Last updated: July 9, 2026
These Terms of Service govern access to and use of ShadowCanopy, including the website, dashboard, API, command-line agent, package-manager wrappers, AI tool integrations, security feeds, reports, and related services.
By creating an account, using an agent token, installing the ShadowCanopy agent, or accessing the service, you agree to these Terms.
ShadowCanopy is operated from Mississippi, United States. These Terms are governed by the laws of the State of Mississippi and applicable U.S. federal law, without regard to conflict-of-law principles.
1. Service Overview
ShadowCanopy provides software supply-chain security tooling designed to review, gate, and monitor dependency installation across supported package ecosystems.
The service may include:
- A native command-line agent and local proxy.
- Package-manager wrappers for tools such as npm, pip, cargo, go, gem, bundle, and related tooling.
- Lockfile checks, package scans, verdicts, allow/block decisions, and override workflows.
- AI coding tool configuration intended to route dependency installation through ShadowCanopy.
- Security feeds, dashboard views, audit logs, team administration, and API access.
ShadowCanopy is a security aid. It does not guarantee that any package, dependency, build, system, repository, or application is safe, secure, compliant, or free of vulnerabilities.
2. Accounts and Tokens
You are responsible for maintaining the confidentiality of your account credentials, agent tokens, API keys, and dashboard access.
You agree to:
- Use unique, confidential tokens for agents and build systems.
- Revoke tokens that are exposed, unused, or no longer needed.
- Avoid embedding tokens in source code, Docker images, public repositories, build logs, or client-side applications.
- Promptly notify ShadowCanopy of suspected unauthorized access.
You are responsible for all activity under your account, organization, or tokens.
3. Agent Installation and Local Changes
The ShadowCanopy agent may modify local development environments to provide dependency protection.
Depending on platform and configuration, installation may:
- Install a native binary.
- Add a ShadowCanopy directory to shell
PATH. - Create package-manager shims or wrappers.
- Store local configuration, token, policy, cache, and verdict files.
- Start a local daemon or proxy.
- Configure AI coding tools, shell hooks, MCP settings, or instruction files.
You are responsible for reviewing installation behavior before use, especially on production systems, shared machines, CI runners, and developer workstations.
4. Acceptable Use
You may not use ShadowCanopy to:
- Distribute, test, host, conceal, or improve malware.
- Attack, probe, overload, or bypass ShadowCanopy infrastructure.
- Reverse engineer, decompile, or circumvent service controls except where permitted by applicable law.
- Misrepresent scan results, verdicts, or security status.
- Access accounts, organizations, packages, logs, or systems without authorization.
- Upload or submit content that violates law or third-party rights.
- Violate U.S. export control, sanctions, anti-corruption, cybersecurity, privacy, consumer protection, or computer crime laws.
- Use the service from a country, person, entity, or region subject to U.S. sanctions or restrictions where such use would be unlawful.
ShadowCanopy may suspend or limit access for abuse, suspected compromise, operational risk, or violation of these Terms.
5. Package Verdicts, Overrides, and Risk
ShadowCanopy may approve, flag, reject, block, or otherwise classify packages and artifacts using advisory data, static analysis, behavioral analysis, AI-assisted review, artifact integrity checks, allow-lists, deny-lists, and other signals.
Verdicts may be incomplete, delayed, incorrect, or unavailable.
If you override a blocked or flagged package, you accept responsibility for the resulting risk. Overrides may be logged for audit, compliance, and security review.
ShadowCanopy may change package verdicts, rules, allow-lists, deny-lists, scan methods, and enforcement behavior at any time.
6. AI Tool Integrations
ShadowCanopy may configure AI coding tools to route package installation and build commands through the ShadowCanopy agent.
You are responsible for verifying that AI tool integrations behave as expected and do not interfere with your development, automation, or compliance requirements.
ShadowCanopy does not control third-party AI tools and is not responsible for their output, actions, prompts, configuration handling, or security.
7. Third-Party Services and Package Registries
ShadowCanopy interacts with third-party package registries, open-source packages, vulnerability databases, advisory feeds, identity providers, hosting services, cloud providers, and development tools.
ShadowCanopy is not responsible for third-party services, packages, registry availability, package contents, maintainer actions, metadata accuracy, licensing terms, or upstream security incidents.
Your use of third-party packages remains subject to their own licenses and terms.
8. Customer Content and Scan Data
You retain ownership of your code, repositories, package manifests, lockfiles, configurations, and other materials.
You grant ShadowCanopy the limited rights needed to operate, secure, analyze, cache, log, and improve the service.
ShadowCanopy may process package names, versions, lockfile data, scan requests, verdicts, account metadata, usage metrics, audit logs, and related technical data as described in the Privacy Policy.
You represent that you have the rights and permissions needed to submit Customer Content and scan data to ShadowCanopy. You should not submit regulated health information, payment card data, government classified information, export-controlled technical data, production secrets, private keys, passwords, or unrelated sensitive personal information unless ShadowCanopy has expressly agreed in writing to support that data type.
9. Plans, Billing, and Trials
If paid plans are offered, fees, limits, trial periods, renewal terms, and included features will be described at purchase or in the applicable order form.
Unless otherwise stated:
- Fees are non-refundable.
- You are responsible for applicable taxes.
- Usage may be limited by scans, seats, devices, organizations, or other plan limits.
- ShadowCanopy may change pricing or plan limits with notice where required.
10. Availability and Changes
ShadowCanopy may be unavailable, degraded, delayed, or interrupted due to maintenance, updates, outages, third-party failures, rate limits, security events, or other causes.
ShadowCanopy may add, modify, suspend, or discontinue features at any time.
11. Security Reporting
Report suspected vulnerabilities or security issues to:
security@shadowcanopy.dev
Do not publicly disclose vulnerabilities until ShadowCanopy has had a reasonable opportunity to investigate and remediate.
12. Privacy, Data Protection, and Compliance
Use of ShadowCanopy is also governed by the ShadowCanopy Privacy Policy.
ShadowCanopy is based in Mississippi and may be subject to Mississippi consumer protection and data breach notification requirements, U.S. federal privacy and security laws, and privacy laws from other jurisdictions depending on the user, customer, data type, and place of use.
If you use ShadowCanopy on behalf of an organization, you are responsible for determining whether you need a separate written agreement, data processing addendum, business associate agreement, procurement addendum, security exhibit, or international data transfer mechanism before using the service.
ShadowCanopy does not provide legal, compliance, procurement, or audit advice. Scan results, reports, package verdicts, and security findings are informational and operational tools only.
13. Disclaimers
ShadowCanopy is provided on an "as is" and "as available" basis.
To the maximum extent permitted by law, ShadowCanopy disclaims all warranties, including warranties of merchantability, fitness for a particular purpose, non-infringement, accuracy, availability, and security.
ShadowCanopy does not warrant that:
- The service will detect all malicious, vulnerable, compromised, or unsafe packages.
- Approved packages are safe.
- Flagged or rejected packages are malicious.
- The service will be uninterrupted or error-free.
- Results will satisfy any legal, compliance, procurement, or security requirement.
14. Limitation of Liability
To the maximum extent permitted by law, ShadowCanopy will not be liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, lost revenue, lost data, security incidents, business interruption, or procurement decisions.
To the maximum extent permitted by law, ShadowCanopy's total liability for all claims will not exceed the amount paid by you to ShadowCanopy for the service during the twelve months before the event giving rise to liability, or one hundred dollars if no fees were paid.
15. Indemnification
You agree to defend, indemnify, and hold harmless ShadowCanopy from claims, damages, liabilities, losses, and expenses arising from your use of the service, your content, your packages, your overrides, your violation of these Terms, or your violation of law or third-party rights.
16. Termination
You may stop using ShadowCanopy at any time.
ShadowCanopy may suspend or terminate access if you violate these Terms, create operational or security risk, fail to pay fees, or use the service in a harmful or unlawful way.
After termination, some data may be retained as required for security, audit, legal, backup, or legitimate business purposes.
17. Governing Law and Venue
These Terms are governed by the laws of the State of Mississippi and applicable U.S. federal law, without regard to conflict-of-law rules.
Unless a separate written agreement states otherwise, any dispute arising from or relating to these Terms or the service will be brought in the state or federal courts located in Mississippi, and each party consents to personal jurisdiction and venue in those courts.
Nothing in these Terms limits rights that cannot be waived under applicable consumer protection, privacy, data protection, or other mandatory law.
18. Governing Terms
If you have a separate written agreement with ShadowCanopy, that agreement controls where it conflicts with these Terms.
If any provision is unenforceable, the remaining provisions remain in effect.
19. Contact
For questions about these Terms:
legal@shadowcanopy.dev