Legal & Terms

End User Licence
Agreement (EULA)

Terms of service and licence agreement governing the use of the SitRep Continuous Analysis platform, web applications, and APIs.

Last Updated: September 2026 · Version 0.1 (Early Access)

01Early Stage Service Notice

SitRep (accessible via sit-rep.co.uk and app.sit-rep.co.uk, together with all associated APIs, scanners, and tools, collectively referred to as the "Service") is currently in an early stage of product development.

By accessing or using the Service, you acknowledge and agree that features, data models, API endpoints, and interfaces may evolve, change, or undergo rapid iteration. We provide the Service for evaluation, testing, and continuous analysis workflows, and we actively welcome feedback, bug reports, and suggestions from early users.

Early Access Status

SitRep is in active development. While we take data integrity and stability seriously, features may be added, adjusted, or deprecated as the platform matures.

02Licence Grant & Scope

Subject to your compliance with this Agreement, SitRep grants you a limited, non-exclusive, non-transferable, revocable licence to:

  • Access and interact with the SitRep dashboard and web interface;
  • Submit scan artefacts, SBOMs, and vulnerability reports to our ingestion endpoints via automated CI/CD pipelines or manual uploads;
  • Generate and utilise Personal Access Tokens (PATs) for programmatic API access within your organisation's authorised scope;
  • View, query, compare, and analyse historical build records, diffs, and compliance postures generated by the Service.

All rights not expressly granted to you under this Agreement remain reserved by SitRep and its licensors.

03Customer Data & Ownership

You retain complete and unencumbered ownership of all data, reports, Software Bill of Materials (SBOMs), vulnerability manifests, licence lists, repository metadata, and pipeline artefacts that you submit to SitRep ("Customer Data").

SitRep does not claim any intellectual property rights or ownership over your Customer Data or your underlying source code.

You grant SitRep a limited, non-exclusive licence solely to store, process, parse, compute diffs, and display your Customer Data as necessary to operate, maintain, and provide the Continuous Analysis service to you and your organisation.

04Data Export & Portability

We believe you should always maintain control of your security and compliance history without vendor lock-in.

Customer Data Export: We can export your customer data upon request. You may retrieve your raw ingestion payloads, scan outputs, diff histories, and product records through our REST API or by contacting support.

Upon receipt of a data export request, we will provide your Customer Data in standard, machine-readable formats (such as JSON or CSV) within a reasonable timeframe.

No Vendor Lock-In

Your security history is yours. You can export your ingested reports, SBOM records, and vulnerability timelines at any time upon request.

05GDPR & Data Protection

SitRep complies with applicable data privacy and data protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

In relation to personal data processed through your use of the Service (such as user account email addresses, usernames, and authentication logs):

  • Lawful Basis: We process personal data strictly to administer accounts, secure authentication, and provide the requested services.
  • Right of Access: You have the right to request a copy of the personal data we hold about you.
  • Right to Rectification: You may update or correct inaccurate account details at any time.
  • Right to Erasure ("Right to be Forgotten"): You may request the deletion of your account and associated personal data, subject to any statutory record-keeping obligations.
  • No Data Brokering: We do not sell, rent, or trade your personal information or Customer Data to any third party for marketing or commercial purposes.

To exercise any of your statutory data protection rights, please contact our data compliance point of contact at nmunro@sit-rep.co.uk.

06Acceptable Use & Security

When accessing or integrating with SitRep, you agree not to:

  • Use the Service for any unlawful, abusive, or fraudulent purpose;
  • Attempt to probe, scan, or compromise the vulnerability of SitRep infrastructure, networks, or databases without explicit prior written consent;
  • Upload or transmit malware, malicious binaries, Trojan horses, or corrupted files designed to compromise SitRep or other users;
  • Reverse engineer, decompile, or disassemble any portion of the Service, except where strictly permitted by applicable mandatory law;
  • Circumvent or attempt to bypass rate limits, authentication barriers, or token permission scopes;
  • Share account credentials or Personal Access Tokens (PATs) across unauthorised parties. You are solely responsible for maintaining the confidentiality and security of your access tokens.

07Availability & No Uptime Guarantee

The Service is provided on an "AS IS" and "AS AVAILABLE" basis.

As SitRep is in its early stages:

  • We offer no guarantee of uninterrupted uptime, specific availability percentages, or service level agreements (SLAs);
  • The Service may experience temporary unavailability, maintenance windows, latency, or server restarts without prior notice;
  • We will make commercially reasonable efforts to communicate planned maintenance and restore access in a timely fashion in the event of unexpected outages, but accept no liability for downtime or transmission delays.
No Service Level Agreement (SLA)

SitRep does not currently provide a formal uptime guarantee or SLA. You should not rely on the platform as a mission-critical real-time dependency for hard pipeline gating without independent fallbacks.

08Disclaimer of Warranties

To the maximum extent permitted by applicable law, SitRep and its creators, contributors, and suppliers provide the Service without warranty of any kind, whether express, implied, statutory, or otherwise.

Specifically, and without limiting the generality of the foregoing:

  • We disclaim all implied warranties of merchantability, fitness for a particular purpose, non-infringement, and quiet enjoyment;
  • We do not warrant that the Service will meet your specific business or compliance requirements, or that reports will be completely error-free or uninterrupted;
  • Security Disclaimers: Continuous Analysis provides historical visibility and vulnerability tracking based on outputs from external security scanning tools (such as Grype, Syft, and Grant) and third-party vulnerability feeds. SitRep does not guarantee that your software, dependencies, base images, or licences will be free of vulnerabilities, exploits, or regulatory non-compliance. SitRep is an analytical tool and does not substitute for dedicated application security practices.

09Limitation of Liability

To the fullest extent permitted by applicable law, in no event shall SitRep, its operators, employees, affiliates, or licensors be liable for:

  • Any indirect, incidental, special, consequential, exemplary, or punitive damages;
  • Loss of profits, revenue, anticipated savings, or business opportunity;
  • Loss, corruption, or degradation of data;
  • Costs associated with the procurement of substitute goods or services;
  • Any security incidents, software vulnerabilities, supply chain exploits, or breaches affecting your systems, regardless of whether such issues appeared in reports generated by the Service.

Our total aggregate liability arising out of or relating to this Agreement or your use of the Service, under any legal theory (contract, tort, negligence, or otherwise), shall not exceed the total amounts actually paid by you to SitRep for the Service in the twelve (12) months preceding the incident, or fifty pounds sterling (£50.00) if no fees have been paid.

10Termination

You may terminate this Agreement at any time by ceasing all use of the Service, revoking your Personal Access Tokens, and closing your account.

We reserve the right to suspend or terminate your access to the Service at our discretion, without prior notice, if we reasonably determine that you have violated this Agreement, abused platform resources, or posed a security risk to other users or our infrastructure.

Upon termination, your licence to access the Service terminates immediately. You may request the export or deletion of your Customer Data in accordance with our data export and GDPR policies set out in Sections 04 and 05.

11Governing Law & Jurisdiction

This Agreement, and any dispute or claim (including non-contractual disputes or claims) arising out of or in connection with it or its subject matter or formation, shall be governed by and construed in accordance with the laws of England and Wales.

The courts of England and Wales shall have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with this Agreement.

12Contact Information

If you have any questions regarding this End User Licence Agreement, wish to request a data export, or wish to exercise your data protection rights under the UK GDPR, please contact:

SitRep Support & Legal

Email: nmunro@sit-rep.co.uk

Website: sit-rep.co.uk

Application: app.sit-rep.co.uk