Legal
Terms of Service
Last updated 2026-07-27.
The subscription
One product, three ways to pay for it, all billed by Stripe. Nothing is held back on the cheaper terms — a longer term is simply less money.
- $49/month— a recurring subscription. New subscriptions include 7 days free; you aren't charged until the trial ends, and cancelling during the trial costs nothing. After the trial it renews monthly until you cancel.
- $265 for six months and $470 for twelve months — a single charge that buys a fixed window of access. These do not auto-renew. When the window ends, access simply stops until you choose to buy another.
Cancelling the monthly plan: self-serve, any time — open Billing from your dashboard to manage or cancel through Stripe's billing portal (or email support@shiplock.devand we'll do it for you). You keep access through the end of the period you've already paid for; we don't offer partial-month refunds.
Prepaid terms carry no cancellation fee, because there is nothing to cancel — you bought a window, not a commitment. We don't charge an early termination fee under any plan, ever.
Refunds and withdrawal.If you're a consumer in the EU, UK, or another jurisdiction with a statutory cooling-off period, you keep that right and nothing here waives it: you may withdraw within 14 days of purchase, and we'll refund what you paid, less a proportionate amount for the period you actually had access. Outside that, prepaid terms are non-refundable — but if a prepaid term isn't working out for you, email us. We'd rather refund you than keep money you feel you shouldn't have spent.
Your authorisation to scan
ShipLock works by sending automated requests to infrastructure you tell us is yours. By connecting a project you are giving us express permissionto do that, and you confirm that you own the Supabase project and application URL you submit — or are authorised by whoever does to have them scanned. Please don't submit anything you don't have that authority over.
Our checks are read-only and non-destructive. We look at how your project is configured and what it will answer to an anonymous request. We do not attempt to exploit, damage, degrade, or persist in anything we find, and we do not attempt to access other customers' data. You can revoke this permission at any time by disconnecting the project or cancelling.
Your infrastructure providers have their own acceptable-use terms governing security testing. Our checks are designed to stay within ordinary, documented API use of the public endpoints your app already exposes, but you remain responsible for your relationship with your own providers.
What you get
A 16-check audit of your connected Supabase project and — while your subscription is active — the fix for every finding, delivered as a reviewable pull request or handed to your coding agent. Continuous monitoring is genuinely live for the pieces we say are live: a re-scan on every pull request, an hourly lightweight critical-check pass, and a full deep scan every 48 hours. GitHub source scanning and the coding-agent integration activate when you connect them; anything we haven't shipped yet is labeled “coming soon” in the product itself, and we won't bill you differently based on roadmap features landing.
What ShipLock is — and isn't
ShipLock identifies configuration issues in your project using automated checks against your Supabase project's public API surface. It is not a penetration test, not a guarantee that your application is free of vulnerabilities, and not a substitute for a professional security review where the stakes call for one. We do not attempt to exploit anything we find. You're responsible for reviewing and applying the fixes we surface.
No security tool finds everything, and we say so throughout the product rather than in the fine print. Business logic, chained flaws, runtime-only issues, and anything requiring human judgement are outside what automated checking can reach. A clean ShipLock result means the checks we run found nothing — it does not mean your application is secure.
Warranties and liability
We take this seriously and we run ShipLock against our own infrastructure before yours. But the service is provided “as is”, and to the extent the law allows we disclaim implied warranties of merchantability and fitness for a particular purpose. We don't warrant that the service will be uninterrupted or error-free, or that it will identify every issue in your application.
Our total liabilityto you for any claim connected to ShipLock is limited to the amount you paid us in the twelve months before the claim arose. We aren't liable for indirect, incidental, special, or consequential damages, or for lost profits, revenue, data, or goodwill — including damages arising from a vulnerability we didn't catch, a fix applied incorrectly, or downtime caused by a change you made on our recommendation.
None of the above limits liability for our own gross negligence, wilful misconduct, fraud, death or personal injury, or anything else that can't lawfully be limited. If you're a consumer, your statutory rights are unaffected by anything in this section.
The Verified report
You can publish a Verified report and badge showing that your project is under continuous monitoring. It's off until you turn it on, and you control it.
What it attests: that a project was connected to ShipLock, which checks we run, and when we last ran them. What it does not attest: that your application is secure, that it is free of vulnerabilities, or that it meets any particular standard, certification, or regulatory requirement. It is a statement about monitoring, not a certification, and it never displays your findings.
The report is provided for information only. We aren't liable to you or to any third party who reads it for decisions taken in reliance on it, and you agree not to present it as a security certification, audit opinion, or compliance attestation. Please don't display it for a project we're not actually monitoring — if monitoring stops, the report says so, and you should take the badge down.
Your data, and your customers' data
What we collect and why is set out in our Privacy Policy, including the third parties that process data on our behalf. In the ordinary course we don't process your end users' personal data — our checks look at configuration and at whether endpoints answer, not at the contents of your tables.
If your use of ShipLock does involve us processing personal data on your behalf and you need a data processing agreement, email support@shiplock.devand we'll put one in place.
Your account
You're responsible for keeping your login credentials secure and for the accuracy of the Supabase URL and anon key you provide us. Don't submit credentials or projects you don't have the right to have scanned.
Changes
We may update these terms as the product changes. We'll update the date at the top of this page when we do.