Effective 10 September 2026
Terms of Service
These terms cover GuardAPI accounts, billing, and the GitHub Action GuardAPI/ghost-api@v6.
They replace earlier terms written for a hosted scanner.
1. Authorized targets only
You may point the Action only at systems you own or are explicitly authorized to test (typically your own HTTPS staging API).
Using someone else’s API as base-url without authorization is prohibited. We will cooperate with lawful requests about abuse.
2. What the service is
GuardAPI is a GET-only Broken Object Level Authorization check that runs in your CI. It is not a penetration test, not a complete DAST, not legal advice, and not a SOC 2 Type II certification. A “pass” means the probed GET pairs did not produce a proven leak under the published verdict rules — not that the API is safe.
3. Data
You instruct the Action to POST a redacted run summary to our API. Tenant tokens must stay in GitHub Secrets. See the Privacy Policy.
4. Billing
Paid plans are Team ($199/month, 3 repositories) and Scale ($499/month, unlimited repositories), plus a 14-day trial on one repository. Checkout is Stripe. Repository caps are enforced when ingesting runs. You can cancel via the Stripe billing portal.
5. Disclaimer
The service is provided “as is.” We are not liable for breaches on APIs you test or for merge decisions you make from a pass, fail, inconclusive, or error verdict.