skip to content
// legal

Terms of service

Effective September 16, 2026

These Terms of Service ("Terms") govern your access to and use of the websites, applications, and related services (together, the "Service") offered by Midkernel, Inc., a Delaware corporation ("Midkernel," "we," "us," or "our"), including Midkernel Scan, Midkernel Threat Intel, and any Midkernel plugin or marketplace listing that incorporates these Terms by reference.

By creating an account, buying credits, connecting a repository, running a scan, or otherwise using the Service, you agree to these Terms. If you use the Service on behalf of an organization, you represent that you have authority to bind that organization, and "you" means that organization.

The service

What Midkernel provides

Midkernel is an AI-assisted security service. Depending on what you enable, the Service may include:

  • Scan — You connect a GitHub repository (or other supported source). Midkernel runs an open workflow in an isolated sandbox and produces a report and run log. Profiles currently include low, balanced, and max.
  • Threat Intel — Ranked threat classes derived from public sources. Status labels may include watching, trending, or active-exploit. Midkernel packages and ranks public information; we do not claim to originate every item.
  • Plugin / marketplace — Where Midkernel offers a plugin or marketplace package, use of that package is part of the Service and is subject to these Terms and any marketplace terms that also apply.

What is not a public product under these Terms

Dev Boxes (ephemeral cloud boxes) are an admin-only capability and are not offered as a public product under these Terms.

How Scan works

Unless we tell you otherwise in-product:

  • The Midkernel GitHub App requests read access to code and metadata for the repositories you select. It does not request write access. Organization-wide access occurs only if you choose it. Continuous-run features that would comment on pull requests (if offered later) would require a separate, optional permission and are not part of the Service today.
  • Each Scan run clones the selected repository into an isolated, single-use sandbox that is destroyed when the run ends.
  • What persists after a run is the report, artifacts, and run log. The run log may include excerpts of files the workflow read.
  • Model traffic for runs goes through OpenRouter commercial APIs (using Midkernel's per-organization keys). Profile defaults (low, balanced, max) select default models; you may override the model where the product allows. Midkernel records the model and version used on the run (provenance).
  • Provenance for a run (including repository commit, workflow commit, profile, recorded model/version, and sandbox image, as applicable) is shown with the report.

Accounts and eligibility

You must provide accurate account information and keep it current. You are responsible for activity under your account and for safeguarding credentials. You must be able to form a binding contract where you live. The Service is not directed to children under 16.

Changes to the Service

We may modify, suspend, or discontinue features. Continuity of any particular workflow, model, or profile is not guaranteed.

Acceptable use

You may use the Service only for lawful security testing and related research on repositories and systems you own or are authorized to test.

You must not: (a) use the Service to attack or access systems or data without authorization; (b) probe, bypass, or disrupt Midkernel infrastructure, sandboxes, billing, or other customers; (c) upload malware intended to harm Midkernel or third parties except as necessary and disclosed for authorized research against targets you may test; (d) resell or provide the Service as a managed offering without our written agreement; (e) reverse engineer the Service except where prohibited restrictions are unenforceable; (f) misrepresent findings, provenance, or Midkernel's role; (g) violate export controls, sanctions, or other law.

We may suspend or terminate access for violations, risk to the Service, or legal requirement.

Your content and licenses

You retain ownership of Customer Content. You grant Midkernel a worldwide, non-exclusive license to host, copy, process, transmit, display, and otherwise use Customer Content and Service data (including Scan reports, logs, artifacts, prompts, model outputs, configurations, and metadata) to:

(a) provide, maintain, secure, and support the Service;

(b) prevent abuse and enforce these Terms; and

(c) improve and develop the Service (including routing, ranking, evaluation, workflows, and related models or systems).

For Scan runs paid for with purchased credits, including credits bought through verified native USDC deposits on Base, clause (c) applies by default as a contractual license and permitted purpose. This is a rights grant; it does not mean Midkernel operates any particular training pipeline or product today. Admin, internal testing, or other non-paid grant credits are not treated as "purchased" under clause (c) unless Midkernel states otherwise in-product. If Midkernel later offers an opt-out for Service-improvement use, it will be described in-product.

You are responsible for how you act on findings. Midkernel does not guarantee that the Service will find all vulnerabilities or that any finding is complete or free of false positives. You acknowledge security testing and AI-assisted analysis are inherently incomplete, and that third-party model outputs may be incorrect or unsafe to rely on without your own review.

Feedback may be used by Midkernel without obligation to you.

Credits and billing

Credits

The Service uses Midkernel credits. One Midkernel credit has a face value of approximately one U.S. dollar (USD $1). Credits are a prepaid unit of Service usage, not a bank deposit, stored-value instrument, or cryptocurrency. Paying with cryptocurrency does not make Midkernel credits themselves a cryptocurrency.

Scan credit costs

Unless we publish a different price in-product before you start a run, Scan runs deduct credits by profile as follows: low = 10 credits; balanced = 25 credits; max = 50 credits. A run does not start unless your workspace has enough credits. The in-product price shown before you confirm a run controls for that run.

Buying credits

Credit packs can be purchased only with native USDC on the Base network, sent to the organization deposit address shown in the app. Cards, other assets and other networks are not accepted. Usage is deducted from your credit balance; there is no separate pay-per-scan checkout.

Current pack amounts, subject to change and to what the app shows before payment:

  • Starter: 20 USDC → 20 credits
  • Standard: 100 USDC → 100 credits
  • Bulk: 450 USDC → 500 credits

Credits are granted after Midkernel verifies a native USDC transfer on Base to the organization's deposit address. Each verified transaction is processed once and grants the largest listed pack fully covered by that transfer. A transfer below 20 USDC grants no credits. An amount above the matched pack price grants only that pack's credits; the excess does not buy additional credits. Separate transfers are not combined to reach a pack threshold.

Send the pack amount displayed in the app. You are responsible for using the correct asset, network, address and amount. Transfers on other networks or in other assets are not credited. Midkernel is not responsible for funds sent incorrectly, except where required by law.

Packs and expiration

Unless we state otherwise at purchase, purchased credit packs do not expire. Promotional or programme grants may have different rules disclosed when granted.

Plans

Midkernel is priced primarily for runs and credits (credit packs), not per-seat licensing, except where a plan description expressly says otherwise.

Taxes and billing questions

Prices may exclude taxes. You are responsible for applicable taxes except taxes based on Midkernel's net income. For billing questions, contact hello@midkernel.com. Except where required by applicable law, Midkernel does not commit to refunds in these Terms (including for cryptocurrency payments, which are typically irreversible).

Chargebacks and abuse

We may suspend credit grants or accounts associated with payment disputes, fraud, or abuse pending resolution.

Third-party services and subprocessor path

The Service depends on third parties, including GitHub (when you connect a repository), cloud compute and hosting providers (for example AWS and Vercel), OpenRouter, underlying model providers, email, analytics, and payment processing.

By connecting a repository and running a Scan (white-box security testing), you instruct Midkernel to transmit Customer Content as needed along that path. Those third parties may process, log, or retain data under their own terms and retention practices. Midkernel does not control those independent practices and, to the maximum extent permitted by law, is not liable for them.

Midkernel's policy regarding its own commercial OpenRouter usage is described in the Privacy Policy; that policy does not bind every downstream model provider's independent practices.

Confidentiality and security research

We treat Customer Content as confidential except as permitted by these Terms and the Privacy Policy (including Service provision, subprocessors, and Service-improvement license above). If you believe you found a vulnerability in Midkernel itself, email security@midkernel.com. Do not publicly disclose Midkernel product vulnerabilities until we have had a reasonable chance to respond.

Disclaimers

THE SERVICE AND ALL REPORTS, THREAT INTEL, LOGS, AND MATERIALS ARE PROVIDED "AS IS" AND "AS AVAILABLE." TO THE MAXIMUM EXTENT PERMITTED BY LAW, MIDKERNEL DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.

Midkernel does not warrant that the Service will be uninterrupted, error-free, or that it will identify all security issues.

Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW:

(a) Midkernel will not be liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, revenue, goodwill, or data;

(b) Midkernel will not be liable for acts or omissions of third parties it does not control, including GitHub, OpenRouter, model providers, and cloud hosts, or for data retained or used by those parties under their own terms;

(c) Midkernel's total liability arising out of or relating to the Service or these Terms will not exceed the amounts you paid to Midkernel for credits or subscriptions in the twelve (12) months before the event giving rise to the claim.

Some jurisdictions do not allow certain limitations; in those cases liability is limited to the maximum extent permitted.

Indemnity

You will defend and indemnify Midkernel against claims arising from (a) Customer Content, (b) your use of the Service in violation of these Terms or law, or (c) unauthorized testing of third-party systems.

Termination

You may stop using the Service at any time. We may suspend or terminate access if you breach these Terms, if required by law, or if we discontinue the Service. On termination, your right to use the Service stops. Survival includes ownership, licenses granted, payment obligations incurred, disclaimers, liability limits, indemnity, and governing law. We retain then delete reports, logs, and artifacts as described in the Privacy Policy, unless law requires longer retention.

Privacy and DPA

Our Privacy Policy explains how we collect and use personal data and is incorporated into these Terms. Where we process personal data as a processor for your organization, our Data Processing Addendum (DPA) also applies.

Changes to these Terms

We may update these Terms. For material changes, we will provide reasonable notice. Continued use after the effective date constitutes acceptance, except where law requires a different process.

Governing law

These Terms are governed by the laws of the State of New York, excluding conflict-of-law rules. Exclusive jurisdiction and venue for disputes lie in the state or federal courts located in New York, New York, and you consent to personal jurisdiction there.

General

These Terms are the entire agreement between you and Midkernel for the Service. If a provision is unenforceable, the rest remains in effect. Failure to enforce a provision is not a waiver. You may not assign these Terms without our consent; we may assign them in connection with a merger, acquisition, or sale of assets. Notices to Midkernel: hello@midkernel.com. Notices to you: the email on your account.