Terms of use

Gawlo is pre-release. This page states, in plain language, what we expect of you and what you can expect of us. It is a summary, not a negotiated contract — if you need signed terms, email us.

Scan only what you are allowed to scan

Gawlo sends real traffic — including adversarial prompts and vulnerability probes — at whatever target you point it at. You must own that target or have documented permission to test it. Scanning systems you are not authorised to test may be illegal, and you are responsible for that decision, not us.

What the results are, and are not

Findings are evidence-backed: each one includes the request and response that produced it. They are not a certification, an audit, or a guarantee that anything else is secure. A clean scan means the checks that ran found nothing — not that your system is safe. AI-generated remediation is a suggestion to review, never a patch to apply blindly.

Your account

Keep your credentials and API keys to yourself; you are responsible for activity under your account. Do not use Gawlo to attack third parties, to resell scanning capacity, or to circumvent the limits of your plan. We may suspend an account that does.

Availability during pre-release

We do not promise uptime, retention, or backwards compatibility while Gawlo is pre-release. Features can change and data can be migrated. We will tell you before anything destructive happens to your data.

Questions

Anything unclear, or you need terms your legal team can sign? Email support@gawlo.dev.