Skip to content

Latest commit

 

History

History
145 lines (78 loc) · 10.2 KB

File metadata and controls

145 lines (78 loc) · 10.2 KB

FLUID ATTACKS

END USER LICENSE AGREEMENT (EULA)

CI Gate

Effective Date: 2026-04-07


IMPORTANT — READ CAREFULLY: This End User License Agreement ("Agreement") is a legal agreement between you (either an individual or a legal entity, hereinafter "You" or "User") and Fluid Attacks ("Fluid Attacks", "we", "us", or "our") for the use of the CI Gate product (the "Software"), available through GitHub Marketplace as a GitHub Action. By installing, copying, or otherwise using the Software, You agree to be bound by the terms of this Agreement. If You do not agree to the terms of this Agreement, do not install or use the Software.


1. DEFINITIONS

"Software" means the CI Gate tool developed by Fluid Attacks, distributed as a GitHub Action through GitHub Marketplace, including all updates, patches, documentation, and related materials.

"CI Gate Results" means any output generated by the Software, including but not limited to vulnerability reports, security findings, severity classifications, compliance status, and any associated metadata retrieved from the Fluid Attacks Platform.

"Fluid Attacks Platform" means Fluid Attacks' external servers and infrastructure to which the Software connects in order to authenticate, retrieve vulnerability data, and transmit execution metadata.

"Repository" means the GitHub repository where the Software is executed as part of a CI/CD pipeline.


2. LICENSE GRANT

Subject to the terms and conditions of this Agreement, Fluid Attacks grants You a non-exclusive, non-transferable, revocable, royalty-free license to install and use the Software solely as a GitHub Action within Your GitHub repositories for the purpose of querying the Fluid Attacks Platform for reported vulnerabilities and enforcing CI/CD security gates.

This license does not grant You any right to: (a) modify, adapt, reverse engineer, decompile, or disassemble the Software; (b) sublicense, sell, lease, rent, or distribute the Software to third parties; (c) remove or alter any proprietary notices, labels, or marks on the Software; or (d) use the Software for any unlawful purpose or in violation of any applicable laws or regulations.


3. DATA COLLECTION AND TRANSMISSION

3.1 Data Transmitted

You acknowledge and agree that the Software transmits the following data to the Fluid Attacks Platform:

  • Authentication credentials, specifically the CI Gate token provided by You, used solely to authenticate requests to the Fluid Attacks Platform.
  • Execution metadata, including the repository nickname and execution parameters passed to the Software, used to scope the vulnerability query to the relevant repository.

3.2 Data Retrieved

The Software retrieves the following data from the Fluid Attacks Platform:

  • Vulnerability findings, severity classifications, compliance status, and associated metadata previously reported by Fluid Attacks for Your repository.

3.3 Data NOT Collected

The Software does NOT transmit any of the following to the Fluid Attacks Platform:

  • Your source code or repository contents.
  • Branch names, commit hashes, or workflow execution identifiers.

3.4 Purpose of Data Collection

The data transmitted is used solely for the purpose of authenticating Your request and retrieving the vulnerability information associated with Your repository on the Fluid Attacks Platform.

3.5 Data Security

Fluid Attacks employs industry-standard security measures to protect transmitted data, including encryption in transit and at rest. However, no method of electronic transmission or storage is completely secure, and Fluid Attacks cannot guarantee absolute security of Your data.

3.6 Data Retention and Deletion

You may request deletion of Your data from the Fluid Attacks Platform at any time by contacting us at help@fluidattacks.com. Fluid Attacks will process deletion requests within thirty (30) days.


4. DISCLAIMER OF WARRANTIES

THE SOFTWARE IS PROVIDED "AS IS" AND "AS AVAILABLE", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, ACCURACY, COMPLETENESS, OR RELIABILITY OF RESULTS.

FLUID ATTACKS DOES NOT WARRANT THAT: (A) THE CI GATE RESULTS RETRIEVED FROM THE FLUID ATTACKS PLATFORM WILL BE ACCURATE, COMPLETE, OR CURRENT AT THE TIME OF RETRIEVAL; (B) THE SOFTWARE WILL OPERATE WITHOUT INTERRUPTION OR ERROR; OR (C) THE SOFTWARE WILL BE COMPATIBLE WITH ALL CI/CD ENVIRONMENTS, GITHUB ACTIONS RUNNER CONFIGURATIONS, OR NETWORK CONDITIONS.


5. LIMITATION OF LIABILITY FOR PLATFORM DATA

THIS SECTION IS OF CRITICAL IMPORTANCE AND CONSTITUTES A MATERIAL TERM OF THIS AGREEMENT.

5.1 You expressly acknowledge and agree that the Software acts solely as a gate that queries and surfaces vulnerability data already reported on the Fluid Attacks Platform. The Software does not perform independent vulnerability detection. The completeness and accuracy of the CI Gate Results depend entirely on the findings previously reported by Fluid Attacks through its security assessment services, which are governed by separate agreements between You and Fluid Attacks.

5.2 FLUID ATTACKS SHALL BEAR NO RESPONSIBILITY OR LIABILITY WHATSOEVER FOR ANY VULNERABILITY NOT REFLECTED IN THE CI GATE RESULTS AT THE TIME OF EXECUTION. YOU AGREE THAT FLUID ATTACKS, ITS OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, AFFILIATES, SUCCESSORS, AND ASSIGNS SHALL NOT BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES ARISING FROM OR RELATED TO ANY VULNERABILITY NOT PRESENT IN THE PLATFORM DATA AT THE TIME OF RETRIEVAL, INCLUDING BUT NOT LIMITED TO:

  • Data breaches, unauthorized access, or data loss resulting from vulnerabilities not yet reported on the Platform;
  • Financial losses, including but not limited to regulatory fines, penalties, litigation costs, remediation costs, or loss of revenue;
  • Reputational harm or loss of business opportunities;
  • Service disruptions, system downtime, or operational interruptions;
  • Any harm to third parties, including Your end users or customers, resulting from exploited vulnerabilities not reflected in the CI Gate Results.

5.3 You acknowledge that the Software is intended to be used as one component of a comprehensive security program and NOT as a sole or definitive measure of the security posture of Your repository. You are solely responsible for implementing additional security measures appropriate for Your use case.

5.4 You assume all risk associated with reliance on the CI Gate Results and acknowledge that Fluid Attacks has made no representations or guarantees regarding the completeness or currency of the vulnerability data available on the Platform at any given time.


6. GENERAL LIMITATION OF LIABILITY

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, FLUID ATTACKS SHALL HAVE NO LIABILITY WHATSOEVER TO YOU FOR ANY CLAIMS ARISING OUT OF OR RELATED TO THIS AGREEMENT OR THE USE OF THE SOFTWARE, REGARDLESS OF THE FORM OF ACTION OR THEORY OF LIABILITY (WHETHER IN CONTRACT, TORT, NEGLIGENCE, STRICT LIABILITY, OR OTHERWISE). IN NO EVENT SHALL FLUID ATTACKS' TOTAL AGGREGATE LIABILITY EXCEED ZERO DOLLARS (USD $0.00).

THIS EXCLUSION OF LIABILITY APPLIES EVEN IF FLUID ATTACKS HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES AND REGARDLESS OF WHETHER ANY LIMITED REMEDY FAILS OF ITS ESSENTIAL PURPOSE. YOU ACKNOWLEDGE THAT THIS LIMITATION OF LIABILITY IS A FUNDAMENTAL ELEMENT OF THE BASIS OF THE BARGAIN BETWEEN FLUID ATTACKS AND YOU, AND THAT THE SOFTWARE WOULD NOT BE PROVIDED WITHOUT SUCH LIMITATION.


7. INDEMNIFICATION

You agree to indemnify, defend, and hold harmless Fluid Attacks, its officers, directors, employees, agents, and affiliates from and against any and all claims, demands, actions, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising from or related to: (a) Your use of the Software; (b) Your reliance on CI Gate Results; (c) any breach of this Agreement by You; (d) any claim by a third party related to Your repository or the security thereof; or (e) any violation of applicable laws or regulations in connection with Your use of the Software.


8. INTELLECTUAL PROPERTY

The Software, including all intellectual property rights therein, is and shall remain the exclusive property of Fluid Attacks. This Agreement does not convey to You any rights of ownership in or related to the Software. All rights not expressly granted herein are reserved by Fluid Attacks.

Your repository contents and any proprietary data remain Your exclusive property. Nothing in this Agreement grants Fluid Attacks any ownership rights over Your repository contents.


9. TERM AND TERMINATION

This Agreement is effective upon Your installation or use of the Software and shall remain in effect until terminated. Fluid Attacks may terminate this Agreement at any time, with or without cause, by providing notice through GitHub Marketplace or other reasonable means. You may terminate this Agreement at any time by uninstalling the Software and ceasing all use.

Upon termination: (a) all licenses granted herein shall immediately terminate; (b) You must cease all use of the Software; and (c) Sections 4, 5, 6, 7, 8, and 11 shall survive termination.


10. MODIFICATIONS

Fluid Attacks reserves the right to modify this Agreement at any time. Modifications will be communicated through GitHub Marketplace or by updating the Agreement on our website. Your continued use of the Software after any such modification constitutes Your acceptance of the modified terms. If You do not agree with the modifications, You must cease using the Software.


11. GOVERNING LAW AND DISPUTE RESOLUTION

This Agreement shall be governed by and construed in accordance with the laws of the Republic of Colombia, without regard to its conflict of law provisions. Any dispute arising out of or in connection with this Agreement shall be submitted to the exclusive jurisdiction of the competent courts located in the city of Bogotá D.C., Colombia.


12. CONTACT INFORMATION

For questions, concerns, or data deletion requests regarding this Agreement or the Software, please contact:

Fluid Attacks Email: help@fluidattacks.com Website: https://fluidattacks.com