Shomar terms

Terms and conditions

These terms govern access to Shomar websites, applications, APIs, documentation, scan workers, reports, and related services.

Last updated: July 12, 2026

Authorized use

You may only use Shomar for assets, repositories, systems, organizations, and evidence workflows you are authorized to assess or manage.

  • Do not scan assets without permission.
  • Do not use Shomar to attack, disrupt, or access third-party systems unlawfully.
  • Do not upload malicious content except as part of authorized, controlled security testing.

Organization responsibility

Organizations are responsible for user access, role assignment, scan authorization, evidence accuracy, integration credentials, and policy configuration.

  • Org admins should review invitations, roles, SSO/MFA policy, source-code policy, and evidence storage settings.
  • Customers remain responsible for validating legal, regulatory, audit, and procurement obligations.
  • Shomar supports audit readiness but does not replace legal, regulatory, or audit advice.

Plans, billing, and procurement

Commercial terms may be provided through a signed order form, quote, statement of work, invoice, or subscription agreement. Where a signed agreement exists, it controls conflicting commercial terms.

Service changes

Shomar may improve, modify, suspend, or remove features to improve security, reliability, compliance posture, or product quality. Material customer-impacting changes should be communicated where commercially reasonable.

Limitations

Security tools reduce risk but do not guarantee complete vulnerability discovery, breach prevention, regulatory approval, or audit success. Customers should combine Shomar with governance, testing, remediation, and independent review where appropriate.

Related pages:PolicyTermsLegal