Skip to main content
Platform Review
PricingSign in
← All platforms
Developer / Coding · semgrep.dev

Semgrep AI

Graded against 804 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.

Overall riskHIGHReviewed 2026-08-21
Creator: low · GRC: low · Counsel: low
creator band
Caution
enterprise · pending
Dealbreaker · Training without opt-out
Exhibit A · Terms of Service · verbatim

Customer Data. Customer grants Company a limited license during the Term to use Customer Data to provide the Service to the Customer and gather Usage Data. Company uses Usage Data to improve the Service, including the accuracy of security findings.

cited by the training without opt-out dealbreaker — tap for the citation
19 verified findings7 policy surfaces1/2 core docs verified

Partially verified: Terms of Service assessed · Privacy Policy pending. Everything below comes only from what was read in full.

Risk triage

Watch: indemnity liability

Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.

0
high
7
medium
12
low
1/2
docs
Trains on your data?
Not yet assessed
no verified finding covers this surface yet
Who owns outputs?
You own your outputs
from 1 cited finding
Commercial use?
Not yet assessed
no verified finding covers this surface yet
Every rating:verbatim-citedsnapshot-datedchange-loggedHow we keep ratings honest →
Risk by role
Select a role to tailor the summary and reorder the findings below.

Scores derived from 8 enriched findings — same verbatim citations as below. AI-generated, not legal advice.

What this means for you
  • Semgrep AI's training terms are conditional — check the tier, opt-out, and enterprise exceptions before relying on protection.
  • Your outputs and prompts are explicitly yours — Semgrep AI's terms include affirmatively protective IP language.

Derived from AI-enriched analysis of the verified findings below — informational only, not legal advice.

How to read this page: Overall risk rates what Semgrep AI's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.

Creator lens
Your prompts, your outputs, your IP
CAUTION
Dealbreaker — Training without opt-out. Your inputs/outputs are used to train models and the policy provides no way to decline. see the clause

Based on 31 verified, verbatim-cited findings below — read the citations.

Enterprise lens
NOT YET ASSESSED

privacy assessment pending — privacy policy not yet verified This lens receives a band only once its source document has been captured and read in full.

Know where this document lives? Point us to the URL or PDF and the pipeline will verify it.

Automated assessment against a published rubric — not legal advice.

Partially verifiedDeveloper / Coding

Partially verified — Terms of Service — Verified (read in full, 19 findings); Privacy Policy — Capture pending. Findings below are from fully-read, verified documents only; remaining core documents are pending capture.

Why partial?

Capture blocked

A known core policy document could not be publicly captured after the available capture strategies were tried.

Blocked core document: Privacy Policy

Document status
  • Terms of Service
    Verified - read in full - 19 citationsstaticLast captured 2026-08-21
  • Privacy Policy
    Capture blocked - document not publicly capturable
Tier conditions

Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.

plan language
Moderation & enforcement

This segment grants Customer a royalty-free, nonexclusive, nontransferable, worldwide right to use the Service during the Term, and separately establishes that Beta Features are for testing only and may be removed without notice or liability, thereby defining the permitted scope of commercial use and limiting rights with respect to beta functionality.

" Right to Access and Use Service. Subject to the terms of this Agreement, Company grants Customer a royalty-free, nonexclusive, nontransferable, worldwide right during the Term to use the  Service available at  semgrep.dev  (the “ Subscript..."
📍 § 2 (ACCESS TO AND USE OF SERVICES)Jump to exact text →
plan language
Indemnity & liability

Expressly disclaims all warranties beyond the limited warranties in Section 7, including implied warranties of merchantability, fitness for purpose, performance, and non-infringement, and disclaim warranties that the Service is error-free, uninterrupted, or will meet Customer's requirements, limiting Company's liability exposure.

" Disclaimer. With the exception of the limited warranties set forth in this Section 7, the Service and Beta Features are provided “as is” to the fullest extent permitted by law. Company and its licensors expressly disclaim all other warrant..."
📍 § 7 (REPRESENTATIONS AND WARRANTIES)Jump to exact text →

Evidence appendix

Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.

High - 0
Medium - 7
Tier-specific - 0
Total citations - 19
Severity
Surface
Document
Tier
Prompt / input ownership
CautionHigh
" Customer Data. Customer grants Company a limited license during the Term to use Customer Data to provide the Service to the Customer and gather Usage Data. Company uses Usage Data to improve the Service, including the accuracy of security findings.  "
§ 5 (DATA PROTECTION)Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

Grants Company a limited license to use Customer Data to provide the Service and to collect Usage Data, and explicitly permits Company to use Usage Data to improve the Service including security findings accuracy, establishing the scope of permissible data use.

AI-generated interpretation, not legal advice.

Indemnity & liability
High
" NEITHER PARTY, NOR ITS AFFILIATES, NOR THE OFFICERS, DIRECTORS, EMPLOYEES, SHAREHOLDERS, OR REPRESENTATIVES OF ANY OF THEM, WILL BE LIABLE TO THE OTHER PARTY FOR ANY INCIDENTAL, INDIRECT, SPECIAL, EXEMPLARY OR CONSEQUENTIAL DAMAGES, THAT MAY ARISE OUT OF THIS AGREEMENT, EVEN IF THE OTHER PARTY HAS BEEN NOTIFIED OF THE POSSIBILITY OR LIKELIHOOD AND WHETHER BASED ON CONTRACT, TORT, NEGLIGENCE, STRICT LIABILITY, SERVICES LIABILITY OR OTHERWISE."
§ 9 (LIMITATIONS OF LIABILITY)Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

Excludes both parties and their affiliates from liability for incidental, indirect, special, exemplary, or consequential damages arising from the agreement regardless of notice or legal theory, substantially limiting the scope of recoverable harm.

AI-generated interpretation, not legal advice.

Moderation & enforcement
NeutralHigh
" Right to Access and Use Service. Subject to the terms of this Agreement, Company grants Customer a royalty-free, nonexclusive, nontransferable, worldwide right during the Term to use the  Service available at  semgrep.dev  (the “ Subscription ”). Beta Features made available by Company are provided to Customer for testing purpose only. Company may immediately and without notice remove Beta Features for any reason without liability to Customer."
§ 2 (ACCESS TO AND USE OF SERVICES)Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

This segment grants Customer a royalty-free, nonexclusive, nontransferable, worldwide right to use the Service during the Term, and separately establishes that Beta Features are for testing only and may be removed without notice or liability, thereby defining the permitted scope of commercial use and limiting rights with respect to beta functionality.

AI-generated interpretation, not legal advice.

Moderation & enforcement
High
" These Terms of Service   (this “ Agreement ”) govern the use of services provided by Semgrep Inc., a Delaware corporation (“ Company ”), to the Customer and end user of the services (“ Customer ”).  By accepting this Agreement, whether by clicking a box indicating its acceptance or navigating through a login page where a link to this Agreement is provided, Customer agrees to the terms of this Agreement. If Customer and Company have executed a written agreement governing Customer’s access to and use of the Service, then the terms of such signed agreement will govern and will supersede this Agreement. PLEASE NOTE THAT IF AN INDIVIDUAL SIGNS UP FOR THE SERVICE USING AN EMAIL ADDRESS FROM THEIR EMPLOYER OR ANOTHER ENTITY, OR OTHERWISE SIGNS UP FOR THE BENEFIT OF THEIR EMPLOYER OR ANOTHER ENTITY, THEN (A) THEY WILL BE DEEMED TO REPRESENT SUCH PARTY, (B) THEIR ACCEPTANCE WILL BIND THE EMPLOYER OR THAT ENTITY TO THESE TERMS, AND (C) THE WORD “CUSTOMER” IN THESE TERMS WILL REFER TO THE EMPLOYER OR THAT ENTITY. This Agreement is effective as of the earlier of the date that Customer accepts the terms of this Agreement as indicated above or first accesses or uses the Service (the “ Effective Date ”). Company reserves the right to modify or update the terms of this Agreement in its discretion, the effective date of which will be the earlier of (i) 30 days from the date of such update or modification and (ii) Customer’s continued use of the Service."
Terms of Service › “Terms of Service”Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

This segment defines the Agreement, identifies the contracting parties (Semgrep Inc. and Customer), establishes the mechanism of acceptance (clickwrap or navigation through login), and incorporates a supersession rule that a separately executed written agreement will govern over this Agreement, thereby establishing the contractual framework and hierarchy of documents.

AI-generated interpretation, not legal advice.

Indemnity & liability
High
" Customer will indemnify, defend, and hold harmless Company, its Affiliates, and their respective owners, directors, members, officers, and employees (together, the “ Company Indemnitees ”) from and against any claim, action, demand, suit or proceeding made or brought by a third party (each a “ Claim ”) against the Company Indemnitees related to (i) Customer’s or a User’s engaging in a Prohibited Use, and (ii) any grossly negligent acts or omissions of its Users. Customer will pay any settlement of and any damages finally awarded against any Company Indemnitee by a court of competent jurisdiction as a result of any such Claim so long as Company (a) gives Customer prompt written notice of the Claim, (b) gives Customer sole control of the defense and settlement of the Claim (provided that Customer may not settle any Claim without Company’s prior written consent which will not be unreasonably withheld), and (c) provides to Customer all reasonable assistance, at Customer’s request and expense."
§ 8 (INDEMNIFICATION)Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

Obligates Customer to indemnify, defend, and hold harmless Company and its affiliates against third-party claims arising from Customer's Prohibited Use or grossly negligent acts of its Users, and requires Customer to pay any settlement or court-awarded damages against Company Indemnitees, allocating litigation risk to Customer for specified conduct.

AI-generated interpretation, not legal advice.

Indemnity & liability
High
" Disclaimer. With the exception of the limited warranties set forth in this Section 7, the Service and Beta Features are provided “as is” to the fullest extent permitted by law. Company and its licensors expressly disclaim all other warranties, express or implied, including warranties of performance, merchantability, fitness for any particular purposes, and non-infringement. Company does not warrant that the Service (i) are error-free, (ii) will perform uninterrupted, or (iii) will meet Customer’s requirements."
§ 7 (REPRESENTATIONS AND WARRANTIES)Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

Expressly disclaims all warranties beyond the limited warranties in Section 7, including implied warranties of merchantability, fitness for purpose, performance, and non-infringement, and disclaim warranties that the Service is error-free, uninterrupted, or will meet Customer's requirements, limiting Company's liability exposure.

AI-generated interpretation, not legal advice.

Governing law & disputes
High
" This Agreement is the entire agreement between Customer and Company and supersedes all prior agreements and understandings concerning the subject matter hereof. Customer and Company are independent contractors, and this Agreement will not establish any relationship of partnership, joint venture, or agency between Customer and Company. Failure to exercise any right under this Agreement will not constitute a waiver. There are no third-party beneficiaries to this Agreement. This Agreement is governed by the laws of California without reference to conflicts of law rules. For any dispute relating to this Agreement, the Parties consent to personal jurisdiction and the exclusive venue of the courts in San Francisco County, California. Any notice provided by one party to the other under this Agreement will be in writing and sent by overnight courier or certified mail (receipt requested) to the address on file with the party providing the notice. If any provision of this Agreement is found unenforceable, this Agreement will be construed as if it had not been included. Neither party may assign this Agreement without the prior, written consent of the other party, except that either party may assign this Agreement without such consent in connection with an acquisition of the assigning party or a sale of all or substantially all of its assets."
§ 10 (MISCELLANEOUS)Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

Establishes California law as governing law without conflicts-of-law rules, designates the agreement as the entire agreement superseding prior understandings, declares the parties independent contractors with no partnership or agency relationship, and provides that failure to exercise rights is not a waiver and there are no third-party beneficiaries, collectively governing how disputes are interpreted and resolved.

AI-generated interpretation, not legal advice.

Moderation & enforcement
NeutralHigh
" Support. Customer may join Company’s Slack at  https://go.semgrep.dev/slack  to participate in the user community. Company will not provide support beyond the Documentation and knowledge base articles."
§ 2 (ACCESS TO AND USE OF SERVICES)Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

This segment limits Company's support obligations to Documentation and knowledge base articles only, and directs Customer to a community Slack channel for assistance, thereby defining the ceiling of Company's support commitments and differentiating service tiers.

AI-generated interpretation, not legal advice.

Confidentiality
High
" Additional Exclusions. A Receiving Party will not violate its confidentiality obligations if it discloses the Disclosing Party’s Confidential Information if required by applicable laws, including by court subpoena or similar instrument so long as the Receiving Party provides the Disclosing Party with written notice of the required disclosure so as to allow the Disclosing Party to contest or seek to limit the disclosure or obtain a protective order. If no protective order or other remedy is obtained, the Receiving Party will furnish only that portion of the Confidential Information that is legally required, and agrees to exercise reasonable efforts to ensure that confidential treatment will be accorded to the Confidential Information so disclosed."
§ 4 (CONFIDENTIALITY)Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

This segment creates an exception to confidentiality obligations for legally compelled disclosures, subject to a procedural requirement that the Receiving Party provide written notice to the Disclosing Party to allow it to seek a protective order, and limits any compelled disclosure to only the legally required portion of Confidential Information.

AI-generated interpretation, not legal advice.

Prompt / input ownership
NeutralHigh
" The definitions of certain capitalized terms used in this Agreement are set forth below. Others are defined in the body of the Agreement. “ Affiliate ”   means, with respect to an entity, any entity or person which directly or indirectly controls, is controlled by, or is under common control with that entity. “ Beta Features ” means any Service features, functionality or services which Company may make available to Customer to try at no additional cost, and which is designated as beta, trial, non-production or another similar designation.  “ Customer Data ”   means (i) User authentication information, such as name and email address, (ii) Customer’s source code, and (iii) Metadata (as defined below). “ Documentation ” means the written or online documentation regarding the Service made available by Company at  https://semgrep.dev/docs . “ Metadata ” means the results of the scanning of Customer’s source code, such as filepath, project identity, committer email address, and the OWASP vulnerability type and severity detected. “ Output ” means source code and electronic reports generated through Customer’s use of the Service. “ Rules ” means the sets of instructions based on which the Semgrep OSS Engine and/or the Service detects patterns in source code. “ Semgrep OSS Engine ” means the Semgrep open source software program in object code form used for the purpose of detecting source code vulnerabilities.  “ Service ”   means Company’s proprietary, Software-as-a-Service solution, known as the Semgrep AppSec Platform, for use by Customer for the purpose of detecting, managing, and remediating vulnerabilities in source code. "
§ 1 (DEFINITIONS)Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

This segment defines key capitalized terms including 'Affiliate,' 'Beta Features,' and 'Customer Data,' which are operative definitions that govern the scope of data rights, service access, and party relationships throughout the Agreement.

AI-generated interpretation, not legal advice.

Prompt / input ownership
NeutralHigh
"The Service includes various proprietary features, the Software, the Rules, the Documentation, and all modifications, updates, and upgrades thereto and derivative works thereof. “ Software ”   means the software that Company develops and maintains in order to provide the Service, and all modifications, updates, upgrades thereto and derivative works thereof but specifically excludes Semgrep OSS Engine. “ Subscription ” has the meaning ascribed to it in Section 2.1. “ Term ” has the meaning ascribed to it in Section 3.1.  “ Usage Data ” means statistical and performance-related information regarding Customer’s use of the Service. “ Users ” means individuals or entities that are authorized by Customer to use the Service."
§ 1 (DEFINITIONS)Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

This segment defines 'Service,' 'Software,' 'Subscription,' 'Term,' and 'Usage Data,' establishing the scope of proprietary rights in the Service and Software and the nature of statistical/performance data, which are operative definitions governing IP ownership, licensing, and data use provisions throughout the Agreement.

AI-generated interpretation, not legal advice.

Output ownership
FavorableHigh
" Customer Property. As between the parties, Customer owns and retains all right, title, and interest in and to the Customer Data and the Output. Customer does not by means of this Agreement or otherwise transfer any rights in the Customer Data or Output to Semgrep, except for the limited licenses set forth in Section 5.1.  Semgrep hereby assigns to Customer all of Semgrep’s right, title and interest, if any, in and to the Output."
§ 6 (OWNERSHIP)Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

Establishes that Customer owns all right, title, and interest in Customer Data and Output as between the parties, limits the transfer to Company only to the licenses in Section 5.1, and includes an express assignment by Semgrep to Customer of any rights Semgrep may have in the Output.

AI-generated interpretation, not legal advice.

Moderation & enforcement
NeutralHigh
" Semgrep OSS Engine. Semgrep OSS Engine is available for download at  https://github.com/returntocorp/semgrep  and licensed under the LGPL 2.1, available at  www.gnu.org/licenses . If Customer chooses to make use of Semgrep OSS Engine, Customer is responsible for downloading and running it in its environment and for complying with the terms of the applicable license. "
§ 2 (ACCESS TO AND USE OF SERVICES)Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

This segment addresses the Semgrep OSS Engine as a separately licensed open-source component under LGPL 2.1, incorporates the terms of that external license by reference, and allocates responsibility to Customer for downloading, running, and complying with the applicable open-source license, thereby defining the legal framework for use of that component.

AI-generated interpretation, not legal advice.

Indemnity & liability
High
" Mutual Representations and Warranties. Each party represents and warrants it has validly entered into this Agreement and has the legal power and authority to do so. "
§ 7 (REPRESENTATIONS AND WARRANTIES)Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

Imposes mutual obligations on each party to represent and warrant that it has validly entered the Agreement with full legal authority, creating a foundation for contractual liability if those representations prove false.

AI-generated interpretation, not legal advice.

Indemnity & liability
High
" “ Uncapped Claims ” means any claim or liability associated with: (a) Customer’s indemnification obligations under Section 8; or (b) any liability of a party which cannot be limited under applicable law, including gross negligence, recklessness, or intentional misconduct."
§ 9 (LIMITATIONS OF LIABILITY)Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

Defines 'Uncapped Claims' as claims related to Customer's indemnification obligations under Section 8 or liabilities that cannot be limited by applicable law such as gross negligence or intentional misconduct, carving out exceptions to the liability cap established in Section 9.

AI-generated interpretation, not legal advice.

Confidentiality
High
" Confidentiality Obligations.  Each party will use the Confidential Information of the other party only as necessary to perform its obligations under this Agreement, will not disclose the Confidential Information to any third party, and will protect the confidentiality of the Disclosing Party’s Confidential Information with the same standard of care as the Receiving Party uses or would use to protect its own Confidential Information, but in no event will the Receiving Party use less than a reasonable standard of care. Notwithstanding the foregoing, the Receiving Party may share the other party’s Confidential Information with those of its employees, agents and representatives who have a need to know such information and who are bound by confidentiality obligations at least as restrictive as those contained herein (each, a “ Representative ”). Each party shall be responsible for any breach of confidentiality by any of its Representatives."
§ 4 (CONFIDENTIALITY)Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

This segment imposes affirmative obligations on each party to use Confidential Information only as necessary to perform its obligations, prohibits disclosure to third parties, requires at least a reasonable standard of care in protecting Confidential Information, and permits sharing with employees and contractors on a need-to-know basis, thereby establishing the core confidentiality duties of both parties.

AI-generated interpretation, not legal advice.

Confidentiality
High
" Confidential Information. Except as explicitly excluded below, any information of a confidential or proprietary nature provided by a party (the “ Disclosing Party ”) to the other party (the “ Receiving Party ”) constitutes the Disclosing Party’s confidential and proprietary information (“ Confidential Information ”). Company’s Confidential Information includes the Service and any information conveyed to Customer in connection with Support. Customer’s Confidential Information includes Customer Data and Output. Confidential Information does not include information which is (i) already known by the Receiving Party without an obligation of confidentiality other than pursuant to this Agreement; (ii) publicly known or becomes publicly known through no unauthorized act of the Receiving Party; (iii) rightfully received from a third party without a confidentiality obligation to the Disclosing Party; or (iv) independently developed by the Receiving Party without access to the Disclosing Party’s Confidential Information."
§ 4 (CONFIDENTIALITY)Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

This segment defines 'Confidential Information,' 'Disclosing Party,' and 'Receiving Party,' establishes what constitutes each party's confidential information (including Customer Data and Output as Customer's confidential information), and sets out exclusions from confidentiality protection, thereby establishing the operative scope of confidentiality obligations throughout the Agreement.

AI-generated interpretation, not legal advice.

Audit rights / DPA / residency
FavorableHigh
" Security & Data Processing. Company maintains the physical, technical, and administrative safeguards (“ Security Measures ”) described at  https://trust.semgrep.dev  (the “ Trust Portal ”) in order to protect Customer Data and to assist Customer with securing its own account in its use of the Service. Updates to the Security Measures will be posted to the Trust Portal from time to time, and subscribed Customers will be notified via email. Semgrep will process Customer Data for the purposes set forth in this Agreement and in accordance with the Data Processing Addendum available on the Trust Portal."
§ 5 (DATA PROTECTION)Jump to exact text →
Source: Terms of Service- Snapshot 2026-06-08- View source
Permalink to this finding →
Automated analysis

Obligates Company to maintain specified security safeguards described at the Trust Portal to protect Customer Data, requires posting updates to those measures and notifying subscribed Customers, and incorporates the Data Processing Addendum as the framework governing how Customer Data will be processed.

AI-generated interpretation, not legal advice.

Common questions about Semgrep AI's policies

Who owns the content you create with Semgrep AI?
You own your outputs — based on 1 verified finding from Semgrep AI's published policy. Informational only, not legal advice.

Clause detail — protections, your obligations, and coverage

Every clause below is a verbatim quote from Semgrep AI's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.

✅ Protections found

6 verified clauses

Clauses in Semgrep AI's policies that work in your favour — commitments the platform made to you.

  • Moderation & enforcementterms can change anytime
    These Terms of Service   (this “ Agreement ”) govern the use of services provided by Semgrep Inc., a Delaware corporation (“ Company ”), to the Customer and end user of the services (“ Customer ”).  By accepting this Agreement, whether by clicking a box indic…

    This segment defines the Agreement, identifies the contracting parties (Semgrep Inc. and Customer), establishes the mechanism of acceptance (clickwrap or navigation through login), and incorporates a supersession rule th…

    • Terms changes: advance notice promised
    📍 Terms of Service › “Terms of Service”Jump to exact text →
  • Confidentiality
    Confidential Information. Except as explicitly excluded below, any information of a confidential or proprietary nature provided by a party (the “ Disclosing Party ”) to the other party (the “ Receiving Party ”) constitutes the Disclosing Party’s confidential a…

    This segment defines 'Confidential Information,' 'Disclosing Party,' and 'Receiving Party,' establishes what constitutes each party's confidential information (including Customer Data and Output as Customer's confidentia…

    📍 § 4 (CONFIDENTIALITY)Jump to exact text →
  • Confidentiality
    Confidentiality Obligations.  Each party will use the Confidential Information of the other party only as necessary to perform its obligations under this Agreement, will not disclose the Confidential Information to any third party, and will protect the confide…

    This segment imposes affirmative obligations on each party to use Confidential Information only as necessary to perform its obligations, prohibits disclosure to third parties, requires at least a reasonable standard of c…

    📍 § 4 (CONFIDENTIALITY)Jump to exact text →
  • Confidentiality
    Additional Exclusions. A Receiving Party will not violate its confidentiality obligations if it discloses the Disclosing Party’s Confidential Information if required by applicable laws, including by court subpoena or similar instrument so long as the Receiving…

    This segment creates an exception to confidentiality obligations for legally compelled disclosures, subject to a procedural requirement that the Receiving Party provide written notice to the Disclosing Party to allow it…

    📍 § 4 (CONFIDENTIALITY)Jump to exact text →
  • Audit rights, DPA & residency
    Security & Data Processing. Company maintains the physical, technical, and administrative safeguards (“ Security Measures ”) described at  https://trust.semgrep.dev  (the “ Trust Portal ”) in order to protect Customer Data and to assist Customer with securing…

    Obligates Company to maintain specified security safeguards described at the Trust Portal to protect Customer Data, requires posting updates to those measures and notifying subscribed Customers, and incorporates the Data…

    📍 § 5 (DATA PROTECTION)Jump to exact text →
  • Output ownership
    Customer Property. As between the parties, Customer owns and retains all right, title, and interest in and to the Customer Data and the Output. Customer does not by means of this Agreement or otherwise transfer any rights in the Customer Data or Output to Semg…

    Establishes that Customer owns all right, title, and interest in Customer Data and Output as between the parties, limits the transfer to Company only to the licenses in Section 5.1, and includes an express assignment by…

    📍 § 6 (OWNERSHIP)Jump to exact text →

📋 Rules you must follow

1 verified clause

What Semgrep AI requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.

  • Moderation & enforcement
    Semgrep OSS Engine. Semgrep OSS Engine is available for download at  https://github.com/returntocorp/semgrep  and licensed under the LGPL 2.1, available at  www.gnu.org/licenses . If Customer chooses to make use of Semgrep OSS Engine, Customer is responsible f…

    This segment addresses the Semgrep OSS Engine as a separately licensed open-source component under LGPL 2.1, incorporates the terms of that external license by reference, and allocates responsibility to Customer for down…

    📍 § 2 (ACCESS TO AND USE OF SERVICES)Jump to exact text →

What the policies actually cover

3 topics
  • Damages & liability cap3 clauses
  • Indemnity direction1 clause
  • Terms can change at any time1 protective1 clause

14 further verified clauses are cited on this page but not yet assigned a topic.

Clause intelligence

Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.

54
clauses
9
patterns
9
stances
privacy sharing · 6ip license · 3
ip licenseHIGH§ 2 (ACCESS TO AND USE OF SERVICES)

The clause includes sublicensable, transferable, or assignable rights.

Restrictions. Customer will not: (i) access (or allow a third party to access) the Service in order to monitor the availability, security, performance, or functionality of the Service, or benchmark the Service, for any competitive purposes without Company’s express written consent; (ii) market, sublicense, resell, lease, loan, transfer, or otherwise commercially exploit or make the Software or Service available to...
Open source citation
ip licenseHIGH§ 2 (ACCESS TO AND USE OF SERVICES)

The clause includes sublicensable, transferable, or assignable rights.

Restrictions. Customer will not: (i) access (or allow a third party to access) the Service in order to monitor the availability, security, performance, or functionality of the Service, or benchmark the Service, for any competitive purposes without Company’s express written consent; (ii) market, sublicense, resell, lease, loan, transfer, or otherwise commercially exploit or make the Software or Service available to...
Open source citation
ip licenseHIGH§ 2 (ACCESS TO AND USE OF SERVICES)

The clause includes sublicensable, transferable, or assignable rights.

Restrictions. Customer will not: (i) access (or allow a third party to access) the Service in order to monitor the availability, security, performance, or functionality of the Service, or benchmark the Service, for any competitive purposes without Company’s express written consent; (ii) market, sublicense, resell, lease, loan, transfer, or otherwise commercially exploit or make the Software or Service available to...
Open source citation
privacy sharingMEDIUM§ 2 (ACCESS TO AND USE OF SERVICES)

The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.

Restrictions. Customer will not: (i) access (or allow a third party to access) the Service in order to monitor the availability, security, performance, or functionality of the Service, or benchmark the Service, for any competitive purposes without Company’s express written consent; (ii) market, sublicense, resell, lease, loan, transfer, or otherwise commercially exploit or make the Software or Service available to...
Open source citation
privacy sharingMEDIUM§ 4 (CONFIDENTIALITY)

The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.

Confidentiality Obligations. Each party will use the Confidential Information of the other party only as necessary to perform its obligations under this Agreement, will not disclose the Confidential Information to any third party, and will protect the confidentiality of the Disclosing Party’s Confidential Information with the same standard of care as the Receiving Party uses or would use to protect its own Confide...
Open source citation

Tier matrix

Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.

TierSurfaceVerdictRiskCitations
All applicable tierscommercial useworsensHIGH6
Standardsubprocessors data sharingconditionalMEDIUM3

Policy evolution

Open full timeline

Before/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.

Aug 21, 2026content licenseHIGH

Latest stance: sublicensable or transferable on commercial use

Restrictions. Customer will not: (i) access (or allow a third party to access) the Service in order to monitor the availability, security, performance, or functionality of the Service, or benchmark the Service, for any competitive purposes without Company’s express written consent; (ii) market, sublicense, resell, lease, loan, transfer, or otherwise commercially exploit or make the Software or Service available to any third party; (iii) modify, create derivative works, decompile, reverse engineer, attempt to gain access to the source code, or copy the Service, or any of their components; (iv) use the Service to conduct any fraudulent, malicious, or illegal activities (each of (i) through (iv), a “ Prohibited Use ”).
Open timeline citation
Aug 21, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on commercial use

Restrictions. Customer will not: (i) access (or allow a third party to access) the Service in order to monitor the availability, security, performance, or functionality of the Service, or benchmark the Service, for any competitive purposes without Company’s express written consent; (ii) market, sublicense, resell, lease, loan, transfer, or otherwise commercially exploit or make the Software or Service available to any third party; (iii) modify, create derivative works, decompile, reverse engineer, attempt to gain access to the source code, or copy the Service, or any of their components; (iv) use the Service to conduct any fraudulent, malicious, or illegal activities (each of (i) through (iv), a “ Prohibited Use ”).
Open timeline citation
Aug 21, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on subprocessors data sharing

Confidentiality Obligations. Each party will use the Confidential Information of the other party only as authorized under this Agreement, will not disclose the Confidential Information to any third party other than as necessary to perform its obligations under this Agreement, or in connection with a permitted use or license grant, and will protect the confidentiality of the Disclosing Party’s Confidential Information with the same standard of care as the Receiving Party uses or would use to protect its own Confidential Information, but in no event will the Receiving Party use less than a reasonable standard of care. Notwithstanding the foregoing, the Receiving Party may share the other party’s Confidential Information with those of its employees, agents, representatives, and third party service providers who have a need to know such information and who are bound by confidentiality obligations (each, a “ Representative ”). Each party shall be responsible for any breach of confidentiality by any of its Representatives.
Open timeline citation
Jul 29, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on commercial use

Restrictions. Customer will not: (i) access (or allow a third party to access) the Service in order to monitor the availability, security, performance, or functionality of the Service, or benchmark the Service, for any competitive purposes without Company’s express written consent; (ii) market, sublicense, resell, lease, loan, transfer, or otherwise commercially exploit or make the Software or Service available to any third party; (iii) modify, create derivative works, decompile, reverse engineer, attempt to gain access to the source code, or copy the Service, or any of their components; (iv) use the Service to conduct any fraudulent, malicious, or illegal activities (each of (i) through (iv), a “ Prohibited Use ”).
Open timeline citation
Jul 29, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on subprocessors data sharing

Confidentiality Obligations. Each party will use the Confidential Information of the other party only as necessary to perform its obligations under this Agreement, will not disclose the Confidential Information to any third party, and will protect the confidentiality of the Disclosing Party’s Confidential Information with the same standard of care as the Receiving Party uses or would use to protect its own Confidential Information, but in no event will the Receiving Party use less than a reasonable standard of care. Notwithstanding the foregoing, the Receiving Party may share the other party’s Confidential Information with those of its employees, agents and representatives who have a need to know such information and who are bound by confidentiality obligations at least as restrictive as those contained herein (each, a “ Representative ”). Each party shall be responsible for any breach of confidentiality by any of its Representatives.
Open timeline citation
Jul 29, 2026content licenseHIGH

Latest stance: sublicensable or transferable on commercial use

Restrictions. Customer will not: (i) access (or allow a third party to access) the Service in order to monitor the availability, security, performance, or functionality of the Service, or benchmark the Service, for any competitive purposes without Company’s express written consent; (ii) market, sublicense, resell, lease, loan, transfer, or otherwise commercially exploit or make the Software or Service available to any third party; (iii) modify, create derivative works, decompile, reverse engineer, attempt to gain access to the source code, or copy the Service, or any of their components; (iv) use the Service to conduct any fraudulent, malicious, or illegal activities (each of (i) through (iv), a “ Prohibited Use ”).
Open timeline citation
Jun 28, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on commercial use

Restrictions. Customer will not: (i) access (or allow a third party to access) the Service in order to monitor the availability, security, performance, or functionality of the Service, or benchmark the Service, for any competitive purposes without Company’s express written consent; (ii) market, sublicense, resell, lease, loan, transfer, or otherwise commercially exploit or make the Software or Service available to any third party; (iii) modify, create derivative works, decompile, reverse engineer, attempt to gain access to the source code, or copy the Service, or any of their components; (iv) use the Service to conduct any fraudulent, malicious, or illegal activities (each of (i) through (iv), a “ Prohibited Use ”).
Open timeline citation
Jun 28, 2026data sharingMEDIUM

Latest stance: third party or vendor sharing on subprocessors data sharing

Confidentiality Obligations. Each party will use the Confidential Information of the other party only as necessary to perform its obligations under this Agreement, will not disclose the Confidential Information to any third party, and will protect the confidentiality of the Disclosing Party’s Confidential Information with the same standard of care as the Receiving Party uses or would use to protect its own Confidential Information, but in no event will the Receiving Party use less than a reasonable standard of care. Notwithstanding the foregoing, the Receiving Party may share the other party’s Confidential Information with those of its employees, agents and representatives who have a need to know such information and who are bound by confidentiality obligations at least as restrictive as those contained herein (each, a “ Representative ”). Each party shall be responsible for any breach of confidentiality by any of its Representatives.
Open timeline citation

Capture recency

  • Terms of Service:Last captured 2026-08-21· verified 2026-08-21
  • Privacy Policy:Last captured 2026-06-08

Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.

↑ 6 more findings this quarter vs last (54 vs 48). First scan: June 2026.

Claim this profile

Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Semgrep AI's policies — no human edits the data.

Need this for procurement or legal diligence?

Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.

Know where the missing document lives?

We haven't yet verified Semgrep AI's Privacy Policy. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.

Every finding above is a verbatim quote from Semgrep AI's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.