Acceptable Use Policy
This policy is part of the Terms of Service. It covers what you may and may not do with Atmos.
Scan code you are allowed to scan
Point Atmos at code you own or are authorized to analyze. Do not scan a third party's code in order to find vulnerabilities in their product without their permission, and do not upload findings whose file paths or traces you are not allowed to share with us.
Do not work around the plan you are on
The scan allowance, the seat count and the private repository limit are the product's commercial terms, not a technical inconvenience. Do not tamper with the license check, share one workspace token across teams that should hold their own, split one team across several Free workspaces to avoid paying for seats, or misrepresent a private repository as public to avoid metering. If you need more room, ask us and we will usually say yes.
Do not attack the service
No denial of service, no volumetric or automated load beyond normal product use, no probing another customer's data, no attempt to bypass authentication or tenant isolation. Security research is welcome and has its own route on the security page, which is the only sanctioned way to test us.
Do not take the product apart to rebuild it
Do not extract the managed ruleset or the advisory data to build or improve a competing product, and do not resell or host Atmos as a service for third parties. The full license terms are in section 6 of the Terms of Service.
Do not use Atmos to break the law
No use that is illegal where you are or where we are, no infringement of anyone's rights, no malware development or distribution, no exporting the software where an export control forbids it, and no use that harms people.
Keep your credentials to yourself
A workspace token is a credential. Keep it in a secret store or an environment variable, never on a command line and never committed to a repository. If one leaks, revoke it. You are responsible for what happens under your tokens.
What happens if you break this
We will normally tell you first and give you a fair chance to put it right. Where the breach is serious, ongoing, or a risk to other customers or to the service, we may suspend or terminate access immediately, as the Terms of Service allow. If you think we got that wrong, write to support@atmoslab.dev and a person will read it.
Reporting abuse
If you believe someone is using Atmos in a way this policy forbids, tell us at support@atmoslab.dev.