainguard”) may make Code Analysis Offerings available pursuant to an Order or through another applicable enrollment or activation process. Customer’s use of the Code Analysis Offerings is also governed by the separate and binding agreement in effect between the parties for the provision of Chainguard’s products and services to Customer, or if no such agreement is in effect, Chainguard’s online Master Services and License Agreement (as applicable, the “Agreement”). These Terms are incorporated into and form part of the Agreement. Capitalized terms used, but not defined in these Terms have the meanings ascribed in the Agreement.
If these Terms conflict with the Agreement, these Terms will control solely with respect to the applicable Code Analysis Offering and only to the extent of the conflict. By accessing or using a Code Analysis Offering, including as part of an Evaluation, the individual accepting these Terms represents that they have authority to bind the entity or organization on whose behalf they are acting, and Customer agrees to be bound by these Terms. These Terms have the same force and effect as a written agreement signed by Customer and Chainguard. If Customer does not agree to these Terms, Customer may not access or use any Code Analysis Offering.
1. GENERAL
1.1. Artificial Intelligence (“AI”). Chainguard maintains policies and procedures designed to support the responsible development and deployment of AI. In order to provide, operate, continuously improve, maintain and support the Code Analysis Offerings, Chainguard may use AI or similar technologies for Permissive AI Uses. “Permissive AI Uses” means use of AI to analyze customer-provided data to the Code Analysis Offerings in connection with Customer’s use of the offering (“Code Analysis Inputs”) for:
(a) maintaining up-to-date Products and related offerings, and providing security-enhancing recommendations via agentic-based analysis, de-duplication, vulnerability identification, and patch development;
(b) fulfilling support functionality (e.g., answering and triaging support requests and utilizing technical knowledge repositories to generate automated responses); and
(c) administering Chainguard’s own business operations (e.g. phishing identification) and/or routine office productivity tasks.
1.2. Chainguard’s use of any Customer Confidential Information in connection with Permissive AI Use cases as described in Section 1.1 (Artificial Intelligence) above shall not constitute a breach of its obligation of confidentiality under the Agreement. Customer Confidential Information will not be used by Chainguard, its Affiliates or any of their respective personnel, to train third-party foundation models or large language models (“LLMs”) used generally across customers. Chainguard does not guarantee the AI-generated outputs (“Code Analysis Outputs”) will be accurate, complete, error-free or that they will detect, identify, or address all potential vulnerabilities or exploits present in the Code Analysis Inputs. Customers should always independently verify all Code Analysis Outputs for accuracy, completeness, and fitness for Customer’s intended purpose before taking any action in reliance on them as Chainguard may not separately validate these results with human review.
1.3. Restricted Third-Party AI LLMs. In connection with its provision of the Code Analysis Offerings, Chainguard may utilize third-party AI LLMs, including models designated by the applicable third-party provider, and as may be reflected in Chainguard’s product documentation, as beta, pre-release, preview, or models subject to heightened safeguards or other treatment (collectively, “Restricted LLMs”). Use of Restricted AI LLMs requires Customer’s prior opt-in and are not enabled by default. Notwithstanding any Customer opt-in, Chainguard reserves the right to disable, suspend, or discontinue any Restricted LLMs in connection with a Code Analysis Offering at any time for any reason without prior notice or liability. Customer acknowledges that the applicable Restricted LLM provider may retain Code Analysis Inputs and Code Analysis Outputs for safety or other similar reviews.
2. CUSTOMER RESPONSIBILITIES
2.1. General Obligations. Customer acknowledges the Code Analysis Offerings are analytical tools designed to assist in the identification and remediation of potential vulnerabilities or security flaws based on the information available to Chainguard at the time of analysis. Customer has and will retain sole responsibility for the accuracy, content, and legality of all Code Analysis Inputs. Customer represents and warrants that Customer has and will have sufficient rights in the Code Analysis Inputs to grant any necessary rights to Chainguard under these Terms. Customer further represents and warrants that, to the extent Chainguard processes Customer Confidential Information, Chainguard’s processing of Customer Confidential Information is in accordance with these Terms and the Agreement, and will not violate any laws or the rights of any third party. Without limiting the generality of the foregoing, Customer is responsible for all acts and omissions of its authorized users, and any act or omission by an authorized user that would constitute a breach of these Terms if taken by Customer will be deemed a breach of these Terms by Customer. Customer will notify Chainguard in writing immediately upon becoming aware of any actual or suspected breach of these Terms by Customer, its users, or any third party under its reasonable control.
2.2. Additional Requirements. Customer’s use of Code Analysis Offerings and Code Analysis Outputs will comply with applicable laws, government regulations, and any other legal requirements, including but not limited to, any data privacy, localization or sovereignty laws, regulations, and any other third-party legal requirements applicable to Customer. Customer is responsible for sanitizing any sensitive or regulated data before submitting it to, or otherwise making it available in connection with any Code Analysis Offerings (e.g. API keys, secrets, emails, tokens, and data subject to FedRAMP-requirements). In addition to Customer’s obligations under Section 8(a) of the Agreement, Customer will defend Chainguard and its Affiliates against any third-party claim, and indemnify them for resulting judgments and approved settlements, arising out of (i) Code Analysis Inputs, including any claim that Chainguard’s analysis or testing of Code Analysis Inputs was unauthorized, or (ii) Customer’s breach of Section 2.1 (General Obligations). Such obligations constitute obligations under Section 8 (Indemnification) of the Agreement.
3. INTELLECTUAL PROPERTY RIGHTS
3.1. License Grant. Subject to these Terms, Customer hereby grants Chainguard a non-exclusive, worldwide, royalty-free license to access, copy, modify, reproduce and process the Code Analysis Inputs as necessary to provide, operate, and continuously improve Chainguard’s Products and Services, or as may be required by law. As between the parties, Customer retains all right, title, and interest in and to the Code Analysis Inputs and any Code Analysis Outputs to the extent such outputs are specifically derived from and pertain to Customer’s business logic, architecture or functionality, including any Customer modifications made thereto or outputs made thereof, in the course of operation of Code Analysis Offerings.
3.2. Chainguard Rights. Chainguard will retain all right, title, and interest (including, without limitation, all patent, copyright, trade secret, or other proprietary rights) in and to the Code Analysis Offering;and any Chainguard modifications, improvements,, and derivative works of the foregoing, including any patches or remediation code developed, built, or authored by Chainguard; and vulnerability discoveries and CVE filings pursuant to Chainguard’s Coordinated Vulnerability Handling Policy, located here: https://www.chainguard.dev/legal/coordinated-vulnerability-handling-policy. Except for the express limited rights set forth in these Terms, no right, title or interest in the Code Analysis Offering is granted to Customer. Usage Data is processed and retained in accordance with Section 2(c) of the Agreement and includes structured records of each session (e.g. an opaque user identifier, session type, token counts, timing, and a status code) to monitor for usage metering and for Chainguard to provide, operate, maintain, continuously improve, and support its systems delivering its Products and Services.
3.3. Restrictions. Customer shall not, and shall not permit any third party to (i) directly or indirectly: sell, rent, lease, license, distribute, provide access to, sublicense, or otherwise make Code Analysis Offerings available to a third party (ii) use Code Analysis Offerings or Code Analysis Outputs to provide a substantially similar service for the benefit of a third party, including as part of a paid or unpaid platform, product, or service; (iii) reverse engineer, decompile, disable, modify, create derivative works of, derive, or attempt to discover the source code (in whole or in part) underlying Code Analysis Offering; (iv) include in Code Analysis Inputs any content intended to instruct, manipulate, or extract information from any Third-Party AI LLMs, and will not attempt to obtain any prompt, transcript, model reasoning, or unedited AI-generated content; (v) breach, circumvent, or attempt to breach the security or authentication measures of the Code Analysis Offerings or willfully or intentionally render any part of Code Analysis Offerings unusable; (vi) use Code Analysis Offerings other than as described in Chainguard’s product documentation; or (vii) use Code Analysis Offerings in violation of Chainguard’s Acceptable Use Policy. Further, Customer shall not use Code Analysis Offerings in a manner that (a) causes Chainguard to be in breach of its obligations under applicable laws and regulations; or (b) violates the rights or terms of any third party.
4. PRIVACY
4.1. Supplemental Feature Data Processing Agreement (“Supplemental Feature DPA”). To the extent Chainguard processes Code Analysis Inputs containing personal data, the Supplemental Feature DPA (“DPA”), located at: https://www.chainguard.dev/legal/supplemental-dpa, shall apply. For clarity, as between Chainguard and Customer, Chainguard shall process (as defined in the Supplemental Feature DPA) uploaded Code Analysis Inputs containing personal data as a Processor acting on behalf of Customer.
5. USAGE
5.1. Usage Tiers. The term for Customer’s authorized use of Code Analysis Offering begins on the earlier of (i) the date Customer first accesses or uses Code Analysis Offerings, or (ii) the effective date of the applicable Order, and continues through the end of the subscription period identified at the time of purchase, unless earlier terminated or subsequently renewed under a subsequent Order or similar mechanism. During the term, Customer may access and use the Code Analysis Offering, subject to the usage limits (e.g., a maximum number of consumption units per annum) and other usage parameters set forth in the applicable Order or if no such Order is in effect, as otherwise indicated by Chainguard. If Customer’s usage exceeds the applicable usage parameters, Chainguard may, at its option, (a) invoice Customer in arrears for the excess usage at the the cost-per-unit (“CPU”) set forth in the Order, or if no Order is then-in-effect, at the then-current per-unit rate published on Chainguard’s website or platform, or (b) require the parties to negotiate amended terms that reflect Customer’s actual usage. Any unused portions thereof are non-assignable, non-transferable, non-sublicensable, and do not carry-over to subsequent Orders. Optional Features will be identified and made available to Customers in the Code Analysis Offering product documentation, which Chainguard may update from time to time. Optional Features may also be subject to separate pricing as indicated through the Service, which Chainguard may update at any time by providing reasonable notice to Customer.
5.2. Cooperation & Suspension. Customer will cooperate fully with any investigation by Chainguard relating to any actual or suspected misuse of the Code Analysis Offering, including assistance to (a) verify Customer and authorized user identity, location, and use of the Code Analysis Offering and will respond to any such request within five (5) business days, or sooner if Chainguard reasonably determines that the request relates to an imminent security threat. If Customer fails to comply with this Section, Chainguard may suspend Customer’s access to the Code Analysis Offering until Customer complies, in addition to any other rights or remedies available to Chainguard under this Agreement. Chainguard may also suspend Customer’s access to the Code Analysis Offerings at any time if Chainguard reasonably believes there is excess usage, a material breach of the Agreement, including these Terms, or Customer’s access to or use of Code Analysis Offering poses a security risk to or may adversely impact any Code Analysis Offering or other Products or Services.