Solace Terms of Service
Last updated: September 14, 2026
These Terms of Service ("Terms") govern Your access to and use of Solace ("Service"), operated by Cyfrin Inc ("Company", "We", "Us", or "Our"). By accessing or using the Service, You agree to be bound by these Terms. If You do not agree to these Terms, do not use the Service.
These Terms should be read together with the Solace Privacy Policy.
1. Interpretation and Definitions
Interpretation
Words with initial capital letters have defined meanings under the following conditions. These definitions apply whether they appear in singular or plural form.
Definitions
- Account means the unique account created for You to access the Service. An Account is tied to an individual GitHub identity and owns Your Credits, Scans, and Reports. The Service has no teams, organizations, or seats.
- Affiliate means an entity that controls, is controlled by, or is under common control with a party.
- Company refers to Cyfrin Inc, 9066 Cascada Way, Naples, FL 34114.
- Content means any code, data, text, Findings, Reports, or other materials submitted to, generated by, or displayed through the Service.
- Context Docs means the markdown files within Scope that describe a codebase's intent rather than its behavior — known issues, design decisions, trust model, invariants, supported tokens. They are read during a Scan and may suppress Findings.
- Credit means a prepaid entitlement to one Complete Scan, banked on Your Account.
- Deployment chain means the single blockchain a Scan targets, such as Ethereum, Base, or Solana. Each Scope is bound to exactly one deployment chain.
- Device means any device that can access the Service, such as a computer, cellphone, or tablet.
- Finding means a single structured security observation in a Report — severity, location, root cause, impact, proof of concept, and recommendation.
- nSLOC means non-blank, non-comment source lines, counted only over in-scope source files eligible for the selected deployment chain.
- Operator means a Cyfrin team member acting on the Service from the inside, for example to grant Credits, resolve a paused Credit, or cancel or restart a Scan Attempt.
- Order means one trip to payment for one specific Scan. It fixes the Scope, commit, deployment chain, and price.
- Personal Data is any information that relates to an identified or identifiable individual.
- Recovery Package means a private, bounded snapshot of engine state captured from a failed Scan Attempt, used only to continue that Scan in a new Attempt.
- Report means the deliverable of a completed Scan: an in-app page and a downloadable PDF, pinned to a commit SHA and a Scope.
- Scan means one examination of one commit of one repository against one Scope. A Scan is the unit You buy.
- Scan Attempt means one physical execution of a Scan against one commit SHA. A Scan may take several Attempts.
- Scan Cap means the maximum nSLOC a single Scan accepts. It is 6,000 nSLOC.
- Scope means the set of files a Scan examines — source files plus any Context Docs — fixed at purchase and pinned into the Report alongside the commit SHA.
- Service refers to Solace, including the web application, the scanning engine, and the GitHub App integration.
- Smart Contract Code means any source code, including but not limited to Solidity and Rust, submitted to the Service for analysis.
- You means the individual accessing or using the Service, or the company or legal entity on behalf of which such individual is accessing or using the Service.
2. Account Registration and Eligibility
2.1 Account Creation
To use the Service, You must create an Account by signing in with GitHub. GitHub is the only supported sign-in method; the Service does not issue passwords. We receive Your name, email address, avatar, and GitHub user ID from GitHub when You sign in, and We do not receive or store Your GitHub credentials.
You are responsible for the security of the GitHub account You use to access the Service, including its own authentication factors. Loss of control of that GitHub account is loss of control of Your Solace Account.
2.2 Eligibility
You must be at least 18 years of age to use the Service. By creating an Account, You represent and warrant that You meet this requirement.
2.3 Account Responsibility
You are responsible for all activity that occurs under Your Account. You must notify Us immediately at security@cyfrin.io of any unauthorized use of Your Account or any other breach of security.
2.4 Individual Accounts Only
The Service has no shared accounts, organizations, or seats. Credits, Scans, and Reports belong to the individual Account that purchased them and are not transferable.
3. Description of Service
3.1 Overview
Solace is an AI-assisted smart contract security service, sold as individual Scans. You connect a GitHub repository, select a Scope and deployment chain, buy a Complete Scan, and receive a Report.
3.2 Core Capabilities
The Service provides:
- Repository connection — access to the repositories You grant through Our GitHub App.
- Measurement and Scope selection — resolution of a commit, counting of nSLOC over eligible source files, a Suggested Scope with stated exclusions, and Your ability to add or remove any listed file before purchase.
- Complete Scan — AI-assisted analysis of the files in Scope for security issues across six severities: Critical, High, Medium, Low, Informational, and Gas.
- Report — an in-app Report page and a downloadable PDF containing Findings with code context, analysis, and remediation recommendations, pinned to the commit SHA and Scope that were scanned.
3.3 Repository Access and Execution
A Scan clones Your repository at a pinned commit using a token scoped to exactly that repository, with read access to contents and metadata. That token is revoked after use. Repository access is governed by the GitHub App installation grant on Your Account; if GitHub denies access, the Scan cannot proceed.
To measure and analyze a codebase, the Service may execute build tooling against Your repository inside an isolated, network-restricted sandbox. You are responsible for ensuring You have the right to submit the repository for this purpose.
3.4 Scope and Its Limits
A Scan examines only the files in Scope, against one deployment chain, at one commit. Files outside Scope are not examined and are stated as such in the Report. Cross-chain behavior is outside the Scope of any single Scan. Where a codebase exceeds the Scan Cap, the Service is designed to be used across several narrower Scans rather than one Scan spread thin; issues that span two separately scanned portions of a codebase may be invisible to both.
3.5 AI-Assisted Analysis
The Service uses artificial intelligence and large language models to analyze Smart Contract Code. You acknowledge and agree that:
- AI-generated Findings are not a substitute for a professional security audit conducted by qualified human auditors, including Cyfrin's own private audit practice.
- The Service may produce false positives (flagging code that is not actually vulnerable) and false negatives (failing to identify actual vulnerabilities).
- Findings represent the Service's automated assessment and do not constitute a guarantee that Your code is free of vulnerabilities.
- The accuracy and completeness of Findings depend on the quality and completeness of the code and Context Docs within Scope.
- The specific model configuration used to produce a Report is Our internal engineering choice and may change between Scans. It is recorded internally against each Scan so that a past Report remains explicable.
4. Your Code and Data
4.1 Code Submission
When You use the Service, You grant the Company a limited, non-exclusive license to access, clone, execute, and analyze Your Smart Contract Code solely for the purpose of providing the Service to You. This license terminates when You delete the relevant Scan or Your Account, subject to Our data retention obligations described in the Privacy Policy.
4.2 Ownership
You retain all ownership rights to Your Smart Contract Code. The Company does not claim ownership of any code You submit to the Service. Reports and Findings generated by the Service based on Your code are provided to You for Your use.
4.3 No Model Training
We do not use Your Smart Contract Code, Context Docs, Findings, Reports, prompts, or completions to train, fine-tune, or otherwise improve any machine learning model, and We route inference only through providers configured not to do so. See Section 5 of the Privacy Policy.
4.4 Confidentiality
We treat Your Smart Contract Code and Reports as confidential information. We will not disclose them to third parties except as required to provide the Service (for example, transmission to the inference providers that perform the analysis, and storage with Our infrastructure providers) or as required by law.
4.5 Retention and Deletion
Data retention, including the limited retention of diagnostic material after a failed Scan Attempt, is described in the Privacy Policy. Upon deletion of a Scan or an Account, We will remove the associated data in accordance with those periods, except where retention is required by law.
5. Fees, Credits, and Payment
5.1 Price
A Complete Scan is sold at a fixed price per Scan, displayed at the point of purchase. The launch price is an introductory price and will rise. We do not represent it as a discount from any prior or regular price, and We do not commit to a date on which it ends.
5.2 Orders
An Order fixes the Scope, commit, deployment chain, and price You took to Our payment provider. Payment is processed by Stripe; We do not receive or store Your full payment card number. A settled Order yields one Credit and one queued Scan. A cancelled or expired Order yields nothing and may be resumed as a new Order at the price then in effect.
5.3 Credits
A Credit is a prepaid entitlement to one Complete Scan. A Credit:
- records the price You actually paid, and keeps it even if the list price later changes;
- survives failed Scan Attempts and is consumed only when a Report is delivered to You;
- may be paused pending manual review — a paused Credit is unconsumed but not immediately spendable;
- is revoked if its Order is refunded, and is then recorded but never spendable.
Credits have no cash value, are not redeemable for cash, and are not transferable between Accounts.
5.4 Failed Scan Attempts
A failed Scan Attempt consumes no Credit. Where an Attempt fails for reasons within Your repository, You may start a new Attempt at the same or a different commit under the same Credit. Where an Attempt fails twice at the same commit SHA for reasons attributable to Us, the Scan is escalated to manual review by an Operator and Your Credit is paused while that review is carried out. Attempts do not restart automatically after a terminal failure.
5.5 Refunds
Refunds are at Our discretion except where required by law, and are executed through Stripe. A refund revokes any unconsumed Credit associated with the refunded Order.
5.6 Changes to Pricing
We may modify the price of a Complete Scan at any time. A price change applies to Orders placed after the change and never alters the price recorded on a Credit You already hold.
6. Acceptable Use
6.1 Permitted Use
You may use the Service only for its intended purpose: security analysis of smart contract code that You own or are authorized to analyze.
6.2 Prohibited Conduct
You agree not to:
- Submit code that You do not own or have the right to analyze.
- Use the Service to facilitate attacks, exploits, or malicious activity against any blockchain, protocol, or system.
- Use the Service, its sandbox, or its network access as a general-purpose compute, storage, or egress facility.
- Attempt to gain unauthorized access to the Service, other Accounts, or the underlying infrastructure, including attempting to escape or subvert the Scan sandbox.
- Attempt to extract, reconstruct, or manipulate the Service's prompts, engine configuration, or model routing, including through content placed in a submitted repository.
- Reverse engineer, decompile, or disassemble any part of the Service.
- Interfere with or disrupt the Service or its infrastructure.
- Resell, sublicense, or redistribute the Service or its output as a scanning service of Your own without prior written consent. This does not restrict Your use, publication, or sharing of a Report about Your own code.
- Use automated scripts, bots, or scrapers to access the Service.
- Circumvent any usage limits, rate limits, Scan Cap, or access controls imposed by the Service.
6.3 Enforcement
We reserve the right to suspend or terminate Your Account if You violate these Terms, with or without notice, at Our sole discretion. Where We terminate an Account for a violation of this Section, unconsumed Credits are forfeited.
7. GitHub Integration
Connecting Our GitHub App requires Your explicit authorization through GitHub, and determines which repositories the Service may read. You may modify or revoke that grant in GitHub at any time; doing so may prevent Scans of the affected repositories from starting or completing. Your use of GitHub is governed by GitHub's own terms and privacy policy, and the Company is not responsible for the availability, accuracy, or practices of GitHub or any other third-party service.
8. Intellectual Property
8.1 Service Ownership
The Service, including its underlying technology, scanning engine, prompts, algorithms, user interface, and documentation, is owned by the Company and is protected by intellectual property laws. Nothing in these Terms grants You any right to the Company's intellectual property except the limited right to use the Service as described herein.
8.2 Reports
You may use, publish, and share Reports about Your own code without restriction. The Report template, layout, and branding remain the Company's intellectual property; You may not present a Report as the output of a Cyfrin human private audit, and You may not alter a Report and continue to present it as Solace output.
8.3 Feedback
If You provide suggestions, ideas, or feedback about the Service ("Feedback"), You grant the Company a non-exclusive, worldwide, royalty-free, perpetual license to use, modify, and incorporate such Feedback into the Service without obligation to You.
9. Disclaimers
9.1 "As Is" Basis
THE SERVICE IS PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS, WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, OR COURSE OF PERFORMANCE.
9.2 No Security Guarantee
THE COMPANY DOES NOT WARRANT THAT THE SERVICE WILL IDENTIFY ALL SECURITY VULNERABILITIES IN YOUR CODE. A SCAN IS AN AUTOMATED, AI-ASSISTED EXAMINATION OF A DEFINED SCOPE AT A SINGLE COMMIT AND IS NOT A SUBSTITUTE FOR A COMPREHENSIVE SECURITY AUDIT BY QUALIFIED PROFESSIONALS. YOU ACKNOWLEDGE THAT THE SERVICE MAY FAIL TO DETECT CRITICAL VULNERABILITIES, THAT FILES OUTSIDE SCOPE ARE NOT EXAMINED AT ALL, AND THAT RELIANCE ON A REPORT IS AT YOUR OWN RISK.
9.3 No Financial Guarantee
THE COMPANY MAKES NO REPRESENTATIONS OR WARRANTIES REGARDING THE FINANCIAL SECURITY OF ANY SMART CONTRACT OR BLOCKCHAIN APPLICATION ANALYZED BY THE SERVICE. THE COMPANY IS NOT LIABLE FOR ANY FINANCIAL LOSSES RESULTING FROM VULNERABILITIES NOT IDENTIFIED BY THE SERVICE.
9.4 Third-Party Services
THE COMPANY DOES NOT WARRANT THE AVAILABILITY, ACCURACY, OR RELIABILITY OF GITHUB, THE PAYMENT PROVIDER, ANY INFERENCE PROVIDER, OR ANY OTHER THIRD-PARTY SERVICE THE SERVICE DEPENDS ON.
10. Limitation of Liability
10.1 Exclusion of Damages
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL THE COMPANY, ITS DIRECTORS, EMPLOYEES, PARTNERS, AGENTS, SUPPLIERS, OR AFFILIATES BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING WITHOUT LIMITATION:
- Loss of profits, revenue, data, or business opportunities
- Financial losses from undetected smart contract vulnerabilities
- Losses from exploits, hacks, or attacks on smart contracts analyzed by the Service
- Cost of procurement of substitute services
- Losses arising from unauthorized access to or alteration of Your data
WHETHER BASED ON WARRANTY, CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, OR ANY OTHER LEGAL THEORY, WHETHER OR NOT THE COMPANY HAS BEEN INFORMED OF THE POSSIBILITY OF SUCH DAMAGE.
10.2 Liability Cap
TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE COMPANY'S TOTAL LIABILITY ARISING OUT OF OR IN CONNECTION WITH THESE TERMS OR YOUR USE OF THE SERVICE SHALL NOT EXCEED THE AMOUNT YOU HAVE PAID TO THE COMPANY FOR THE SERVICE IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM, OR ONE HUNDRED U.S. DOLLARS ($100), WHICHEVER IS GREATER.
11. Indemnification
You agree to indemnify, defend, and hold harmless the Company and its officers, directors, employees, agents, and affiliates from and against any claims, liabilities, damages, losses, costs, or expenses (including reasonable attorneys' fees) arising from:
- Your use of the Service
- Your violation of these Terms
- Your violation of any third-party rights, including submitting a repository You were not authorized to submit
- Any Smart Contract Code or Content You submit to the Service
- Any financial losses incurred by You or third parties resulting from smart contracts You deployed after a Scan
12. Termination
12.1 By You
You may terminate Your Account at any time by contacting Us at support@cyfrin.io. Upon termination, Your right to use the Service will cease immediately. Unconsumed Credits are not refundable on voluntary termination except where required by law.
12.2 By Us
We may suspend or terminate Your Account at any time, with or without cause, and with or without notice. Grounds for termination include, but are not limited to, violations of these Terms, fraudulent activity, or a chargeback against a settled Order.
12.3 Effect of Termination
Upon termination, We will make reasonable efforts to delete Your data, including repository contents, Findings, and Reports, subject to Our data retention obligations and legal requirements. Download Your Reports before terminating Your Account.
12.4 Survival
Sections 4.2 (Ownership), 4.4 (Confidentiality), 8 (Intellectual Property), 9 (Disclaimers), 10 (Limitation of Liability), 11 (Indemnification), and 14 (Governing Law and Dispute Resolution) shall survive termination of these Terms.
13. Modifications to Terms
We reserve the right to modify these Terms at any time. We will notify You of material changes by posting the updated Terms on the Service and updating the "Last updated" date. Your continued use of the Service after such changes constitutes acceptance of the modified Terms.
14. Governing Law and Dispute Resolution
14.1 Governing Law
These Terms shall be governed by and construed in accordance with the laws of the State of Florida, United States, without regard to its conflict of law provisions.
14.2 Dispute Resolution
Any dispute arising out of or relating to these Terms or the Service shall first be attempted to be resolved through good-faith negotiation. If the dispute cannot be resolved within thirty (30) days, either party may pursue resolution through binding arbitration in accordance with the rules of the American Arbitration Association, conducted in the State of Florida.
14.3 Class Action Waiver
YOU AGREE THAT ANY DISPUTE RESOLUTION PROCEEDINGS WILL BE CONDUCTED ONLY ON AN INDIVIDUAL BASIS AND NOT IN A CLASS, CONSOLIDATED, OR REPRESENTATIVE ACTION.
15. General Provisions
15.1 Entire Agreement
These Terms, together with the Privacy Policy, constitute the entire agreement between You and the Company regarding the Service and supersede all prior agreements and understandings.
15.2 Severability
If any provision of these Terms is held to be unenforceable, the remaining provisions shall remain in full force and effect.
15.3 Waiver
The failure of the Company to enforce any right or provision of these Terms shall not constitute a waiver of such right or provision.
15.4 Assignment
You may not assign or transfer these Terms or Your rights under these Terms without the Company's prior written consent. The Company may assign these Terms without restriction.
15.5 Force Majeure
The Company shall not be liable for any failure or delay in performance due to circumstances beyond its reasonable control, including but not limited to natural disasters, acts of government, blockchain network disruptions, or third-party service outages.
16. Contact Us
If You have any questions about these Terms of Service, You can contact Us:
- Email: support@cyfrin.io
- Security: security@cyfrin.io
- Mailing address: Cyfrin Inc, 9066 Cascada Way, Naples, FL 34114, United States
These Terms of Service should be reviewed by qualified legal counsel before publication. This document is a template and may require modifications to comply with applicable laws in Your jurisdiction.