← Back to home

Terms of Service

Last updated: June 29, 2026

These Terms govern your use of Kavaca (the "Service"), operated by JOHO DIGITAL FZE, a free zone establishment registered in the United Arab Emirates ("Kavaca", "we", "us"). By creating an account or using the Service, you agree to these Terms. If you do not agree, do not use the Service.

1. The Service

Kavaca runs automated security and production-readiness checks against a code repository you authorize, and produces a report with findings and remediation guidance. The Service is informational and intended to help you, not to replace professional security review.

2. Accounts & eligibility

You sign in with GitHub and are responsible for activity under your account. You must be at least 16 years old and able to enter into these Terms.

3. Acceptable use

Authorizing repository access through GitHub does not constitute our verification that you are entitled to scan a given repository. Responsibility for confirming you have the necessary rights and permissions rests entirely with you.

4. Scans are informational — no guarantee

The Service uses automated and AI-based analysis. It may miss issues, and it may report items that are not actually problems (false positives). A scan does not guarantee that your application is secure or production-ready, and is not a substitute for professional security advice. You remain solely responsible for your application, its security, and its compliance.

Because the Service relies on automated and AI-based analysis, its outputs — including findings, severity ratings, and remediation guidance — may be incomplete, inaccurate, or out of date, and must be independently verified before you rely on them. Remediation guidance is provided for convenience only and is not professional security advice. Unless we expressly state otherwise in a report, we do not warrant that a scan tests against, or conforms to, any particular standard, framework, or checklist (including OWASP). You are responsible for evaluating the suitability of any finding or guidance for your application.

5. Payments & refunds

6. Intellectual property

You retain all rights to your code. You grant us a limited license to access and process it solely to provide the Service (and, as described in our Privacy Policy, we discard your code after each scan). We retain all rights to the Service itself.

While we discard your source code after each scan, we retain the report and related scan data we generate — including findings, severity, scores, and metadata — associated with your account as your scan history, until you delete it or as described in our Privacy Policy. Separately, we may retain and use data derived from scans in aggregated or de-identified form to operate, secure, improve, and develop the Service. In all cases, retained data excludes your source code.

7. Third-party services

The Service relies on GitHub (authentication and repository access) and Stripe (payments). Your use of those services is subject to their own terms. We are not responsible for the availability of, or the acts or omissions of, these third-party services.

8. Disclaimers & limitation of liability

The Service is provided "as is" and "as available", without warranties of any kind, express or implied, including merchantability, fitness for a particular purpose, and non-infringement.

To the maximum extent permitted by law, Kavaca will not be liable for any indirect, incidental, special, consequential, or punitive damages, or for any loss arising from a security incident the scan did not detect. Our total liability for any claim is limited to the amount you paid us in the 12 months before the claim.

Nothing in these Terms limits or excludes liability that cannot be limited or excluded under applicable law, including liability for death or personal injury caused by negligence, fraud, or fraudulent misrepresentation. Where our liability cannot lawfully be capped at the amount you paid, our total liability for any claim is limited to the greater of (a) the amounts you paid us in the 12 months before the claim, or (b) USD 100.

9. Indemnification

You agree to indemnify and hold Kavaca harmless from claims arising out of your use of the Service or your violation of these Terms, including scanning repositories you were not authorized to scan.

10. Termination

You may stop using the Service and disconnect your GitHub account at any time. We may suspend or terminate access if you breach these Terms or to protect the Service.

11. Changes to these Terms

We may update these Terms from time to time. We will update the "last updated" date above and, for material changes, provide notice before they take effect and, where required by law, obtain your consent. Continued use of the Service after changes take effect means you accept the updated Terms.

12. Governing law & contact

These Terms are governed by the laws of the United Arab Emirates. Questions? Email legal@kavaca.io.

13. Dispute resolution

Before filing any claim, you agree to first contact us at legal@kavaca.io and attempt to resolve the dispute informally for at least 30 days. To the extent permitted by applicable law, any dispute not resolved informally will be resolved on an individual basis, and you and Kavaca waive any right to participate in a class, collective, or representative action. This section does not apply where, and to the extent that, applicable consumer-protection law grants you non-waivable rights to bring a claim in your local courts or to participate in collective proceedings.

14. General