Terms

The rules that exist, and the one that does not yet.

What follows is accurate and incomplete, and the incomplete part is named first rather than hidden at the bottom.

  • Last reviewed 2026-08-21
  • Status not a contract

Status of this page

This is not a terms-of-service agreement, and it would be dishonest to present it as one. A terms-of-service is a contract between a named legal party and you. Myrqen currently has no company behind it: no registered entity, no company number, no registered address, and no jurisdiction to name as governing law. Until that exists, publishing a filled-in template would mean naming a party that does not.

What this page is: an accurate statement of the licence, the rules of use, and the limits of liability as they stand. Treat it as a description of how Myrqen is offered rather than as an agreement you have entered.

Myrqen itself is a working codename, and it has passed a preliminary name-collision screen only, not a professional trademark clearance.

The licence

The published source is under the Myrqen Source-Available Licence 1.0. It is not an open-source licence: it is not OSI-approved, and it does not meet the Open Source Definition. Please do not describe it as open source or add it to a list of open-source tools.

You may, without asking:

  • read, study, and learn from the source, and clone it to read it locally;
  • run it on your own machines, for your own work, including commercial work;
  • run it against systems you own or are authorised to test;
  • quote short excerpts in a review, a lesson, an article, or a security report, with attribution;
  • open an issue containing whatever excerpt describes a defect, and submit a fix.

You may not, without written permission:

  • redistribute it, in source or compiled form, or publish a fork or a mirror;
  • modify it and distribute the result;
  • run it as a hosted or managed service for other people;
  • build it into a product or service you distribute or host.

The authoritative text, which governs over this summary, is LICENSE in the repository. Copyright is retained.

What you may test with it

This is the part that matters most, because Myrqen is a security tool and misusing one has consequences for other people.

Only systems you own, or are explicitly authorised in writing to test. Running a security assessment against somebody else's application without permission is unlawful in most jurisdictions, and the fact that a tool made it convenient is not a defence.

Myrqen is built to make that boundary hard to cross by accident rather than to rely on you reading this paragraph:

  • Anything outside your own machine requires an exact-origin grant. Authorizing https://api.example.com does not authorize a sibling host, another port, or another scheme, and there is no wildcard form.
  • Destructive actions are refused at every effort level, with no opt-in flag, and each refusal is written into the report.
  • An origin Myrqen only learned about from project content that also tried to instruct it is quarantined and refused even with an explicit grant.

Do not attempt to work around any of that. If you find a way to, please report it under the security policy, that is a vulnerability in Myrqen.

Against the hosted service itself, SECURITY.md defines what is in scope. Testing against an account you created is welcome. Testing against anybody else's is not.

The hosted service

An account is optional. Local scanning, local reports in all four formats, the fix prompt, and applying a fix are free, unlimited, and unaffected by whether you have one.

The hosted service is offered as it is, with no uptime commitment and no support-response commitment. It is early software. Plan limits, how much you can sync, how long it is kept, how many people you can share with, are on the pricing page and are read from the same module the application enforces.

An account may be suspended for using the service to attack systems you do not own, for attempting to reach another account's data, or for volume that degrades it for other people. In each case you will be told which.

Keep your own copies. A synced report is a convenience, not a system of record: free reports are deleted after 21 days, and the local copy in your project has no expiry. Retention in full.

Payment

Nothing can currently be bought. Checkout is not configured on the hosted deployment, so no card can be taken and no subscription can exist. The free plan needs no payment method.

When paid plans become purchasable, the terms of payment, billing period, renewal, refunds, and cancellation, will be published here before the first charge, not after.

No warranty, and specifically not a security warranty

Myrqen is provided as is, without warranty of any kind, to the maximum extent permitted by law. Nothing here creates a guarantee of fitness for a particular purpose.

One part of that deserves stating plainly rather than in capitals at the bottom of a template:

A Myrqen report with no findings is not evidence that your application is secure. Recall is measured at 0.441 against our own gate of 0.90, and 0.294 on the only corpus nobody had tuned against. Myrqen does not parse Python, Java, Ruby, or Go at all, and does not follow data across a module boundary. Do not present a Myrqen report as an audit, a penetration test, or a compliance artefact, it is none of those, and no third party has audited it. Every number, and how it was measured.

To the extent permitted by law, no liability is accepted for a vulnerability Myrqen did not find, for a finding it reported that was not real, for damage caused by a change made in response to a finding, or for loss of a synced report. Your statutory rights as a consumer, where they apply, are not affected by any of this.

Changes

This page changes in the repository's history, so every revision is inspectable. The Last reviewed date above moves when the content does, and a change that reduces what you get - rather than describing existing behaviour more accurately, will be called out on the changelog.

Questions: support@myrqen.cc. Security: security@myrqen.cc.