Back to home
Limits & Warranties

Disclaimer

LAST UPDATED: AUGUST 13, 2026

1. Purpose of This Page

ShipReady is built to be trustworthy, which means being explicit about what it cannot tell you. This Disclaimer sets out the limits of the Service and is incorporated by reference into our Terms of Service. It supplements, and does not replace, the disclaimer of warranties and limitation of liability in Sections 12 and 13 of those Terms.

2. Informational Service Only

A clean report is not a guarantee

ShipReady tells you what its checks observed. It does not, and cannot, tell you that an application is secure. A high Launch Readiness score means the checks we ran found no evidence of the problems they look for — not that no problems exist.

Scan results, findings, severity ratings, readiness scores, and remediation guidance are provided for informational purposes only. They are not a security certification, a compliance attestation, a penetration test, an audit, or professional legal, regulatory, or security advice. Do not represent ShipReady output to a customer, investor, auditor, or regulator as any of those things.

3. How Detection Works — And Where It Stops

Detection in ShipReady is deterministic: findings come from explicit rules run against observable evidence, not from a model’s judgment. We deliberately prefer false negatives over false positives — we would rather miss something than report a vulnerability we cannot evidence. That design choice has a direct consequence:

What a finding means

A rule observed specific evidence — a header, a response body, a configuration value — matching a known problem pattern. The evidence is shown so you can verify it yourself.

What no finding means

The checks we ran did not observe that evidence, on the surfaces they reached, at the time they ran. It is not proof of absence.

Scans are subject to real limits, including:

  • Coverage. Checks run mainly against externally observable surfaces and any repository or project you explicitly connect. Code paths, background jobs, internal services, and authenticated flows we cannot reach are not evaluated.
  • Point in time. A scan describes the target as it was when the scan ran. A deploy, a configuration change, a dependency update, or a newly disclosed vulnerability can invalidate a result minutes later.
  • Passive by design. We do not exploit vulnerabilities to confirm them. Some classes of issue can only be confirmed by active exploitation, which we do not perform.
  • Third-party data. Some checks rely on external data sources whose accuracy, availability, and timeliness we do not control.
  • Interference. WAFs, rate limiting, bot protection, CDNs, geo-routing, and blocked requests can prevent a check from observing what is actually there, producing an incomplete result.
  • Rule error. Rules are written by humans and can be wrong, out of date, or miscalibrated for your stack.

4. AI-Generated Content

AI is used in ShipReady to explain findings, improve readability, and generate remediation guidance and fix prompts. AI never decides whether something is vulnerable.

AI-generated explanations and fix prompts may nevertheless be inaccurate, incomplete, out of date, or wrong for your specific framework, version, or architecture. Applying them without review can introduce new vulnerabilities, break functionality, cause outages, or lose data. Before applying any generated fix you must:

  • read and understand what the change does;
  • have it reviewed by someone qualified to assess it;
  • keep a restorable backup;
  • test outside production;
  • apply your own change control and rollback procedure.

Every decision to act, or not act, on Service output is yours alone.

5. No Professional Relationship

Using ShipReady does not create a professional, advisory, fiduciary, or consultant-client relationship between you and us. We do not monitor your systems, have no duty to discover every issue, no duty to warn you of threats discovered after a scan, and no obligation to update a past report.

6. Compliance Frameworks

Where the Service references a framework such as OWASP, GDPR, SOC 2, PCI DSS, or similar, those references are heuristic mappings intended to help you orient. They are not an assessment of compliance, and passing a mapped check does not make you compliant. Compliance requires organizational controls, documentation, and assessment that automated scanning cannot perform.

7. Third-Party Content & Links

The Service incorporates data from third-party sources and may link to third-party websites, documentation, and tools. We do not control, endorse, or warrant any of it. Any third-party service you use is governed by that party’s own terms and is at your own risk. Our current providers are listed on our Subprocessors page.

8. No Warranty; Assumption of Risk

The Service is provided “AS IS” and “AS AVAILABLE,” without warranties of any kind, express, implied, or statutory. To the maximum extent permitted by law we disclaim all implied warranties of merchantability, fitness for a particular purpose, non-infringement, accuracy, and completeness, and any warranty that the Service will be uninterrupted, error-free, or will detect any particular issue.

The Service is not designed or authorized for use in any application requiring fail-safe performance — including life support, medical devices, nuclear facilities, aircraft navigation, air traffic control, or weapons systems — where failure could lead to death, injury, or severe property or environmental damage. You assume all risk if you use it in such an application.

Your use of the Service, and any action taken on the basis of its output, is at your sole risk. Our liability is limited as set out in Section 13 of the Terms of Service. Nothing here excludes liability that cannot lawfully be excluded.

9. Changes

We may update this Disclaimer as the Service evolves. The current version is always at /disclaimerwith a “Last updated” date.

10. Contact

Questions about the scope or limits of the Service? Contact us at:

hello@useshipready.dev