The EU Cyber Resilience Act’s 24-hour reporting duty starts 11 September 2026. What it actually requires

Terms of Service

The agreement between you and LockDep covering your use of the managed StackRadar dashboard.

Last updated 20 August 2026

1. This agreement

These terms are a contract between LockDep, Norway — “StackRadar”, “we”, “us” — and the person or organisation using the service — “you”.

You accept them by creating an account, accepting an invitation to an organisation, or using the service. If you are accepting on behalf of a company, you confirm you are authorised to bind it, and “you” means that company.

When you accept — at sign-up, when you accept an invitation, or when you confirm an updated version in the dashboard — we record which version of these terms you accepted and when. Where you act within an organisation, we also record that the version was accepted on the organisation’s behalf, by whom and in what role. Each version is identified by its effective date, shown at the top of this page.

Our privacy policy forms part of these terms.

2. What the service is — and what these terms cover

StackRadar has two halves, and they are governed separately.

  • The scanner is source-available. It runs in your own clusters under the licence in its repository. That licence, not this document, governs your use of it. Nothing here restricts rights you have under it.
  • The dashboard is a managed service. The hosted application at app.stackradar.io and the API at api.stackradar.io — where your SBOMs are stored, matched against vulnerability data and displayed — is what these terms govern.

3. Accounts

You sign in with GitHub or Google; we issue no passwords. You are responsible for everything done through your account and for the security of the provider account you sign in with. Tell us at security@stackradar.io if you believe it has been compromised.

You must be at least 16 years old and legally capable of entering this contract. One person, one account — do not share credentials.

4. Organisations, members and API keys

Data belongs to an organisation, not an individual. The organisation owner is responsible for who they invite and what those members do, and for removing members who should no longer have access. Roles (owner, admin, member) determine what each member can do; assigning them correctly is your job, not ours.

Each cluster authenticates with its own scoped API key. Treat those keys as secrets. You are responsible for data uploaded using your keys, including by anyone who obtains one. Revoke a compromised key from the dashboard immediately — you can do this yourself and it takes effect at once.

5. Acceptable use

You agree not to:

  • scan infrastructure you do not own or are not authorised to scan, or upload SBOMs describing it;
  • upload unlawful content, or content infringing someone else’s rights, in any field the service accepts;
  • attempt to access another organisation’s data, probe or circumvent our authentication, or test our security without written permission — coordinated disclosure to security@stackradar.io is always welcome;
  • work around plan limits, rate limits or quotas, including by splitting usage across accounts;
  • resell, sublicense or provide the dashboard as a service to third parties without a written agreement with us;
  • interfere with the service’s operation or place a load on it designed to degrade it for others.

None of this restricts anything you do with the scanner under its own licence.

6. Plans, limits and fair use

The service is offered on a free tier and paid plans. The current plans, prices and limits — clusters, monthly unique image scans, team members and history window — are on the pricing page, which forms part of these terms. They are not restated here so that there is only one place for them to be wrong.

Your plan’s history window governs how far back your history reaches — trend charts, scan records, and the SBOM archive of images you no longer run. History older than the window is deleted by a periodic sweep; the SBOM of an image that is still running is part of your current inventory and is never expired by the window. If you downgrade, the shorter window applies immediately and history older than it stops being shown, then is deleted on the next sweep.

If you exceed your plan’s limits we may throttle or reject further uploads and ask you to upgrade. We will not delete data for going over a limit without telling you first.

7. Billing

  • Payment. Paid plans are billed monthly in advance through Stripe. By subscribing you authorise recurring charges to your payment method until you cancel. Stripe’s terms govern the payment itself.
  • Taxes. Prices exclude VAT and any other applicable taxes, which are added where required.
  • Cancellation. Cancel at any time from the billing portal. Your plan stays active until the end of the period you have paid for, then reverts to Free.
  • Refunds. Part-months are not refunded. Where something went genuinely wrong on our side, write to us — we would rather resolve it than argue about it.
  • Failed payment. If a charge fails we may retry and, after notice, downgrade the organisation to Free. Your data is not deleted for non-payment.
  • Price changes. We will give at least 30 days’ notice before a price change affects you. If you do not accept it, cancel before it takes effect.

If you are a consumer rather than a business, your statutory rights — including any right of withdrawal — apply and are not limited by this section.

8. Your data

You own everything you upload. SBOMs, workload metadata and scan history remain yours. You grant us only the licence necessary to host, process, analyse and display that data in order to provide the service to you, and to make backups. That licence ends when the data is deleted.

We do not sell your data, we do not share SBOM content with third parties, and we do not use it to train models. We may use aggregate, de-identified operational statistics — counts, timings, error rates — to run and improve the service; nothing derived this way identifies you, your organisation or your software.

You can export your data or request its deletion at any time by writing to contact@stackradar.io. Where the data you upload contains personal data, we process it as your processor and the privacy policy sets out the terms; a separate DPA is available on request.

9. What vulnerability scanning can and cannot tell you

Read this section even if you skip the rest.

StackRadar reports findings by matching the components in your SBOMs against a continuously synced mirror of OSV.dev. That process is inherently incomplete:

  • A finding may be a false positive. A vulnerable version may be present but unreachable, already patched by a distribution backport, or mitigated in your configuration.
  • An absence of findings is not an absence of vulnerabilities. We can only report what has been published as an advisory, for components the scanner could identify. Unpublished, embargoed and unknown vulnerabilities do not appear, and neither do misconfigurations, secrets or vulnerabilities in your own code.
  • Upstream data can be wrong or late. Advisories are published, corrected and withdrawn by third parties on their own schedule.
  • Severity scores are indicative. CVSS reflects a generic context, not yours.

StackRadar is a tool that informs your security programme. It is not a security audit, not a compliance certification, and not professional advice. Decisions about what to patch and what risk to accept remain yours. Because the underlying data is public, every finding we show can be checked against its advisory independently of us — see how matching works.

10. Availability and changes to the service

We aim for high availability and will keep planned maintenance short and, where practical, announced. We do not offer a contractual uptime commitment on the Free, Pro or Business plans; SLAs are available on Enterprise agreements.

The service evolves. We may add, change or remove features. Where we remove something you depend on, or make a materially adverse change, we will give reasonable notice. Features described as planned are not promised — do not buy on the strength of a roadmap.

11. Suspension and termination

You may stop using the service and close your account at any time. We may suspend or terminate an account that breaches these terms, that we are legally required to suspend, or that presents a security risk to the service or its other users. Except where the breach is serious or urgent, we will give you notice and a chance to fix it first.

After termination we retain your data for 30 days so an account closed by mistake can be recovered, then delete it as described in the privacy policy. Ask us within that window and we will export it for you.

12. Our intellectual property

We own the dashboard, the API, the website and the StackRadar name and marks. These terms grant you a limited, non-exclusive, non-transferable right to use the service — nothing more. The scanner is excluded from this section; it is governed by its own source-available licence.

If you send us feedback, we may use it without obligation or compensation to you.

13. Disclaimer of warranties

To the fullest extent permitted by law, the service is provided “as is” and “as available”, without warranties of any kind, whether express or implied, including merchantability, fitness for a particular purpose and non-infringement. We do not warrant that the service will be uninterrupted or error-free, or that vulnerability findings will be complete or accurate — see section 9.

14. Limitation of liability

To the fullest extent permitted by law, neither party is liable for indirect, incidental, special or consequential damages, or for lost profits, lost revenue, lost data or business interruption, even if advised of the possibility.

Our total aggregate liability arising out of or relating to these terms or the service is limited to the greater of (a) the fees you paid us in the 12 months before the event giving rise to the claim, or (b) EUR 100.

Nothing in these terms excludes or limits liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for anything else that cannot lawfully be excluded. If you are a consumer, your statutory rights are unaffected.

15. Indemnity

You will indemnify us against third-party claims arising from your use of the service in breach of these terms, from data you upload, or from your scanning of infrastructure you were not authorised to scan.

16. Changes to these terms

We may update these terms. For material changes we will give at least 30 days’ notice in the dashboard or by a notice on this site before they take effect, the “last updated” date above will change, and the dashboard will ask you to review and accept the updated terms before you continue using it. For minor changes — clarifications and corrections that do not affect your rights or obligations — we update the page without asking for re-acceptance.

If you do not accept an updated version, stop using the service and cancel; continuing to use the service after the notice period means you accept the new terms.

17. General

  • Assignment. You may not assign these terms without our consent. We may assign them to a successor in connection with a merger, acquisition or sale of assets.
  • Severability. If a provision is held unenforceable, the rest stays in force.
  • No waiver. Not enforcing a provision is not a waiver of it.
  • Entire agreement. These terms, the privacy policy and the pricing page are the whole agreement between us on this subject, unless we have signed a separate written agreement with you, which prevails where it conflicts.

18. Governing law and disputes

These terms are governed by the laws of the laws of Norway, without regard to conflict-of-law rules. Disputes are subject to the exclusive jurisdiction of Oslo District Court (Oslo tingrett), Norway. If you are a consumer, you keep the protection of the mandatory laws of your country of residence and may bring proceedings there.

19. Contact

LockDep, Norway. General and contractual enquiries: contact@stackradar.io. Security reports: security@stackradar.io.