Terms of Service
Last updated: September 29, 2026
These terms describe what you're agreeing to when you use CamelHive: what the service is, what an audit or a badge does and doesn't claim, what happens to your code, and how payment works. Where something isn't built yet, we say so instead of promising a process that doesn't exist.
Acceptance of these terms
By creating an account, connecting a repository, or using any part of CamelHive, you agree to these terms. If you're agreeing on behalf of a company, you're confirming you have the authority to do that.
What CamelHive is
CamelHive audits a codebase against a published catalog of rules and produces findings, a score, and a coverage figure -- the score is never shown without stating how much of the catalog it's actually based on. Some rules are checked by deterministic tools; others are evaluated by an AI reviewer. A second, adversarial step reviews that reviewer's conclusions, including every critical and high failure; medium and low failures that skip that review are marked as such.
Every rule closes as pass, fail, not applicable, undetermined, or excluded by your own declaration. An undetermined result is never presented as a pass -- if we couldn't determine something, the report says so and why.
What an audit or badge does and doesn't claim
An audit is a snapshot: it evaluates the exact commit it ran against, not your repository as it exists at any later time. A badge or attestation reflects that commit's result at the time it was issued, and its level also depends on the project's previous attestation. A small number of rules that check continuous-integration evidence may fall back to the branch's most recent CI run when none exists for the exact commit audited.
An audit is not a guarantee that your code is secure, bug-free, or free of vulnerabilities, and it is not a substitute for a professional security review, a penetration test, or legal or compliance advice. It reports what our catalog of rules found, evaluated the way our documentation describes, with the coverage and limitations the report states -- nothing broader than that.
A rule marked "undetermined" means we could not reach a conclusion (missing access, evidence that needed a retry, a case that needs a person) -- it is not evidence of a pass, and it is never presented as one.
Your code during an audit
To audit a repository, we clone it into a temporary, ephemeral environment (a GitHub Actions runner) that is destroyed automatically when the audit finishes. We don't upload that clone to any persistent storage.
While the clone itself isn't kept, some information derived from it is: the specific file and line cited as evidence for a finding (a short excerpt of the code at that location), the full exported report (the internal, staff-only version that embeds every citation), and an internal run record kept as a GitHub Actions artifact. Citation excerpts and the full exported report are purged automatically 90 days after we first audit that commit -- re-auditing the same commit later doesn't restart the clock. The run record is deleted separately, by GitHub itself, 90 days after the run. The findings themselves (pass/fail per rule, file and line), the analysis text we write for them (including the reason a finding was disputed, if it was) -- which can include short fragments of your code quoted literally -- and the computed score are retained indefinitely as the audit record; only the literal citation excerpts and the full exported report are purged. See our Privacy Policy for the complete data-retention schedule.
Some rules are evaluated by an AI model, which reads the contents of files it decides are relevant to the rule it's checking. Every audit run on behalf of your account only reaches AI providers whose terms do not permit training their models on what we send -- that's enforced on our server, not left to a UI setting you have to remember to pick.
You keep ownership of your code. Connecting a repository grants us the limited license we need to clone it, run the audit described above, and produce, store, and use your findings and report as described in this section and our Privacy Policy -- nothing more.
Payment
Paid plans aren't available yet. When they launch, they will be billed through Stripe's hosted checkout: we won't receive or store your card number -- Stripe will process and store it under its own terms and security standards -- and we'll keep your subscription status and plan, not your payment details.
There are no refunds once an audit has started. You can ask to cancel your subscription at any time, and the cancellation takes effect from the next billing period. Cancelling today goes through contacting us -- there isn't a self-service cancel button yet.
Your account and acceptable use
You're responsible for keeping your account credentials secure, and for what happens under your account. You agree not to interfere with the service's operation.
You may only audit repositories that are your own or that you're authorized to audit. You may not resell or republish audit reports or badges in a misleading way, and you may not use the service to attack third parties.
Limitation of liability
The service is provided "as is," without warranties of any kind, express or implied, including any warranty of merchantability, fitness for a particular purpose, or non-infringement.
To the maximum extent permitted by law, CamelHive is not liable for indirect, incidental, special, consequential, or punitive damages, including lost profits or lost data, arising from your use of the service.
Our total liability to you for any claim related to the service is limited to the amount you paid us in the 12 months before the claim.
Termination
You can stop using CamelHive at any time. Either of us can end this agreement with 30 days' notice. We may also suspend or terminate an account that violates these terms, including the acceptable-use section above.
Changes to these terms
If what we actually do changes, this page changes with it. We'll update the date at the top when we do -- check back periodically.
Governing law and disputes
These terms are governed by the laws of the State of Wyoming, USA. Any dispute will be brought in the courts of Wyoming. We don't use arbitration.
Company and contact
CamelHive™ is a brand operated by PDE IT Services LLC, a Wyoming (USA) limited liability company. Questions about these terms: reach us through our contact form.