Scope and acceptance
These terms govern access to and use of Scorpio, an automated engine for economic security analysis of Solidity code, including the preflight, the analysis request, the x402 payment and the download of results.
By requesting an analysis, the user states that they have read and accepted these terms and the Privacy policy. If they act on behalf of an organisation, they state that they have sufficient authority to bind it.
Identity of the operator
The holder and provider of the service is José Luis Sánchez, tax ID 71223690G, address calle Repullete 100, 23300 Villacarrillo (Jaén), Spain. Scorpio is a product of Automaton Colony and is run by the same person. The service operates under the domain scorpio.automatoncolony.xyz.
Contact: jls.17@automatoncolony.xyz. The treasury that receives payments is 0x3a6e…30aB on the Base network, and it is public and verifiable in any explorer.
Eligibility and authority over the code
The user must have legal capacity to contract and to use a wallet compatible with the payment requested. They may only submit repositories they are authorised to run security analysis on.
The fact that a repository is public grants no permission to exploit, harm or gain unauthorised access to a deployed protocol. Use of the results must respect the project's rules, the bounty programme's rules and applicable law.
Description of the service
The active product, Full audit (AUDIT-149), runs automated analysis over the ten families included in the current catalogue. It accepts public Foundry-compatible repositories with up to 1,200 of the project's own Solidity files, provided they pass the preflight.
Current technical scope
- The analysis is performed on the code and the commit identified in the order.
- The active product does not read the current on-chain state.
- The time stated in the catalogue is an execution estimate, not a service level agreement.
- Features in preparation are not part of the contracted service until they appear as active in the public catalogue.
Preflight and formation of the order
The preflight is free and checks that the URL, the repository, the expected compilation and the number of files fall within scope. Its result is informational until the server issues a valid offer.
A repository rejected at preflight does not generate a payment order. The offer identifies the product, the price, the network, the asset, the recipient and the validity period. A change to the repository or the commit may require a new preflight.
Price and x402 payment
The price of AUDIT-149 is 149 USDC, unless the active catalogue shows a different condition before the payment is accepted. Payment is made through the x402 protocol on the network and address stated in the offer.
This is the offer the service issues today, and it prevails over any figure copied from anywhere else:
| Network | Base (eip155:8453) |
| Asset | Native Base USDC, 0x8335…2913 |
| Amount | 149 USDC (149000000 units, 6 decimals) |
| Authorisation validity | 30 minutes from issue |
| Execution | around 5 minutes estimated, with a ceiling of 22 |
- The user is responsible for selecting the correct network and holding sufficient funds.
- Network or third-party fees are shown and handled outside Scorpio's price.
- Execution starts once the payment is verified and settled under the x402 flow.
- Transactions confirmed on a public blockchain are visible and cannot be deleted by Scorpio.
States and delivery
Every order can show one of these states:
- PENDING: the payment or the execution is still pending.
- DONE: the expected delivery has finished.
- INCOMPLETE: a partial delivery exists and its limits are documented in the result.
- FAILED: the engine could not produce the delivery.
- EXPIRED: the delivery existed and has been deleted after reaching its retention period.
What is delivered, exactly
The AUDIT-149 delivery consists of two things, and they are the ones the service produces today:
- The audit report in English, in Markdown, carrying its own SHA-256 seal inside.
- The revision analysed: the exact commit and tree of the clone that was worked on, so any finding can be pointed at a concrete revision.
They can be retrieved as many times as needed at GET /audit/<identifier> for 30 calendar days from the moment the order finishes. After that the delivery is deleted and the same request answers EXPIRED, with only the payment record kept. It is worth downloading and saving the report when you receive it.
Engine failure and refunds
If Scorpio accepts and settles the payment but the engine or the infrastructure under the operator's control cannot produce the contracted delivery, the order is marked FAILED and the service price is refunded.
Network fees, exchange differences and costs charged by third parties are not part of the refund. No refund applies for finding no vulnerabilities, for disagreement with a severity, for loss of access to the wallet, or for use of the result outside the contracted scope.
How it is carried out
The refund is manual, not automatic. The service does not hold the payment in deposit or in an escrow contract: when the payment settles, the amount reaches the treasury. That is why, if the order fails, a person orders the refund.
What makes it possible is that every order is recorded with its identifier, the transaction hash, the address that paid and the exact reason for the failure. With those details the operator refunds to the same address the payment came from.
- Deadline: the refund is ordered within 14 calendar days of the order entering FAILED. Confirmation on the network may take a few minutes longer.
- Channel: no claim is needed for it to apply. The operator reviews the orders in FAILED and orders the refund. If it has not arrived once the deadline has passed, you can claim at jls.17@automatoncolony.xyz, quoting the order identifier and the transaction hash.
- Destination: the same paying address, in the same asset and on the same network. No refund is made to an address other than the one that paid.
An order in INCOMPLETE is not a failure: there is a delivery, with its limits written into the result itself, and it does not trigger an automatic refund. If that partial delivery is not fit for the intended use, it can be raised through the same channel.
Permitted and prohibited use
Scorpio is intended for secure development, authorised review, responsible research and legitimate participation in bounty programmes.
The service may not be used to exploit systems, conceal malicious activity, analyse unlawfully obtained code, disrupt services, infringe third-party rights, evade sanctions or facilitate crime. The operator may refuse or stop an order on reasonable evidence of abusive use.
Intellectual property
The user and the original rights holders keep their rights over the repository analysed. Submitting the URL grants the operator a limited authorisation to fetch, compile and process the code for the sole purpose of providing the service.
The engine, its detectors, its interface and its components remain the property of the operator or its licensors. The user may use, reproduce and share the report to fix the project, document risks or submit authorised findings, respecting third-party rights over the code.
Results and absence of warranties
Scorpio provides automated analysis and technical evidence. It does not guarantee zero false positives, total coverage, detection of every vulnerability, correctness of the code, uninterrupted availability, or that a bounty programme will accept a finding.
The result is not equivalent to a human audit, a certification, legal or financial advice, or an investment recommendation. The user must verify every finding and apply their own review, testing and deployment processes.
Limitation of liability
To the extent permitted by law, the operator is not liable for indirect losses, loss of profit, loss of opportunity, loss of digital assets, deployment decisions or damage arising from exploiting, ignoring or misinterpreting a result.
Total liability tied to an order is limited to the amount paid for that order, except where the law does not allow liability to be excluded or limited. Nothing in these terms limits mandatory consumer rights where they apply.
Suspension, changes and termination
The operator may suspend access for maintenance, technical risk, fraud, breach of these terms or legal requirement. If a suspension attributable to the operator prevents a delivery already paid for, the refund clause applies.
These conditions may be updated to reflect technical, commercial or legal changes. The version applicable to an order is the one identified and accepted at the moment of payment.
Governing law and dispute resolution
Spanish law applies, being the law of the provider's country of establishment. Disputes are submitted to the courts of Spain, without prejudice to the mandatory forums that consumer protection rules grant to anyone contracting as a consumer. If any clause is declared void, the rest remains in force.
Any complaint is sent to the email address in section 15 and is answered within a maximum of five working days. If the answer is not satisfactory, anyone contracting as a consumer may turn to the consumer protection bodies of their place of residence. The provider is not a member of any out-of-court dispute resolution scheme.
Contact
For support, payment incidents or questions about these terms: jls.17@automatoncolony.xyz.
