Terms of Service
Last updated: January 2026
Welcome to Repoloom. These Terms of Service ("Terms") govern your use of our security scanning platform and services ("Service"). By accessing or using Repoloom, you agree to be bound by these Terms.
Repoloom is a code security platform that scans your repositories for vulnerabilities, secrets, outdated dependencies, and other security issues.
Operator: Repoloom is operated by Tim Fischer, an independent software developer based in Switzerland. This is not a registered company but a sole proprietorship (Einzelunternehmen).
To use Repoloom, you must:
- Be at least 18 years old or have parental consent
- Provide accurate and complete registration information
- Authenticate via a supported OAuth provider (GitHub or GitLab)
- Be responsible for maintaining the security of your account
- Notify us immediately of any unauthorized access to your account
You are responsible for all activities that occur under your account. We reserve the right to suspend or terminate accounts that violate these Terms.
Repoloom provides the following security scanning capabilities:
- Dependency Scanning: Detection of known vulnerabilities (CVEs) in your project dependencies
- Secret Detection: Identification of exposed API keys, tokens, and credentials
- SAST Analysis: Static Application Security Testing for code vulnerabilities
- Outdated Package Detection: Identification of packages with available updates
- End-of-Life Detection: Detection of deprecated or unsupported packages
- Container Scanning: Security analysis of Docker containers (Pro tier)
Repoloom offers different subscription tiers with varying features and limits. Payment processing is handled securely through Stripe.
- Subscriptions are billed monthly or annually as selected
- Trial periods, when offered, are subject to specific terms
- You may cancel your subscription at any time through the billing portal
- Refunds are handled on a case-by-case basis
- We reserve the right to change pricing with 30 days notice
You agree not to:
- Use the Service for any illegal purpose or in violation of any laws
- Attempt to gain unauthorized access to any systems or networks
- Interfere with or disrupt the integrity or performance of the Service
- Use the Service to scan repositories you do not own or have authorization to scan
- Reverse engineer, decompile, or attempt to extract source code from the Service
- Resell, sublicense, or share your account access with third parties
- Use automated means to access the Service beyond the provided API
By connecting your GitHub or GitLab account, you grant Repoloom permission to:
- Read repository metadata and content for security scanning
- Access dependency manifest files (package.json, requirements.txt, etc.)
- Read source code for SAST analysis
- Access Dockerfile and container configurations for container scanning
We access repositories only when you explicitly add them for scanning. You can revoke access at any time by removing repositories or disconnecting your OAuth connection.
We take security seriously. Our security practices include:
- Encryption of OAuth tokens at rest
- Secure HTTPS connections for all data transmission
- HTTP-only cookies for session management
- Regular security audits and updates
For detailed information about data collection and processing, please refer to our Privacy Policy.
Repoloom and its original content, features, and functionality are owned by Repoloom and are protected by international copyright, trademark, and other intellectual property laws.
You retain all rights to your repositories and code. We claim no ownership over your content. Scan results and reports generated by Repoloom are provided for your use and may be exported or shared at your discretion.
The Service is provided "as is" and "as available" without warranties of any kind, either express or implied. We do not guarantee that:
- The Service will be uninterrupted, secure, or error-free
- All security vulnerabilities will be detected
- Scan results are complete or accurate in all cases
- The Service will meet all of your requirements
Security scanning is a tool to assist in identifying potential issues. It does not replace manual security reviews or professional security audits.
To the maximum extent permitted by law, Repoloom shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including but not limited to loss of profits, data, or business opportunities.
Our total liability for any claims arising from your use of the Service shall not exceed the amount you paid us in the twelve (12) months prior to the claim.
We may terminate or suspend your access to the Service immediately, without prior notice, for any reason, including breach of these Terms.
Upon termination, your right to use the Service will cease immediately. You may request deletion of your data by contacting us. Certain data may be retained as required by law or for legitimate business purposes.
We reserve the right to modify these Terms at any time. We will notify you of material changes by posting the new Terms on this page and updating the "Last updated" date.
Your continued use of the Service after changes constitutes acceptance of the new Terms. If you do not agree to the new Terms, you must stop using the Service.
If you have any questions about these Terms, please contact: