Service
PatchProof coordinates self-hosted verification jobs and presents deterministic evidence about code patches. It is an engineering aid, not a guarantee that software is secure, correct, compliant, or suitable for release.
Accounts and workspaces
You must provide accurate account information, protect credentials, keep at least one responsible workspace owner, and grant only the access each member needs. Actions performed through your session, API token, runner token, or invitation link are treated as authorized until the credential is revoked.
Runner responsibility
You control the machines that execute repository code. You are responsible for isolation, network access, secrets, package registries, Git credentials, operating-system hardening, backups, and the legal authority to process each repository. Never expose a privileged Docker socket to the cloud control plane.
Acceptable use
Do not use PatchProof to access repositories without authorization, distribute malware, evade security controls, overload shared infrastructure, probe other workspaces, or store unlawful content. Verification commands should be bounded and relevant to the project being reviewed.
Evidence and decisions
Risk findings, verdicts, logs, and checks reflect configured rules and available evidence. You remain responsible for merge, deployment, incident, and compliance decisions. A safe verdict does not replace human review or production safeguards.
Availability and changes
Features may evolve and maintenance may temporarily interrupt the control plane. Runner execution and cloud availability are separate boundaries. Deployment operators should monitor readiness, queue health, scheduler drift, mail delivery, storage, and backups.
Data and deletion
You retain responsibility for repository and workspace data. Archiving a project preserves its evidence; deleting infrastructure or workspace records may be irreversible. Follow the privacy notice and your deployment operator's retention policy.
Warranty and liability
PatchProof is provided on an as-available basis to the extent permitted by applicable law. The deployment operator is responsible for any commercial warranty, support commitment, limitation of liability, governing law, and dispute terms offered to its users.