Scope, up front. This page covers this website, the free public repository, and the build guides. It is not a services contract. If you hire OpsFox, a separate written agreement governs that work and it takes precedence over everything here.
1.What these terms cover
These terms apply to your use of this website and the freely published material linked from it: the baseline repository, the audit tooling, the build guides, and the weekly dispatch.
They do not govern paid work. Consulting engagements — sprints, fixed-scope engagements, and monthly retainers — are governed by a signed agreement and statement of work covering scope, response windows, access, liability, confidentiality, and data handling. If there is any conflict between that agreement and this page, that agreement wins.
The registered legal entity and the governing jurisdiction for formal disputes are being finalised and will be published here before any paid engagement is signed. If you need those details for a vendor record, ask and you'll get them directly rather than from a placeholder.
2.The free repository is licensed separately
The public baseline and the audit tooling are released under the Apache License 2.0. That licence — not this page — governs what you may do with that code, and it is deliberately permissive: use it commercially, modify it, deploy it for your own clients, fork it and never mention where it came from.
Two things the Apache licence does not grant, and this page states explicitly:
- No trademark rights. The OpsFox name, the fox mark, and the component code names are not licensed for your use. Run the code, ship the code, just don't present your service as being OpsFox.
- No warranty. The code is provided as-is, which is worth reading literally when the code in question configures security controls.
Individual components deployed by that code are separate upstream open-source projects under their own licences, which differ from one another. If you plan to redistribute or modify a bundle, check each component's licence — the transparency pack lists every one.
3.The build guides come with no warranty
The guides describe things that were actually built, and they are written as honestly as possible, including the parts that went wrong. They are still just writing on the internet.
- You are responsible for your own hardware. Some builds involve flashing firmware, opening devices, and lithium batteries. It is possible to destroy equipment or hurt yourself.
- You are responsible for your own legality. Some guides cover network and wireless auditing tools. Use them only on networks and systems you own or have written permission to test. Laws vary by jurisdiction and ignorance of yours is not a defence.
- You are responsible for your own data. Follow the backup steps before the steps that delete things.
- Nothing in a guide is a security guarantee. Running a hardened configuration reduces risk; it does not make you unbreachable, and any writing that claims otherwise is selling you something.
If a guide is wrong, say so and it gets corrected with a date on the fix. That is the actual remedy on offer here, and it is a real one.
4.Using this website
Please don't:
- Attempt to break, overload, or gain unauthorised access to this site or its hosting. If you find a way to, report it — see the disclosure policy.
- Scrape the site in a way that degrades it for anyone else.
- Republish the written content wholesale as your own. Quote it, link it, argue with it — all fine.
- Use the OpsFox name or marks in a way that implies endorsement or partnership that does not exist.
Security research on this site is welcome under the disclosure policy on the how this works page. Acting in good faith under that policy will not be met with legal action.
5.What is not promised anywhere on this site
Repeated here because it belongs in the legal terms and not only in the marketing copy:
- No third-party security certification is held. There is no SOC 2 report and no ISO 27001 certification.
- No authority to assess, audit, or certify anyone against any compliance framework is held or claimed.
- No round-the-clock human availability is offered. Automated detection runs continuously; a person does not.
- No uptime commitment is made, because there is no hosted platform to commit one for. Systems deployed under an engagement run on infrastructure the client owns and controls.
6.Links and third parties
This site links to upstream open-source projects, hardware vendors, and other people's writing. Those are not under OpsFox control and their content, pricing, availability, and security are their own responsibility. A link is a pointer, not an endorsement of everything behind it forever.
7.Limitation of liability
To the fullest extent permitted by law, OpsFox is not liable for indirect, incidental, consequential, or punitive damages arising from your use of this website, the free repository, or the build guides — including lost profits, lost data, or business interruption.
The material on this site is provided free of charge, and liability arising from it is limited accordingly. Liability connected to paid work is addressed in the engagement agreement, where it is capped and negotiated properly, as it should be.
Some jurisdictions do not allow certain limitations, in which case the limitations above apply only as far as that jurisdiction permits.
8.Changes and contact
These terms may change. When they do, the date at the top changes with them. Continuing to use the site after a change means the updated terms apply to you.
Questions about anything on this page: hello@opsfox.io. How data is handled is covered separately in the privacy policy.