Terms of Service
CUBES
Version: 2.0
Effective Date: 29 July 2026
Last Updated: 29 July 2026
1. Operator and scope
CUBES is operated by an individual founder residing in Italy (the "Operator", "we", "us", or "our"). At this stage, CUBES is not operated by a registered legal entity. The Operator may assign these Terms to a legal entity following incorporation, restructuring, financing, or transfer of the Service.
These Terms govern access to and use of the CUBES websites, platform, private-beta environment, software-analysis tools, reports, integrations, and related services (collectively, the "Service").
The Service is offered only for business and professional use during the controlled private beta. It is not offered for personal, household, or consumer use.
2. Business eligibility and authority
To use the Service, you must:
- be at least eighteen (18) years old;
- use the Service solely for business or professional purposes;
- have authority to act for and bind the business, organization, partnership, sole proprietorship, or other professional customer you identify (the "Customer"); and
- provide accurate and current account, business, and representative information.
If you do not have the required authority, you must not accept these Terms, connect a repository, or use the Service for another person or organization.
3. Agreement and affirmative acceptance
These Terms become binding when an authorized representative affirmatively accepts them through the Service or signs another agreement that incorporates them. Access, OAuth authentication, account use, or silence alone does not constitute acceptance of a new or materially changed version.
The following documents also apply where relevant and are incorporated by reference:
- the Privacy Policy;
- the Acceptable Use Policy;
- the CUBES Private Beta Program Terms;
- each Repository Access and Processing Authorization;
- the Data Processing Agreement, when applicable; and
- any order form, written beta invitation, or other signed agreement.
If documents conflict, a signed agreement or order form controls first, the Data Processing Agreement controls for processing of personal data, and the more specific document controls over the more general document for its subject matter.
4. Controlled private beta
CUBES is an experimental AI-assisted software-analysis service. Features, integrations, models, outputs, availability, retention settings, and data-processing configurations may change during the beta.
The Service may contain errors, interruptions, incomplete analysis, false positives, false negatives, or other limitations. No production service-level commitment, guaranteed availability, response time, recovery objective, or support level applies unless separately agreed in writing.
We may introduce, remove, suspend, or modify beta functionality where reasonably necessary for testing, security, legal compliance, provider changes, or operational integrity.
5. AI-assisted outputs and human review
The Service may use artificial intelligence, automated analysis, heuristics, and third-party models to generate reports, findings, recommendations, classifications, and other outputs ("Outputs").
Outputs may be incomplete, inaccurate, outdated, misleading, or unsuitable for a particular purpose. The Customer must ensure that a qualified human reviews Outputs before any action is taken.
The Service must not be used as the sole basis for decisions concerning production deployment, cybersecurity remediation, legal rights, financial or investment matters, employment, healthcare, credit, insurance, eligibility, safety-critical systems, regulated activities, or other high-impact decisions.
The Customer remains responsible for its decisions, implementation, validation, testing, and use or disclosure of Outputs.
6. Accounts, credentials, and security
The Customer is responsible for:
- maintaining the confidentiality and security of account credentials;
- restricting access to authorized personnel;
- promptly updating inaccurate account or business information;
- promptly reporting suspected unauthorized access, credential exposure, security incidents, or misuse; and
- maintaining independent backups of repositories, documents, configurations, and other materials.
The Customer must not share credentials in a manner that defeats access controls or permit access by persons who are not authorized to act for the Customer.
7. Customer Content and repository authority
"Customer Content" means repositories, source code, documents, configuration, metadata, prompts, instructions, files, and other materials submitted, uploaded, connected, or made available by or for the Customer.
As between the parties, the Customer retains its rights in Customer Content. The Customer represents and warrants that it has all rights, permissions, notices, lawful bases, and authority required to:
- provide or connect the Customer Content;
- instruct CUBES to access and process it;
- authorize access to each selected repository, branch, path, and integration; and
- permit the processing described in these Terms and the applicable Repository Access and Processing Authorization.
GitHub OAuth or another technical connection authenticates an integration but does not replace the Customer's separate legal authorization.
8. Limited processing license
The Customer grants the Operator and its authorized service providers a limited, non-exclusive, worldwide, revocable license to access, copy, transmit, host, cache, analyze, transform, and otherwise process Customer Content only as reasonably necessary to:
- provide the requested Service and Outputs;
- operate, secure, troubleshoot, and support the Service;
- prevent fraud, abuse, or security threats;
- comply with the Customer's documented instructions and applicable agreements; and
- satisfy legal obligations or protect legal rights.
This license does not transfer ownership of Customer Content to the Operator. Revocation or termination ends future authorized processing, subject to technical deletion cycles and retention reasonably required for security, legal compliance, dispute resolution, or defense of legal claims.
9. Data eligibility and restricted content
Before connecting or submitting content, the Customer must accurately disclose the intended purpose and whether the content includes personal data, regulated data, or secrets.
The Customer must remove or rotate passwords, access tokens, private keys, production credentials, certificates, and unnecessary live customer data before connection.
Unless CUBES gives prior written approval and all required safeguards and agreements are in place, the Customer must not submit or connect:
- special-category, health, biometric, payment-card, government-identifier, children's, employee-monitoring, or similarly regulated data;
- data subject to professional secrecy or sector-specific restrictions that prohibit the intended processing;
- production secrets or credentials; or
- content the Customer is not legally authorized to access or process.
Where personal data is processed on behalf of the Customer, the applicable Data Processing Agreement and approved processing configuration must be in place before processing begins.
CUBES may block, pause, or require manual review of a repository or analysis where the data classification is incomplete, inconsistent, or presents elevated legal or security risk.
10. Acceptable use
The Customer must comply with the Acceptable Use Policy and must not use the Service to:
- violate applicable law, regulation, sanctions, court orders, or third-party rights;
- access, analyze, or disclose content without authorization;
- introduce malware or harmful code;
- probe, bypass, disable, or interfere with safeguards, rate limits, access controls, or monitoring;
- misrepresent the source, accuracy, scope, or status of Outputs;
- conduct unlawful surveillance, discrimination, deception, or harmful activity; or
- use the Service in a way that creates unreasonable security, legal, or operational risk.
11. Third-party services and subprocessors
The Service may depend on GitHub, hosting and storage providers, AI providers, communications providers, monitoring providers, and other subprocessors or integrations.
Their availability, functionality, and terms may affect the Service. The Customer authorizes the use of providers identified in the Privacy Policy, applicable Data Processing Agreement, Security Statement, or current subprocessor information, subject to the agreed processing configuration.
We are not responsible for third-party services outside our reasonable control, but this does not limit obligations that cannot lawfully be excluded or obligations expressly accepted in a signed agreement or Data Processing Agreement.
12. Confidentiality
Each party may receive non-public technical, commercial, security, or business information of the other party ("Confidential Information"). The receiving party must use reasonable care to protect Confidential Information and use it only to perform or receive the Service.
Confidential Information does not include information that the receiving party can demonstrate was lawfully known without restriction, independently developed, received lawfully from another source without confidentiality duty, or made public without breach of an obligation.
A party may disclose Confidential Information where required by law, provided it gives advance notice where legally permitted and limits disclosure to what is required.
13. Service, intellectual property, and Outputs
The Operator and its licensors retain all rights in the Service, software, workflows, models, interfaces, documentation, branding, and general technology, excluding Customer Content.
Subject to these Terms, the Customer may use Customer-specific Outputs for its internal business purposes. Rights in an Output do not override rights in Customer Content, third-party materials, open-source software, or other underlying content, and no warranty is given that an Output is protectable or free of third-party rights.
The Customer must not remove proprietary notices, copy or resell the Service itself, or reverse engineer the Service except to the limited extent such restriction is prohibited by applicable law.
14. Feedback
The Customer may provide suggestions, evaluations, or other feedback. The Operator may use feedback to improve the Service without payment or restriction, provided that this does not transfer ownership of Customer Content, Customer Confidential Information, or Customer-specific Outputs.
15. Suspension and termination
We may suspend or restrict access where reasonably necessary to:
- address a violation of these Terms or the Acceptable Use Policy;
- respond to suspected unauthorized access, abuse, or security risk;
- comply with law or a binding request;
- protect the Customer, other users, providers, or the Service; or
- manage or end the private-beta program.
Where reasonably practicable, we will provide notice and an opportunity to remedy a curable issue. Immediate action may be taken where delay would create material risk.
The Customer may stop using the Service and revoke integrations at any time. Provisions concerning ownership, confidentiality, accrued obligations, disclaimers, liability, indemnification, dispute resolution, and lawful retention survive termination as applicable.
16. Privacy and data protection
Personal data is handled as described in the Privacy Policy. Where CUBES acts as a processor on behalf of the Customer, the applicable Data Processing Agreement governs that processing.
The Customer is responsible for determining whether it has a lawful basis and has provided required notices for personal data included in Customer Content. CUBES may require a no-personal-data configuration, executed Data Processing Agreement, or manual approval before processing begins.
17. Disclaimers
To the maximum extent permitted by law, the Service and Outputs are provided "as is" and "as available" without warranties of uninterrupted availability, accuracy, completeness, merchantability, fitness for a particular purpose, non-infringement, or achievement of any particular result.
CUBES does not provide legal, financial, investment, security-certification, audit, employment, healthcare, or other regulated professional advice. A report or finding is not a certification that a system is secure, compliant, error-free, or fit for production.
Nothing in these Terms excludes any warranty, right, or remedy that cannot lawfully be excluded.
18. Limitation of liability
To the maximum extent permitted by law, neither party is liable under these Terms for indirect, incidental, special, exemplary, punitive, or consequential loss, or for loss of profit, revenue, opportunity, goodwill, or data, arising from use of or inability to use the Service.
To the maximum extent permitted by law, the Operator's total aggregate liability arising out of or relating to the Service or these Terms will not exceed the amount paid by the Customer for the Service during the twelve (12) months preceding the event giving rise to the claim.
These limitations do not apply to liability that cannot lawfully be limited and do not exclude liability for fraud, fraudulent misrepresentation, willful misconduct, or other liability that applicable law requires to remain unlimited.
19. Indemnification
To the extent permitted by law, the Customer will defend and indemnify the Operator against third-party claims, damages, liabilities, and reasonable costs arising from:
- Customer Content or the Customer's instructions;
- the Customer's lack of authority or required rights;
- unlawful or unauthorized use of the Service;
- breach of these Terms or the Acceptable Use Policy; or
- infringement of third-party rights by materials supplied by the Customer.
This obligation does not apply to the extent a claim was caused by the Operator's breach, willful misconduct, or unauthorized use of Customer Content.
20. Changes, notices, and re-acceptance
We may update these Terms to reflect changes in the Service, law, risk, providers, or business operations. Each published version will have an identifiable version and effective date.
For a material change, CUBES may require an authorized representative to affirmatively accept the new version before continued access, repository connection, or analysis. Continued use alone does not replace required re-acceptance.
Non-material notices may be delivered through the Service, account interface, or email. The Customer is responsible for maintaining current contact details.
21. Assignment
The Customer may not assign these Terms without the Operator's prior written consent, except as part of a merger or transfer of substantially all relevant business assets where the assignee agrees to be bound by these Terms.
The Operator may assign these Terms in connection with incorporation, restructuring, financing, merger, sale, or transfer of the Service, provided that the assignment does not reduce mandatory rights or applicable data-protection obligations.
22. Governing law and jurisdiction
These Terms are governed by the laws of Italy, without regard to conflict-of-law rules.
Subject to any mandatory jurisdiction or rights that cannot lawfully be excluded, disputes will be subject to the exclusive jurisdiction of the competent courts in Italy.
23. Force majeure
Neither party is liable for delay or failure caused by events beyond its reasonable control, including widespread infrastructure failures, third-party outages, natural disasters, war, labor disputes, governmental action, or interruption of essential communications, provided that the affected party uses reasonable efforts to mitigate the impact.
24. General terms
If a provision is unenforceable, it will be limited or removed only to the minimum extent necessary, and the remaining provisions remain effective.
Failure to enforce a provision is not a waiver. Headings are for convenience only. These Terms and the documents incorporated under Section 3 form the agreement concerning the Service unless a signed agreement states otherwise.
25. Contact
Legal notices and contractual questions must be submitted using the current contact details published on the CUBES Legal / Contact page.
End of Terms of Service