Clear terms for using BoundaryCI and BoundaryCI Cloud.
These terms explain the service BoundaryCI provides, how paid Cloud subscriptions renew and end, and the limits customers should understand before purchasing.
License and service scope
The BoundaryCI scanner is distributed under the MIT License. BoundaryCI Cloud adds hosted scan history, organization access, usage allowances, and optional paid subscription capacity.
Paid organizations can authorize a managed Fireworks semantic review. AI findings can be incomplete, incorrect, or misleading and remain advisory unless the customer explicitly includes them in the CI exit decision.
BoundaryCI is an engineering aid for reviewing tenant-isolation controls. It is not a penetration test, security certification, legal or compliance opinion, managed security service, or guarantee that an application is secure.
Prices, currency, and automatic renewal
Paid prices, billing interval, included usage, and any promotion are displayed before authorization in Stripe Checkout. Public BoundaryCI prices are stated in United States dollars unless Checkout explicitly shows otherwise.
Monthly and annual subscriptions renew automatically using the saved payment method until canceled. Future pricing changes apply only with the notice and authorization required by Stripe and applicable law.
Cancellation and refunds
Customers can manage payment methods, invoices, plan changes, and cancellation through Stripe's hosted customer portal. Cancellation normally takes effect at the end of the current paid period, so access continues through that period unless Stripe indicates otherwise.
Charges are non-refundable except where required by law or expressly agreed in writing. A payment refund and a subscription cancellation are separate actions; refunding a payment does not by itself cancel future renewal.
Payment processing and service delivery
Stripe processes payment methods, invoices, billing addresses, and tax identifiers. BoundaryCI does not receive or store complete card numbers. Card statements should identify the charge with the BoundaryCI statement descriptor configured in Stripe.
Paid capacity is delivered to the BoundaryCI Cloud organization associated with Checkout after Stripe confirms the subscription. Access or ingestion can be limited when an allowance is exhausted or a subscription is incomplete, unpaid, past due, paused, or canceled.
Customer responsibilities
Customers must use BoundaryCI only on code and systems they are authorized to assess, protect credentials and confidential material, and review findings before making security or production decisions.
A customer enabling managed AI represents that it is authorized to send the selected migration text for processing by BoundaryCI and Fireworks. Organization managers are responsible for communicating that choice to their repository teams and using the available organization, repository, or workflow opt-outs when appropriate.
Do not submit production credentials, unnecessary personal data, or proprietary migrations through public support channels. Third-party services such as Supabase, Stripe, GitHub, npm, Cloudflare, and Fireworks operate under their own terms.
Support, changes, and complete agreement
Support is provided on a reasonable-effort basis without an uptime or response-time commitment unless a separate Enterprise agreement states otherwise. Material changes are published through the BoundaryCI repository and public site.
The complete BoundaryCI End User License Agreement remains available in the public sir-gig/boundaryci GitHub repository. If this page and that agreement conflict, the complete agreement controls.