The highlighted blanks below are the details only the operator of this deployment can supply. They must be filled in, and this document reviewed by a lawyer, before it is relied on as a contract.
1. The agreement
These terms are between you and legal entity name (“Arca”, “we”). Creating an account or using the service means you accept them. If you are accepting on behalf of a company, you confirm you are allowed to bind it.
2. What the service does
Arca runs six analysis agents over a public Git repository you nominate: secrets, dependencies, static analysis, configuration, commit history, and an authorization and logic review. It returns a ranked list of findings with a suggested fix for each, plus a combined score and separate code and dependency scores. The logic agent sends a bounded selection of the repository’s source files to Anthropic’s API for analysis; it runs only where it is enabled, and the scan reports which agents ran.
3. Your account
- Give accurate signup details and keep them current.
- You are responsible for everything done with your credentials and your API keys. Treat a key like a password: it is shown once and it carries your scopes.
- Tell us promptly at security contact address if a key leaks.
- An organisation owner is responsible for the members they invite.
4. What you may scan
Only repositories that are public, and that you are permitted to analyse. Submitting a repository is you confirming both. You must not use Arca to:
- attack, probe, or map infrastructure you do not own or have written permission to test
- harvest secrets from third-party code for any purpose other than reporting them
- work around a rate limit, quota, or access control, whether ours or a code host's
- resell the service, or run it as the backend of a competing scanner
- break any law that applies to you or to us
Arca surfaces credentials that were committed to public code. Finding a live secret does not entitle you to use it. If you find one that is not yours, the only acceptable action is disclosing it to its owner.
5. What a result means, and what it does not
Arca is an aid to review, not a certificate of security, and not professional advice. Static analysis misses real vulnerabilities and reports issues that are not exploitable in context. A high score does not mean a repository is safe, a clean run does not mean it is free of defects, and a suggested fix has not been tested against your code.
Where a deployment has LLM-suggested fixes enabled, those suggestions are machine-generated and can be wrong. Review every change before you apply it. Decisions you make on the basis of a scan are yours.
6. Availability
The service is provided as it stands. Agents can fail or be unavailable, and a scan can return partial results, which the report marks. We may change, suspend, or withdraw features. Where a paid plan carries an availability commitment it is stated at service level terms URL; absent that, no uptime is guaranteed.
7. Fees
Paid plans and their limits are described at pricing page URL. Fees are charged in advance, are non-refundable except where the law requires otherwise, and exclude taxes. We will give notice period before a price change affecting you.
8. Ownership
We own the service, the software, and the marks. You own the code you scan; scanning it gives us no rights in it beyond the licence needed to run the scan, store the result, and show it back to you and your organisation. You own your scan reports.
9. Suspension
We may suspend or close an account that breaks section 4, that threatens the stability or security of the service, or that has unpaid fees. Where circumstances allow, we will warn first and give you a chance to fix the problem.
10. Liability
To the fullest extent the law allows, Arca is not liable for indirect or consequential loss, for lost profit or data, or for any security incident that a scan did not catch. Our total liability under this agreement is capped at liability cap: e.g. fees paid in the prior 12 months. Nothing here limits liability that cannot lawfully be limited, including for death, personal injury, or fraud.
11. Indemnity
You will cover us against claims arising from your use of the service in breach of section 4, including claims from the owner of a repository you were not entitled to scan.
12. Termination
You may close your account at any time. On closure we stop processing and delete your data in line with the Privacy Notice. Sections 5, 8, 10, and 11 survive.
13. Changes
We will post material changes on this page and email account holders notice period before they take effect. Continuing to use the service after that means you accept the new terms.
14. Governing law
This agreement is governed by the law of governing jurisdiction, and the courts of venue have exclusive jurisdiction.
See also the Privacy Notice.