Terms of Service
Version 1.0 · 23 September 2026
1. Who you are contracting with
Borehole is operated by AELaboratories, a business registered in the United States. Contact: support@borehole.dev. In these terms, "we" and "us" mean AELaboratories, and "you" means the person or organisation using the service.
2. What the service is
Borehole reads a git repository and reports what it found, with evidence. Every finding carries a commit, a path or a line range that you can check yourself. Every check that ran and did not fire is published in the rejection log, with the numbers it observed.
3. What the service is not
This matters more than anything else on this page, so it is stated plainly rather than buried.
- It is not advice. A report is a set of observations about a codebase. It is not legal, financial, investment or security advice, and nothing in it is a recommendation to buy, sell, invest in, acquire or decline anything.
- It is not a security audit. Some checks look at security-adjacent facts. A clean report is not a statement that a codebase is secure, and must not be presented as one.
- It is not a substitute for professional diligence. It is a tool that makes a human's diligence faster and better informed. A repository answers roughly three and a half of seven dimensions; the report says which ones it could not answer and what a human would have to ask instead.
- It can be wrong. Every threshold is a judgement. Findings can be false positives, and an absence of findings is not proof of absence. The evidence is published precisely so you can check rather than trust.
You are responsible for any decision you make. If a decision matters, have a person who is accountable for it read the evidence.
4. Repositories you may submit
You may submit a repository only if you have the right to do so — because it is public, because you own it, or because its owner has authorised you. You must not use the service to survey a repository you obtained without permission.
Public repositories are surveyed from publicly available data. If you control a repository and would rather its report were not listed, you can delist it after proving control through GitHub, and you can write to takedown@borehole.dev.
5. Private repositories
Where you grant access to a private repository through our GitHub App:
- The access token is scoped to reading repository contents, minted for a single scan, and discarded after that scan. It is not retained.
- The working copy is deleted when the scan ends, including when the scan fails.
- No source content is sent to any language model in the deterministic layer.
- A private report is not listed, does not generate a shareable card or badge, and is readable only by the account that bought it, by anybody GitHub says controls the repository, and by anyone holding a share link you chose to create.
- A share link makes the report readable by anyone who has it, with no sign-in. You choose whether one exists and you can revoke it.
Your code remains yours. We claim no ownership of it and no right to use it beyond producing the report you asked for.
6. Payment
Prices are shown on the pricing page and are what you pay. Payment is taken through Stripe; we never see or store your card details. A purchase grants an entitlement — a counted number of surveys — which does not expire unless the product description says so.
The email containing your entitlement key is the only copy we send. If it does not arrive, write to billing@borehole.dev and we will re-send it.
7. Refunds
If a survey fails for a reason on our side, the use is returned to your entitlement automatically. If that does not happen, or if the report you received is not what was described, write to billing@borehole.dev and we will refund it. We would rather refund a disappointed buyer than argue with one.
Where you are an EU consumer, your statutory right of withdrawal applies. Because a survey is delivered immediately, starting one is a request for immediate performance; once a report has been produced the service has been supplied.
8. Availability
The service is provided as it is. We do not promise it will be available without interruption. /status reports what is actually working at any moment, and it is designed to be able to say no.
9. Liability
To the extent the law allows, our total liability for any claim arising out of the service is limited to the amount you paid us for it in the twelve months before the claim. We are not liable for indirect or consequential loss, including lost profit or lost opportunity arising from a transaction you did or did not complete.
Nothing here limits liability for fraud, for death or personal injury caused by negligence, or for anything else that cannot be limited by law.
10. Verification marks
A report may carry a Borehole Official Analysis code. The code resolves to the report we actually issued, and it commits to the checks that ran at the time. It is not a certification, an endorsement or a rating, and it does not cover checks written after it was issued — the verification page says so when the two differ.
11. Acceptable use
Do not attempt to defeat quotas, probe for other people's private reports, or use the service to build a competing assessment product. Do not present a report as something it is not, including as a security certification or as our endorsement.
12. Changes and termination
We may change these terms. A material change will be noted here with a new version and date, and we will not apply it retroactively to a purchase you have already made. You may stop using the service at any time. We may suspend access that is abusive or unlawful.
13. Governing law
Pending legal review. AELaboratories is registered in the United States, the infrastructure is in the EU, and buyers are expected in both. Choosing a forum here without advice would be a guess, and a guess that appears in a contract is worse than an honest gap.
14. Contact
General: support@borehole.dev
Billing: billing@borehole.dev
Takedown: takedown@borehole.dev
See also the Privacy Policy.