Terms

Last updated 28 July 2026.

These terms cover this website and your use of the Draugr open-source software. Draugr Server is not yet available; when it is, it will have its own agreement.

The software

Draugr is licensed under the Apache License 2.0. That license governs your use of it, and its terms prevail over anything on this page. Two of its provisions are worth stating in plain words, because they matter:

There is no warranty. Draugr is provided "as is". We don't promise it is fit for any purpose, error-free, or that it will find anything in particular.

There is no liability. To the extent the law allows, neither Draugr nor its contributors are liable for any damages arising from your use of it, including a vulnerability it failed to find, a license obligation it failed to flag, or a build it failed or passed.

What a scan result means

A passing verdict means the controls you configured found nothing they were looking for. It is not a statement that your software is secure, compliant, or fit to ship. Draugr is silent about anything your descriptor doesn't declare, controls you didn't enable, and whatever the underlying third-party scanners miss.

License findings are information, not legal advice, and create no attorney–client relationship. Reports and SBOMs are a record of what was run, not a certification against any standard. The scope and disclaimer page sets this out in full.

Scanning responsibly

Some controls make requests to hosts you name, and the dast control actively probes them. In many jurisdictions that is lawful only against systems you own or have written permission to test. Obtaining that permission is your responsibility.Draugr scans what it is pointed at and cannot tell whether you were entitled to.

Third-party tools

Draugr runs external scanners rather than embedding them. When you use them you do so under their own licenses and terms, not ours. Some fetch data from third-party services while scanning. The integrations catalog names each tool and its license.

This website

The site is provided as is, and may change or go offline without notice. Content here is documentation and opinion, not professional advice, legal, security, or otherwise. Don't use the site to break the law, attack it, or misrepresent your identity when contacting us.

"Draugr" and the Draugr mark are ours. The Apache-2.0 license covers the code; it does not grant trademark rights. You're welcome to say you use Draugr, and to write about it.

See Privacy for what the site collects.

Changes

If these change materially we'll update the date above. Your continued use of the site after that is your acceptance of the change; if you'd rather be told, ask at hello@draugr.devand we'll email you.

Contact

hello@draugr.dev, or the contact form.