Eriksen Labs

Terms

Last updated 9 August 2026

Marketplace apps · Licensing

Eriksen Labs apps distributed through the Atlassian Marketplace are licensed under the Bonterms Standard End User Agreement, adopted through the Marketplace.

We use a standard agreement deliberately. It is a recognised set of terms that most legal teams have already reviewed, so adopting our apps does not require reading a bespoke contract first. Purchase, renewal, billing and refunds are handled by Atlassian under the Atlassian Marketplace Terms of Use.

Marketplace apps · Provider-specific terms

The following apply in addition to the Bonterms Standard End User Agreement.

1. Support. Support is provided through the Eriksen Labs support portal and by email at [email protected] during Norwegian business hours. Response targets by severity are published in our service level agreement.

2. Availability. Eriksen Labs apps run entirely within Atlassian infrastructure. Eriksen Labs operates no servers of its own and makes no separate uptime commitment; app availability follows the availability of the customer's Atlassian site.

3. Third-party components. Mermaid Studio renders diagrams using Mermaid and CodeMirror, open-source libraries distributed under the MIT licence. Request Again uses only Atlassian's own Forge packages.

4. Customer data. What an app can access differs by app, and is shown on its install screen before installation.

Mermaid Studio requests no Atlassian permission scopes. Diagram content is rendered in the customer's browser and stored by Atlassian within the customer's own Confluence instance.

Recurring Requests asks for the permission scopes shown on its install screen, and stores schedules, the details of the requests being repeated, and per-project settings in Forge storage within the customer's own Atlassian instance. This includes personal data, as described in the privacy policy.

In both cases the data remains inside Atlassian's infrastructure. Eriksen Labs operates no servers that receive it and has no means of accessing it.

5. Data processing. Where an app processes personal data on the customer's behalf, our Data Processing Addendum applies and forms part of these terms.

what it does · Licensing

The scanner is free software. The what-it-does command line tool is published on npm and licensed under the MIT licence, whose text travels with the package. You may use it for anything, including commercially, and nothing on this page narrows that. It will not be withdrawn or relicensed out from under you: the versions already published cannot be unpublished from your machine.

The pull request check is licensed separately. The GitHub Action that runs the same comparison on every pull request is not open source. It is free to use on public repositories. On private repositories it requires a paid licence key, granted for as long as the subscription is active.

A licence key covers one organisation and as many repositories as it owns. The tier is set by active committers — people who have committed to the repository in the last ninety days — counted inside your own CI runner by the equivalent of git shortlog -sn --since=90.days. That number is computed where your code already is, used to decide which tier you are on, and discarded. It is never sent to us, and we ask no questions about your company's size because we have no need of the answer.

You may not redistribute, resell or sublicense the Action, or remove its licence notice. You may read it: it is plain JavaScript in a public repository, and reading what a tool does before running it in your pipeline is exactly the habit this product exists to support.

what it does · Purchase and refunds

Subscriptions are sold through Polar, who act as merchant of record. Polar is the seller for the purposes of the transaction: they take the payment, issue the invoice, and collect and remit any sales tax or VAT due in your jurisdiction. Their terms and privacy policy govern the payment itself.

Refunds. Write to [email protected] within fourteen days of a charge and we will refund it in full. No reason is required and none will be asked for. After fourteen days, cancelling stops the next renewal and the licence keeps working until the period you have paid for ends; we do not refund part of a period, and we do not bill you again once you have cancelled.

Prices are listed on the product page, including the largest tier. If a price changes, existing subscriptions keep the price they were bought at for as long as they remain active.

what it does · What it does not promise

The scanner reads code without running it. It cannot see a path chosen at runtime, and the absence of a finding is not proof that nothing is wrong. Every report says so on its own front page rather than in a footnote here. It is a tool for noticing things worth checking, not an audit, a security certification, or a guarantee about your software.

Findings can be wrong. A check may live behind an import the scanner could not follow, and where that is possible the report says which import blinded it. Nothing in this product should be actioned without a person looking.

The Action fails open by design. If a scan errors, or a licence check cannot reach the network, the check passes and says so in the log. It will not block your pipeline because something on our side went wrong. The only failure it produces is one you asked for by setting fail-on-new.

To the extent permitted by law, our total liability under these terms is limited to the amount you paid us in the twelve months before the claim. For the free scanner, which you paid nothing for, that amount is nothing — the MIT licence's warranty disclaimer applies and is the whole of it.

Support

Support is provided by email at [email protected]. We aim to respond to all requests within two business days.

Support covers installation, configuration, defect reports and questions about intended behaviour. It does not include authoring content on your behalf, support for Atlassian products themselves, or interpreting what a scanner finding means for your particular application.

Response targets by severity are set out in our service level agreement.

Trademarks

Atlassian, Jira and Confluence are trademarks of Atlassian Pty Ltd. Eriksen Labs is an independent Atlassian Marketplace Partner, and is not affiliated with or endorsed by Atlassian.