Terms & Conditions

Last updated: May 2026

See also: Privacy Policy · Documentation

These Terms and Conditions govern your use of DockerSec, available at dockersec.com.

By accessing or using DockerSec, you agree to these Terms. If you do not agree to them, you must not use the service.

1. About DockerSec

DockerSec is a Dockerfile security analysis service. It allows users to submit Dockerfile content, either anonymously or through a registered account, and receive automated findings that may indicate security risks, weaknesses, or insecure configuration patterns.

DockerSec is intended to assist with security review. It is not a replacement for professional security assessment, manual code review, threat modelling, or environment-specific risk analysis.

2. Scope and Limitations of the Service

DockerSec analyses the contents of Dockerfile submissions against a set of known patterns and advisories. Results are informational only. A scan result — including a result showing no findings — does not constitute a security audit, a guarantee of security, or a professional security assessment.

Effective container security requires a holistic approach combining automated tooling, manual code review, professional security analysis, and ongoing monitoring. DockerSec is one component of that posture, not a substitute for it.

You are solely responsible for evaluating scan results, determining their relevance to your environment, and deciding what action to take. DockerSec accepts no liability for any security incident, data breach, or loss arising from reliance on scan results, whether or not those results were accurate, complete, or up to date at the time of the scan.

The results are provided for information and guidance only. They do not guarantee that:

  • a Dockerfile is secure;
  • all security issues have been identified;
  • every reported finding represents a real or exploitable risk in your environment;
  • the recommended remediation is complete or appropriate for every use case; or
  • the results remain valid after the time of the scan, as new vulnerabilities and advisories are published continuously.

Security analysis tools may produce false positives, omit relevant issues, or provide output that requires technical judgement. You are responsible for reviewing the findings and deciding whether and how to act on them.

In particular, users should be aware that the security of Docker containers extends well beyond the Dockerfile. How a container is run, the host daemon configuration, network isolation, secrets management, and runtime behaviour all contribute to the overall security posture. For regulated environments or high-risk deployments, you should engage a qualified security professional.

3. Acceptable Use

You may use DockerSec only to analyse Dockerfiles that you own, are authorised to assess, or otherwise have the right to submit.

You must not:

  • submit content that you do not have the right to share;
  • submit content that unlawfully contains personal data, confidential information, credentials, secrets, or third-party intellectual property;
  • attempt to access, interfere with, or compromise another user's account, data, or submissions;
  • attempt to circumvent rate limits, quotas, authentication controls, or other service restrictions;
  • use DockerSec in a way that disrupts, degrades, or harms the availability, integrity, or security of the service;
  • reverse engineer, probe, scan, or test the service except as expressly authorised by us;
  • use the service to develop, test, or improve malicious activity; or
  • use DockerSec in breach of any applicable law or regulation.

We may suspend, restrict, or terminate access where we reasonably believe these Terms have been breached or where use of the service presents a risk to DockerSec, other users, or third parties.

4. Your Content

You retain ownership of Dockerfiles and other content that you submit to DockerSec.

By submitting content, you grant DockerSec a limited right to receive, process, analyse, store, display, and otherwise use that content solely for the purposes of operating, securing, maintaining, and improving the service.

You are responsible for ensuring that you have the necessary rights and permissions to submit the content to DockerSec.

You should avoid submitting secrets, credentials, tokens, private keys, commercially sensitive information, or personal data unless this is necessary and lawful.

DockerSec may automatically attempt to detect and replace credential-like values before storage. This process is intended to reduce risk, but it should not be treated as a guarantee that all sensitive values will be detected or removed.

5. Accounts

Some features may require an account.

You are responsible for keeping your account credentials secure and for all activity carried out using your account. You must notify us promptly if you suspect that your account has been accessed without authorisation.

We may suspend or close accounts that breach these Terms, are used unlawfully, or are used in a way that harms the service, other users, or third parties.

6. Availability and Changes to the Service

We may update, modify, suspend, or withdraw all or part of DockerSec from time to time. We do not guarantee that the service will always be available, uninterrupted, or error-free.

We may also change the way findings are generated, presented, prioritised, or retained.

7. Security and Responsible Disclosure

We take the security of DockerSec seriously. If you believe you have identified a vulnerability in the service, please contact us and provide sufficient detail to allow us to investigate.

You must not exploit, disclose, or use any vulnerability in a way that could harm DockerSec, its users, or third parties.

8. Privacy and Data Protection

Our use of personal data is described in our Privacy Notice.

Submitted Dockerfiles may contain personal data or information that can identify individuals, systems, organisations, or environments. You are responsible for ensuring that any personal data you submit is provided lawfully.

Where required, you should remove or redact personal data, secrets, credentials, internal hostnames, and other sensitive information before submission.

9. Intellectual Property

DockerSec, including its software, design, documentation, branding, and service output format, is owned by us or our licensors and is protected by intellectual property law.

You may use the findings generated by DockerSec for your own internal review, remediation, reporting, and security management purposes.

You must not copy, reproduce, resell, or commercially exploit DockerSec or any substantial part of the service except as expressly permitted by us.

10. No Affiliation with Docker

DockerSec is an independent service and is not affiliated with, endorsed by, sponsored by, or approved by Docker, Inc. or any affiliated company.

Docker and related marks are trademarks or registered trademarks of their respective owners.

11. No Warranty

DockerSec is provided on an "as is" and "as available" basis.

To the fullest extent permitted by law, we exclude all warranties, representations, conditions, and implied terms relating to DockerSec, including any warranty that the service will be accurate, complete, uninterrupted, secure, error-free, or free from vulnerabilities.

Nothing in these Terms affects any statutory rights that cannot lawfully be excluded or limited.

12. Limitation of Liability

Nothing in these Terms excludes or limits liability for:

  • death or personal injury caused by negligence;
  • fraud or fraudulent misrepresentation; or
  • any other liability that cannot be excluded or limited under applicable law.

Subject to the above, DockerSec will not be liable for:

  • loss of profits, sales, business, revenue, or anticipated savings;
  • loss or corruption of data;
  • loss of goodwill or reputation;
  • business interruption;
  • indirect or consequential loss; or
  • decisions made in reliance on automated findings produced by the service.

To the fullest extent permitted by law, our total liability arising out of or in connection with your use of DockerSec is limited to the greater of:

  • the amount you paid to use DockerSec in the twelve months before the event giving rise to the claim; or
  • £100.

If you use DockerSec free of charge, you acknowledge that the service is provided without payment and that this is reflected in the limitations of liability set out above.

13. Export Controls and Sanctions

DockerSec is operated from the United Kingdom. Access to the service may be restricted where required by applicable export control, sanctions, or trade compliance laws.

You must not use DockerSec in breach of applicable sanctions, export control restrictions, or other trade restrictions.

We may suspend, restrict, or terminate access where we reasonably believe this is necessary to comply with applicable law or government guidance.

14. Changes to These Terms

We may update these Terms from time to time.

Where changes are material, we will take reasonable steps to bring them to your attention. The updated Terms will be posted on this page with a revised "Last updated" date.

Your continued use of DockerSec after updated Terms take effect means that you accept the updated Terms.

15. Governing Law and Jurisdiction

These Terms are governed by the laws of England and Wales.

The courts of England and Wales will have exclusive jurisdiction over any dispute arising out of or in connection with these Terms or your use of DockerSec, except where applicable consumer law requires otherwise.

16. Contact

For questions about these Terms, please contact us using the form provided on the DockerSec website.