Skip to content

Terms of service

Plain version: you point us at code you are allowed to have audited, we scan it and tell you what we found, and you decide what to do about it. We charge once, we delete everything, and we do not promise your app is safe — we promise to report what our tools saw.

Last updated

The agreement

These terms are between you and Bowtie.co, who operate ShipDoctor. Using the site or running an audit means you accept them. If you are doing this for an employer or a client, you are confirming you may accept them on that party’s behalf.

What the service does

You submit a repository — an uploaded archive, a public repository URL, or one you pick from a connected GitHub account. We run 8 categories of automated analysis over it, plus a reasoning pass by a language model over what those scanners found, and produce a report: an overall grade, a score per category, and a list of findings with the evidence behind them, an effort estimate and a repair prompt.

The free teaser shows the grade, the category scores, the counts and one finding in full. The rest is behind the purchase, and it is genuinely not sent to your browser until you buy it.

Buying a report

One audit's full report costs $149, charged once. There is no subscription, no account, and nothing recurring.

Payment is handled by Stripe on their own checkout page. Your report unlocks when Stripe confirms the payment to our servers — not when your browser returns from checkout — so if the two happen a moment apart, the report screen will say so and open itself when the confirmation lands.

There are no accounts. After you buy, we email you a link that reopens your report. That link is the only way back to it, it works for as long as the audit survives, and anyone holding it can read that report — so treat it like a password.

Refunds

If the report fails to generate, or the audit could not run, write to support@bowtie.co and we will refund the charge in full. Because the full report is delivered immediately on payment, we do not otherwise refund a report that ran and was delivered.

How long anything lasts

The code you submit is deleted as soon as the audit finishes. The findings, the report and its downloads are deleted automatically 15 days after the audit runs, and the return link stops working with them. Download what you want to keep — the three files on the report screen are yours, and nothing stops you keeping them forever. Details are in the privacy policy.

What you agree to

  • Submit only code you own or are authorised to have audited. You are responsible for having that right.
  • Do not submit malware, or code whose purpose is to attack the systems that analyse it.
  • Do not attempt to reach any part of our infrastructure other than this site, and do not attempt to obtain a report you have not paid for.
  • Do not use the service to build a competing dataset — automated bulk submission is what the rate limits and the daily budget exist to stop.

We may refuse or stop an audit that breaks these rules, or that threatens the service’s stability, and we may rate-limit or block traffic that looks automated.

Your code stays yours

You keep every right in the code you submit. You grant us permission to copy, build and analyse it for exactly one purpose — producing your report — and that permission ends when the audit does. We do not use your code to train models, and we do not share it with anyone outside the processors named in the privacy policy.

The report is yours to use however you like, inside your company or with your clients. The site, its design and the software that produced the report remain ours.

What an audit is not

The audit reports what our scanners and models found in the code you gave us, at the time they ran. It is not a security certification, a penetration test, a legal compliance assessment, or a guarantee that your application is safe to ship. Automated analysis misses things and sometimes flags things that are fine. Decisions about your software remain yours.

The service is provided as is. We do not warrant that it will be available uninterrupted, that every scanner will run on every repository, or that a finding will always be correct. Where a check could not run, the report says so rather than quietly grading around it.

Limits of liability

To the extent the law allows, our total liability for anything arising out of your use of ShipDoctor is limited to what you paid us for the audit in question — $149, or nothing if you never bought one. We are not liable for lost profits, lost data, or damage arising from a vulnerability the audit did not find. Nothing here limits liability that cannot lawfully be limited.

Changes, and ending it

We may change the service or these terms. The date at the top of this page moves when we do, and the terms that apply to an audit are the ones published when you ran it. You can stop using the service at any time; there is nothing to cancel.

Governing law

These terms are governed by the laws of the State of New York, United States, and disputes belong to the courts sitting there.

Contact

Questions about these terms, a refund, or anything the site did that it should not have: support@bowtie.co.