Terms of service
Can I Run That? is a product of Infosec Chicago (“Infosec Chicago,” “we,” “our,” or “us”). These Terms of Service (“Terms”) govern your access to and use of Can I Run That? (the “Service”). By using the Service, you agree to these Terms.
1. The service
Can I Run That? provides automated, AI-assisted analysis of source-accessible software and vendor security documentation to generate structured reports, risk scores, control and evidence-gap summaries, severity groupings, and related indicators intended to support software adoption and implementation decisions.
2. Automated analysis limitations
No guarantee of detection, accuracy, or completeness
The Service does not guarantee that it will identify all vulnerabilities, malicious code, supply-chain issues, licensing concerns, privacy risks, or other problems. AI-generated outputs may contain inaccuracies, false positives, false negatives, incomplete analysis, or misinterpretations of code behavior.
Reports are informational indicators only and do not constitute professional security, legal, or compliance advice. You are solely responsible for independently reviewing findings and making final deployment decisions.
Risk scores, grades, and severity labels generated by the Service do not represent regulatory compliance determinations and should not be interpreted as certification of legal or industry standard compliance.
3. Not for safety-critical systems
The Service is not designed, intended, or certified for use in safety-critical, life-critical, or mission-critical environments, including medical systems, aviation systems, autonomous vehicles, nuclear facilities, industrial control systems, or emergency response infrastructure.
You agree not to rely on the Service as the sole basis for decisions affecting human safety or critical infrastructure.
4. No professional services relationship
Use of the Service does not create a professional services relationship, security audit engagement, legal advisory relationship, or consulting engagement between you and Infosec Chicago.
5. Not a licensed audit or certification authority
Can I Run That? does not issue certifications, compliance attestations, penetration test reports, or legally binding security assessments. Reports are internal decision-support tools only.
6. Your responsibilities
- You are responsible for your software approval and deployment decisions.
- You will comply with applicable laws and regulations.
- You will not attempt to disrupt or interfere with the Service.
- You are responsible for safeguarding your account credentials.
- You represent that you have the legal right and authorization to submit any repositories, extensions and packages, source archives, vendor documents, or other submitted evidence to the Service for analysis.
- You are solely responsible for ensuring submissions do not violate confidentiality obligations, contractual restrictions, or applicable law.
7. Confidentiality of submitted content
While we implement reasonable safeguards designed to protect submitted content, including encryption in transit and at rest, you acknowledge that the Service is not a secure code escrow or regulated data storage environment. You are responsible for determining whether it is appropriate and authorized to submit proprietary source code, vendor documents, or other sensitive evidence for analysis.
8. AI processing and data handling
For fully inclusive plans, submitted content and contextual data may be processed via Anthropic Claude under a commercial API agreement that prohibits submitted data from being used for AI model training.
For Bring Your Own Key (BYOK) plans, processing occurs under your own Anthropic API credentials and is governed by your Anthropic account settings and agreement. If AI model training is enabled for that account, your Anthropic terms control that use.
Source code files are not retained after processing. Cryptographic file hashes and underlying file-level assessment results from code reviews are retained indefinitely by default, including after the code review assessment itself is deleted. For a sensitive codebase, an option available during the initial scan can delete the stored hashes and file-level results created for unique files first seen in that repository after report generation. This option is generally not recommended because it reduces retained analysis history and reuse. A file-level result is primarily a generated summary of the file's purpose and its associated security findings. In rare circumstances it may include a small code snippet. It cannot identify or reconstruct the submitted source file. Vendor documents are retained by default, retention can be disabled, and the vendor assessment plus retained documents can be deleted by the customer. We do not sell submitted content.
9. Social login authentication
The Service may allow authentication through third-party identity providers (e.g., Google, Apple, Microsoft, Facebook) via Clerk. Use of those providers is subject to their respective terms and privacy policies.
10. Fees and billing
Paid plans are billed in advance on a recurring month-to-month basis unless otherwise agreed in writing and may be processed through a third-party billing provider.
Fees are generally non-refundable except where required by law or as expressly described in our Refund Policy.
Subscriptions may be canceled at any time prior to renewal and will remain active through the end of the current billing term.
Bring Your Own Key plans include a seven-day trial. Included monthly code assessments and vendor reviews reset each billing cycle and do not roll over. Purchased additional lines-of-code capacity does not expire.
11. No monitoring obligation
Infosec Chicago has no obligation to monitor user activity or submitted content. We reserve the right, but not the obligation, to review, limit, or remove content that violates these Terms or creates risk to the Service.
12. Disclaimer of warranties
The Service is provided on an “AS IS” and “AS AVAILABLE” basis without warranties of any kind, express or implied, including warranties of merchantability, fitness for a particular purpose, non-infringement, or that the Service will be error-free or uninterrupted.
13. Limitation of liability
To the fullest extent permitted by law, Infosec Chicago shall not be liable for indirect, incidental, consequential, special, or punitive damages, including loss of profits, data, or business interruption.
Infosec Chicago’s total aggregate liability shall not exceed the greater of:
- (a) fees paid by you in the twelve (12) months preceding the claim; or
- (b) US $100.
14. Indemnification
You agree to defend, indemnify, and hold harmless Infosec Chicago from and against claims, damages, losses, and expenses (including reasonable attorneys’ fees) arising out of:
- Your use of the Service;
- Your submitted repositories, extensions and packages, source archives, vendor documents, or other submitted evidence;
- Your deployment decisions;
- Your violation of these Terms or applicable law.
15. Export compliance
You agree to comply with U.S. export control and sanctions laws. You represent that you are not located in a comprehensively sanctioned country and are not on a denied-party list, and you will not use the Service for any prohibited end use.
16. Force majeure
Infosec Chicago shall not be liable for delays or failures caused by events beyond reasonable control, including acts of God, internet outages, cloud provider failures, government actions, labor disputes, or cyber incidents.
17. Beta features
We may designate certain features as beta, preview, or experimental. Such features may change or be discontinued without notice and are provided without warranties.
18. Governing law and venue
These Terms are governed by the laws of the State of Illinois, without regard to conflict of law principles. Any disputes shall be resolved in state or federal courts located in Illinois, and you consent to personal jurisdiction and venue in those courts.
19. Survival
Sections relating to limitation of liability, indemnification, governing law, export compliance, disclaimers, and confidentiality of submitted content shall survive termination of your access to the Service.
20. Changes
We may update these Terms from time to time. Continued use after changes become effective constitutes acceptance of the updated Terms.
21. Contact
Questions regarding these Terms may be sent to: [email protected]