Legal
Version 2026-06-03
Terms of use
This portal is operated by FOSSID AB ("FOSSID", "we") to perform open-source and security audits and to exchange audit deliverables and related materials. These Terms of use govern your access to and use of the portal, including any audit you perform through it. Where you or your organisation has also signed a separate agreement with FOSSID (an "Agreement", such as a services agreement or NDA), that Agreement applies and, to the extent of any conflict, prevails over these terms. Where there is no such Agreement, these terms alone govern your use of the portal.
Accepting these terms
By accessing or using the portal, or by submitting source code, hashes, or other materials, you agree to these terms on behalf of yourself and any organisation you represent. If you do not agree, do not use the portal.
Acceptable use
- Access only the projects and materials assigned to your organisation.
- Do not attempt to circumvent access controls, or to probe, scan, or disrupt the service.
- Upload only material you are authorised to submit for audit.
- Keep your credentials confidential; you are responsible for activity under your account.
- Do not upload malware, unlawful content, or material that infringes third-party rights.
- Do not reverse-engineer, decompile, benchmark, or attempt to extract or replicate FOSSID's tooling or knowledge base, or use the portal to build a competing product.
- Do not attempt to identify, access, or contact other parties to an engagement except as permitted.
Your submissions
By submitting source code, hashes, or other materials, you represent and warrant that you have all rights and authorisations necessary to submit them and to have FOSSID process them for the audit, including any necessary intellectual-property rights, data-protection lawful bases, and export-control clearances (see the Export-control notice).
You grant FOSSID a limited, non-exclusive, worldwide licence to host, copy, and process submitted materials for the sole purpose of performing your audit and producing the related deliverables. This licence is the basis on which FOSSID handles your materials where no separate Agreement applies, and it ends when the materials are deleted or returned in line with the stated retention period.
Intellectual property
FOSSID's tooling, knowledge base, and report formats are and remain the property of FOSSID. Materials you submit remain owned by you or your organisation. Ownership of deliverables and reports is as set out in the Agreement or, where none applies, you may use the deliverables for your internal purposes in connection with the audit.
Audit outputs and warranties
Audit outputs are provided for your use in connection with the relevant audit and reflect analysis at a point in time. They are not a guarantee that all open-source components, licences, or vulnerabilities have been identified, and they are not legal advice. To the maximum extent permitted by applicable law, the portal and audit outputs are provided "as is" and "as available", and FOSSID disclaims all warranties, express or implied, including merchantability, fitness for a particular purpose, and non-infringement. Where an Agreement applies, the warranties in that Agreement prevail.
No liability
To the maximum extent permitted by applicable law, FOSSID accepts no liability in connection with the portal or your use of it. This includes any liability for the accuracy, completeness, or fitness of audit outputs, for any decision or action taken in reliance on them, and for any loss or damage arising from access to, use of, or inability to use the portal. The exclusion covers direct, indirect, incidental, and consequential loss, and loss of profit, data, or goodwill, however arising. Nothing in these terms excludes or limits liability that cannot be excluded or limited under applicable law (for example, for personal injury caused by negligence, or for fraud). Where an Agreement applies, its liability provisions prevail.
Availability
The portal is provided on an "as available" basis. FOSSID may suspend or restrict access for maintenance or security, or where these terms or any applicable Agreement are breached.
Changes to these terms
We may update these terms; the version date above indicates the current version. Continued use after an update constitutes acceptance of the updated terms.
Governing law
These terms are governed by the laws of Sweden, with disputes subject to the competent courts of Sweden. Where an Agreement applies, its governing-law and dispute provisions prevail.
Questions about these terms? Contact your FOSSID AB representative.
Privacy
FOSSID AB processes a limited amount of personal data to operate this portal. This summary explains what we hold and why.
Our role: controller and processor
For operating the portal (your account details and activity records), FOSSID AB is the data controller. For personal data contained within materials you submit for audit, FOSSID AB acts as a processor on behalf of your organisation and processes that data only on your documented instructions. Where you have a separate Agreement or data-processing agreement with FOSSID, those data-processing terms apply. Where you do not, the Data processing terms below govern that processing.
Controller identity & contact
The controller is FOSSID AB, with its principal place of business at Gasgrand 3, 111 27 Stockholm, Sweden. For data-protection questions or to exercise your rights, contact your FOSSID AB representative.
What we process
- Account details: your email address and name, used to sign you in and contact you about the audit.
- Activity records: an audit log of sign-ins, uploads, and downloads, kept to secure the service.
- Materials you upload or download in the course of an audit. These may contain personal data (for example, contributor names or email addresses in code or version-control metadata). Ensuring a lawful basis to provide such data to FOSSID is the responsibility of the submitting party.
Legal basis
We process account and activity data to provide the portal (performance of these terms or your Agreement) and on the basis of our legitimate interests in operating and securing it. Where FOSSID acts as a processor for personal data within submitted materials, the lawful basis for that content is determined by your organisation as controller.
Recipients & sub-processors
Personal data is accessed by authorised FOSSID personnel and by vetted service providers (for example, hosting) acting as sub-processors under appropriate agreements.
International transfers
The portal and its data are hosted in Europe. Where any processing takes place outside the EEA, we rely on an adequacy decision or appropriate safeguards such as the EU Standard Contractual Clauses; details are available on request.
Retention
Account and activity records are retained for the duration of the audit relationship and as required to meet our legal and security obligations; technical identifiers such as IP address are minimised over time. Submitted materials are retained, returned, or deleted in accordance with the Agreement or, where none applies, the Data processing terms and the retention period stated on the portal. On request, and subject to our obligations, your personal data can be erased or anonymised.
Security
We protect personal data with encryption in transit and at rest, access controls, and logical isolation between audits. See the Security section below for more.
Cookies
The portal uses only essential cookies required to sign you in and keep your session secure.
Automated decision-making
The portal does not make automated decisions producing legal or similarly significant effects.
Providing your data
Account details are necessary to use the portal; without them we cannot provide you access.
Your rights
Subject to applicable law, you have the right to access, rectify, erase, restrict, or object to the processing of your personal data, and to data portability. You also have the right to lodge a complaint with the Swedish supervisory authority, the Swedish Authority for Privacy Protection (IMY, Integritetsskyddsmyndigheten), or your local authority. To exercise these rights, contact your FOSSID AB representative; where FOSSID acts as a processor, we will refer your request to the relevant controller.
Confidentiality notice
Everything made available through this portal is confidential, including audit deliverables, reports, source-hash submissions, tooling, and related materials. These terms create confidentiality obligations that apply directly to your use of the portal, whether or not you also have a separate non-disclosure or other agreement with FOSSID. Where such an agreement exists, it also applies and, to the extent of any conflict, prevails.
Confidentiality & ownership
FOSSID's tooling, instructions and report formats are proprietary to FOSSID AB. Materials you submit remain owned by you or your organisation. Deliverables and reports are owned as set out in the Agreement or, where none applies, may be used by you for your internal purposes in connection with the audit.
FOSSID's commitment to you
FOSSID will treat the source code, hashes, and other materials you submit as confidential, will use them only to perform your audit and as described in these terms, and will not disclose them to third parties except to sub-processors bound by confidentiality obligations, or where required by law.
Your obligations
- Do not disclose, copy, or redistribute any material obtained here outside the parties permitted by these terms or your Agreement.
- Use the material only for the purpose of the audit it was provided for.
- Keep your account credentials secure and do not share access.
- Do not upload, paste, or submit confidential materials into third-party services, including public or unapproved AI or code-analysis tools, except as expressly permitted.
- Do not reverse-engineer or attempt to extract FOSSID's tooling or knowledge base.
- Where an audit involves multiple parties with different access, do not attempt to identify, access, or contact other parties except as permitted.
- Report any suspected unauthorised access or disclosure to FOSSID AB without delay.
Return, destruction & survival
On completion of the audit, or on request, confidential materials will be returned or securely destroyed in accordance with the Agreement or, where none applies, these terms and the portal's stated retention period. Confidentiality obligations survive the termination of your portal access.
If you do not agree to these terms, do not access the portal. For any questions, contact FOSSID AB.
Data processing terms
These Data processing terms apply where FOSSID AB processes personal data contained within materials you submit and you do not have a separate data-processing agreement with FOSSID. They form part of the Terms of use and reflect the requirements of Article 28 GDPR.
The arrangement
- Roles: you (or your organisation) are the controller; FOSSID is the processor for personal data within submitted materials.
- Subject matter & purpose: FOSSID processes such personal data only to perform the open-source and/or security audit you request.
- Duration: for the audit and any retention period stated on the portal.
- Nature of processing: hosting, scanning, matching, analysis, and generation of audit deliverables.
- Types of personal data: as contained in materials you submit (for example, contributor names and email addresses in code or version-control metadata).
- Categories of data subjects: as determined by your submissions (for example, code contributors).
FOSSID's commitments
- Process personal data only on your documented instructions, including as to transfers, unless required by law (in which case we inform you where lawful).
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational security measures (see the Security section below).
- Engage sub-processors only under equivalent data-protection obligations, and inform you of intended changes so you may object.
- Assist you, so far as possible, with data-subject requests and with your security, breach-notification, and data-protection-impact-assessment obligations.
- On completion, delete or return the personal data in accordance with the stated retention period, unless retention is required by law.
- Make available information necessary to demonstrate compliance and allow for audits as required by Article 28.
- Process personal data in Europe; where transfers occur, rely on an adequacy decision or appropriate safeguards.
Your responsibilities
- Ensure you have a lawful basis and the authority to provide the personal data to FOSSID.
- Provide only the personal data necessary for the audit, and minimise where possible.
Security
FOSSID AB takes the security of submitted source code, hashes, and audit materials seriously. This section summarises how we protect data on the portal; specific technical and organisational measures are available on request.
How we protect your data
- Encryption of data in transit (TLS) and at rest.
- Role-based access controls; access limited to authorised personnel on a need-to-know basis.
- Logical isolation between audits, so parties can access only their assigned projects.
- Audit logging of sign-ins, uploads, and downloads.
- Vetted sub-processors under appropriate security and confidentiality obligations.
- Retention and secure deletion of submitted materials in line with the stated retention period.
Vulnerabilities found during an audit
Security findings identified in the course of an audit are communicated to the relevant party in the deliverables and handled in accordance with applicable responsible-disclosure practice.
Acceptable submissions & prohibited content
You are responsible for what you submit. When uploading source code, hashes, or other materials:
- Submit only material you are authorised to submit and to have FOSSID process.
- Do not submit malware or other content designed to disrupt or compromise systems.
- Do not submit content that is unlawful or that infringes the intellectual-property or other rights of third parties.
- Do not submit export-controlled or dual-use material without flagging it in advance (see the Export-control notice).
- Minimise personal data in your submissions to what is necessary for the audit.
FOSSID may decline, quarantine, or remove material that breaches these requirements, and may suspend access where necessary to protect the service or comply with law.
Export-control notice
Source code and related technical materials may be subject to export-control and sanctions laws, including the EU Dual-Use Regulation (2021/821) and, where US-origin technology is involved, the US Export Administration Regulations (EAR).
By submitting materials, you confirm that:
- you are entitled to submit and transfer them to FOSSID AB in Sweden for the purpose of the audit;
- you have obtained any licences or authorisations required for that transfer; and
- you will inform FOSSID in advance if any submission is subject to export controls, contains cryptography of controlled strength, or relates to a sanctioned party or destination.
FOSSID may decline to receive or process any material it cannot lawfully handle. Responsibility for export-control compliance for submitted materials rests with the submitting party.