Publisher agreement
The terms you accept when you submit a build to BackProbe Integrity Authority.
This is a plain-language summary of the operative terms. It is not legal advice, and you should have your own counsel review it before relying on it commercially.
1. What you are asking us to do
You submit a compiled artifact. We analyse it, review it, and either issue a certificate attesting that it passed our published review standards at that time, or decline with reasons.
2. What you promise us
- You hold the rights to distribute every artifact you submit.
- The artifact you upload is byte-identical to the one you distribute publicly.
- You have disclosed any network, filesystem or telemetry behaviour in the project description.
- You will not submit a build you know to be malicious, including as a test of our process.
3. What we promise you
- Your artifact is stored access-controlled and is not redistributed.
- A named analyst reviews every build; no certificate is issued automatically.
- You receive the reviewer's notes whichever way the decision goes.
- You may withdraw your own certificate at any time, for any reason.
4. Scope of a certificate
A certificate covers one artifact, identified by SHA-256, for the stated validity period. Presenting it as covering a project, an author, or any other build is a misuse of the badge and grounds for revocation.
5. Public inspection of certified builds
When a build is certified, the contents of that artifact become publicly readable through the inspection view on this site. Anyone can browse the files inside it, read the declarations, methods, external calls and embedded text of each compiled class, and read resources and manifests as written. No sign-in is required to do so.
This is central to how the service works. A certificate asks the public to trust our judgement, and that is only reasonable if the public can check the same artifact we checked. By submitting a build you grant BackProbe Integrity Authority permission to make its contents available for inspection in this way, and you confirm you hold the rights to grant it.
If you are not willing for a build to be readable, do not submit it. Withdrawing a certificate also withdraws its inspection view. Builds we withhold as malicious are never published.
6. Badge display
You may display the badge wherever you distribute the certified build. The badge must link to its verification page and must be loaded from our servers so its state stays current. You may not alter the badge artwork, rehost the image, or present an expired or revoked badge as current.
7. Revocation
We may revoke a certificate at any time on the grounds listed in the review standards. Revocation is immediate and public. Where an investigation is ongoing we may withhold the specific reason until it concludes.
8. Limits of liability
A certificate is an informed professional opinion about one artifact, not a guarantee. Static analysis and human review reduce risk; they do not eliminate it. To the maximum extent permitted by law, our liability arising from a certificate is limited to the fee paid for that certificate.
9. Fees
Fees are charged when a certificate is issued, as set out on the pricing page. Submitting a build costs nothing, and a rejected build is not charged for.
10. Termination
Either party may end the relationship at any time. Certificates already issued remain valid until they expire or are revoked. Suspending your account does not automatically revoke your live certificates.
11. Changes
Material changes to these terms or to the review standards are notified to publishers before they take effect. Certificates issued under earlier terms are governed by the terms in force when they were issued.
12. Independence
BackProbe Integrity Authority is independent of Mojang Studios and Microsoft. Minecraft is their trademark. Nothing we issue implies their endorsement of a mod or of this service.
Questions about these terms: legal@backprobe.org