legal
Terms
Effective: August 2026
These terms cover your use of nittim. You agree to them when you run an audit, create an account, or buy credits. They are written to be read — if something here is unclear, ask us before you rely on it.
Who you are contracting with
nittim is operated by Ilan Wolberger, trading as nittim, a sole proprietor in the United States. Our support address is 7950 NW 53RD ST STE 337, Miami, FL 33166, USA. Reach us through the contact form.
What nittim does — and what it does not promise
nittim analyses a repository and returns a report: findings, scores, and a verdict on whether the code looks safe to ship. Part of that analysis is deterministic — a secret scan and a dependency CVE check. The rest is produced by a large language model reviewing your code against a fixed framework.
A nittim report tells you what we found. It cannot tell you that nothing else is there.
This matters, so we will be blunt about it. nittim is an advisory tool, not a certification, a guarantee, or a substitute for a penetration test or a review by a qualified security professional. A clean report does not mean your software is secure. The model can be wrong in both directions: it can report a problem that is not real, and it can miss a real one. We publish a benchmark measuring exactly that, and we would rather you treat the report as a well-informed second opinion than as a clearance to ship without judgement.
If you think a finding is wrong, tell us — we adjudicate on evidence and correct the record.
Your account
You can sign in with GitHub, with Google, or with an email address and password. The one-time covered Audit requires a GitHub or Google identity, because those verify that an account belongs to a real person.
API keys issued to you are secrets. You are responsible for everything done with your keys and under your account, including credits spent. If a key leaks, revoke it from your account immediately. Rate limits apply per key to protect the service.
Your code
You must have the right to submit a repository for audit. By submitting one, you grant us a limited licence to fetch and process that code for the sole purpose of producing your report.
We do not train any model on your code. Never stored. Fetched into server memory during analysis, discarded when the pipeline finishes. Two deliberate exceptions: a finding's evidence includes the offending lines it points at — those excerpts live in your report (access-gated for private repos), because a finding without evidence is an opinion; and the uploaded zip below, if you ask us to hold it while an audit runs. A multi-pass or batch audit also parks its own working state on the report row as it goes, and those same lines sit in it. Nothing clears that state when the run finishes: it stays with the report, and it goes when the report goes. Reports generated from a private repository are private to the account that requested them. The full detail is in the privacy policy.
Credits
- What they costA single-pass AI run costs 5.14 credits, on every surface — the web, MCP, the API, or the GitHub Action. A single module run costs 5.03 credits. The deterministic scans are free and always will be.
- ExpiryCredits never expire.
- Not moneyCredits are a prepaid unit of service, not currency. They have no cash value, cannot be transferred or sold, and cannot be exchanged for anything other than audits — except under the refund policy below.
- Failed auditsIf an audit fails before it produces a report, the credits are returned to your balance automatically. Automatic refunds pause after a few failures in one day; if that happens we tell you on the page, and review it within a day.
- False positivesIf we confirm a finding as a false positive, you get 1 credit back per finding, up to what that report cost you.
Promotional and complimentary credits — anything we grant rather than sell — carry the same restrictions and are not refundable.
BYOK Pro
BYOK Pro is $49 per month, recurring until you cancel. It covers the software: the scanners, the orchestration, the report engine, and the programmatic surfaces. It does not cover model usage — under BYOK the tokens are billed to your own Anthropic account by Anthropic, at their prices.
The subscription includes a 100-credit monthly allowance, granted on the initial charge and again on every renewal, that covers our own compute cost for a single-pass AI run through the API, MCP, or GitHub Action — about 50 single-pass audits. Anything you do not use stays yours: each renewal ADDS a new allowance to your balance rather than replacing what is left of the old one. If you use more than the allowance in a billing period, further single-pass AI runs on those surfaces draw from your ordinary prepaid credit balance like any other credits purchase; module runs (run_module) are unaffected and never spend credits under BYOK. Single-pass AI runs started from the web app always spend credits at the ordinary rate, allowance or not.
You can cancel at any time from your account. Access continues until the end of the period you have already paid for. If a payment fails, your subscription keeps working for a three-day grace period before it is suspended.
Enterprise
Enterprise accounts are governed by the written agreement signed with them. Where that agreement and these terms disagree, the agreement wins.
Acceptable use
Do not:
- Audit others' codeSubmit a repository you have no right to submit.
- Resell the verdictPresent a nittim report as your own certification, or resell audits as a security assurance service, without a written agreement with us.
- Extract the mechanismAttempt to extract, reverse engineer, or replicate the prompts, scoring logic, or orchestration that produce a report. These are our confidential property.
- Attack anyoneUse nittim to find weaknesses in software you do not own or have permission to test.
- Evade limitsCircumvent rate limits, the free-tier limits, or account controls — including by creating multiple accounts to repeat one-time offers.
We may suspend or close an account that breaches this section, or that we reasonably believe is being used fraudulently.
Availability
Self-serve tiers are provided as they are, with no uptime commitment. We may change, add, or withdraw features. Enterprise service levels are set by agreement.
Warranties and liability
To the fullest extent the law allows, nittim is provided “as is” and we disclaim implied warranties, including merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that a report is complete, accurate, or that it identifies every defect or vulnerability in your code.
We are not liable for indirect or consequential loss, including lost profits, lost data, business interruption, or a security incident affecting software you shipped in reliance on a report. Our total liability for any claim is capped at the greater of the amount you paid us in the twelve months before the claim, or $100.
Nothing here limits liability that cannot be limited by law — including fraud, and your statutory rights as a consumer where you live.
Changes and termination
You may stop using nittim at any time. We may update these terms; the version here with its effective date is the one that applies, and we will flag material changes rather than quietly reissue the page. If we close your account other than for breach, unused purchased credits are refundable under the refund policy.
Governing law
These terms are governed by the laws of the State of New Jersey, United States, and disputes belong to its courts. If you are a consumer elsewhere, this does not remove the protection of mandatory laws in your own country.
Contact
Questions about these terms? Use the contact form.