POSTQ CODE SCANNER PRODUCT TERMS

Licensor: POSTQ SOFTWARE LABS PRIVATE LIMITED
Product: PostQ Code Scanner
Terms version: 1.0.0-Beta
Revision date: 8 September 2026
Classification: PostQ Code Scanner-Beta private invite-only evaluation release

These Product Terms supplement the PostQ Software Product License Agreement and the applicable
Order. Capitalized terms not defined here have the meaning in that agreement. An applicable
third-party license continues to control its component where required.

1. Product Components

PostQ Code Scanner may be supplied as a scanner CLI/service, VS Code extension, Eclipse plug-in,
standalone Scanner Report Viewer, prerequisite checker, OCI container, proprietary rule pack,
report schema, documentation, or another module stated in the Order. Entitlement to one delivery
form does not imply entitlement to every delivery form.

2. Authorized Purpose

Customer may use entitled components to identify and review cryptographic assets, parameters,
operations, groupings, FIPS-related evidence, post-quantum migration relevance, crypto-agility
signals, and related code findings in Authorized Environments. Customer must have authority to scan
the relevant code and systems.

Usage limits for repositories, applications, projects, runners, scans, users, CI/CD, production,
non-production, Affiliates, contractors, and report viewers are stated only in the Order.

3. Protected PostQ Scanner Intelligence

Subject to verified ownership and third-party rights, PostQ Materials include proprietary scanner
architecture, rule packs, rule definitions, encrypted or compiled rules, signatures, metadata,
taxonomies, normalized operations, classification models, parameter mappings, provider/library
mappings, risk logic, FIPS assessment logic, PQC readiness and crypto-agility logic, scoring,
recommendations, knowledge-base relationships, schemas, and report templates.

Customer must not extract, publish, redistribute, sublicense, sell, use as a standalone rule library,
or use these protected materials to create a competing scanner or substantially equivalent
proprietary detection library, except to the extent mandatory law or an applicable third-party
license permits the activity. Customer may use findings and recommendations for its own remediation.

No restriction applies to independently developed material that does not use PostQ Confidential
Information or copy protected expression.

4. Customer Code, Facts And Reports

Customer retains Customer Content and source code. PostQ does not acquire ownership of algorithms,
identifiers, code locations, configuration values, vulnerabilities, or other facts originating in
Customer's environment merely because the Product reports them.

Customer may use Reports internally and share them with authorized Affiliates, developers, security
teams, auditors, advisers, regulators, and remediation providers under appropriate confidentiality.
Customer-specific output rights do not transfer the generic PostQ report renderer, template,
taxonomy, methodology, rule intelligence, or software.

5. Detection, Resolution, Grouping And Assessment

Detection indicates that configured static-analysis evidence matched a rule. Parameter resolution
indicates only the value and confidence the scanner could derive from supported local data-flow and
configuration evidence. Unresolved data may depend on another file, runtime input, environment,
reflection, framework behavior, generated code, native code, or unavailable dependencies.

Operation grouping infers that findings contribute to a common cryptographic intent or asset.
Assessment applies configured deterministic policy and metadata to available evidence. These stages
can be incomplete and must not be represented as runtime proof.

6. FIPS And Post-Quantum Statements

A FIPS-related finding or assessment is not a module validation, NIST certificate, laboratory
result, government approval, or legal compliance opinion. FIPS status may depend on exact algorithm,
mode, key size, hash, curve, provider, cryptographic module, runtime configuration, operating mode,
certificate scope, deployment, and operational controls that source analysis cannot prove.

Quantum-vulnerability, PQC-alternative, migration-priority, and crypto-agility output is planning
guidance based on observed evidence. It is not assurance that an application, protocol, product, or
organization is quantum safe or compliant.

7. Scanner Accuracy And Remediation

The scanner may miss assets or produce false positives. It may not resolve dynamic values, indirect
calls, reflection, generated code, unsupported languages, binary dependencies, runtime providers,
environment-specific configuration, or custom cryptography. Customer must validate each material
finding and test remediation in the full system and protocol context.

Recommended algorithms, libraries, providers, key sizes, modes, and PQC alternatives are not a
drop-in guarantee. Customer is responsible for threat model, interoperability, data lifetime,
performance, certificate lifecycle, protocol negotiation, regulatory scope, vendor support, and
deployment testing.

8. Rule And Metadata Updates

Rule packs, metadata, policy mappings, and recommendations may change as standards, libraries,
threats, and product support evolve. Update rights and supported rule versions depend on the Order.
Customer must retain Product/rule versions with Reports when reproducibility is required.

Customer may not remove provenance, copyright, third-party, or integrity information from a rule
pack. Encryption or compilation of a rule pack does not alter applicable third-party rights.

9. OpenGrep

Native CLI, VS Code, and Eclipse deployments currently use a separately installed OpenGrep
executable. The reviewed OCI image includes OpenGrep as a separate executable. The release-specific
THIRD_PARTY_NOTICES.txt and SOURCE_INFORMATION.txt identify whether it is included and the rights
that apply.

OpenGrep is not owned by PostQ. Its applicable upstream license governs OpenGrep itself, and no PostQ
restriction limits rights that license preserves. The OpenGrep name is used descriptively and does
not imply endorsement.

10. Local Processing And Optional Integrations

The reviewed self-managed scanner and report viewer operate in Customer-controlled environments.
PostQ does not receive Customer source or Reports through ordinary local operation. Any future hosted
processing, telemetry, update service, external AI, or third-party integration must be identified in
the applicable Product version, Documentation, and Order and is subject to approved data terms.

11. Delivery-Specific Rights

- CLI: may be used by authorized developers, automation, and CI/CD only within the ordered
  metric.
- VS Code and Eclipse: may be installed by Authorized Users within the ordered developer/user
  entitlement; platform software is separately licensed.
- Container: may be deployed only in authorized registries, clusters, runners, and environments;
  redistribution outside Customer's organization requires express rights.
- Scanner Report Viewer: internal report viewers may be unlimited only if the Order says so.
- Prerequisite checker: may be used solely to prepare or validate Authorized Environments.

12. Reports And Retention

Reports can contain sensitive source locations, cryptographic design, vulnerabilities, and
compliance evidence. Customer is responsible for access control, retention, export, backup, and
secure deletion. PostQ may define report schemas for interoperability; schema publication does not
grant rights in proprietary rules or detection logic.

13. Support Boundaries

PostQ support covers entitled PostQ components and documented integrations. Unless an Order says
otherwise, it does not cover customer modifications, unsupported runtimes, custom rules, separately
installed third-party tools, customer code, or a remediation's effect on application behavior.

14. Product-Specific Release Conditions

Every distributed artifact must include the approved PostQ agreement and these terms, filtered
third-party notices and full licenses, source information where required, a release-specific SBOM,
and legal traceability metadata. Missing or unapproved legal material blocks a commercial release.

15. Product Contacts

- Legal notices: contact@postqsoftwarelabs.com
- Privacy: contact@postqsoftwarelabs.com
- Security and vulnerability reports: contact@postqsoftwarelabs.com
- Support: contact@postqsoftwarelabs.com
- Open-source compliance: contact@postqsoftwarelabs.com

Copyright (c) 2026 POSTQ SOFTWARE LABS PRIVATE LIMITED. All rights reserved for verified PostQ-owned
material. Third-party components remain subject to their applicable licenses.
