Terms of Service
1. These Terms
These terms are an agreement between you and Viktor Mares, a sole trader based in Burgas, Bulgaria, trading as cupel ("cupel", "we"). They cover the dashboard at app.cupel.sh and the service at api.cupel.sh. By creating an account or using the service, you accept them.
If you use cupel for an organisation, you confirm you may accept these terms on its behalf, and "you" includes that organisation. You must be at least 18 years old.
The cupel command-line tool runs on your own machines and is provided under the licence that accompanies it. If you have a signed Enterprise agreement with us, that agreement takes precedence where it differs from these terms.
2. The Service
cupel analyses whether known vulnerabilities in your dependencies are reachable from your code. The analysis runs in your own environment; the service receives the results, stores them for your organisation, and lets you review, triage and set policy on them. Your source code is never uploaded to the service.
We improve cupel continually, so features may change. If we remove or materially reduce a feature of a paid plan, we will tell you in advance, and you may cancel.
3. Your Account
Keep your sign-in details and any access tokens you create confidential; you are responsible for what happens under your account. If you believe your account or a token has been compromised, revoke the token and tell us at security@cupel.sh.
4. Your Data
Your results, projects, triage decisions and policies remain yours. You give us permission to store and process them only to provide the service to you. Our Privacy Policy explains how personal data is handled.
You are responsible for having the right to analyse the code and repositories you connect.
5. Acceptable Use
You agree not to:
- attack, overload, or try to gain unauthorised access to the service or other customers' data;
- work around plan limits or billing, or the security controls of the service;
- use the service to analyse code you have no right to analyse;
- resell or provide the service to third parties without our written agreement;
- put unlawful content into names, labels, notes or other text you enter.
Security research is welcome when it is responsible: report what you find tosecurity@cupel.sh, don't access data that isn't yours, and don't disrupt the service.
6. What cupel's Results Are
cupel gives each finding a verdict — reachable, not reachable, orunknown — with the evidence behind it. unknown means cupel could not determine the answer, and says so rather than guessing.
The results help you decide what to act on. They are not a guarantee that your software is free of vulnerabilities, and they depend on the advisory data available when you scan. Decisions about your software's security, and what you do with the results, remain yours.
7. Plans, Prices and Payment
Free lets an organisation's workspace hold up to five repositories at a time.Team is a paid monthly subscription: the first five repositories are free, each repository beyond five is charged per month, and while you are subscribed at least one repository is charged. Team holds up to 20 repositories at a time. Enterprise is arranged with us directly.
The price shown when you subscribe is the price you pay. cupel is not registered for VAT under the Bulgarian Value Added Tax Act, so no VAT is charged on its prices.
- Payment is taken in advance through Stripe, and the subscription renews monthly until you cancel.
- A repository counts for the whole billing period it was connected in, even if you disconnect it before the period ends. Connecting a different repository in its place is counted separately; reconnecting the same one is not counted twice. Counts reset when the period renews.
- Connecting more repositories during a period increases the charge from that point, prorated.
- We may change prices with at least 30 days' notice before the change applies to your next period; you may cancel before it does.
- If a payment fails and is not resolved after we contact you, your subscription may end and your workspace return to Free. Repositories already connected keep working; stored results older than the Free plan's 90-day window are then deleted.
Paid plans have no hard usage limit on scans. If an organisation's scanning is persistently out of proportion to its plan, we will contact you to discuss it — we won't silently refuse or slow down your scans.
8. Cancelling
You can cancel at any time from the billing page in the dashboard. Cancellation stops the next renewal: your plan stays active until the end of the period already paid for, and that period is not refunded, except where the law says otherwise — including your right of withdrawal below.
9. Your Right to Withdraw (Consumers)
If you are a consumer — using cupel outside your trade, business or profession — you have the right to withdraw from a paid subscription within 14 days of subscribing, without giving a reason.
When you subscribe, you ask us to start providing the service immediately, within those 14 days. If you then withdraw, you pay only for the part of the period provided up to when you told us, and we refund the rest within 14 days. Once the period has been fully provided, the right of withdrawal no longer applies to it.
To withdraw, send a clear statement to billing@cupel.sh, for example: "I withdraw from my contract for the cupel Team subscription, ordered on [date], for the account [email address]."
10. Ending Your Use of cupel
You can delete your account, or remove an organisation, at any time from the dashboard. Export anything you want to keep first — removal deletes your data as described in the Privacy Policy.
We may suspend or end your access if you seriously or repeatedly break these terms, if needed to protect the service or other customers, or if the law requires it. Where we reasonably can, we will warn you first and give you the chance to fix the problem and to export your data.
11. Availability
We work to keep cupel available and reliable, but we do not guarantee uninterrupted service, and paid plans other than Enterprise carry no uptime commitment. We will give notice of planned maintenance where we reasonably can.
12. Our Intellectual Property
The service, the dashboard and the cupel name and brand belong to us. These terms give you the right to use the service; they don't transfer ownership. If you send us feedback, we may use it without obligation to you.
13. Liability
Nothing in these terms limits liability for intent or gross negligence, for death or personal injury, or any other liability that the law does not allow to be limited, and nothing affects your statutory rights as a consumer.
If you use cupel as a business, then, to the extent the law allows: our total liability arising from these terms and the service in any 12 months is limited to the fees you paid us in the 12 months before the event giving rise to the claim; we are not liable for indirect or consequential loss, lost profits, or lost data; and the service is provided as it is, without warranties beyond those in these terms.
If you are a consumer, we are responsible for foreseeable loss caused by our failure to meet these terms or to use reasonable care, and your statutory rights about the conformity of digital services apply in full.
14. Changes to These Terms
We may update these terms. If a change matters, we will tell you by email or in the dashboard at least 30 days before it applies. If you don't agree, you can cancel and stop using cupel before then; if you are a consumer on a paid plan, you can also end the subscription with a refund of any period paid for after the change takes effect.
15. Law and Disputes
These terms are governed by the law of Bulgaria. If you are a consumer, you also keep the protection of the mandatory rules of the country where you live, and may bring proceedings in its courts. If you use cupel as a business, disputes go to the competent courts in Burgas, Bulgaria.
Before any formal step, please contact us at support@cupel.sh— most problems are resolved faster that way.
16. Contact
General and support: support@cupel.sh
Billing and withdrawal: billing@cupel.sh
Security: security@cupel.sh