arrow_backBack to home

Terms of Service — VibeScan

Last updated: August 6, 2026 Effective date: August 6, 2026

1. Acceptance of terms

By creating an account, verifying domain ownership, connecting a GitHub repository, authorizing a scan, or using VibeScan in any way, you agree to these Terms of Service ("Terms"), and to the Privacy Policy, Cookie Policy, Refund & Cancellation Policy, and the applicable scan authorization, all of which are incorporated by reference.

2. What VibeScan is

VibeScan is a consent-based security scanning service. We scan web applications and source-code repositories for common vulnerability patterns — particularly ones associated with AI-assisted ("vibe-coded") development — and return a plain-English report with suggested fixes.

VibeScan is not:

  • A general penetration-testing service
  • A guarantee of security or freedom from vulnerabilities
  • A substitute for a full professional security audit
  • Legal or compliance advice

3. Eligibility & authorization

You may only scan assets you own or are authorized to test:

  • Website scans: you must verify domain ownership (DNS TXT record) before any scan begins.
  • Repository scans: you must connect the repository through GitHub's authorization flow, which confirms you have access to it. Connecting a repository authorizes VibeScan to clone and analyze it for the purpose of scanning.

Submitting a domain or repository you are not authorized to test is a violation of these Terms and may expose you to independent legal liability.

4. Consent & authorization requirement

No scan is performed without a valid authorization tied to the specific target:

  • For websites, a verified, timestamped authorization tied to the exact domain(s) in scope.
  • For repositories, your GitHub authorization granting access to the specific repositories you connect.

That authorization defines the scope and the test types performed. VibeScan never performs destructive testing, data exfiltration, denial-of-service, social engineering, or automated/manual exploitation beyond the minimum necessary to confirm that a finding exists.

5. Scope of service

VibeScan currently offers two independent features; you may use one, both, or neither:

  • Feature A — Website scan: a passive + light-active scan of a verified domain (security headers, exposed sensitive paths, common misconfiguration, outdated client-side JavaScript libraries, and TLS/SSL configuration).
  • Feature B — Repository scan: static analysis of a connected GitHub repository, using a combination of open-source scanning tools and VibeScan's own rules to detect insecure code patterns, vulnerable dependencies (known CVEs), committed secrets, and infrastructure-as-code misconfigurations.

Scans can be triggered from the VibeScan dashboard, via the VibeScan API, or via the VibeScan MCP server for supported AI coding tools. On paid plans, verified domains can also be scanned automatically on a recurring schedule ("auto-scan") — see your plan's details on the pricing page for frequency.

Not included: authenticated scanning (logging in as a test user), and multi-tenant team accounts.

Absence of findings is not a certification of security — see Section 9.

6. Plans, fees & payment

VibeScan is offered on a recurring monthly subscription basis. All plans, including Free, receive the full plain-English report with fixes — plans differ by daily scan limit, API/MCP access, and auto-scan frequency:

  • Free — no charge, no card required. 5 scans/day, full plain-English reports, limited API and MCP-triggered scans (counted against the same daily limit), weekly auto-scan of your verified domain(s).
  • Pro — $9.99/month — 15 scans/day, full plain-English reports, unlimited API access, unlimited MCP-triggered scans, auto-scan 3 times per week.
  • Max — $19.99/month — 30 scans/day, full plain-English reports, unlimited API access, unlimited MCP-triggered scans, daily auto-scan.

Exact plan names, prices, and limits are shown on our pricing page and may change with notice; the pricing page governs in the event of a discrepancy with this section.

Payment is processed by Dodo Payments, acting as merchant of record — your billing statement may show "Dodo" or "Dodo Payments" rather than "MakeLabs" or "VibeScan." By subscribing to a paid plan, you authorize Dodo Payments to charge your payment method on a recurring basis until you cancel. See the Refund & Cancellation Policy for how cancellations, refunds, and plan changes are handled.

7. Your obligations

You agree to:

  • Provide accurate ownership and contact information
  • Only authorize scans against domains, repositories, or assets you own or are legally authorized to test
  • Not use VibeScan's reports to attack, exploit, or gain unauthorized access to any system — including the one you had scanned or any third party's
  • Not attempt to use VibeScan's infrastructure, tokens, or reports for any unlawful purpose
  • Keep your account credentials and any connected GitHub authorization secure

8. Report confidentiality

Scan results and findings are disclosed only to you, the authorizing party, unless disclosure is required by law. We do not sell or share your findings with third parties. See the Privacy Policy for full data-handling detail, including how repository source code is deleted after each scan.

9. Disclaimers

  • VibeScan makes no guarantee that a scan identifies all possible vulnerabilities. Absence of findings is not a certification of security.
  • VibeScan is not liable for any pre-existing vulnerabilities discovered during a scan, or for how you choose to act (or not act) on a report.
  • The service is provided "as is" and "as available," without warranties of any kind, express or implied, to the maximum extent permitted by law.

10. Limitation of liability

To the maximum extent permitted by applicable law, VibeScan's and MakeLabs' total liability arising out of or related to these Terms or the service is limited to the amount you paid for the plan in the month giving rise to the claim (and is zero where the service was used free of charge). We are not liable for indirect, incidental, consequential, or punitive damages.

11. Indemnification

You agree to indemnify and hold VibeScan and MakeLabs harmless from claims arising out of your breach of these Terms, including scanning a domain or repository you were not authorized to test.

12. Termination

We may suspend or terminate your access if you violate these Terms, including submitting a target without valid authorization. You may stop using VibeScan at any time and disconnect any connected repository; see the Refund & Cancellation Policy for how this affects any paid plan.

13. Governing law & disputes

These Terms are governed by the laws of India. Any dispute arising out of these Terms will be subject to the exclusive jurisdiction of the courts of Udupi, Karnataka.

14. Changes to these terms

We may update these Terms from time to time. Material changes will be notified to registered users before taking effect.

15. Contact

MakeLabs (sole proprietorship), Udyam Registration Number UDYAM-KR-26-0061081. Support: support@usevibescan.com. See our Contact page for full details, including our Grievance Officer.