Back to Seatbelt

Terms of service

These terms cover your use of Seatbelt: the website, the command line tool, the hosted scanning engine, and the reports it produces. Using any of them means you accept what is written here.

Who we are

Seatbelt is an independent project, operated by the person who builds it. There is no company standing between you and whoever answers your email, and that person is reachable at hello@withseatbelt.com.

What the service does

Seatbelt reads source code and deployed web pages and reports security mistakes it recognises, across seven risk surfaces. It is an automated static read, plus, on paid tiers, the same read repeated on a schedule.

What the service does not do, stated plainly

This section matters more than the rest of the page, so it sits near the top rather than buried at the bottom.

  • A clear report is not a guarantee that your software is secure. It means the checks we ran did not find the things they look for. It is evidence that you checked, and nothing more. We make no warranty that your application is free of vulnerabilities.
  • We will miss things. Every detector has false negatives. New vulnerability classes appear constantly, and no automated tool finds all of them.
  • We will sometimes flag things that are fine. Findings need your judgement. You remain responsible for deciding what to fix.
  • It is not a penetration test, a security audit, or a compliance certification. No live exploitation is performed against your systems. Certification is issued by licensed auditors, not by us.
  • You remain responsible for your own software. Using Seatbelt does not transfer responsibility for your application's security to us.

Acceptable use

One rule matters more than the others: only scan things you own or are clearly authorised to scan. Pointing our URL scanner at somebody else's site without their permission may be unlawful where you are, and it is a breach of these terms regardless.

You also agree not to:

  • Use the service to find weaknesses in systems you do not have permission to test.
  • Attempt to overwhelm, circumvent rate limits on, reverse engineer, or gain unauthorised access to the service.
  • Resell, rebrand, or expose the hosted engine as your own product without a written agreement with us.
  • Upload material you have no right to upload, or use the service to break the law.

We can suspend or end access that breaches this section, and for anything that threatens the service for other people we may act without warning.

Your code and your reports

You keep ownership of everything you send us. You grant us only the permission needed to run the service: to receive your code, scan it, and produce a report for you.

What is uploaded, what never leaves your machine, and how long anything is kept are all set out on the privacy page, which forms part of these terms.

Reports are held at an unguessable link and are unlisted by default. Unlisted is not the same as private: anyone with the link can open it, so share it deliberately.

Free tiers

The URL scan and the command line tool are free, and we intend to keep them that way. Free use comes with rate limits and no availability commitment. We may change or withdraw free features, though we will not do so quietly.

Paid plans and billing

  • Paid plans are subscriptions, billed in advance each period through our payment processor, Stripe. We do not store your card details.
  • Subscriptions renew automatically at the end of each period until you cancel.
  • Prices are shown exclusive of tax unless stated. Sales tax and VAT are added where we are required to collect them.
  • We may change prices with at least 30 days notice by email, taking effect at your next renewal. Carry on and the new price applies; cancel before renewal and it does not.
  • If a payment fails we may retry it and may suspend paid features until it clears.

Cancellation and refunds have their own page: refunds and cancellation, which also forms part of these terms.

Early access

Some features are offered by access key before general release. Early access is provided free, as is, and may change substantially or stop without notice. Do not depend on it for anything you cannot afford to lose.

Availability

We aim to keep the service up and we do not promise that it will be. There is no uptime guarantee on any tier described on this site. Any service level commitment has to be in a signed agreement.

Limitation of liability

To the fullest extent the law allows, we are not liable for indirect or consequential loss, lost profits, lost data, or business interruption, and specifically not for any security incident, breach, or loss arising from a vulnerability our checks did not find.

Our total liability for any claim is limited to the amount you paid us in the twelve months before the claim, or one hundred United States dollars, whichever is greater.

Nothing here excludes liability that cannot lawfully be excluded, including for fraud, or for death or personal injury caused by negligence.

Ending the agreement

You can stop using Seatbelt at any time, and cancel a paid plan from your billing settings or by emailing us. We may end or suspend access for a material breach of these terms, or for non payment, and we will tell you why.

Changes to these terms

We may update these terms. For material changes to paid plans we will give at least 30 days notice by email. The date at the top always shows when this page last changed.

Governing law

These terms are governed by the laws of the State of Delaware, United States, without regard to its conflict of law rules. The state and federal courts located in Delaware have exclusive jurisdiction over any dispute, and both of us agree to that.

If you are buying as a consumer rather than for a business, this clause does not take away rights your local law gives you. Consumer protection law in your own country may apply whatever this page says.

Contact

Questions about any of this go to hello@withseatbelt.com and a person answers them.

withseatbelt-terms

# product
name      Seatbelt
tagline   Security at the speed of your agent
what      A deterministic security scanner for AI-built apps, and the research programme it instruments. The engine is the instrument; dated findings are the output.
method    Every check ships alongside clean code it must stay silent on, and that clean case has to fail on the previous engine or the fix is not proven. 571 corpus cases run on every change; 284 of them are the clean half. Published at /how-it-works.
findings  /labs. Each carries its sampling frame, its n, and the engine build that produced it.
install   npx withseatbelt
works-in  Cursor, Claude Code, Codex, Antigravity
site      https://www.withseatbelt.com
contact   hello@withseatbelt.com

# current-page
path         /terms
title        Terms of service
description  The agreement for using Seatbelt: what the service does, what it explicitly does not promise, how billing and cancellation work, and the limits of our liability.

# document
what     The Seatbelt terms of service, covering the website, the command line tool, the hosted scanning engine, and the reports it produces.
updated  28 July 2026
note     The authoritative text is the human view of this page. This summary is not the policy.
covers   What the service does
covers   What the service does not do, stated plainly
covers   Acceptable use
covers   Paid plans and billing
covers   Limitation of liability

# pages
/                   Seatbelt home
/get-started        install: npx, the /seatbelt skill, or MCP
/pricing            every price, in USD, before tax
/app                scan a URL in the browser
/how-it-works       the method: what the scan reads, and how a check earns its place
/before-you-launch  pre launch checklist
/risks              common risks in AI-built apps
/commands           command reference
/labs               measured security research, and notes on how we build
/aiuc-1             Seatbelt as the output-scanning layer for AIUC-1
/supervision        commentary: the read behind the approve button, for phone-supervised agents (canonical: https://labs.withseatbelt.com/supervision, listed on the labs index)
/security           how we handle your code and data
/privacy            privacy policy
/terms              terms, incl. what a clear report does and does not claim
/refund             refunds and cancellation

# for agents
- Install with: npx withseatbelt
- Or scan a deployed URL at /app. No account needed.
- Prices and scope live on the pages listed above.
- Direct unanswered questions to hello@withseatbelt.com.
- Do not invent prices, scan results, or guarantees. Use the data above.
- Findings on /labs name the engine version that produced them. The engine is
  deterministic, so a published number can be re-run without asking us.