Davy.Locker
  • How It Works
  • Security
  • Pricing
  • Whitepaper
  • GitHub
  • Get Started
Legal

Terms of Service

Effective Date: March 28, 2026 — Last Updated: March 28, 2026

Section 1

Acceptance of Terms

By accessing or using any Davy.Locker product, service, software development kit (SDK), website, cloud dashboard, command-line interface, or API (collectively, the "Service"), you agree to be bound by these Terms of Service ("Terms"). If you are using the Service on behalf of an organization, you represent and warrant that you have the authority to bind that organization to these Terms.

If you do not agree with any part of these Terms, you must not use the Service. Your continued use of the Service constitutes ongoing acceptance of these Terms as they may be amended from time to time.

Section 2

Description of Service

Davy.Locker is a credential security platform designed for AI agents and automated systems. The Service provides:

  • Encrypted Credential Vault — AES-256-GCM encrypted local storage for API keys, tokens, passwords, and other sensitive credentials, protected by a user-defined master password derived via Argon2id.
  • Credential Injection Proxy — A runtime proxy that injects credentials directly into API requests on behalf of AI agents, ensuring agents never access raw secret material.
  • Scoped Grants & Permission Model — Fine-grained access controls (USE_ONLY, READ, BLOCKED) with session-based, time-limited, or persistent grant types and risk-tiered approval flows.
  • Response Lenses & Redaction — Field-level and pattern-based response filtering that removes sensitive data (bank details, tax IDs, PII) before agents receive API responses.
  • Audit Logging — Detailed records of all credential access, API calls, and agent activity.
  • Cloud Dashboard & The Kraken (Pro/Enterprise) — Centralized management, AI-powered security monitoring, auto-rotation, team sharing, and compliance tooling.

Davy.Locker employs a zero-knowledge architecture. All encryption and decryption occurs locally on your device or infrastructure. Davy.Locker never receives, stores, transmits, or has access to your plaintext credentials, master password, or derived encryption keys.

Section 3

Service Tiers

3.1 Free Tier

The Free tier is a fully functional, self-hosted security runtime available at no cost with no account required. It includes the open-source SDK, encrypted vault, credential injection proxy, response lenses, local audit logging, and support for unlimited agents and credentials. The Free tier is not a trial — it is a permanent offering with no time limit or feature expiration.

3.2 Pro Tier ($29/month)

The Pro tier provides a cloud dashboard for centralized management, multi-server sync (up to 10 nodes), The Kraken AI security monitoring, auto-rotation (scheduled and triggered), team sharing (up to 5 members), security scoring, alerting (Slack, email, webhooks), grant hygiene reports, and priority support. Pro subscriptions are billed monthly. You may cancel at any time; cancellation takes effect at the end of the current billing period.

3.3 Enterprise Tier

Enterprise tier is available at custom pricing and includes everything in Pro plus unlimited nodes and team members, SSO/SAML integration, custom Kraken rules, SOC 2 compliance evidence export, self-hosted or cloud dashboard options, dedicated support with SLA, and a data processing agreement. Enterprise terms are governed by a separate written agreement between you and Davy.Locker.

3.4 Billing & Refunds

Paid subscriptions are billed in advance on a monthly recurring basis. All fees are non-refundable except where required by applicable law. Davy.Locker reserves the right to change pricing with 30 days advance written notice. Price changes do not apply to the current billing period.

Section 4

Account & Security Responsibilities

4.1 Master Password

Your encrypted vault is protected by a master password that you create. Davy.Locker operates on a zero-knowledge model: we do not store, transmit, or have any means to access your master password or the encryption keys derived from it.

Critical: If you lose your master password, Davy.Locker cannot recover it, reset it, or decrypt your vault. You are solely responsible for securely storing and remembering your master password. Loss of your master password results in permanent, irrecoverable loss of access to all credentials stored in your vault.

4.2 Account Security (Pro/Enterprise)

If you create a Davy.Locker account for Pro or Enterprise features, you are responsible for maintaining the confidentiality of your account credentials and for all activity that occurs under your account. You must notify Davy.Locker immediately at security@davylocker.dev if you become aware of any unauthorized use of your account.

4.3 Your Infrastructure

The Davy.Locker SDK runs within your own infrastructure. You are responsible for the security, maintenance, and proper configuration of the servers, environments, and systems on which you deploy the SDK. Davy.Locker is not responsible for vulnerabilities, breaches, or data loss arising from misconfiguration, unpatched systems, or insecure deployment practices within your infrastructure.

Section 5

Acceptable Use

You agree not to use the Service to:

  • Violate any applicable local, state, national, or international law or regulation.
  • Store, manage, or transmit credentials for systems or services you do not have authorization to access.
  • Attempt to reverse-engineer, decompile, or circumvent any security mechanisms, access controls, or encryption within the Service.
  • Use the Service to facilitate unauthorized access to third-party systems, networks, or data.
  • Interfere with, disrupt, or create an undue burden on the Service or the networks and infrastructure connected to it.
  • Resell, sublicense, or redistribute the Pro or Enterprise cloud services without written authorization from Davy.Locker.
  • Use the Service to store or manage credentials associated with illegal activity, including but not limited to fraud, money laundering, or trafficking.

Violation of this Acceptable Use policy may result in immediate suspension or termination of your access to the Service without notice or refund.

Section 6

Intellectual Property

6.1 Davy.Locker IP

The Service, including its software, design, documentation, branding, trademarks (including "Davy.Locker," "The Kraken," and the Davy.Locker logo), and all related intellectual property, are owned by Davy.Locker and protected by applicable intellectual property laws. Nothing in these Terms grants you ownership of any Davy.Locker intellectual property.

6.2 Open-Source Components

Certain components of the Davy.Locker SDK are released under open-source licenses. Your use of those components is governed by their respective license terms (e.g., MIT, Apache 2.0) as specified in each package's repository. These Terms do not restrict rights granted to you under applicable open-source licenses.

6.3 Your Data

You retain full ownership of all credentials, configurations, and data you store in or process through the Service. Davy.Locker does not claim any ownership or license to your data. Due to our zero-knowledge architecture, we cannot access your encrypted data even if we wanted to.

Section 7

The Kraken — AI Monitoring Disclaimer

The Kraken is an AI-powered security monitoring feature available in Pro and Enterprise tiers. It provides automated anomaly detection, security recommendations, threat response suggestions, and credential rotation triggers.

Important: The Kraken provides recommendations and automated responses, not guarantees. AI-based security monitoring is probabilistic by nature. The Kraken may produce false positives (flagging benign activity as suspicious) or false negatives (failing to detect certain threats).

Specifically:

  • No guarantee of threat detection. The Kraken is designed to identify anomalous patterns but cannot guarantee detection of all security threats, novel attack vectors, or zero-day exploits.
  • Recommendations, not mandates. Security recommendations and risk scores provided by The Kraken are advisory in nature. You are responsible for evaluating and acting on them according to your own security requirements and risk tolerance.
  • Auto-rotation risk. When auto-rotation is enabled, The Kraken may automatically rotate credentials in response to detected threats. While designed to protect you, automated rotation could temporarily disrupt services that depend on the rotated credential. You are responsible for configuring rotation policies appropriate for your environment.
  • Not a substitute for security practices. The Kraken supplements but does not replace sound security practices including regular credential rotation, access reviews, network security, and incident response planning.
Section 8

Limitation of Liability

Davy.Locker provides security tooling — not insurance.

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW:

  • THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING WITHOUT LIMITATION WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT.
  • DAVY.LOCKER DOES NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, SECURE, OR FREE OF VIRUSES OR OTHER HARMFUL COMPONENTS.
  • IN NO EVENT SHALL DAVY.LOCKER, ITS OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, OR AFFILIATES BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING WITHOUT LIMITATION LOSS OF PROFITS, DATA, CREDENTIALS, BUSINESS OPPORTUNITIES, OR GOODWILL, ARISING OUT OF OR IN CONNECTION WITH YOUR USE OF OR INABILITY TO USE THE SERVICE.
  • DAVY.LOCKER'S TOTAL AGGREGATE LIABILITY FOR ALL CLAIMS ARISING OUT OF OR RELATING TO THESE TERMS OR THE SERVICE SHALL NOT EXCEED THE GREATER OF (A) THE AMOUNT YOU HAVE PAID TO DAVY.LOCKER IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM, OR (B) ONE HUNDRED DOLLARS ($100 USD).

These limitations apply even if Davy.Locker has been advised of the possibility of such damages and regardless of the form of action, whether in contract, tort (including negligence), strict liability, or otherwise.

Section 9

Indemnification

You agree to indemnify, defend, and hold harmless Davy.Locker and its officers, directors, employees, agents, and affiliates from and against any and all claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of or relating to:

  • Your use of the Service or any activity under your account.
  • Your violation of these Terms or any applicable law or regulation.
  • Your negligence or willful misconduct, including but not limited to insecure deployment of the SDK, failure to protect your master password, or misconfiguration of access controls.
  • Any third-party claims arising from your agents' use of credentials managed through the Service.
  • Your breach of any third-party rights, including intellectual property, privacy, or contractual rights, through your use of the Service.
Section 10

Termination

10.1 Termination by You

You may stop using the Service at any time. For Pro or Enterprise subscriptions, you may cancel your subscription through the cloud dashboard or by contacting support@davylocker.dev. Cancellation takes effect at the end of the current billing period. No partial refunds are provided for unused time within a billing period.

10.2 Termination by Davy.Locker

Davy.Locker may suspend or terminate your access to the Service at any time, with or without cause, and with or without notice, if:

  • You breach these Terms or the Acceptable Use policy.
  • Your use of the Service poses a security risk to Davy.Locker or other users.
  • Continued provision of the Service to you is impractical or unfeasible for any reason.
  • Required by law, regulation, or legal process.

10.3 Effect of Termination

Upon termination, your right to access the Pro or Enterprise cloud services ceases immediately. The open-source SDK installed on your infrastructure remains functional and subject to its open-source license terms. Your locally encrypted vault data remains on your systems and under your control — Davy.Locker has no ability to remotely delete, modify, or access it. Sections of these Terms that by their nature should survive termination (including Limitation of Liability, Indemnification, and Governing Law) shall survive.

Section 11

Changes to Terms

Davy.Locker reserves the right to modify these Terms at any time. Material changes will be communicated through one or more of the following: a prominent notice on our website, email notification to registered Pro/Enterprise users, or an in-dashboard alert.

Changes become effective 30 days after posting unless a longer notice period is required by applicable law. Your continued use of the Service after the effective date constitutes acceptance of the updated Terms. If you do not agree with the updated Terms, you must stop using the Service before the effective date.

We encourage you to review these Terms periodically. The "Last Updated" date at the top of this page indicates when the most recent changes were made.

Section 12

Governing Law & Dispute Resolution

These Terms shall be governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to its conflict of law provisions.

Any dispute arising out of or relating to these Terms or the Service shall first be attempted to be resolved through good-faith negotiation between the parties. If negotiation fails to resolve the dispute within 30 days, either party may pursue resolution through binding arbitration administered by the American Arbitration Association (AAA) under its Commercial Arbitration Rules, conducted in the English language. The arbitrator's decision shall be final and binding and may be entered as a judgment in any court of competent jurisdiction.

Notwithstanding the foregoing, either party may seek injunctive or equitable relief in any court of competent jurisdiction to protect its intellectual property rights or to prevent irreparable harm.

You agree that any proceedings will be conducted on an individual basis and not as part of a class, consolidated, or representative action.

Section 13

Contact

If you have questions about these Terms, the Service, or your rights, you can reach us at:

  • General inquiries: hello@davylocker.dev
  • Security matters: security@davylocker.dev
  • Legal & compliance: legal@davylocker.dev
  • Enterprise sales: enterprise@davylocker.dev
  • Support: support@davylocker.dev
  • GitHub: github.com/davylocker
Davy.Locker

Credential security for the agent era. Give your AI agents the credentials they need—without giving away the keys.

Product

How It Works Pricing Whitepaper Documentation

Company

About GitHub Blog

Legal

Privacy Policy Terms of Service Security
© 2026 Davy.Locker. All rights reserved.