Legal · Terms
The Terms of Service Driftlock operates under.
The seven clauses that govern the service — acceptance, what counts as acceptable use, how billing runs through the installed Stripe Billing module, who owns the code and the audit trail, where liability is capped, the governing jurisdiction, and how changes are announced. The companion Privacy Policy and Security Posture cover the data-handling and SOC 2 surfaces these terms reference.
terms of service · seven clauses · MSA + DPA referenced
Terms of Service
Last updated: 2026-08-12 · effective immediately
The terms of service Driftlock operates under.
The clauses below cover the seven surfaces Driftlock commits to in writing: acceptance, acceptable use, subscription & billing (referencing the installed Stripe Billing module), IP ownership, limitation of liability, governing law, and how changes are announced. Enterprise customers operating under a master services agreement (MSA) accept that the MSA controls where it conflicts with these terms; the Data Processing Addendum (DPA) referenced on /legal/privacy governs personal data separately.
Acceptance
These terms govern your use of Driftlock, the audit-linked pull request service operated by the Driftlock team. By installing the GitHub App, by signing in to a managed deployment, or by using a self-hosted Driftlock deployment, you accept the terms in this document. If you have signed an enterprise master services agreement (MSA), the MSA controls where it conflicts with these terms; nothing in this document narrows an MSA. Data-processing terms live in the separate Data Processing Addendum and are not repeated here.
Acceptable use
You agree to use Driftlock only on repositories you are authorised to modify, on signal sources (Dependabot, CI, on-call rotations, SBOM feeds) that you or your organisation operate, and with approver groups whose members have consented to receive pull-request review requests from the service. You must not use Driftlock to bypass a change-control process your organisation has put in place, and you must not use Driftlock to issue pull requests against repositories you do not have write access to. You must not reverse engineer, decompile, or attempt to extract the source code of the sandboxed test runner, and you must not circumvent the rate limits, signing checks, or audit-trail linkage that the platform enforces. Enterprise tier customers operating the sandbox in their own VPC accept that the same acceptable-use rules apply to every principal the customer federation issues credentials to.
Subscription & billing
Billing runs through the installed Stripe Billing module on every tier — Driftlock does not invoice directly and does not store raw payment-card numbers. The Team tier bills per seat annually, with the seat count set at the start of each billing period and adjustable upward at any time; downward adjustments take effect at the next renewal. The Platform and Enterprise tiers are annual commits, with the seat minimum named on the order form; mid-period additions are pro-rated against the remaining term. All recurring charges are processed via Stripe Connect against the Connect operating entity named on your invoice. Cancellation is effective at the end of the current billing period; Driftlock does not offer mid-period refunds except as required by applicable law. Failed charges retry on a documented schedule (four attempts across fourteen days, with email notice before each attempt) before access is paused and the audit-trail pipeline is wound down. Prices on the pricing page are exclusive of taxes; applicable sales tax, VAT, and GST are added at checkout per the billing address on file. The Stripe Data Processing Addendum applies to payment data in addition to the Polsia DPA referenced on /legal/privacy.
IP ownership
Driftlock retains ownership of the Driftlock service itself — the application runtime, the sandboxed test runner, the audit-trail append-only ledger, the brand marks (the wave-into-check mark, the wordmark, the trade dress), and the documentation published under the Driftlock name. You retain ownership of the code in your repositories, the data you ingest into Driftlock (signal payloads, alert identifiers, SBOM feeds), and the audit-trail entries produced by your repositories — the per-PR audit row is your data, not Driftlock’s, and on the Enterprise tier it never leaves your storage boundary. Driftlock retains a non-exclusive, royalty-free licence to use the audit-trail entries on your behalf for the sole purpose of operating the service (signing, retention, regulator-time export). Feedback you send in (issue threads, support tickets, design conversations) may be used by Driftlock to improve the service without obligation of attribution or compensation; the same feedback does not include the contents of your repositories.
Limitation of liability
Driftlock is provided as an audit-linked drafting aid. You remain the final reviewer on every pull request; Driftlock does not merge on your behalf and does not approve on your behalf. Driftlock is not liable for downstream consequences of a pull request you approved, and Driftlock is not liable for incidents traced to a trigger you misconfigured — for example, an on-call severity threshold set lower than your platform team intends, or a Dependabot schedule that fans out faster than your reviewers can triage. To the maximum extent permitted by applicable law, Driftlock’s aggregate liability under these terms is capped at the fees paid by you to Driftlock in the twelve months immediately preceding the event giving rise to the claim, or USD 100, whichever is greater; the cap applies to the Team and Platform tiers in their standard form. Enterprise tier customers accept the liability cap named in the MSA, which controls in any conflict with the standard cap. Nothing in this clause limits liability that cannot lawfully be excluded — for example, fraud, death, or personal injury caused by negligence.
Governing law
These terms are governed by the laws of the jurisdiction in which the Driftlock operating entity is incorporated, without regard to its conflict-of-laws principles. The competent courts of that jurisdiction hear any dispute arising out of or relating to these terms, except where an applicable mandatory consumer-protection law gives you the right to bring an action in your home jurisdiction. Enterprise deployments operating under a master services agreement are governed by the laws specified in that agreement; nothing in this document narrows an MSA’s choice-of-law or venue clauses. Data-processing terms live in a separate Data Processing Addendum and are governed by the laws stated there.
Changes to these terms
Material changes to these terms are announced at least thirty days in advance by email to the operator contact on file and by a notice banner on this page. Continued use of Driftlock after the effective date of the change constitutes acceptance of the new terms; if you do not accept the change, you may stop using Driftlock before the effective date and revoke the GitHub App installation from your organisation settings. Non-material changes (corrections of typos, link updates, heading wording that does not alter meaning) ship without a thirty-day notice. The current set of terms replaces every prior version from the effective date forward; archived versions remain available on request to the contact email on this page.
terms of service · seven clauses · MSA + DPA referenced
Questions about the terms?
Contract, MSA, and DPA questions all flow to one inbox.
Terms-of-service questions, contract review requests, and DPA negotiations land on the same inbox. For Enterprise customers operating under an MSA, route the request through your nominated contracts contact and we'll reply on the MSA timeline.