Legal
Acceptable Use Policy
Draft — pending legal review. These terms are published early so you can read what we intend to agree to before you install anything. They have not been reviewed by outside counsel and are not yet in force. Nothing here creates a contract until it is executed or you accept it at sign-up, and we will not apply a materially worse version to an existing customer without 30 days notice.
The rule behind the rules
The service reads private code and executes analysers over code written by strangers. Every rule below exists because breaking it either endangers another customer, endangers the people whose code we hold, or turns a shared resource into somebody’s private compute budget.
Do not attack anyone
- No attempt to escape the sandbox, reach our control plane, or access another organisation’s data — except under the vulnerability disclosure policy, which explicitly invites the attempt against repositories you own.
- No probing, scanning or load-testing our infrastructure without written permission.
- No using the service to attack a third party, including through the analysers.
- No attempting to obtain credentials belonging to us, a customer, or a subprocessor.
Do not abuse the compute
- No using the sandbox for anything other than reviewing your pull requests. Mining, general computation, running a build farm, and hosting a service inside a review instance are all out.
- No circumventing limits: multiple accounts to escape a quota, synthetic pull requests to farm reviews, or automation designed to keep a free plan permanently at its ceiling.
- No routing another product’s traffic through us, and no using the service as a proxy for model access.
Do not misuse the reviewer
- No deliberately crafting repository content to make the reviewer act on it as an instruction, outside a disclosure report.
- No using review comments as a delivery channel for content aimed at other people — phishing, malware links, or harassment.
- No presenting our output as a human review, a security audit, or a compliance attestation. It is none of those things.
Do not process what you may not process
- Do not connect repositories you are not authorised to connect, or code you do not have the rights to have processed.
- Do not place special category personal data, payment card data or health records in connected repositories. Nothing in the product is designed for them.
- Do not use the service where sanctions or export control law prohibits it.
Do not resell the output as a product
- No reselling, sublicensing or white-labelling reviews as your own service without a written agreement.
- No systematic extraction of our prompts, model behaviour or outputs to build a competing product.
- Benchmarking is the exception, and it is encouraged: run our public harness against us and publish what you find, including when it is unflattering. Comparative research is not competitive extraction.
How we enforce this
- Our first step is almost always an email. Most violations are a misconfigured automation, not intent.
- We suspend without notice only where there is an active risk to other customers, to the people whose code we hold, or to the service.
- Suspension pauses reviews; it does not delete your data. Termination follows the process in the Terms of Service.
- We will tell you what rule we think you broke, and you can reply. A suspension you cannot get an explanation for is a bug in our process.
Reporting abuse
Abuse of the service, or content posted by it: support@superdiffs.com. Security vulnerabilities go to security@superdiffs.com under the disclosure policy.
Related: Terms of Service · Privacy Policy · DPA.