Terms of Service
The structure is here. The legal wording is not.
Each clause states what is true about Credda today, read out of the product rather than drafted, then names the operative wording a reviewed document has to supply. Nothing on this page is in force.
01The draft
9 clauses, each set out in two halves.
1. Who this is between
Today
Credda is pre-release and is not yet sold. There is no self-serve sign-up, no paid plan in force and no customer under contract. Anyone running Credda today is doing so by direct arrangement.
Pending review
The legal entity, its jurisdiction of incorporation, its registered address, and the definition of who counts as the customer when an individual installs on an organisation’s repository.
2. What the service does
Today
Credda reproduces a reported failure in a sandbox, captures the failure signature as evidence, diagnoses a cause where the evidence supports one, and, where the provider that ran is model-backed, authors and independently verifies a patch inside that sandbox. It reports all of it. Whether that becomes a change proposal depends on which mechanism ran, and the two answer differently. The GitHub Action opens a pull request when a workflow turns on its open-pull-request input and the run reaches a verified verdict; a default install leaves that input off, so it hands the verified patch back inside its report and opens nothing. The engine’s own hosted path opens one with no flag, for a run that reached a proven verdict. Neither holds a merge function at any time. The permissions and the execution boundary are on the security page.
Pending review
Service description, availability commitments (there are none today and the document should say so rather than imply an uptime), and the notice period for changing what the service does.
3. Your repository, and what happens to it
Today
Credda clones a copy of the repository and runs the repository’s own build and test commands against that copy. Any patch it writes is written in that copy. It never modifies the original, and it never merges anything: a change reaches your repository only as a pull request you review and merge yourself. On the plane the GitHub Action uses, those commands execute in a container with no network interface and no host path mounted into it.
Pending review
The licence you grant for Credda to process your code, how long any artifact is retained, where it is stored, and what happens to it when an account ends.
4. Acceptable use
Today
Credda executes code it did not write on request. The controls that bound that are described on the security page, including the ones that are not complete. Pointing it at a repository whose code is intended to attack the sandbox is the case those controls exist for, and it is also the case that has never been tested.
Pending review
Prohibited uses, the right to suspend a run or an account, rate and volume limits, and the position on running Credda against repositories the operator does not control.
5. What is not promised
Today
Credda makes no claim to find every defect and reports what it could not establish alongside what it could. Its published benchmark records the runs where reproduction failed and where a claimed success stood over a captured failure. Nothing about the product should be read as a warranty that a report is correct.
Pending review
Warranty disclaimers, limitation of liability, the cap, and the exclusions from that cap, in enforceable wording for each jurisdiction the product is offered in.
6. Fees
Today
Public repositories are free at any size, read no licence key and need no plan. The pricing page prices the rest, and no amount on it is set in this site’s own code: the plans, the amounts, what each one grants and whether checkout is open at all are read from Credda billing when the page is opened, and a plan that billing reports as purchasable without pricing it is named rather than guessed at. Nothing has yet been sold under these terms, because these terms have never been in force.
Pending review
Fees, billing period, taxes, renewal, refunds, and what happens to work in flight when a plan changes.
7. Ending it
Today
A run is stopped by removing the Action from the workflow. Where an account exists, closing it is a separate step and is handled by asking us; the Action stops running the moment it leaves the workflow, with or without an account.
Pending review
Termination for convenience, termination for cause, notice periods, and survival.
8. Changes to these terms
Today
This page is a draft and will be replaced in full by a reviewed document. That replacement is not a change of terms, because these have never been in force.
Pending review
How changes are notified, when they take effect, and whether continued use is acceptance.
9. Governing law and disputes
Today
Not determined.
Pending review
Governing law, venue, and the dispute process, all of which follow from the entity in clause 1.
If a security review or procurement process needs a pending item answered before the document exists, ask. Write to legal@credda.io and the answer will say which parts are decided and which are not. See also the privacy draft and the security page, which is not a draft.