Who we are
Armorer Labs, Inc. is a Delaware corporation (Armorer, we, us). Questions about these terms go to support@armorerlabs.com.
Customer agreements
If you become a paying customer, your signed Cloud Service Agreement, Data Protection Agreement and Order Form govern the service. Our agreement is based on the Common Paper Cloud Service Agreement and Data Protection Agreement standards, plus Armorer-specific schedules. The Common Paper Cloud Service Agreement Standard Terms, version 2.1, are incorporated by reference when the signed agreement says so. The Order Form controls fees, term and renewal; the Order Form and the schedules are agreed with each customer and are not reproduced here. Where a signed agreement exists, it takes precedence over this page.
The Armorer-specific schedules are:
- Service description: what the hosted service and Armorer Guard do, and the boundary of the system we operate.
- Subprocessor list: the providers that can reach customer data, published and dated on our Security page.
- Security exhibit: the controls we commit to, stated only where they are in place.
- Deletion and return: how customer data is deleted within 30 days of termination.
- Complementary user entity controls: the responsibilities that stay with the customer, summarized below.
What the service does
A customer installs the read-only Armorer GitHub App and chooses which repositories it may read. The hosted platform clones a repository at a pinned commit into an ephemeral task and runs discovery, attack simulation against an isolated copy of the agent, and remediation synthesis. It returns evidence and a draft pull request. Armorer never merges that pull request; reviewing, approving, merging or rejecting it is the customer's decision.
Armorer Guard is a runtime enforcement binary that customers install on their own hosts. Armorer builds, signs and publishes the binary. Armorer does not operate the customer's host, and Guard sends only content-free decision telemetry, licensing and coverage data back to the hosted platform.
Your responsibilities
The service works on the customer's side of a boundary the customer controls. Under the customer agreement, the customer is responsible for:
- Controlling who may install the Armorer GitHub App on your organization and which repositories it may read.
- Reviewing, approving, merging or rejecting the draft pull requests Armorer opens. Armorer never merges them.
- Operating, patching and protecting the hosts on which you install Guard.
- Managing Console user identity and multi-factor settings in WorkOS or your own identity provider.
- Deciding which repositories and commits are submitted for hosted scanning.
- Treating evidence bundles and findings as your own security data and acting on them.
- Telling us about suspected misuse of your installation, tokens or Guard fleet at security@armorerlabs.com.
- Uninstalling the GitHub App and requesting deletion when the relationship ends.
- Keeping secrets you do not want processed out of scanned repositories, or accepting that a hosted scan reads the pinned commit.
These responsibilities complement our own controls. They do not reduce our responsibility for the controls we own.
Data
How we process personal data is described in our Privacy Policy. For customer data, the Data Protection Agreement governs. When a customer terminates, we delete customer data within 30 days and confirm in writing what was deleted. Where the agreement requires notice of subprocessor changes, we give at least 30 days' notice by email before a new provider begins processing customer data.
Security
Our security controls and their known limitations are described on our Security page. A SOC 2 Type 1 examination is in preparation. We do not currently hold a SOC 2 report, and nothing on this site is a certification of the service.
Commercial terms
The customer agreement completes the Common Paper standard terms as follows:
- Fees, subscription term and renewal are set in the Order Form.
- Free trials and pilots run for 30 days unless an Order Form says otherwise.
- Either party may terminate the agreement for a material breach that remains uncured 30 days after written notice of it.
- No service levels are committed unless an Order Form states them. Support is by email to support@armorerlabs.com on business days.
- Warranties and liability follow the Common Paper standard disclaimers and limitations, with liability capped at the fees paid in the 12 months preceding the claim.
Governing law and venue
These terms and our customer agreements are governed by the laws of the State of Delaware, United States. Disputes are brought in the state or federal courts located in Delaware.
Use of this website
The content on armorerlabs.com, including threat intel entries and blog posts, is provided for information. It describes published research and our own product work and is not advice about your specific environment. The threat-intel subscription is for individual, human use: it is rate-limited and protected by Cloudflare Turnstile, and automated or bulk submissions are not permitted. Book a call links open Cal.com, whose terms and privacy policy apply to information submitted there.
You may not scrape the site, abuse it or its forms, or attempt to circumvent its security controls.
Intellectual property
Armorer Labs, Inc. owns this website, its content and its marks.
Changes to these terms
We may update this page as the agreement, the service or the law changes. We will change the effective date above and notify customer account contacts of material changes by email.
Contact
support@armorerlabs.com. Armorer Labs, Inc. is a Delaware corporation; we operate remotely and do not publish a street address. Postal correspondence can be arranged by email.