Legal

Terms of Service

The agreement between you and us for using Hatch'd — what the service does, your responsibility to only scan what you own, acceptable use, how fixes and billing work, and the limits on our liability.

Last updated: 16 June 2026


These Terms of Service (“Terms”) are the agreement between you and TGM Studios LLC (“we,” “us,” or “our”), the company that operates Hatch'd (the “Service”) at gethatchd.com. By using the Service you agree to these Terms. Please read them carefully — they include important things about authorization to scan, the limits of what a scan can promise, and how our liability is capped.

1. Agreement to these Terms

By creating an account, running a scan, or otherwise using Hatch'd, you accept these Terms. If you are using the Service on behalf of an organization, you confirm you are authorized to bind that organization, and “you” means both you and that organization. If you do not agree, please do not use the Service.

2. What Hatch’d does

Hatch'd is a security tool with two parts:

  • A free scan. We run a read-only security scan of an application you point us at. The scan uses only the public, anonymous credentials the application already ships to every visitor. It is count-only and ownership-gated, it reads but never writes, and it fails closed — an incomplete scan is reported as “incomplete,” never “clean.”

  • Proposed fixes. If you choose a paid fix, we prepare a fix and deliver it to you as a GitHub pull request against your repository. You review it, test it, and merge it. We never deploy to your production systems ourselves.

Importantly, the free scan never holds your service-role key and never writes to your production. It works only with the public anonymous credentials your application already exposes.

3. Eligibility and your account

You must be old enough to form a binding contract where you live to use the Service. When you create an account you agree to give accurate information and to keep it up to date. You are responsible for what happens under your account, including keeping your credentials secure and any actions taken with them. Tell us promptly at hello@gethatchd.com if you suspect unauthorized use of your account. How we handle the personal data tied to your account is described in our Privacy Policy.

4. Authorization to scan

This is the most important condition of these Terms. Each time you submit a target to Hatch'd, you represent and warrant that you own that application, domain, database, or system, or that you have written authorization from the owner to test it. There are no exceptions.

Your use of the Service is also governed by the Acceptable use rules below, which form part of these Terms. Submitting a target is your affirmative statement of authorization; if that statement is untrue, you are in breach of these Terms and solely responsible for the consequences, including under computer-misuse and unauthorized-access laws.

5. Acceptable use

These rules govern your use of Hatch'd and the security scan it performs. They form part of these Terms. By using Hatch'd you agree to them. If you do not agree, do not use the Service.

The authorization rule

You may only run a scan against an application, domain, database, or system that you own, or that you have written authorization from the owner to test. There are no exceptions. Each time you submit a target to Hatch'd, you represent and warrant that you are authorized to test it. Submitting a target is your affirmative statement of authorization. If that statement is untrue, you are in breach of these Terms and solely responsible for the consequences.

How the scan is designed to stay in bounds

Hatch'd is built to minimize blast radius, but these controls support the authorization rule — they do not replace it:

  • Ownership-gated. We require proof of control over a target before a scan runs.

  • Read-only and public-credential only. The free scan uses only the public credentials an application already ships to every visitor. It reads; it does not write.

  • Count-only and fail-closed. We report whether data is exposed without exfiltrating it, and an incomplete scan reads as “incomplete,” never “clean.”

  • No service-role key, no production writes. Fixes are delivered as pull requests you review and merge. We never hold your service-role key and never mutate your production systems.

Prohibited uses

You must not use Hatch'd to:

  • scan, probe, or test any system you do not own or are not authorized to test;

  • attempt to access, copy, exfiltrate, or expose data belonging to third parties;

  • circumvent, disable, or interfere with the ownership gate or any other safety control;

  • use scan output to attack, extort, or harm any person or organization;

  • resell, sublicense, or provide the service to scan others’ systems without their authorization;

  • violate any applicable law, including computer-misuse and unauthorized access laws (see below); or

  • overload, disrupt, reverse engineer, or attempt to gain unauthorized access to Hatch'd itself.

Authorized security testing only

Hatch'd is a tool for authorized security testing. Using it against systems you are not permitted to test may be a criminal offense, including under the U.S. Computer Fraud and Abuse Act (CFAA), the UK Computer Misuse Act 1990, and equivalent laws in the EU and elsewhere. You are responsible for ensuring your use is lawful in every jurisdiction that applies to you and your targets.

Enforcement

We may log scan requests for security and abuse-prevention purposes. If we reasonably believe a scan is unauthorized or these rules are being violated, we may, without notice, refuse or halt a scan, suspend or terminate your access, and where appropriate cooperate with affected owners or law enforcement.

Your responsibility and indemnity

You assume all liability arising from scans you initiate. You agree to indemnify and hold harmless Hatch'd and TGM Studios LLC from any claim, loss, or liability arising out of an unauthorized scan or any other breach of these rules, as further set out in the Indemnification section below.

Reporting abuse

If you believe someone has used Hatch'd to scan a system without authorization, or you have a security concern, contact us at hello@gethatchd.com. To report a vulnerability in Hatch'd itself, email the same address or see our published security.txt.

6. Fixes and your responsibility

When you purchase a fix, we deliver it as a pull request that you review, test, and merge. Hatch'd does not deploy, push to production, or otherwise change your live systems. We never hold your service-role key, and we never write to your production environment.

Because of this, you are solely responsible for reviewing every proposed change, testing it in your own environment, deciding whether to merge it, and deploying it. You remain responsible for your application and its security at all times. A pull request from us is a suggestion you control — not a change we make on your behalf.

7. Plans and billing

We offer the following:

  • Free scan — $0. The read-only security scan is free.

  • Hatch an app — $499. A single payment for one fix, delivered as a pull request.

  • Monitor & Grow — $199 per month. An ongoing plan billed monthly, which renews automatically until you cancel.

Payments are processed by our payment provider, Stripe; we do not store your full card details. For the subscription, you authorize us (through our payment provider) to charge your payment method each billing period until you cancel. Prices are in the currency shown at checkout and may exclude taxes, which we add where required. We may change our prices, but we will give you reasonable advance notice, and changes will not apply to a one-time purchase you have already paid for.

8. Cancellation and refunds

You can cancel your subscription at any time from your account settings or by emailing hello@gethatchd.com. When you cancel, your subscription stays active until the end of the current billing period, and we do not charge you again after that. We do not provide prorated refunds for the unused part of a billing period unless required by law.

Refunds for one-time purchases are handled as follows: you may request a refund within 14 days of purchase provided the work has not already been substantially delivered; once the work has been substantially delivered, one-time purchases are non-refundable except where mandatory law requires otherwise. Nothing here limits any refund or cancellation rights you have under mandatory law, including the consumer rights described in the next section.

9. EU consumers — right of withdrawal

If you are a consumer in the EU (or another jurisdiction with similar rules), you normally have the right to withdraw from a purchase of digital services within 14 days, without giving a reason. To exercise it, just tell us within that period at hello@gethatchd.com.

However, our scans and fixes are digital services you usually want delivered right away. To start the scan or prepare your fix immediately — before the 14-day period ends — you give your express consent to us beginning performance now, and you acknowledge that you will lose your right of withdrawal once the service has been fully performed. If you do not give that consent, performance begins only after the 14-day period ends. We will ask for this consent at checkout where it applies, and we will confirm it to you on a durable medium.

10. Disclaimer of warranties

The Service is provided “as is” and “as available,” without warranties of any kind, whether express or implied, to the fullest extent permitted by law.

Security is never absolute. We do not guarantee that a scan finds every issue in your application, that it is free of false positives or false negatives, or that any fix will make your application secure or compliant. A scan is not a guarantee of safety and a clean result is not a certification — you should not treat either as proof that your application is secure. You remain responsible for your own security testing and decisions.

11. Limitation of liability

To the fullest extent permitted by law, neither TGM Studios LLC nor anyone working with us will be liable for any indirect, incidental, special, consequential, or punitive damages, or for any loss of profits, revenue, data, or goodwill, arising out of or relating to the Service.

Our total liability for all claims relating to the Service is capped at the greater of (a) the total fees you paid us for the Service in the 12 months before the event giving rise to the claim, or (b) one hundred US dollars ($100).

Nothing in these Terms excludes or limits any liability that cannot be excluded or limited under applicable law — for example, liability for death or personal injury caused by negligence, for fraud, or any mandatory rights you have as a consumer. If you are a consumer, these limits apply only to the extent the law allows.

12. Indemnification

You agree to indemnify and hold harmless TGM Studios LLC and Hatch'd, and the people who work with us, from any claim, loss, liability, or expense (including reasonable legal fees) arising out of your breach of these Terms or the Acceptable use rules — and in particular from any unauthorized scan you initiate or any scan of a target you were not entitled to test.

13. Intellectual property

We own the Service, including Hatch'd, our software, scan engine, and brand. These Terms do not transfer any of our intellectual property to you beyond the right to use the Service as permitted here.

You own your code and your application. A proposed fix we deliver as a pull request is yours to use, modify, merge, or reject. You grant us only the limited permission we need to scan a target you submit and to prepare and deliver fixes to you.

14. Data processing

Where we process personal data on your behalf — for example, when personal data happens to live inside the scan target you authorize us to scan — you (the customer) are the controller and Hatch'd, operated by TGM Studios LLC, is the processor. For data where we decide the purposes and means (your account, billing, and analytics), we are the controller and our Privacy Policy applies instead.

In line with Article 28 of the GDPR, when we process personal data on your behalf we process it only on your documented instructions, keep it confidential and secure, engage subprocessors only under equivalent flow-down terms (listed at Subprocessors), assist you with data-subject requests, notify you without undue delay of any personal-data breach, delete or return the data when the service ends, and make available the information needed to demonstrate compliance.

A full, executable Data Processing Addendum is available on request. Email hello@gethatchd.com with your entity details and we’ll send it for signature; once countersigned by both parties, that executed DPA prevails over this summary.

15. Operator and legal notice

This site and the Hatch’d service are operated by:

  • Entity: TGM Studios LLC

  • Address: 5830 E 2nd St, Ste 7000 #33694, Casper, WY 82609

  • Country: United States

  • Support phone: +1 (747) 257-1506

  • Support email: hello@gethatchd.com

16. Suspension and termination

You can stop using the Service at any time and close your account. We may suspend or terminate your access if you breach these Terms or the Acceptable use rules, if we reasonably believe a scan is unauthorized, or if we need to in order to comply with law or protect the Service or others. Where it is reasonable to do so, we will give you notice. Provisions that by their nature should survive termination — including authorization representations, disclaimers, liability limits, and indemnities — survive.

17. Governing law and venue

These Terms are governed by the laws of the State of Wyoming, United States, without regard to its conflict-of-laws rules. You agree that the courts of the state and federal courts located in Wyoming, United States have jurisdiction over any dispute arising from these Terms. If you are a consumer, this does not deprive you of the protection of mandatory laws or the right to bring proceedings in the country where you live.

18. Changes to these Terms

We may update these Terms from time to time. If we make a material change, we will give you reasonable notice, for example by email or a notice in the Service. Changes take effect when posted unless we say otherwise. If you keep using the Service after a change takes effect, you accept the updated Terms; if you do not agree, please stop using the Service.

19. Contact

Questions about these Terms, your account, or a purchase? Email us at hello@gethatchd.com or call +1 (747) 257-1506.