HomeFeaturesDocumentationContactDownload

Terms of Service

SiteCMD is operated by Brambleworks LLC, referred to here as "we" and "us". These terms govern your use of the services we operate: SiteCMD Connect, the connected service that runs hosted scans, sends alerts and reports, and answers CI operations; the SiteCMD CLI when it talks to that service; beta access; the maintained fix-guide catalog; existing subscriptions; and this website. By using any of them, you agree to these terms. If you use them on behalf of a company or a client, you confirm that you have authority to bind them, and "you" includes them.

Eligibility

You must be at least 18 years old, or the age of majority where you live, to use the hosted services or hold a subscription. The open-source desktop software is governed by its license rather than by this requirement.

What SiteCMD is

SiteCMD is a local-first website command center. It combines built-in website and source-code checks with integrations to third-party services, then organizes those signals into a desktop workflow for understanding what changed, what matters, and what to do next.

License

The SiteCMD software is made available under the Apache License 2.0. That license governs your rights to use, inspect, modify, and redistribute the open-source software. The source, including the license text, is published at github.com/brambleworks/SiteCMD-Local.

These terms govern hosted services, commercial intelligence catalogs, and subscriptions, and do not restrict rights granted by an applicable open-source license. The complete local workbench is available under its open-source license without a paid feature gate.

Your data

SiteCMD is local-first. Scan results, project data, and configuration are stored in a SQLite database on your machine. Desktop integration credentials (API keys for GA4, Cloudflare, GitHub, etc.) are stored in your operating system's keychain, never in the database.

We do not have access to your source code or your desktop integration credentials. If you authorize a Vercel or Netlify deployment provider, the connected service receives and stores that provider credential encrypted so it can read the selected deployment state and manage its deploy webhook. We do not have access to your scan results or the websites you scan either, unless you connect a site to the connected service, which is off until you set it up. Our Privacy Policy summarizes the categories a connected site sends, and the in-app payload inspector shows the exact serialized snapshot.

Third-party integrations

SiteCMD connects to third-party services (Google Analytics, Search Console, Bing Webmaster Tools, Plausible, Cloudflare, GitHub, Jira, UptimeRobot, PageSpeed Insights) using credentials you provide. These connections are made directly from your machine to the third-party service. We do not proxy, intercept, or store the data returned by these services beyond what SiteCMD caches locally for your use.

Vercel and Netlify deployment providers work differently: you authorize them through the connected service, which holds that provider credential encrypted and uses it only to read the selected deployment state and manage its deploy webhook.

Your use of third-party services through SiteCMD is subject to those services' own terms.

Scanning and checks

SiteCMD performs automated HTTP requests and HTML analysis against URLs you provide. You are responsible for ensuring you have permission to scan any URL you enter. Do not use SiteCMD to scan websites you do not own or operate without explicit written authorization from the owner.

A connected site can also be scanned by hosted scans that run from our infrastructure, on a schedule and with the app closed. Hosted scans run only against a site whose ownership you have verified through the connected service, and only within the scan scope you chose. By verifying a site you confirm that you are authorized to have it scanned from our infrastructure. We may pause or stop hosted scans for a site if its operator objects, if the scans threaten the stability of the service, or if the law requires it.

Scan results are informational. SiteCMD identifies potential issues based on deterministic rules, but does not guarantee that fixing all reported issues will make your site secure, compliant, or performant. You are responsible for evaluating and acting on scan results.

Connected service

The connected service is organized around accounts, the installations that belong to them, and the sites each installation is assigned to. You are responsible for the installations and people you grant access to, and for keeping the credentials the service issues to you confidential: installation credentials, CI tokens, webhook secrets, and the passphrase on an exported connection. Tell us promptly if one is exposed. You can rotate CI tokens and webhook secrets yourself from Settings.

Alert email goes only to destinations that have confirmed they want it, and you may add only addresses you are entitled to have alerted. Webhooks send signed alert and report payloads to a URL you control. A report link lets anyone who holds it view that report until it expires or you revoke it, so share links only with people who should see the findings. CI tokens are scoped to one site and belong in your CI provider's secret store, never in a repository.

You may not use the connected service to scan sites you are not authorized to scan, to probe or interfere with the service or with other accounts, to circumvent allowances or rate limits, or to resell access without our written agreement.

MCP server

The MCP server runs locally on your machine and exposes complete local scan results and fix context to AI coding tools you configure. It does not transmit your scan data to our servers.

Beta, payments, and subscriptions

Connected-service access is free during the beta. The future billable unit is a connected production site, with flat bundles and no metered overages intended. Public prices and included quantities are not set until the beta pricing pass.

A beta service is still being shaped. We may change, limit, suspend, or discontinue beta features, and we do not promise uptime or support response times during the beta. If we end the beta or a feature within it, we will give notice through the application and to your verified alert addresses, and connected data will be deleted under the retention schedule in our Privacy Policy unless you export or erase it first.

Existing subscriptions are processed through LemonSqueezy and remain governed by the terms shown when they were purchased. Existing subscribers can cancel through the SiteCMD app or the SiteCMD billing portal to stop future renewals. Any future paid offering will state its price, allowance, renewal terms, and refund terms before purchase.

Updates

SiteCMD may check for updates and notify you when new versions are available. You are not required to update, but older versions may not include the latest checks or security fixes.

Termination and suspension

You can stop at any time: disconnect a site, erase its data, deactivate a license, or delete the application. We may suspend or terminate your access to the hosted services if you breach these terms, if your use creates a security or legal risk for us or for a site you scan, if a subscription that access depends on lapses, or if the law requires it. Where practical we will tell you why and give you a chance to put it right first. On termination, connected data is deleted under the retention schedule in our Privacy Policy, and the sections of these terms that by their nature should survive, including limitation of liability and indemnification, continue to apply.

Limitation of liability

SiteCMD is provided "as is" without warranty of any kind. To the fullest extent permitted by law, we are not liable for any damages arising from your use of SiteCMD, including but not limited to: data loss, security breaches on your websites, downtime, or inaccurate scan results. Our total liability is limited to the amount you paid for SiteCMD in the 12 months preceding the claim, or 100 US dollars if you have paid nothing.

Indemnification

If a third party brings a claim against us because you scanned a site without authorization, sent alerts to an address you had no right to use, or otherwise used the services in breach of these terms, you agree to defend us against that claim and to cover the resulting damages and reasonable costs.

Governing law

These terms are governed by the laws of the State of Vermont, without regard to its conflict-of-law rules. Any dispute arising from these terms or the services will be brought in the state or federal courts located in Vermont, and you consent to their jurisdiction. Nothing in this section removes protections you hold under the mandatory consumer laws of the place you live.

Changes to these terms

We may update these terms. Material changes will be communicated through the application, to the verified alert addresses on a connected account, and by email if you've subscribed to our mailing list, and the date at the top of this page will change. Continued use of the hosted services after changes constitutes acceptance.

Contact

Questions about these terms: contact us or email support@sitecmd.com.