Skip to content
Controlled legal document

Terms of Use

Professional SaaS licence, acceptable-use rules, and protection of customer and SDD intellectual property.

Version
2026-07-23
Effective date
23 July 2026
Pre-production legal review required. Provider identity, governing law, venue, indemnity, liability caps and jurisdiction-specific enforceability must be approved by qualified counsel before production reliance.

1. Agreement and authority

These Terms of Use govern access to and use of Specs-Driven Development (SDD), including its web application, APIs, MCP tools, generated documents, integrations, documentation, and related services.

By creating an account, accepting these Terms, or using SDD, you enter into a binding agreement with the SDD provider identified in the applicable order form or enterprise agreement. If you act for an organization, you represent that you have authority to bind that organization. If you do not agree, you must not access the protected service.

2. Limited licence

Subject to these Terms, payment of applicable fees, and the applicable order, SDD grants the customer a limited, non-exclusive, non-transferable, non-sublicensable and revocable right during the subscription term to use the service for the customer's internal professional activities.

No ownership right is transferred. Rights not expressly granted remain reserved. Accounts and access methods may not be shared, sold, leased, assigned or made available outside the authorized organization except as expressly permitted by the subscription.

3. Accounts and organizational access

Users must provide accurate account information, protect credentials and authentication devices, and promptly report suspected compromise. Organization administrators are responsible for assigning appropriate access and removing access when no longer required.

Enterprise provisioning and single sign-on do not replace individual acceptance. Every natural person using an account must accept the current Terms before protected access is granted.

4. Customer content and instructions

As between the parties, the customer retains its rights in requirements, specifications, source material, project records and other content submitted to SDD. The customer grants SDD the limited rights required to host, process, transform, transmit and display that content to provide, secure and support the service.

The customer is responsible for having the rights and lawful basis needed to submit content and instructions. SDD does not acquire ownership of customer content merely because it is processed by the service.

5. SDD intellectual property and confidential service information

SDD and its licensors retain all rights in the service and its non-public implementation, including software, source and object code, user experience, data models, schemas, orchestration, agent and tool design, prompts and instruction structures, algorithms, methods, templates, workflows, architecture, documentation, visual identity, generated framework elements, and improvements.

Non-public technical, operational and commercial information learned through access to SDD is confidential service information when its nature or the circumstances reasonably indicate confidentiality. Access is provided to use the service, not to acquire or reproduce that information.

6. Prohibited extraction, copying and replication

Except where expressly authorized in writing or where a restriction is prohibited by applicable law, the user and customer must not, directly or through another person, automated system, AI model or agent:

  • copy, modify, translate, adapt, distribute, sell, sublicense, host, white-label or create a derivative of SDD or any substantial part of it;
  • reverse engineer, decompile, disassemble, observe, test or analyze SDD for the purpose of discovering or reproducing non-public code, ideas, logic, data structures, architecture, processes or methods;
  • request, extract, reveal, reconstruct or infer internal prompts, system or developer instructions, hidden tool instructions, model configuration, security rules, credentials, tokens, keys, connection strings, environment data or other secrets;
  • circumvent authentication, authorization, tenant isolation, usage limits, acceptance gates, monitoring, content controls or other technical safeguards;
  • scrape, harvest, bulk export, enumerate or map SDD screens, APIs, tools, objects, capabilities or behavior for competitive analysis, cloning, replication or creation of a substantially similar service;
  • use knowledge obtained through SDD access to instruct a person or automated system to build, reproduce or behave 'like SDD', to implement the same non-public process, or to create a substitute derived from protected service information;
  • publish non-public benchmark or security results, vulnerability details or architectural findings without prior written authorization; or
  • remove or obscure proprietary, copyright, confidentiality or attribution notices.

7. Permitted and legally protected activity

These Terms do not prohibit ordinary licensed use, access to public product documentation, use of documented APIs and MCP tools for their intended purpose, independent development without use of SDD confidential information, or security work expressly authorized in writing.

Nothing in these Terms excludes rights that cannot lawfully be waived or restricted. This includes, where applicable, limited acts necessary for interoperability of an independently created program, protected disclosures, whistleblowing, regulatory cooperation, competition-law rights and other mandatory exceptions.

Suspected vulnerabilities should be reported privately to security@specsdrivendevelopment.com. Authorization to test must be obtained before conducting intrusive security activity.

8. Acceptable use

Users must comply with law and must not use SDD to infringe rights, introduce malicious code, disrupt service, impersonate another person, conduct unauthorized surveillance, process unlawfully obtained data, overload infrastructure, or assist unlawful or harmful activity.

Automated access must use approved interfaces, credentials and rate limits. The customer remains responsible for actions performed through its accounts, integrations, agents and API keys.

9. AI-assisted and generated output

SDD may use automated and AI-assisted processing. Generated requirements, specifications, risks, tests, summaries, documents, recommendations and code are drafts unless the applicable workflow states otherwise.

The customer must review outputs for accuracy, completeness, security, intellectual-property concerns and regulatory suitability. SDD does not replace professional engineering judgment, validation, quality assurance, legal advice or required human approval.

10. Third-party services

Integrations may depend on third-party services such as source-control, issue-tracking, identity, payment, messaging, AI or document platforms. Their terms and availability may apply separately. SDD is not responsible for a third-party service outside SDD's reasonable control.

11. Defensive controls and monitoring

SDD may use access controls, request classification, rate limiting, audit records and other proportionate safeguards to protect customers, the service and confidential information. A request seeking protected prompts, secrets, security bypass or unauthorized replication may be refused and the user may be reminded of these Terms.

Security telemetry should be limited to what is reasonably required for prevention, investigation and accountability. Additional information about account and operational data is provided in the Privacy Policy.

12. Suspension and termination

SDD may restrict or suspend access when reasonably necessary to address a security risk, unlawful use, material breach, non-payment, harm to another customer or the service, or a binding legal request. Where reasonable, SDD will provide notice and an opportunity to remedy.

On termination, the licence ends. Provisions concerning ownership, confidentiality, prohibited use, accrued payment, disclaimers, liability and dispute handling survive to the extent their nature requires.

13. Service standard and disclaimers

SDD will provide the service with reasonable professional care, subject to the applicable subscription and service-level commitments. Preview, beta and evaluation features may change and may be provided without a service-level commitment.

To the maximum extent permitted by law, and except for express commitments in an order or enterprise agreement, the service is provided without implied warranties of uninterrupted operation, merchantability, fitness for a particular purpose or non-infringement. Mandatory statutory warranties remain unaffected.

14. Liability

Any liability exclusions, caps, indemnities, governing law and venue must be completed in the applicable order form or enterprise agreement and reviewed for the customer's jurisdiction. Nothing excludes liability that cannot lawfully be excluded, including liability for fraud or deliberate misconduct where applicable.

Until provider identity, governing law and the commercial liability schedule are finalized by qualified counsel, this public version is a pre-production contractual draft and must not be relied on as the sole commercial agreement.

15. Changes, notices and order of precedence

SDD may update these Terms for legal, security, operational or product reasons. The service records the accepted version and requires renewed acceptance before protected use when the controlled version changes.

An enterprise agreement, data-processing agreement or signed order form prevails over these Terms to the extent of an express conflict. Notices may be delivered through the service or to the registered email address.

16. Contact

Questions about these Terms may be sent to legal@specsdrivendevelopment.com. Security reports should be sent to security@specsdrivendevelopment.com and privacy requests to privacy@specsdrivendevelopment.com.

Document SHA-256 7FD89F2FCB08D51E0566EFD9FB1756087CAEA2E52AAA35A67D44C7FD004CFF09

Privacy and audit-data information is available in the Privacy Policy.