GuardAPI

Effective 10 September 2026

Terms of Service

These terms cover GuardAPI accounts, billing, and the GitHub Action GuardAPI/ghost-api@v6. They replace earlier terms written for a hosted scanner.

1. Authorized targets only

You may point the Action only at systems you own or are explicitly authorized to test (typically your own HTTPS staging API). Using someone else’s API as base-url without authorization is prohibited. We will cooperate with lawful requests about abuse.

2. What the service is

GuardAPI is a GET-only Broken Object Level Authorization check that runs in your CI. It is not a penetration test, not a complete DAST, not legal advice, and not a SOC 2 Type II certification. A “pass” means the probed GET pairs did not produce a proven leak under the published verdict rules — not that the API is safe.

3. Data

You instruct the Action to POST a redacted run summary to our API. Tenant tokens must stay in GitHub Secrets. See the Privacy Policy.

4. Billing

Paid plans are Team ($199/month, 3 repositories) and Scale ($499/month, unlimited repositories), plus a 14-day trial on one repository. Checkout is Stripe. Repository caps are enforced when ingesting runs. You can cancel via the Stripe billing portal.

5. Disclaimer

The service is provided “as is.” We are not liable for breaches on APIs you test or for merge decisions you make from a pass, fail, inconclusive, or error verdict.

6. Contact

support@guard-api.com