Skip to content
Shipmoor Shipmoor
  • Pricing
  • Blog
  • Docs
  • FAQ
Start free › Sign in Sign in

Terms of Service

Last updated: August 28, 2026

These Terms of Service (“Terms”) govern your access to and use of Shipmoor’s website, account console, CLI, Free and Pro plans, billing, documentation, and related services (the “Services”). “Shipmoor,” “we,” “us,” and “our” mean the operator of the Services. “You” means the person or organization using them.

By creating an account, authorizing a device or CI token, starting Pro access or checkout, or using the Services, you agree to these Terms. If you use the Services for an organization, you represent that you have authority to accept these Terms for it. If you do not agree, do not use the Services.

1. Accounts and Authorized Devices

An account and authorized device are required for all Shipmoor product work. The only supported unauthenticated public CLI commands are help, version, login, logout, and doctor. An internal subprocess operating beneath an already-authorized parent command may rely on that parent’s authorization. Non-interactive CI uses a scoped machine token instead of interactive device authorization.

You must provide accurate account information and keep it current. You are responsible for activity under your account and for protecting browser sessions, device codes, local credentials, signed leases, machine tokens, and provider credentials. Promptly revoke affected devices or tokens and notify us if you suspect compromise.

You may not share an individual account as a team license or sell, publish, sublicense, transfer, forge, tamper with, reverse engineer, or bypass access tokens, refresh credentials, signed leases, machine tokens, entitlement checks, allowance checks, or issuance endpoints.

2. Plans

Shipmoor uses the plan names Free, Pro, Team, and Enterprise. Team and Enterprise availability and capabilities are governed by a separate order or written agreement and may be marked coming soon.

First 30 Days of Pro

Each newly created personal account receives full Pro access for exactly 30 consecutive 24-hour periods from account creation. No payment card, invitation, Stripe customer, Checkout Session, or subscription is required. This is a one-time account grant, not a recurring monthly trial. Existing unpaid accounts do not receive it retroactively unless Shipmoor expressly runs a separate migration campaign.

At the end of the 30 days, the account either continues through an active paid Pro subscription or automatically falls back to Free. Fallback does not delete local configuration, reports, attestations, Agent Harness setup, Agent Skills setup, or other local evidence.

Free

Free includes unlimited deterministic Scan, Agent Harness, and Agent Skills. It also includes four independent monthly allowances:

Command familyFree allowance
Claim Check (shipmoor claim-check)5 invocations per month
Code Review (shipmoor review)5 invocations per month
Test Evidence (shipmoor test-evidence)5 invocations per month
Blast Radius (shipmoor blast)5 invocations per month

All four counters renew at 00:00 UTC on the first day of each calendar month. Unused invocations do not roll over, and one command family cannot use another’s allowance. Structured repair guidance included in a Claim Check result is part of that Claim Check invocation; standalone advanced repair, IDE Pro features, advanced verification configuration, and richer verification history require Pro where offered. Free raw artifacts remain local.

Pro

Paid Pro is $19 per month or $190 per year when purchased at standard self-service pricing. Pro includes unlimited use of the four metered command families and available Pro IDE, advanced configuration, repair, and local-history features. “Unlimited” remains subject to reasonable technical, security, anti-abuse, and provider limits.

3. How Free Invocations Count

A Free invocation counts once when an authenticated, syntactically valid top-level command passes argument and configuration validation and crosses its documented execution boundary. Consumption occurs before engine, model, runner, evidence collection, progress rendering, or output-file work.

After admission, the invocation counts even if its result is READY, BLOCKED, INCONCLUSIVE, advisory, clean, contains findings, fails later, is cancelled, or is followed by a repair. Running the top-level command again is a new invocation. A command launched by an agent, Skill, Harness, or IDE counts exactly like one typed by a user.

The following do not consume a metered allowance:

  • help or version output, parse errors, authentication failures, and invalid configuration rejected before admission;
  • shipmoor claim-check init and other documented setup-only or non-execution paths;
  • the lifecycle-only shipmoor test-evidence hook spool recorder;
  • Scan, Agent Harness, and Agent Skills themselves;
  • internal Review or Test Evidence work composed inside one already-admitted top-level Claim Check; and
  • transport retries that reuse the same random idempotency key for the same invocation.

claim-check resolve and claim-check probes are functional Claim Check executions and count when admitted. Review preview counts only when it enters the review engine. One Claim Check that internally composes Review or Test Evidence consumes only one Claim Check unit. A separate explicit Review or Test Evidence command consumes from its own counter.

Free metered commands require the allowance service to be online for each invocation. Six simultaneous unique calls to a command with five remaining units may produce five admissions and one exhaustion response; the other three command counters are unaffected. An allowance snapshot shown in an offline lease is informational, not authorization to run a Free metered command.

Upgrading to Pro makes access unlimited immediately. If the account later returns to Free, its counters resume for the current UTC month without resetting Free usage already consumed in that month.

4. Authentication, Leases, and CI Tokens

Shipmoor may issue short-lived access tokens, rotating device-bound refresh credentials, and signed offline entitlement leases. Access tokens are not offline entitlement proof. Refresh-token rotation, credential replay detection, lease expiry, grace periods, revocation, and online checks may affect availability as described in the product.

Free signed leases support seven days plus a 72-hour grace period for unlimited Scan, Harness, and Skills. Pro trial and paid Pro leases support fourteen days plus a 72-hour grace period for Pro capabilities. These lease lifetimes are refresh intervals and do not shorten the 30-day Pro grant or a paid subscription term.

CI machine tokens are named, scoped, revocable, and may expire. Free machine tokens are limited to Scan. Store a CI token as the SHIPMOOR_TOKEN environment secret and prevent it from entering source, logs, artifacts, caches, pull requests, or untrusted jobs. You are responsible for your CI provider, runner permissions, secret policy, and token rotation.

5. Subscriptions and Billing

Paid Pro subscriptions are billed monthly or annually in advance through Stripe or another payment flow we identify. Unless checkout or a written order says otherwise:

  • subscriptions renew automatically for the selected billing period;
  • you authorize recurring charges and are responsible for applicable taxes;
  • fees are non-refundable except where law requires otherwise;
  • a failed payment may receive a grace period before Pro falls back to Free; and
  • cancellation at period end leaves Pro active until that period ends, while immediate cancellation, chargeback, fraud, or invalid payment may end Pro earlier.

You may cancel through the billing portal. Ending paid Pro changes entitlements; it does not delete your account or local files. Existing subscriptions and legacy Stripe-managed trials retain the price and contractual end date shown in their applicable checkout or agreement.

6. Local Code and Provider Responsibility

Shipmoor product commands execute in your environment. As between you and Shipmoor, you retain your rights in source code, repositories, diffs, prompts, tickets, acceptance criteria, tests, and other content. Normal Shipmoor authentication, entitlement, allowance, and analytics requests do not require source or project content to be uploaded to Shipmoor.

You choose what repositories and changes to process and must have authority to do so. You are responsible for securing your code, local files, runners, reports, logs, artifacts, and backups; reviewing Shipmoor output; validating repairs; and deciding whether to merge, deploy, or rely on a result.

Code Review and model-assisted Claim Check features use a coding agent or model provider that you select and operate under your own provider account, terms, privacy policy, permissions, model behavior, rate limits, and charges. Shipmoor does not host that model. You are responsible for what content your configuration sends to the provider and for confirming that the provider is appropriate for your code and obligations. Using a local or offline provider may avoid a provider network transfer.

If a future optional integration asks to transmit content to Shipmoor or another provider, its disclosed configuration and any additional terms apply only when you enable it.

7. Acceptable Use

You may not use the Services to:

  • violate law, sanctions, export controls, privacy rights, intellectual-property rights, or contracts;
  • access, scan, test, or process systems, repositories, or code without authorization;
  • attack, disrupt, overload, scrape, or interfere with the Services;
  • evade authentication, command allowance, billing, rate, seat, token, or entitlement controls;
  • replay or reuse idempotency keys for a different account or command;
  • share individual Pro access as a team or organization license;
  • resell, sublicense, rent, or commercially exploit non-public Services without written permission;
  • build or improve a competing product using non-public APIs, Services, outputs, or documentation; or
  • represent Shipmoor output as a certification, warranty, or guarantee.

We may suspend or restrict access when we reasonably believe use violates these Terms, creates legal or security risk, threatens service integrity, or is abusive.

8. Third-Party Services

The Services use or integrate with third parties including WorkOS for authentication, Stripe for billing, Supabase for hosted account data, Vercel for hosting and allowlisted analytics, and providers you choose for source hosting, CI, package registries, coding agents, and models. Their terms and policies govern their services. Shipmoor is not responsible for third-party services you choose or control.

9. Product Changes and Support

Shipmoor may update, improve, suspend, or discontinue parts of the Services. We will use commercially reasonable efforts to avoid materially reducing paid Pro functionality during an active subscription term. Free support may be limited to documentation and public channels; Pro support includes the channels we make available.

No service level, uptime commitment, custom response time, data residency, DPA, or enterprise support applies unless stated in a signed agreement.

10. Intellectual Property and Feedback

Shipmoor and its licensors retain all rights in the Services, software, documentation, rules, workflows, designs, interfaces, trademarks, and related technology. Open-source components remain governed by their licenses.

If you provide feedback, bug reports, false-positive reports, suggestions, or feature requests, you grant Shipmoor a worldwide, royalty-free, perpetual, irrevocable license to use them without restriction or compensation. Do not include code or confidential content you are not authorized to share.

11. Termination

You may stop using the Services and cancel paid Pro at any time. We may suspend or terminate access for breach, overdue payment, credential or token misuse, legal or security risk, abuse, or discontinuation.

When Pro access ends, the account falls back to Free unless the account itself is terminated or restricted for legal, security, or abuse reasons. Free fallback preserves local files and setup. Sections that by nature should survive do survive, including payment obligations, intellectual property, disclaimers, liability limits, indemnity, and dispute provisions.

12. Disclaimers

The Services are provided “as is” and “as available” except as expressly stated in a signed agreement. To the maximum extent permitted by law, Shipmoor disclaims all express, implied, and statutory warranties, including merchantability, fitness for a particular purpose, title, non-infringement, accuracy, availability, security, and error-free operation.

Shipmoor does not promise to find every defect, avoid false positives, prove correctness, prevent incidents, ensure compliance, or make code safe for production. Review and validate all output before relying on it.

13. Limitation of Liability

To the maximum extent permitted by law, Shipmoor will not be liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, revenue, data, business interruption, security incidents, production outages, or substitute services.

Shipmoor’s total liability arising from the Services or these Terms will not exceed the greater of the amount you paid Shipmoor for the affected Service during the preceding twelve months or USD $100 if you used only Free Services. These limits apply regardless of legal theory and even if a remedy fails of its essential purpose.

14. Indemnity

You will defend, indemnify, and hold harmless Shipmoor and its affiliates, officers, directors, employees, contractors, and agents from claims, damages, liabilities, costs, and expenses, including reasonable attorneys’ fees, arising from your content, provider configuration, systems, repositories, violation of these Terms, violation of law or third-party rights, or misuse of credentials, leases, or tokens.

15. Export and Sanctions

You may not use, export, re-export, or transfer the Services in violation of export controls, sanctions, or other law. You represent that you are not prohibited from using the Services under applicable restrictions.

16. Changes to These Terms

We may update these Terms. For material changes, we will provide reasonable notice through the website, product, email, console, CLI, or another appropriate channel. The date at the top identifies the effective version. Continued use after the effective date constitutes acceptance where permitted by law.

17. Governing Law and Venue

These Terms are governed by Delaware law without regard to conflict-of-law rules. Disputes will be resolved in the state or federal courts located in Delaware, and each party consents to their jurisdiction and venue, unless a signed agreement states otherwise.

18. Contact

Questions about these Terms may be sent to legal@shipmoor.dev.

Language agnostic verification

Shipmoor works with any language through your existing build and test toolchain. Native deterministic Scan rules currently cover:

  • Python
  • TypeScript
  • JavaScript
  • Go

Supported editors & agents

  • VS Code
  • Codex
  • Claude Code
  • Cursor
  • Aider
Shipmoor Shipmoor

© 2026 Shipmoor. Legal: legal@shipmoor.dev

  • Pricing
  • Terms
  • Privacy
  • Blog
  • Console