01
Use ICTX responsibly
ICTX helps you investigate and triage scanner findings. Use it only with repositories, scanner output, and systems you are authorized to assess, and follow the laws and security policies that apply to your work.
02
Local execution
The ICTX CLI and keyboard-driven TUI are designed to run where you work, over SARIF you already have. You are responsible for the machine, repository, credentials, scanner configuration, and any third-party service you choose to connect.
03
Your content and results
You keep your rights to your code, repositories, scanner output, and other material you provide or process with ICTX. You are responsible for having permission to use that material and for reviewing findings and verdicts before acting on them.
04
No security guarantee
ICTX is an analysis and triage aid, not a guarantee that a repository is secure or that every finding is correct. Rules, indexing, scanner output, and available evidence can be incomplete. Validate important decisions with your own engineering and security processes.
05
Availability and changes
ICTX is provided as available, and features, supported stacks, documentation, and distribution methods may change. We may update these terms as the project evolves; the date above identifies the current version.
06
Contact
Questions about these terms or responsible use of ICTX can be sent to hello@ictx.sh.