Qopanza is offered to businesses in the United States. It is not offered to consumers, and it is not currently offered to customers in the United Kingdom or the European Economic Area. If you are outside the United States and want to use the Service, email support@qopanza.com — we would rather tell you where we stand than have you assume.
Effective date: 8 September 2026
1. Agreement
These Terms are a contract between Gsente LLC (“we”, “us”), a limited liability company registered in Colorado, and you — or the organisation you are acting for (“you”). By creating an account, using the API, or clicking to accept, you agree to them. If you are accepting on behalf of an organisation, you confirm you have authority to bind it.
If you do not agree, do not use the Service.
2. What the Service is
Qopanza scans source code, repositories, TLS endpoints and cloud configuration to identify cryptography that is vulnerable to quantum attack or already weak; ranks what it finds; suggests code and configuration changes for you to apply; produces migration plans and tracks them against later scans; and provides post-quantum key management, secrets storage and certificate issuance (the “Service”).
The Service suggests changes. It does not make them. See sections 6.5 and 6.6.
3. Accounts
You must be at least 18 years old and legally able to form a contract. Provide accurate information and keep it current.
You are responsible for everything done with your credentials. API keys are displayed once at creation and stored only as hashes — we cannot recover one for you, and a lost key must be rotated. Tell us immediately at security@qopanza.com if you believe a credential is compromised.
We offer per-key IP allowlisting and role-based access. Whether you use them is your decision.
4. Authorisation to scan — read this section
This is the most important obligation in these Terms.
You may submit a target to the Service only where you own it, or have express, current, documented authorisation from its owner to have it scanned. This applies to every target type: repository URLs, connected repositories, hostnames, TLS endpoints, live websites, cloud accounts and uploaded source.
When you submit a target you represent and warrant that this is true. When you connect a repository for continuous scanning, that representation applies to every future automatic scan, not just the first — so if your authorisation lapses, disconnect the repository.
Scanning systems you do not own or have permission to test may be a criminal offence, including under the Computer Misuse Act 1990 (UK), the Computer Fraud and Abuse Act (US), and equivalents elsewhere. Our infrastructure makes the outbound connection, but you direct it. If you point it somewhere you should not have, that is your act.
We may refuse, block or terminate any scan or account for suspected unauthorised scanning, without notice and without refund. We may preserve and disclose relevant records where legally required.
You agree to indemnify us under section 14 for claims arising from targets you were not authorised to scan.
4.1 Credentials you give us
Where you supply a repository access token or cloud credential:
- Supply the narrowest scope that works — read-only, limited to the specific repository or account. We cannot technically verify the scope you gave us.
- You confirm you are permitted to share it with us.
- Revoke it at your provider when you disconnect. Disconnecting deletes our copy; it does not invalidate the token at GitHub, GitLab, AWS or anywhere else. Only you can do that.
5. Acceptable use
You must not:
- scan or attempt to access systems without authorisation (section 4);
- use the Service to attack, disrupt, overload or gain unauthorised access to anything;
- circumvent rate limits, plan entitlements, throttling or the public scanner's abuse controls, including by automating sign-ups or distributing requests to evade limits;
- upload malware, or content that is unlawful or infringes someone's rights;
- resell, sublicense or provide the Service to third parties as your own, unless we have agreed that in writing;
- reverse engineer or copy the Service, except where that restriction is void by law;
- probe our security outside a disclosure process agreed with us at security@qopanza.com;
- misrepresent our output — see section 6.3.
The public, unauthenticated scanner is offered as a convenience. It is rate-limited by IP, and it is not a licence to scan third parties.
6. What the Service does not promise
These limits are technical facts about static analysis. They are stated here because a customer who misunderstands them makes worse decisions than one who does not.
6.1 Findings are not complete
We do not warrant that the Service will identify every use of vulnerable cryptography in your systems. A scanner reasons about patterns it recognises, in files it can reach, in languages it supports. It will miss things — cryptography behind reflection or dynamic dispatch, inside compiled dependencies, in configuration we cannot see, in a language we do not parse, or written in a way we do not recognise.
A clean scan is not a certificate that you are post-quantum ready. It means we found nothing where we looked. Do not represent it as more than that to your customers, your auditors or your regulator.
Equally, the Service may report findings that turn out not to be exploitable in your context. You are responsible for triage.
6.2 Not legal, regulatory or compliance advice
Nothing in the Service or its documentation is legal advice. Compliance scores, readiness percentages and evidence exports are tools to help you prepare, and are not:
- an audit, an attestation, or a certification;
- a SOC 2 report, or any statement about our own SOC 2 status;
- a determination that you comply with SOC 2, HIPAA, GDPR, PCI DSS, NIST guidance, or anything else.
Where the Service scores “SOC 2 controls”, it scores the subset observable inside your account. A real audit covers vendor management, background checks, change management and an observation period, none of which a scanner can see. Get an auditor.
HIPAA: unless we have signed a Business Associate Agreement with you, do not put protected health information into the Service. Encryption and audit logging do not make processing PHI lawful without that contract.
6.3 Do not overstate our output
You may share scan results and reports with your customers, auditors and regulators — they are yours. You must not describe them as a certification by us, imply we have audited or endorsed you, or use our name or marks to suggest we vouch for your security posture, without our written consent.
6.4 Cryptography
We implement post-quantum algorithms standardised by NIST (ML-KEM, ML-DSA, SLH-DSA) using established libraries. Cryptography is an evolving field: an algorithm believed secure today may be weakened by future research, and standards change. We do not warrant that any algorithm offered will remain unbroken.
Hybrid modes (classical + post-quantum together) are offered because they remain secure if either component holds. We recommend them. The choice is yours.
6.5 Automated changes
Where the Service performs an automated migration action, it does so only on cryptographic material we hold and manage. The Service does not modify your source code, your repositories or your infrastructure. Nothing the Service produces is applied anywhere by us. You apply it, or you do not.
6.6 Suggested code, and why you must review it
The Service shows suggested code. This takes three forms: an edited version of one of your own lines, standalone example code, and configuration values such as HTTP response headers.
All of it is a suggestion. None of it has been executed, compiled or tested against your codebase, and we cannot do so — we do not run your software. You are responsible for reviewing every change, testing it, and deciding whether it is correct for your system before you deploy it.
Three specific things you must not assume, because each has consequences we cannot see from where we sit:
- A replacement is not always drop-in. Changing a hash function changes the length and value of every digest it produces. If those digests are stored, indexed, compared against values computed elsewhere, or exchanged with another party, that other side has to change too. The Service says so alongside each suggestion; the warning is part of the suggestion and applying one without the other is not following our guidance.
- Encryption examples require correct operation, not just correct code. Authenticated encryption depends on never reusing a nonce with the same key, and on retaining the authentication tag. Example code shows the shape of a correct call. It cannot ensure your surrounding code satisfies those conditions.
- Migrating a key exchange or signature scheme affects systems other than yours. Both ends of a connection must understand the new scheme before you switch. Sequencing that rollout is yours to plan.
Where the Service cannot produce a change it is confident in, it produces none and shows the written recommendation alone. The absence of suggested code is not a statement that no fix is needed.
6.7 AI-generated explanations and ordering
A large language model may be used for two things: the explanation attached to an individual finding, and the written plan that accompanies a prioritised list of findings.
The model does not decide anything you act on. The remediation is produced by deterministic rules. The priority order is produced by deterministic rules. The suggested code is produced by deterministic rules. In each case the model is given the decision that has already been made and asked to describe it.
Model output may still be imprecise or wrong. Treat it as commentary, verify before acting, and rely on the stated fix and your own judgement. The Service functions fully when the model is unavailable, and produces the same findings, the same order and the same suggested code without it.
6.8 What "verified" means in the Service
Where the Service marks a remediation item verified, that means one specific thing: a later scan of the same target completed, and it did not report the same algorithm at the same location.
It does not mean:
- that the underlying weakness has been removed from your systems;
- that the change you made was correct, complete or secure;
- that anything outside the scanned target was examined;
- that any conclusion in section 6.1 no longer applies.
An item shown as marked done records only that a person said so, and we make no statement about it at all. Items are not marked verified by us; the status is derived from your own scan history and changes when that history changes.
7. Plans, fees and payment
Paid plans are billed in advance, monthly, at the price shown at checkout, through our payment processor Stripe. Prices are in US dollars (USD) and exclusive of VAT and other taxes unless stated; you are responsible for taxes other than those on our income.
- Renewal. Subscriptions renew automatically until cancelled. Cancel any time before the end of a period; you keep access until it ends.
- Refunds. Fees are non-refundable except where required by law, or where we cancel your account under section 11.2. The Service is sold to businesses; consumer cancellation rights, including any statutory right of withdrawal, do not apply and nothing here attempts to exclude one that does.
- Price changes. We may change prices with at least 30 days' notice by email, effective at your next renewal. Cancel before then if you disagree.
- Failed payment. We may suspend paid features after notice and a reasonable opportunity to fix it.
- Free plan. Offered as-is, with lower limits, and may be changed or withdrawn with reasonable notice.
Usage limits are enforced by plan. Exceeding them results in a 402 response, not a surprise invoice.
8. Your data and your content
You own your content. Source code, repository contents, scan targets, keys, secrets, certificates and support correspondence remain yours. We claim no ownership.
You grant us a limited, non-exclusive, worldwide, royalty-free licence to host, process, transmit and display your content solely to provide the Service to you, to keep it secure, and as you instruct. That licence ends when the content is deleted, subject to the backup cycle described in the Privacy Policy.
We do not use your source code, findings or content to train machine learning models, ours or anyone else's.
Handling of personal data is governed by the Privacy Policy (privacy-policy.md), and for business customers by the Data Processing Addendum (dpa.md).
Aggregated statistics. We may produce and publish aggregate, de-identified statistics (for example, “X% of scanned repositories still use SHA-1”). These will never identify you, your systems or your content, and cannot reasonably be reversed to do so.
Feedback. If you send us suggestions, we may use them without obligation or payment. This covers ideas about the product, not your content.
9. Our intellectual property
We own the Service, its software, detection rules, scoring methodology, documentation and branding. We grant you a limited, non-exclusive, non-transferable, revocable right to use the Service under these Terms during your subscription. Everything not expressly granted is reserved.
SDKs and CLI tools distributed under an open-source licence are governed by that licence.
9.1 Code the Service suggests to you
This grant is deliberate and permanent. A revocable licence over code embedded in your product would be unusable, and no customer's counsel would accept one. It covers only the remediation code the Service writes for you — not the Service, its detection rules or its scoring methodology, which section 9 reserves to us, and not any third-party code the suggestion incorporates, which stays under its own licence.
The Service outputs code and configuration for you to put into your own systems: edited versions of your own lines, standalone example code, and configuration values such as HTTP response headers. This section exists because the general licence above would be useless for that purpose — a revocable right over code embedded in your product would mean removing it when you stop paying, which is not a workable arrangement and is not what we intend.
So, specifically:
- Where the suggestion is a modified version of your own code, it is your code. We claim no ownership of your source code, and none of a changed version of it. That an algorithm name in it came from us gives us no interest in the line.
- Where the suggestion is example code or configuration written by us, we grant you a perpetual, irrevocable, worldwide, royalty-free, sublicensable licence to use, modify and distribute it as part of your own software and systems, with no attribution required.
- That licence survives termination of these Terms, for any reason, by either of us. Code already in your product stays in your product. Section 11.3 does not require you to remove it.
- The licence covers the suggested output only. It is not a licence to the Service, the detection rules, the scoring methodology or anything else in section 9.
We make no claim to be the author of any resulting work, and we take no interest in your product because you followed our advice.
Nothing here reduces section 6.6: the code is a suggestion, it has not been tested against your systems, and reviewing and testing it before deployment remains yours.
10. Third-party services
The Service integrates with third parties — Stripe, git hosts, cloud providers, your identity provider, an AI provider. Your use of those is governed by their terms, and we are not responsible for their acts, omissions or availability. A webhook you configure sends data to an endpoint you chose; securing it is yours.
Current sub-processors are listed in subprocessors.md.
11. Suspension and termination
11.1 By you
Cancel at any time from the dashboard. You may delete your account and all data via DELETE /v1/accounts. Deletion is immediate and irreversible, which is why it requires typed confirmation. Cancel any live subscription first — the endpoint refuses to proceed while one exists, so that a data request never leaves you paying for an account that no longer exists.
Export anything you want to keep before you delete.
11.2 By us
We may suspend or terminate immediately, with notice where practicable, if you materially breach these Terms — in particular section 4 or 5 — if required by law, if your use presents a security risk to the Service or other customers, or if payment fails after notice.
We may also discontinue the Service, or your plan, on 30 days' notice, refunding fees you have paid for the unused remainder.
11.3 Afterwards
Access ends. You may request an export within 30 days, after which we may delete your data. Sections 6, 8, 9, 12, 13, 14, 16 and 17 survive.
For the avoidance of doubt, the licence in section 9.1 survives, and you are not required to remove suggested code already incorporated into your systems.
12. Warranties and disclaimer
We warrant that we will provide the Service with reasonable skill and care.
Except as expressly stated, and to the maximum extent permitted by law, the Service is provided “as is” and we disclaim all other warranties, express or implied, including merchantability, fitness for a particular purpose, non-infringement, and any warranty that the Service will be uninterrupted, error-free, or that it will detect all vulnerable cryptography (see section 6.1).
Nothing excludes liability that cannot lawfully be excluded, including for death or personal injury caused by negligence, or for fraud.
13. Limitation of liability
To the maximum extent permitted by law:
- Neither party is liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, revenue, goodwill, or data, however caused.
- Our total aggregate liability arising out of or relating to these Terms or the Service is limited to the greater of (a) the fees you paid us in the 12 months before the event giving rise to the claim, and (b) US $100.
Specifically, we are not liable for loss arising from vulnerable cryptography the Service did not detect, from a finding you did not act on, from a migration you carried out, or from a compliance conclusion you drew from our output. Those risks sit with you, and section 6 explains why they have to.
These limits do not apply to your obligations under section 14, to either party's breach of confidentiality, or to your liability for fees.
14. Indemnity
You will defend and indemnify us against claims, losses and reasonable costs (including legal fees) arising from:
- your breach of section 4 — scanning a target you were not authorised to scan;
- your breach of section 5;
- your content infringing someone's rights or breaching law;
- your representation of our output as a certification or endorsement (section 6.3);
- personal data in your content processed contrary to your obligations as controller.
We will notify you promptly, let you control the defence (provided any settlement releases us fully and admits no fault on our part), and cooperate reasonably at your expense.
15. Confidentiality
Each party will protect the other's confidential information with at least reasonable care and use it only for this agreement. Your content is your confidential information. Standard exceptions apply: information already public, independently developed, lawfully received from a third party, or required to be disclosed by law — with notice to the other party where legally permitted.
16. Export control and sanctions
This clause is not boilerplate — this product is cryptographic software.
The Service incorporates encryption technology and may be subject to export control laws, including the US Export Administration Regulations, UK export controls and EU Dual-Use Regulation 2021/821.
You represent that you are not located in, ordinarily resident in, or acting on behalf of anyone in a country or territory subject to comprehensive sanctions by the United States, including those administered by the Office of Foreign Assets Control (OFAC); that you are not on any restricted party list; and that you will not use or re-export the Service in breach of those laws.
We may refuse or terminate service to comply with these laws.
On the SDKs specifically. The published client libraries do not implement cryptographic algorithms. They are API clients: the primitives run on our servers against liboqs, and the SDK sends a request and reads a response. That is a materially different export posture from distributing an implementation of ML-KEM, and it is why these are published openly under Apache-2.0.
We have not obtained a formal classification ruling. If you are re-exporting the Service or the SDKs from or into a controlled destination, satisfy yourself independently — and tell us, because we would want to know.
17. Governing law and disputes
These Terms are governed by the laws of the State of Colorado, United States, without regard to conflict-of-laws rules. The state and federal courts located in the State of Colorado have exclusive jurisdiction.
There is no arbitration clause and no class-action waiver. Both need their own drafting, both are unenforceable in places, and neither is worth having before there is anything to arbitrate.
Before filing anything, please contact support@qopanza.com — most disputes are a misunderstanding and are cheaper to fix in an email.
18. Changes to these Terms
We may update these Terms. For material changes we will give at least 30 days' notice by email or in the dashboard. Continuing to use the Service after they take effect means you accept them. If you do not, cancel before then; we will refund fees for the unused remainder of your current period.
We keep prior versions, available on request from support@qopanza.com, so you can see what changed.
19. General
- Entire agreement. These Terms, the Privacy Policy, and any DPA or order form are the whole agreement, superseding earlier discussions.
- Severability. If a provision is unenforceable, the rest stands.
- No waiver. Not enforcing something once is not giving it up.
- Assignment. You may not assign without our written consent; we may assign to an affiliate or in a merger or asset sale.
- Force majeure. Neither party is liable for failure caused by events beyond reasonable control.
- No third-party rights. No one other than the parties may enforce these Terms.
- Notices. To you, at your account email; to us, at support@qopanza.com.
20. Contact
Gsente LLC 3750 Blake St, Denver, CO 80205 support@qopanza.com