# Terms of Service -- MCP Compliance Preflight Scanner
**Effective Date:** 2026-06-05
**Entity:** DynSup Labs LLC, a Wyoming limited liability company
## 1. Service Description
The MCP Compliance Preflight Scanner ("Service") is an automated technical scanning tool that checks MCP (Model Context Protocol) servers for common protocol-level compliance and security issues. The Service performs protocol-level checks only. The Service is available only to business customers located in the United States.
## 2. IMPORTANT DISCLAIMERS
### 2.1 NOT LEGAL ADVICE
**THIS SERVICE DOES NOT CONSTITUTE LEGAL ADVICE.** This scan checks for common protocol-level issues. It does not constitute legal advice. A passing scan does not mean your MCP server is EU AI Act compliant. Consult qualified legal counsel for compliance determinations.
The Service is NOT a substitute for:
- Legal counsel regarding EU AI Act or any other regulation
- A formal compliance audit
- A security penetration test
- A SOC 2 or similar certification audit
- Source code review
### 2.2 Scope Limitations
The Service checks ONLY:
- Protocol-level metadata and tool descriptions
- EU AI Act Art. 50 disclosure indicators
- Tool description quality
- OAuth scope permissiveness
- Known vulnerability patterns at the protocol level
- Semantic quality of descriptions (paid tier, via AI analysis)
The Service does NOT check:
- Source code
- Runtime behavior
- Infrastructure security
- Internal API implementation
- Data handling beyond declared metadata
- Full EU AI Act compliance
### 2.3 AI Disclosure
This Service uses Claude (Anthropic) AI for semantic analysis of tool descriptions in paid-tier scans. AI-analyzed sections of reports are marked accordingly.
## 3. Subscription and Payment
Billing and card processing are handled by Stripe, Inc. as our payment processor. **DynSup Labs LLC is the merchant and seller of record** for all transactions. The Service is offered to business customers in the United States only. Plans:
- **Free tier:** 3 scans per month. No payment required.
- **Developer ($19/month):** 50 scans per month. Includes semantic analysis.
- **Team ($49/month):** Unlimited scans. Includes semantic analysis. Priority support.
## 4. Authorized Use
You may only scan MCP servers that you own or for which you have explicit authorization to scan. Unauthorized scanning of third-party servers is prohibited and may violate the Computer Fraud and Abuse Act (18 U.S.C. Sec. 1030) and state equivalents.
## 5. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, DYNSUP LABS LLC'S TOTAL LIABILITY ARISING OUT OF OR RELATING TO THIS AGREEMENT SHALL NOT EXCEED THE TOTAL SUBSCRIPTION FEES PAID BY YOU IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM.
IN NO EVENT SHALL DYNSUP LABS LLC BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING BUT NOT LIMITED TO DAMAGES FOR LOST PROFITS, LOST DATA, REGULATORY FINES, OR BUSINESS INTERRUPTION.
## 6. Indemnification
You agree to indemnify DynSup Labs LLC against claims arising from your use of scan results, including claims that you relied on scan results as legal advice or compliance certification.
## 7. Governing Law
This Agreement is governed by the laws of the State of Wyoming, USA, without regard to conflicts of law. Disputes shall be resolved by binding arbitration under AAA Commercial Arbitration Rules.
## 8. Data Handling
- Scanned server metadata is processed in memory during scan execution.
- Scan results are stored for 90 days, then deleted.
- Subscriber PII (email, payment info) handled by Stripe.
- See Privacy Policy for full data handling details.
## 9. Modifications
30-day advance notice for material changes. Continued use after notice period constitutes acceptance.
---
**ATTORNEY REVIEW PUNCHLIST (pre-launch):**
- [ ] Verify UPL disclaimer language with WY bar
- [ ] Confirm arbitration clause enforceability in target jurisdictions
- [ ] Review CFAA reference accuracy
- [x] Stripe MoR vs. direct billing language alignment — RESOLVED 2026-06-05 (compliance run 419, self-review): DynSup Labs LLC is MoR; Stripe is PSP only. See memos/proceed/2026-06-05-mcp-compliance-preflight-mor-tax-posture.md.
- [ ] Confirm data retention periods comply with applicable law