These terms cover three things: the hosted SovereignShield API, this website, and the software published under the SovereignShield name. They are written to be read, not to be survived.
SovereignShield operates a hosted scanning API at api.sovereign-shield.net, with a dashboard for accounts, API keys, and credits. By creating an account or using the API you agree to these terms.
Credit purchases are one-time purchases of a digital service. If you are a consumer in the European Union, you have a 14-day right of withdrawal for unused purchases: contact us within 14 days of purchase and any pack whose credits are entirely unused will be refunded. By spending credits from a pack you request immediate performance and accept that the right of withdrawal lapses for the credits used. Business purchases are non-refundable except where required by law.
Every SovereignShield package (sovereign-mcp-gateway, sovereign-mcp, sovereign-shield, intentshield and logicshield) is published under the Business Source License 1.1 on identical terms.
In short: the source is public, you may read it, modify it, fork it, and run it freely for any non-production purpose. Production use is free for an individual or an organisation of four or fewer people. Beyond that, production use requires a commercial licence. Each released version converts to the Apache License 2.0 four years after it was published.
Where these terms and a package's LICENSE file disagree about the software, the LICENSE file governs. It is the operative document; this page is a summary of it. The full text ships with every package and is reproduced on the licensing page.
A commercial licence for self-hosting is granted per production deployment, for a fixed term, against a written agreement. One licence covers all five packages; they are not sold separately. Tell us the shape of your deployment via the licensing page and we will quote. Where a signed commercial licence agreement exists, that agreement governs the relationship and takes precedence over this page.
Using it to test your own systems, publishing what you find, and reporting defects (including defects in the security checks themselves) are all explicitly welcome and need no permission.
The software is provided "as is", without warranty of any kind, express or implied, including merchantability, fitness for a particular purpose, and non-infringement. The hosted API carries the same posture. This matters more than usual here, because this is security software and the failure mode is quiet. Stated plainly:
You are responsible for deciding whether it is appropriate for your use, for configuring it, and for the security of the systems you deploy it in front of.
To the maximum extent permitted by applicable law, neither SovereignShield BV nor the Licensor shall be liable for any indirect, incidental, special, consequential, or exemplary damages, nor for lost profits, lost data, or business interruption, arising from the use of or inability to use the service or software, including where a malicious payload passed through undetected.
Where liability cannot lawfully be excluded, total aggregate liability is limited to the fees you paid in the twelve months preceding the claim, or, if you paid nothing, to fifty euros.
Nothing in these terms excludes liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any other liability that cannot lawfully be limited.
The content here is provided for information. Sample output and figures describe specific runs against specific versions, and are not a guarantee of what you will see. Links to external sites (GitHub, PyPI, and others) are provided for convenience; we do not control them and are not responsible for their content.
These terms may be updated. The date at the top changes when they do. Material changes affecting paying API customers are announced by email with reasonable notice. Changing these terms does not retroactively change the licence of a software version already published; the Change Date on a released version is fixed at publication and cannot be moved.
These terms are governed by the laws of Belgium. The courts of Belgium have exclusive jurisdiction over any dispute arising out of or in connection with them. This does not deprive you of the protection of any mandatory provision of the law of your own country of residence. If you are a consumer resident elsewhere in the European Union, you keep the protections of your local consumer law and the right to bring proceedings there.
The hosted API and this website are operated by:
SovereignShield BV
Nieuwpoortsesteenweg 162, 8400 Oostende, Belgium
Enterprise number (KBO/BCE): 1038.469.726 · VAT: BE 1038.469.726
Email: contact@sovereign-shield.net
Prices are quoted excluding VAT. The treatment that applies (Belgian VAT, the reverse-charge procedure for businesses elsewhere in the European Union holding a valid VAT number, or outside the scope of EU VAT) depends on where you are established, and is stated on the invoice together with the supplier's VAT number.
The copyright in the software is held by Mattijs Moens, who is the Licensor named in every LICENSE file. Licensing enquiries, security reports, and anything else go to the address above. If you have found a vulnerability, say so in the subject line and it will be prioritised over everything else.