← Back to unbreachable
Placeholder content — not legal advice. This page has not been reviewed by an attorney and is not a final Terms of Service. I will replace this before going to Production.

Terms of Service

Last updated: placeholder — not yet finalized.

1. What unbreachable does

unbreachable is a security scanning tool for web applications, aimed at apps built with AI coding tools (Lovable, Bolt, v0, Cursor, and similar). It looks for exposed secret keys, misconfigured database rules, missing security headers, exposed source maps, and other publicly-observable configuration issues, and returns a report with suggested fixes.

2. You may only scan domains you own

You may only submit a domain for scanning if you own it or are otherwise authorized to test it. Before any scan runs, you must prove control of the domain by adding a unique verification meta tag to the page's <head>, which we check before every scan — not just once at signup. We will not scan a domain that fails this ownership check, and re-verification can be revoked at any time by removing the tag.

Submitting a domain you do not own or control, or attempting to bypass or spoof the ownership check, is a violation of these Terms and may violate computer-crime laws in your jurisdiction.

3. Authorized, non-destructive testing only

All scanning performed by unbreachable is passive or configuration-based (e.g. fetching publicly served files, checking response headers, DNS records) plus an authorized active-testing pass available on paid plans. Active testing is designed to be non-destructive: it does not attempt to exfiltrate data, modify data, create or delete records, or disrupt the availability of your application. We do not perform denial-of-service testing, credential-stuffing, or any technique intended to cause harm or downtime.

4. What we store, and for how long

We store: your account information (name, email, and profile image from Google sign-in); the domains you add as projects and their verification status; scan results, including findings, evidence snippets, and remediation text; and your subscription/plan status. Scan evidence may include short excerpts of your own public-facing code or configuration (e.g. a redacted portion of an exposed key) solely to document the finding.

This data is retained for as long as your account is active, so you can track a project's history over time. If you delete your account, associated project and scan data will be deleted or de-identified within a reasonable period, except where retention is required for billing, fraud-prevention, or legal-compliance purposes. (Placeholder — exact retention windows are pending legal review.)

5. No warranty; limitation of liability

Placeholder — pending real legal review. unbreachable is provided "as is" without warranties of any kind. A scan finding no issues is not a guarantee that your application is secure, and unbreachable is not a substitute for a full penetration test or professional security audit. To the fullest extent permitted by law, unbreachable and its operators will not be liable for any indirect, incidental, or consequential damages arising from use of the service. This section will be replaced with reviewed, jurisdiction-appropriate language before Production.

6. Changes to these terms

We may update these Terms as the product changes. Since this entire document is a placeholder, expect it to change substantially before launch.

7. Contact

Questions about these terms: hello@unbreachable.dev.