POSTQ CODE SCANNER PRODUCT TERMS Licensor: POSTQ SOFTWARE LABS PRIVATE LIMITED Product: PostQ Code Scanner Terms version: 0.1.0-Beta Revision date: 19 August 2026 Classification: PostQ Code Scanner-Beta private invite-only evaluation release These Product Terms supplement the PostQ Software Product License Agreement and the applicable Order. Capitalized terms not defined here have the meaning in that agreement. An applicable third-party license continues to control its component where required. 1. Product Components PostQ Code Scanner may be supplied as a scanner CLI/service, VS Code extension, Eclipse plug-in, standalone Scanner Report Viewer, prerequisite checker, OCI container, proprietary rule pack, report schema, documentation, or another module stated in the Order. Entitlement to one delivery form does not imply entitlement to every delivery form. 2. Authorized Purpose Customer may use entitled components to identify and review cryptographic assets, parameters, operations, groupings, FIPS-related evidence, post-quantum migration relevance, crypto-agility signals, and related code findings in Authorized Environments. Customer must have authority to scan the relevant code and systems. Usage limits for repositories, applications, projects, runners, scans, users, CI/CD, production, non-production, Affiliates, contractors, and report viewers are stated only in the Order. 3. Protected PostQ Scanner Intelligence Subject to verified ownership and third-party rights, PostQ Materials include proprietary scanner architecture, rule packs, rule definitions, encrypted or compiled rules, signatures, metadata, taxonomies, normalized operations, classification models, parameter mappings, provider/library mappings, risk logic, FIPS assessment logic, PQC readiness and crypto-agility logic, scoring, recommendations, knowledge-base relationships, schemas, and report templates. Customer must not extract, publish, redistribute, sublicense, sell, use as a standalone rule library, or use these protected materials to create a competing scanner or substantially equivalent proprietary detection library, except to the extent mandatory law or an applicable third-party license permits the activity. Customer may use findings and recommendations for its own remediation. No restriction applies to independently developed material that does not use PostQ Confidential Information or copy protected expression. 4. Customer Code, Facts And Reports Customer retains Customer Content and source code. PostQ does not acquire ownership of algorithms, identifiers, code locations, configuration values, vulnerabilities, or other facts originating in Customer's environment merely because the Product reports them. Customer may use Reports internally and share them with authorized Affiliates, developers, security teams, auditors, advisers, regulators, and remediation providers under appropriate confidentiality. Customer-specific output rights do not transfer the generic PostQ report renderer, template, taxonomy, methodology, rule intelligence, or software. 5. Detection, Resolution, Grouping And Assessment Detection indicates that configured static-analysis evidence matched a rule. Parameter resolution indicates only the value and confidence the scanner could derive from supported local data-flow and configuration evidence. Unresolved data may depend on another file, runtime input, environment, reflection, framework behavior, generated code, native code, or unavailable dependencies. Operation grouping infers that findings contribute to a common cryptographic intent or asset. Assessment applies configured deterministic policy and metadata to available evidence. These stages can be incomplete and must not be represented as runtime proof. 6. FIPS And Post-Quantum Statements A FIPS-related finding or assessment is not a module validation, NIST certificate, laboratory result, government approval, or legal compliance opinion. FIPS status may depend on exact algorithm, mode, key size, hash, curve, provider, cryptographic module, runtime configuration, operating mode, certificate scope, deployment, and operational controls that source analysis cannot prove. Quantum-vulnerability, PQC-alternative, migration-priority, and crypto-agility output is planning guidance based on observed evidence. It is not assurance that an application, protocol, product, or organization is quantum safe or compliant. 7. Scanner Accuracy And Remediation The scanner may miss assets or produce false positives. It may not resolve dynamic values, indirect calls, reflection, generated code, unsupported languages, binary dependencies, runtime providers, environment-specific configuration, or custom cryptography. Customer must validate each material finding and test remediation in the full system and protocol context. Recommended algorithms, libraries, providers, key sizes, modes, and PQC alternatives are not a drop-in guarantee. Customer is responsible for threat model, interoperability, data lifetime, performance, certificate lifecycle, protocol negotiation, regulatory scope, vendor support, and deployment testing. 8. Rule And Metadata Updates Rule packs, metadata, policy mappings, and recommendations may change as standards, libraries, threats, and product support evolve. Update rights and supported rule versions depend on the Order. Customer must retain Product/rule versions with Reports when reproducibility is required. Customer may not remove provenance, copyright, third-party, or integrity information from a rule pack. Encryption or compilation of a rule pack does not alter applicable third-party rights. 9. OpenGrep Native CLI, VS Code, and Eclipse deployments currently use a separately installed OpenGrep executable. The reviewed OCI image includes OpenGrep as a separate executable. The release-specific THIRD_PARTY_NOTICES.txt and SOURCE_INFORMATION.txt identify whether it is included and the rights that apply. OpenGrep is not owned by PostQ. Its applicable upstream license governs OpenGrep itself, and no PostQ restriction limits rights that license preserves. The OpenGrep name is used descriptively and does not imply endorsement. 10. Local Processing And Optional Integrations The reviewed self-managed scanner and report viewer operate in Customer-controlled environments. PostQ does not receive Customer source or Reports through ordinary local operation. Any future hosted processing, telemetry, update service, external AI, or third-party integration must be identified in the applicable Product version, Documentation, and Order and is subject to approved data terms. 11. Delivery-Specific Rights - CLI: may be used by authorized developers, automation, and CI/CD only within the ordered metric. - VS Code and Eclipse: may be installed by Authorized Users within the ordered developer/user entitlement; platform software is separately licensed. - Container: may be deployed only in authorized registries, clusters, runners, and environments; redistribution outside Customer's organization requires express rights. - Scanner Report Viewer: internal report viewers may be unlimited only if the Order says so. - Prerequisite checker: may be used solely to prepare or validate Authorized Environments. 12. Reports And Retention Reports can contain sensitive source locations, cryptographic design, vulnerabilities, and compliance evidence. Customer is responsible for access control, retention, export, backup, and secure deletion. PostQ may define report schemas for interoperability; schema publication does not grant rights in proprietary rules or detection logic. 13. Support Boundaries PostQ support covers entitled PostQ components and documented integrations. Unless an Order says otherwise, it does not cover customer modifications, unsupported runtimes, custom rules, separately installed third-party tools, customer code, or a remediation's effect on application behavior. 14. Product-Specific Release Conditions Every distributed artifact must include the approved PostQ agreement and these terms, filtered third-party notices and full licenses, source information where required, a release-specific SBOM, and legal traceability metadata. Missing or unapproved legal material blocks a commercial release. 15. Product Contacts - Legal notices: contact@postqsoftwarelabs.com - Privacy: contact@postqsoftwarelabs.com - Security and vulnerability reports: contact@postqsoftwarelabs.com - Support: contact@postqsoftwarelabs.com - Open-source compliance: contact@postqsoftwarelabs.com Copyright (c) 2026 POSTQ SOFTWARE LABS PRIVATE LIMITED. All rights reserved for verified PostQ-owned material. Third-party components remain subject to their applicable licenses.