Terms of Service
Last updated 14 September 2026.
1. What this is
DevRadar is a hosted service that stores SBOMs for container images and reports how their vulnerabilities change over time. Using it means accepting these terms.
2. Accounts
- Sign-in is passwordless. You are responsible for the security of the mailbox and the identity provider you sign in with.
- API tokens act on behalf of your account. Treat them as credentials and revoke them from API tokens when they are no longer needed.
- You are responsible for what members of your account do with it.
3. Your data
- SBOMs, VEX documents, and the findings derived from them belong to you. They are used to operate the service and are not sold.
- Do not submit secrets. An SBOM describes software inventory; it is not a place for credentials, and the service does not scan submissions for them.
- Deleting an account removes its stored evidence. Backups age out on their own schedule.
4. Acceptable use
- Do not submit content you have no right to submit.
- Do not use the service to attack it, to attack anyone else, or to work around per-account limits.
- Limits exist to keep the shared instance responsive. Evading them is a reason for suspension.
5. Vulnerability data
Findings come from third-party scanners and public vulnerability databases. They are reported as received. DevRadar does not warrant that a finding is accurate, complete, or applicable to your usage, and an absence of findings is not evidence that an image is free of vulnerabilities. Decisions about shipping software remain yours.
6. Service availability
- DevRadar is operated on a best-effort basis. There is no service level agreement, no uptime commitment, and no guaranteed response time for support requests.
- The service is provided on an “as is” and “as available” basis.
- We may modify, suspend, or discontinue the service, or any part of it, at any time, with or without notice.
- There are no plans, no pricing, and no subscriptions — every feature is available to every account.
7. Liability
To the maximum extent permitted by law, Thingz LLC is not liable for indirect, incidental, or consequential damages arising from use of the service, including losses resulting from acting or failing to act on a reported finding.
8. Changes and contact
These terms may change; the date above records the last revision. The source for this service is on GitHub under the Apache License 2.0, and you are welcome to run your own instance. Questions belong in GitHub issues.