Last updated 9 October 2026.
Introduction
These Terms of Service ("Terms") govern your access to and use of Code Security, FDIE and this website, operated by MAGDOX Private Limited ("MAGDOX", "we", "us" or "our"), a company incorporated under the laws of India with registered address at St No. 8, Arabinda Nagar, Barbani, Bardhaman, Hindustan Cables, West Bengal 713335, India. These Terms constitute an electronic record under the Information Technology Act, 2000. By accessing or using the Service, you agree to these Terms. If you are agreeing on behalf of an organisation, you confirm that you have the authority to bind that organisation. Code Security and FDIE are for business and professional use: by creating an account, accepting an invitation or buying a plan you confirm that you act for a business, profession or organisation and not as a consumer. The Service is intended for users who are at least 18 years old. If you are under 18, you may not use the Service.
1. How these terms fit together
For customer engagements, these Terms are supplemented by an Order Form (or engagement agreement) and, where applicable, a Data Processing Agreement (DPA). If a signed Order Form or Master Service Agreement (MSA) conflicts with these Terms, the signed document controls for that customer. Applicable DPA provisions govern personal-data processing, and mandatory transfer-clause provisions prevail over conflicting commercial terms.
These Terms incorporate the Product and Deployment Schedules and Information Security Addendum. Our Privacy Policy is a processing notice, not consent to optional processing. The MSA applies when executed or expressly incorporated into an accepted order. A DPA and any required transfer annexes must be agreed before covered processing begins.
2. The two Magdox products
MAGDOX Code Security is a source-code security review service. It provides:
- The magdox command-line interface, which scans code on the customer's own machines and in CI, verifies signed rule bundles and uploads nothing unless --upload is requested
- Static analysis findings with severity, evidence and traces, and dependency vulnerability matching against a vulnerability database built from NVD, OSV, EPSS and the CISA KEV catalogue
- Software, cryptographic and AI component inventories (CycloneDX and SPDX SBOMs, CBOM, AIBOM), VEX documents and SARIF output
- A hosted dashboard and API that receive explicitly uploaded findings, with triage, pull-request comments and, depending on the plan, custom policies, signed webhooks and scheduled email reports
- The MAGDOX MCP server, which lets AI assistants on the user's machine run the installed CLI
- Optional AI review of findings, using a model provider the customer configures
Code Security is offered in three plans, priced per developer. A developer, and so a seat, is a member of the organisation with CLI (SuperUser) product access, together with each open invitation for that access. Members with dashboard-only access, such as viewers, managers and auditors, are not charged.
- Team: US$39 per developer a month, or US$399 per developer a year, for up to 20 developers and up to 3 CI tokens. Team includes every scanner, the findings workflow, reports and exports, pull-request comments and the CLI quality gate.
- Business: US$99 per developer a month, or US$999 per developer a year, with no limit on developers or CI tokens. Business adds risk management, the organisation-wide software inventory, the audit log, trends and history, scheduled organisation reports, signed webhooks and custom policies evaluated on every upload.
- Enterprise: by written agreement. MAGDOX sets the seats, term, price and invoicing. Enterprise adds SAML single sign-on for email domains your organisation verifies by DNS, and offline and air-gapped CLI licences that your Super Admins and admins issue within your seats and that end with the agreement.
A Super Admin buys Team or Business online (Section 6). Enterprise, and evaluations MAGDOX arranges, are set out in an Order Form or applied with an Enterprise key MAGDOX issues; the agreement records seats, retention, deployment (hosted in India, or a self-hosted dashboard by arrangement) and support level. The Pricing page and the plan shown in the dashboard at purchase describe what each plan includes. Installing the CLI does not grant access to scans or signed rules. Later website edits do not silently change an existing signed scope or a period already paid for.
FDIE (Firmware Delta Intelligence Engine) analyses authorised firmware images in the selected hosted or customer-operated deployment. Its capabilities include supported extraction, component identification, vulnerability matching, static checks, bounded emulation/fuzzing, release comparisons, threat review and SBOM, CBOM, VEX and report exports. Self-service and Enterprise include the capabilities, subject to image support and configured resources.
FDIE self-service starts at US$499/month or US$4,999/year for 2 seats, 100 GB retained storage and 30 new-image analyses per calendar month. Extra seats, storage and analysis packs are priced in the Product and Deployment Schedules and FDIE Pricing page. An FDIE seat counts every person who can sign in, regardless of role; pending invitations reserve capacity. There is no free trial; the first payment has the 14-day money-back guarantee in Section 6.6.
FDIE Enterprise specifies seats, storage, any monthly allowance, dedicated/shared/on-premises hosting and support in an Order Form. Magdox is the supplier of both products. Each subscription licenses only the product and scope purchased; this website consolidation does not create a shared dashboard, billing account or cross-product entitlement.
3. Your account
For Code Security, you can create an account and a new organisation yourself, after confirming your email address and accepting these Terms, or your organisation's administrators can invite you. Either way you provide accurate, current information. The person who creates an organisation is its first Super Admin; only Super Admins can buy, change or cancel its plan and see its invoices. You are responsible for:
- Keeping your credentials, CLI tokens, activation keys, recovery codes and device key files confidential, and not copying them between machines
- Configuring authentication options, including two-step verification and single sign-on where available, appropriately for your organisation
- Revoking access when a person leaves your organisation
- All activity under your account and tokens
Code Security single sign-on. If your organisation connects its own identity provider, you are responsible for that provider, for who it lets sign in and for keeping it configured correctly. Single sign-on applies only to email domains your organisation has verified with a DNS record, and only people your organisation has invited are admitted. Keep the record in place: we check it every day, and a domain whose record has been missing for seven days stops being verified. If you require single sign-on, members on verified domains can no longer use a password, Google, GitHub or an email code; keep at least one Super Admin able to sign in another way. Only a Super Admin can connect or replace the identity provider or change the sign-in policy, after confirming their identity again. If you use SCIM provisioning, keep its token secret: whoever holds it can add and remove members, and people your identity provider deactivates lose access to your organisation.
FDIE organisations can start through hosted self-service or an agreed Enterprise setup. Authorised administrators manage users and the subscribed resources using FDIE settings. Supported OIDC single sign-on, MFA and recovery require the deployment's configuration; the Code Security domain-verification procedure is not a statement that FDIE uses the same protocol or membership flow. Only the Super Admin can change the identity provider, after entering their password and, where one is set up, an authenticator code. If you use SCIM provisioning, keep its token secret: whoever holds it can add and remove members, and people your identity provider deactivates lose access to your organisation.
If you suspect unauthorised access, tell us immediately at security@magdox.io.
Account and organisation deletion. Nobody deletes their own account. In both products a Super Admin of the organisation deletes members' accounts and can restore them for 30 days; a Super Admin or an admin can instead remove a member from the organisation, which keeps the person's account. A Super Admin can delete the whole organisation (in Code Security under Settings, Danger Zone; in FDIE under Settings, Data & Privacy) after typing DELETE and confirming with their password or authenticator code. Everyone is then signed out at once, API keys and tokens stop working, renewal is paused, no new analyses, scans or scheduled jobs run, and every member is emailed. The data is erased after 30 days unless a Super Admin signs in before then and reactivates the organisation; a reactivated organisation whose plan has ended must choose a plan again. If a period already paid for runs past the deletion date, the subscription ends on that date without a refund for the rest of the period. MAGDOX staff can also delete an account or an organisation, on the same 30-day schedule or, when there is a verified reason, at once. A Super Admin who wants their own account deleted makes another member Super Admin, who can then delete it, or writes to privacy@magdox.io. Privacy Policy Section 13.4 describes the exceptions and what is kept after erasure.
4. User representations
By using the Service, you represent and warrant that:
- All information you submit is true, accurate, current and complete, and you will promptly update it as it changes
- You have the legal capacity to agree to these Terms and are not a minor in the jurisdiction where you reside
- You will not access the Service through automated means except through the CLI, the MCP server and our documented API, within your plan's usage limits
- Your use of the Service will not violate any applicable law or regulation
If any information you provide is untrue, inaccurate or incomplete, we may suspend or terminate your account.
5. Acceptable use
You agree not to:
- Scan or upload code, firmware or other materials your organisation does not have the right to analyse, or misuse third-party intellectual property
- Enable code snippets for repositories whose content your organisation may not share with a processor
- Use the Service to develop or distribute malware for abuse, compromise the platform, or attack systems without authorisation; intended analysis of potentially malicious samples is permitted
- Reverse engineer, decompile or extract the Service itself, including sealed rule bundles, except to the extent the law allows
- Circumvent licence checks, device binding, rate limits, usage quotas or other technical restrictions, or abuse the Service in a way that degrades it for other customers
- Use the Service in violation of export control or sanctions laws (see Section 21)
- Systematically retrieve data from the Service to build a separate collection, other than your own organisation's normal use of the documented API
- Trick, defraud or mislead us or other users, including attempting to obtain another user's credentials
- Circumvent, disable or interfere with security features of the Service
- Impersonate another user, or use another user's account or token without authorisation
- Use the Service to build, operate or support a product that competes with it
As the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 require, you must not host, display, upload, modify, publish, transmit, store, update or share through the Service any information that: belongs to another person and to which you have no right; is obscene, pornographic, paedophilic, invasive of another's privacy including bodily privacy, insulting or harassing on the basis of gender, racially or ethnically objectionable, relates to or encourages money laundering or gambling, or promotes enmity between groups on grounds of religion or caste with intent to incite violence; is harmful to a child; infringes any patent, trademark, copyright or other proprietary right; deceives or misleads about the origin of a message, or knowingly and intentionally communicates misinformation or information that is patently false and untrue or misleading; impersonates another person; threatens the unity, integrity, defence, security or sovereignty of India, friendly relations with foreign States or public order, incites the commission of a cognisable offence, prevents the investigation of an offence or insults another nation; contains a software virus or other computer code, file or program designed to interrupt, destroy or limit the functionality of a computer resource, other than code or firmware your organisation is authorised to submit for its security analysis through the intended workflows; or violates any law in force. If we learn of such information, we may remove or disable access to it and suspend the account concerned; we keep removed information and the related records for 180 days, or longer where a court or lawful authority requires, for investigation. We remind users of these rules at least once a year.
AI review is optional and uses a model provider your organisation chooses. You are responsible for your agreement with that provider and for deciding which repositories may send excerpts to it. Approving a repository lets the CLI send redacted excerpts of that repository's code to the provider each time AI review runs.
If you run the MCP server in HTTP mode, you operate that listener. Keep its token secret, limit it to the folders you intend, and stop it when you are done: anyone holding the token can run read-only scans of those folders.
Analysing authorised code or firmware that contains vulnerabilities, secrets or malicious samples through the intended workflows is permitted. Good-faith research that complies with our Responsible Disclosure policy is governed by that policy's authorisation and safe-harbour terms. Restrictions here apply only to the extent permitted by law. We may suspend accounts for other violations of this policy.
6. Plans, fees and payment
6.1 Code Security plans bought online
A Super Admin can buy Team or Business monthly or yearly from the Plans page, for between 1 and 1,000 seats (up to 20 on Team) and at least as many seats as the organisation has developers (Section 2). Prices are in US dollars per developer. The price, seats and total shown at checkout are what you agree to pay for the period.
Payments are taken by Dodo Payments, which acts as merchant of record for these purchases: it processes the payment, calculates and collects any applicable tax at checkout, issues the invoice and handles payment disputes. Its terms also apply to the purchase. Your payment details are entered on its pages and never reach MAGDOX. Super Admins can download invoices under Settings, Plans.
6.2 Code Security renewal
A subscription renews automatically at the end of each monthly or yearly period, at the plan and seats then in effect, and the payment method on file is charged, until it is cancelled. A subscription that starts with a free trial (Section 7) is first charged when the trial ends.
6.3 Code Security cancellation
A Super Admin can cancel from Settings, Plans at any time. Cancellation takes effect at the end of the period already paid for: access continues until then, and a Super Admin can withdraw the cancellation before it takes effect. Cancelling during a free trial means nothing is charged, and access ends when the trial does. When the plan ends, members of the organisation can reach only the Plans page until a Super Admin chooses a plan again, the platform issues no new CLI leases or rule keys, and the CLI stops loading rules when its current lease ends (Section 15.8).
6.4 Code Security plan and seat changes
Moving to a higher plan, from monthly to yearly billing or to more seats takes effect immediately, with a prorated charge for the rest of the current period; if that charge fails, the change does not happen. Moving to a lower plan, from yearly to monthly billing or to fewer seats takes effect at the next billing date, with nothing charged before then, and can be withdrawn until that date. Moving to a plan without single sign-on switches single sign-on off for the organisation. Moving from Business to Team keeps your data and configuration, but the features Team does not include stop: webhooks and scheduled organisation reports are no longer sent, custom policies are no longer evaluated, and risk management, the software inventory, the audit log and trends are locked until the organisation is on Business again. Nothing is deleted because of the change.
6.5 Code Security failed payments
If a renewal payment fails, access continues for up to seven days while a Super Admin updates the payment method. If the payment still has not succeeded, access stops until it does or a Super Admin chooses a plan again.
6.6 Refunds and disputes
Fees are non-refundable except as these Terms or applicable law require. FDIE self-service has a 14-day money-back guarantee on an organisation's first payment: an authorised administrator can request a full refund from Settings → Billing within 14 days of that payment if the organisation has analysed no more than three new firmware images since it. The guarantee covers the first payment only (not renewals, later prorated charges or Code Security), applies once per organisation and once per person (the requesting administrator and the payer), and is paid by Dodo Payments to the original payment method. The refund ends the FDIE subscription at once: access stops and the organisation's data is then kept and deleted as for a subscription that has ended (Privacy Policy Section 10). It does not limit any non-waivable statutory right. If you terminate for our material breach that remains uncured under Section 19, or if we discontinue the Service, we refund the prepaid fees for the unused part of the term, pro rata. For Code Security, a full payment refund or payment dispute ends the subscription it paid for and access stops; a partial refund does not end the plan. An authorised export and non-waivable dispute/refund rights remain subject to these Terms and the DPA. Questions about a charge can be sent to support@magdox.io.
6.7 Enterprise agreements
Enterprise fees, term, seats and renewal are set out in the Order Form or other signed agreement, which prevails over this Section for that customer. MAGDOX Private Limited invoices Enterprise customers directly in the currency the agreement states (Indian rupees for customers in India, euros in the European Union, US dollars elsewhere, unless agreed otherwise). Invoices are payable by bank transfer within the terms stated on the invoice; a purchase order may be referenced for procurement but is not itself payment. Taxes, duties or levies applicable in your jurisdiction are stated on the invoice and are your responsibility. If an organisation with an online subscription redeems an Enterprise key, the subscription stops renewing and the period already paid for runs out.
6.8 FDIE self-service subscriptions
FDIE self-service is sold by Dodo Payments as merchant of record in US dollars, monthly or annually in advance, with tax shown at checkout. It renews for the selected period until an authorised administrator cancels through Settings → Billing. The first payment is taken at checkout; there is no free trial, and the first payment is covered by the money-back guarantee in Section 6.6. Cancelling stops the next renewal and access continues through the paid term. A payment failure has the grace and retry treatment shown in Billing; Code Security's seven-day grace is not a promise for FDIE.
FDIE resource additions take effect at once with the charge shown before confirmation: a new billing period starts that day, less the unused part of the current one. Fewer seats or less storage is credited against future charges as shown, and cannot go below occupied seats/invitations or retained storage. Fewer analysis packs takes effect at once without credit, and cannot be combined with adding seats or storage in the same change. Monthly new-image analyses reset on the first of each month (UTC), including annual subscriptions, without rollover. Failed analyses do not count; comparisons or intelligence rechecks of retained analysed images do not consume a new-image analysis. Deleting an image does not return the allowance. New uploads are blocked at the monthly limit until capacity is added or the month resets.
FDIE Enterprise pricing, currency, invoicing, resources, location and renewal are agreed in the Order Form. Neither product permits silently charging additional resources without an authorised purchase. Material price changes apply only through the accepted order or a notified future renewal process; they do not change a paid period retroactively.
7. Evaluations
7.1 Code Security online trial
Team and Business bought online start with a 14-day free trial, run by Dodo Payments at checkout. A payment method is required at checkout. During the trial you have everything in the plan you chose, except that CLI offline leases do not run past the trial end. Unless a Super Admin cancels before the 14 days end, the subscription continues and the payment method on file is charged for the first period at the price shown at checkout. Each organisation can have one trial: an organisation that has subscribed before starts without one.
7.2 Code Security evaluations MAGDOX arranges
Separately, MAGDOX can arrange an evaluation: we create your organisation and a Trial licence, your first administrator accepts the invitation, and the evaluation runs for the period stated in the licence. During the evaluation you have the capabilities agreed for it, not a cut-down demonstration.
Nothing is invoiced for an evaluation. An evaluation does not convert automatically into a paid subscription, and you will not be invoiced without your authorisation. If you do not subscribe when the evaluation ends, access to scans and uploads stops. Your organisation and its data are retained for 30 days so you can continue without losing anything, and are then deleted under the schedule in Privacy Policy Section 10.
7.3 FDIE evaluations
FDIE online self-service has no free trial and no permanent free tier: it is paid at checkout, and its first payment is covered by the 14-day money-back guarantee in Section 6.6.
A separately arranged FDIE Enterprise evaluation can run for 14 days with no automatic paid conversion or invoice. Dedicated and on-premises proofs of concept have agreed scope and delivery terms, separate from online checkout. An evaluation ending without purchase leaves a 30-day retention window before data becomes eligible for deletion, subject to earlier valid instructions.
8. Intellectual property
MAGDOX retains all right, title and interest in the Service, including FDIE's analysis software and the magdox CLI, MCP server, dashboards, the rule content and sealed rule bundles that drive analysis, the vulnerability database as compiled, and the documentation.
You and your licensors retain all rights to your source code, firmware, configuration and the findings, inventories, reports and other results derived from it (Customer Data). Source is analysed on your machines; any snippets you explicitly include are part of the uploaded Customer Data. You grant MAGDOX a limited licence to process Customer Data solely to provide, maintain and secure the Service and to comply with law.
MAGDOX does not train models on Customer Data. FDIE uses rule-based static analysis and supported sandboxed execution, not generative AI for findings. Code Security's optional AI review sends approved information directly to the customer's selected provider under its own agreement; MAGDOX does not receive those prompts and cannot promise the independent provider's practices. Other disclosures follow the Privacy Policy, DPA and customer instructions.
Feedback. If you send us feedback, suggestions or ideas about the Service (Submissions), you agree that we may use them for any purpose, including to improve the Service, without any obligation to compensate you. Submissions do not include Customer Data, which remains governed by the terms above.
9. Third-party websites and services
The Service links to or relies on third-party sources and services, including public vulnerability data (NVD, OSV, EPSS and the CISA KEV catalogue), source-control providers you connect, webhook destinations you configure and the AI provider you choose. We do not control and are not responsible for the content, accuracy or practices of these third parties, and each has its own terms. This does not remove MAGDOX's responsibilities for providers it appoints to process Customer Data under the DPA.
This product uses the NVD API but is not endorsed or certified by the NVD.
10. Confidentiality
Each party agrees to protect the other's confidential information with the same degree of care it uses for its own confidential information of a similar nature, and in any event no less than a reasonable standard of care. Each party agrees not to disclose the other's confidential information except as necessary to provide or use the Service, or as required by law.
Your code, firmware, configuration and the findings, inventories and evidence derived from them, are treated as your confidential information. MAGDOX pricing, roadmap, unreleased features and rule content are MAGDOX's.
This Section survives termination of these Terms for five (5) years, except for trade secrets, which remain protected for as long as they retain trade secret status.
Access is limited to people who need the information for the agreement and are bound by confidentiality. Protected information excludes material demonstrably public without breach, independently developed without its use, already lawfully known or lawfully received without restriction. Required disclosures are limited to what law requires, with advance notice and protective assistance where lawful. No residual-knowledge exception permits reuse of confidential customer material.
11. Force majeure
Neither party will be liable for any failure or delay in performing its obligations under these Terms (except payment obligations) to the extent caused by events beyond its reasonable control, including natural disasters, war, terrorism, riots, cyberattacks, denial-of-service attacks, cloud infrastructure or telecommunications outages, power failures or governmental restrictions. The affected party will promptly explain and mitigate the impact and resume performance. An event does not excuse a failure caused by that party's lack of required safeguards, or duties that remain capable of performance. Cyberattacks and provider outages are not blanket exemptions from security or confidentiality obligations.
12. Data protection and security
Our collection and use of personal data is described in our Privacy Policy. If you need a Data Processing Agreement, see our DPA.
The technical and organisational security measures we implement (encryption, access control, secrets management and audit logging) are described in our Information Security Addendum, which is incorporated into these Terms by reference.
Code Security and shared FDIE core hosting run in India; FDIE dedicated or customer-operated locations are agreed separately. Customers must have authority to provide the data and agree the applicable processing and transfer safeguards before covered data is transferred. Use of the Service is not, by itself, a substitute for a lawful transfer mechanism or any required data-subject consent. See our Privacy Policy and DPA.
13. Service availability
We aim to maintain high availability of the hosted Service. For Code Security, scanning with the CLI does not depend on the dashboard being reachable: with a cached licence, rules and vulnerability database, and with --offline, scans continue locally. Any contractual uptime commitment and associated service credits are set out in the Order Form. Credits are applied to future invoices and are not paid out as cash. FDIE hosted analysis depends on its application and worker services being available; it is not a local CLI workflow. Product-specific recovery objectives and limitations are stated in the Information Security Addendum, Section 7.
14. Services management and emergency suspension
We may monitor the Service for violations of these Terms and may restrict, suspend or remove content that is unlawful or infringes third-party rights.
Notwithstanding any cure period in Section 19, MAGDOX may immediately suspend or restrict access to any account or token without prior notice if we reasonably determine that it is being used to launch security attacks, abuse API limits, distribute malicious code, or pose an active threat to the Service or other customers. We will tell you why as soon as we reasonably can.
15. Analysis limits for Code Security and FDIE
15.1 Static analysis
MAGDOX Code Security performs rule-based static analysis of source code, configuration and infrastructure definitions, secrets detection and dependency matching. Results depend on the code, the CLI version, the rule bundle, configuration and the vulnerability database at the time of the run; the run metadata records these so results can be compared. Re-scanning unchanged code can add or retire findings when rules or vulnerability data change. A changed finding is not, by itself, evidence of a regression or a verified fix.
15.2 Vulnerability database timing
The vulnerability database is built by MAGDOX from NVD, OSV, FIRST EPSS and the CISA KEV catalogue, refreshed through approved platform builds and served to signed-in CLIs. The CLI caches it and revalidates it on later runs; offline, the cached or a pinned copy is used and may be older. The Service does not provide real-time vulnerability data, and a vulnerability published after the most recent build may not appear until the next one. An absent EPSS score is shown as not reported, never as low.
15.3 Detection limitations
Analysis covers the languages, frameworks, repository types and manifests documented on the Docs and Coverage pages. The Service cannot guarantee detection in these situations:
- Code in languages or frameworks outside documented coverage, or generated, minified or obfuscated code
- Behaviour that depends on runtime configuration, deployed infrastructure or data not present in the scanned files
- Dependencies not declared in a supported manifest or lockfile, vendored copies without identifiers, or packages named differently from the public databases
- Vulnerabilities described only in vendor advisories not indexed by the databases MAGDOX uses
- Secrets that do not match a recognised format, or that are split, encoded or encrypted
A dependency match does not establish that the vulnerable code is reachable or exploitable in your application.
15.4 Inventory and report completeness
SBOMs, CBOMs, AIBOMs, VEX documents and reports reflect what the analysis identified at the time of the run. They are not a complete or authoritative inventory of everything in a codebase.
15.5 AI review
AI review output is advisory. From CLI version 1.3.2 it is marked as AI-generated in the terminal and JSON output, in uploads and in the dashboard. Model output can be wrong, and proposed fixes are verified by a fresh scan but must still be reviewed by a person before use. The engine's finding is always reported; only with --ai-gate, which you choose, can a high-confidence false-positive verdict keep a finding from failing a CI gate. The quality, availability and terms of the model belong to the provider you choose.
15.6 Compliance is your responsibility
The Service provides findings, inventories and reports to help your security and supply-chain programmes. Using it does not, by itself, make you compliant with any framework or regulation. You remain solely responsible for validating results against your products, determining whether results trigger reporting or disclosure obligations, taking corrective action, and ensuring documents you submit to regulators, customers or other third parties meet their requirements.
15.7 Not a substitute for professional assessment
The Service is an automated analysis tool. It does not replace penetration testing, manual code review or expert security assessment. For high-assurance or safety-critical applications, supplement its output with appropriate professional review.
15.8 Offline use and lapsed plans
A CLI licence works offline for up to 7 days on Team, 30 days on Business and 90 days on Enterprise, bounded by the licence expiry and the signed grant, and never past the end of a trial, a cancelled subscription's last paid period or the grace after a failed payment. Perpetual offline and air-gapped licences are arranged for Enterprise. When an organisation's plan lapses, the platform issues no new leases or rule keys; the CLI stops loading rules when its current lease ends, and deletes its cached rule leases as soon as the platform tells it the plan has ended or access was withdrawn.
15.9 FDIE evidence and coverage
FDIE extraction and identification depend on image packaging, recoverable metadata, engine and feed context. Unsupported, encrypted or opaque regions remain unassessed. Supported CPU architecture alone does not guarantee execution of an image. SBOM, CBOM and VEX exports reflect recovered evidence and reviewed decisions, not guaranteed complete inventories.
FDIE runtime analysis is bounded by execution mode, resource limits and paths exercised. A loaded component does not prove exploitability; a shell launch does not prove injection; non-observation does not establish absence. FunctionDiff highlights patch candidates, but changed bytes, a version bump or disappearing finding are not verification of a fix. Carry-forward suggestions require analyst review. Older assessments may lack complete immutable stage/feed snapshots and cannot be assumed fully reproducible.
Framework grades concern assessed technical controls only. Customer must determine product scope, applicable law, reporting duties and conformity. CRA disclosure records and submission references do not automatically notify an authority or determine reportability. FDIE's TARA and EMB3D views need product and operational context beyond firmware bytes.
16. Corrections
The Service, including this website, may contain typographical errors or inaccuracies, including in plan descriptions, coverage or feature availability. We may correct these errors and update information at any time, without prior notice for non-material corrections. This does not override signed commercial terms or the change process in Section 23.
17. Disclaimers and limits on liability
EXCEPT FOR EXPRESS COMMITMENTS IN THE APPLICABLE AGREEMENT AND RIGHTS THAT CANNOT LAWFULLY BE EXCLUDED, THE SERVICE IS PROVIDED "AS IS" WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE OR NON-INFRINGEMENT.
Excluded losses. To the maximum extent permitted by law, neither party is liable for any indirect, incidental, special, consequential or punitive damages, or for loss of profits, revenue or goodwill, arising out of or related to these Terms, even if advised of their possibility. This exclusion does not apply to a party's fraud, gross negligence or wilful misconduct, to a party's indemnification obligations, to your obligation to pay fees properly due, or to any liability that cannot be limited or excluded under applicable law.
General cap. To the maximum extent permitted by law, each party's total liability arising out of or related to these Terms will not exceed the amount you paid for the Service in the twelve (12) months before the claim.
Enhanced cap for confidentiality and security breaches. The general cap does not apply to these two categories. Instead, each party's total liability for (a) breach of the confidentiality obligations in Section 10, or (b) breach of its own security obligations that results in unauthorised access to the other party's confidential information, will not exceed two (2) times the fees you paid for the Service in the twelve (12) months before the claim.
Carve-outs. Neither cap applies to:
- A party's indemnification obligations under Section 18
- Damages arising from a party's fraud, gross negligence or wilful misconduct
- A party's infringement of the other party's intellectual property rights outside the scope of the licence granted in these Terms
Nothing in this Section limits liability that cannot be limited or excluded under applicable law.
IN PARTICULAR, MAGDOX MAKES NO WARRANTY THAT THE SERVICE WILL DETECT ALL VULNERABILITIES, SECRETS OR DEPENDENCIES IN ANY CODEBASE OR FIRMWARE IMAGE, OR THAT AI REVIEW OUTPUT IS CORRECT. THE LIMITATIONS ABOVE APPLY TO CLAIMS ARISING FROM UNDETECTED ISSUES OR INCOMPLETE ANALYSIS, SUBJECT TO THE EXPRESS COMMITMENTS, ENHANCED CAP AND CARVE-OUTS IN THIS SECTION.
18. Mutual indemnification
18.1 Your indemnity to us
You agree to indemnify, defend and hold MAGDOX harmless from third-party claims arising out of your breach of these Terms, your misuse of the Service, or code or content you scan or upload in violation of Section 5.
18.2 Our indemnity to you
MAGDOX will indemnify, defend and hold you harmless from third-party claims alleging that the Service, as provided by MAGDOX and used in accordance with these Terms, infringes that third party's intellectual property rights, and will pay resulting damages finally awarded or agreed in settlement. This applies only if you promptly notify us of the claim, give us sole control of the defence and settlement, and provide reasonable cooperation.
For either indemnity, the protected party gives prompt notice, reasonable cooperation and control of the defence to the indemnifying party. Late notice reduces responsibility only to the extent materially prejudicial. No settlement may impose an admission or non-monetary obligation, or fail to release the protected party, without its written consent, not unreasonably withheld.
If such a claim arises or is likely to arise, MAGDOX may at its option and expense: (a) procure the right for you to continue using the Service; (b) replace or modify the Service so it becomes non-infringing; or (c) terminate the subscription and refund any prepaid, unearned fees.
This obligation does not apply to claims arising from your Customer Data or third-party materials, modifications not made by MAGDOX, or use of the Service in combination with products or services not provided by MAGDOX where the infringement would not have occurred without that combination.
19. Termination
Either party may terminate the Service for convenience at the end of the current term, or immediately for a material breach that remains uncured for 30 days after written notice. An authorised administrator ends an online plan using the product's billing controls (Section 6). Code Security's full-refund and payment-dispute treatment is described in Section 6.6.
When the Service ends, you will have at least 30 days to arrange an authorised export of your Customer Data. An earlier valid deletion instruction takes priority. Security or legal restrictions may require a supervised export instead of ordinary access. Deletion follows the Privacy Policy and any applicable DPA; the export window does not extend an agreed deletion deadline.
20. Electronic communications and signatures
By using the Service, you consent to receive communications from us electronically, including by email and through notices in the Service. You agree that these communications satisfy any legal requirement that they be in writing and that, to the extent permitted by law, electronic signatures and records have the same legal effect as physical ones.
21. Export compliance and sanctions
The Service may be subject to applicable export controls and economic sanctions. You must not obtain or use the Service where applicable law prohibits its provision to you, your organisation or the intended use, including relevant restricted-party prohibitions, and you must obtain any required authorisations. The applicable restrictions depend on the parties, product, destination and use; this clause does not impose a blanket prohibition based only on nationality.
22. Governing law and disputes
These Terms are governed by and construed in accordance with the laws of India, including the Information Technology Act, 2000 and rules made under it, without regard to conflict-of-laws principles. Any disputes arising under these Terms will be resolved in the competent courts of West Bengal, India.
Customers may negotiate an alternative governing law and venue in their Order Form or MSA. This Section does not override a separately negotiated governing-law clause.
23. Changes to these terms
We may update these Terms from time to time. Material changes will be communicated to the designated customer contact with their effective date. Posting a revision does not retroactively amend an executed MSA or Order Form; changes to those agreements follow their agreed amendment process. The last updated date at the top of this page reflects the most recent revision. Prior versions are archived and available on request.
24. General
These Terms, together with the Privacy Policy, DPA (where applicable), the plan you bought online or any Order Form, are the entire agreement between the parties about the Service and replace all prior agreements on the subject matter.
Failure by either party to enforce any provision will not be deemed a waiver of future enforcement. If any provision is held unenforceable, the remaining provisions stay in full force and effect. Notices under these Terms should be sent to the contact addresses in Section 25.
25. Contact
Questions about these Terms, and formal notices under them, can be sent to legal@magdox.io, through our Contact page, or by post to MAGDOX Private Limited, St No. 8, Arabinda Nagar, Barbani, Bardhaman, Hindustan Cables, West Bengal 713335, India. General enquiries: contact@magdox.io.