// legal

PingTraceSSH Legal

PingTraceSSH provides network change assurance, AWS network visibility, Terraform pre-change analysis, Critical Path validation, alerts, and related engineering tools.

These policies describe what information PingTraceSSH processes, how the service may be used, and the terms governing access to PingTraceSSH Cloud and free browser-based tools.

Last updated: September 15, 2026
policy 01

Privacy Policy

01

Information We Collect

Account information

  • Email address and display name
  • Authentication and account identifiers
  • Subscription and account status

AWS connection information

  • AWS account ID and selected AWS regions
  • IAM role ARN
  • PingTraceSSH-generated External ID
  • Connection and verification status

PingTraceSSH does not require customers to provide long-lived AWS access keys.

Network configuration metadata

PingTraceSSH may process read-only AWS network configuration metadata, including:

  • VPCs and CIDR ranges
  • Subnets and route tables
  • Internet and NAT gateways
  • Transit Gateways and attachments
  • TGW route tables
  • VPN connection state
  • Security-group configuration
  • Gateway relationships
  • Network-resource identifiers

Critical Path configuration

  • Source VPC and destination CIDR
  • Path names
  • Enabled or disabled state
  • Health and evaluation results

Terraform and HCP Terraform data

When HCP Terraform integration or manual Terraform analysis is used, PingTraceSSH may process:

  • Workspace and run identifiers
  • Branch and commit metadata
  • Terraform version
  • Proposed resource changes
  • Terraform network-resource relationships
  • Critical Path analysis results
  • Unresolved references
  • Plan-analysis metadata

Raw Terraform plan content is used for analysis and is not publicly exposed in the PingTraceSSH interface.

Alert configuration

If alerts are configured, PingTraceSSH may process an alert email address, Slack incoming webhook URL, alert preferences, and delivery history or status.

Billing information

PingTraceSSH uses Stripe for subscription billing. PingTraceSSH may store a Stripe customer ID, Stripe subscription ID, plan, billing status, billing-period dates, and cancellation status.

PingTraceSSH does not store full card numbers, CVC codes, or full payment credentials. Payment information is handled by Stripe.

Service and security logs

PingTraceSSH may retain application logs and operational metadata needed to operate the service, troubleshoot failures, secure accounts, investigate abuse, and monitor system health.

02

How We Use Information

PingTraceSSH uses information to:

  • Authenticate users
  • Connect to AWS through STS AssumeRole
  • Discover AWS network configuration
  • Build network snapshots
  • Detect network changes
  • Evaluate Critical Paths
  • Perform Terraform pre-change assurance
  • Deliver HCP Terraform Run Task results
  • Deliver alerts
  • Manage subscriptions
  • Provide customer support
  • Secure and troubleshoot the service
  • Improve product reliability

PingTraceSSH does not sell customer personal information or use customer infrastructure data for advertising.

03

AWS Access Model

PingTraceSSH uses a customer-created PingTraceSSHReadOnlyRole, AWS STS AssumeRole, a customer-specific External ID, temporary credentials, and read-only network-discovery permissions.

PingTraceSSH does not require or store customer IAM access-key pairs for AWS scanning.

Review the Security Architecture
04

Third-Party Service Providers

Stripe

Subscription billing and payment processing.

Amazon Web Services (AWS)

Cloud infrastructure services and customer-authorized AWS role assumption.

HCP Terraform / HashiCorp

Run Task integration and Terraform plan analysis when a customer enables it.

Slack

Delivery of alerts to a customer-provided incoming webhook when Slack alerts are enabled.

Google Analytics

Measurement of site visits and selected product or free-tool interactions.

Lovable Cloud

Application hosting, account authentication, data storage, and transactional email infrastructure.

These providers process information under their own terms and privacy practices.

05

Cookies and Analytics

PingTraceSSH uses Google Analytics to measure site visits and selected interactions, such as page, product-demo, and free-tool activity. PingTraceSSH does not use third-party advertising trackers.

Necessary authentication and session storage is used to keep users signed in and operate account features. The interface and browser-based tools may also store preferences or local state, such as sidebar state, display preferences, or game progress.

06

Data Retention

PingTraceSSH retains account information, infrastructure history, network snapshots, Terraform analysis history, billing metadata, and alert history as needed to provide the service and maintain historical change context.

Canceled subscriptions may retain historical configuration and analysis records unless the customer requests account or data deletion, subject to legitimate legal, security, fraud-prevention, or accounting requirements.

Retention controls may evolve as the service matures.

07

Data Deletion and Account Closure

Users may contact hello@pingtracessh.com to request account or personal-data deletion. PingTraceSSH does not promise an automated deletion timeline.

  • Removing PingTraceSSHReadOnlyRole from AWS immediately prevents future AWS AssumeRole access.
  • Deleting or disabling an AWS connection in PingTraceSSH stops future scanning for that connection.
  • Some billing or accounting records may need to be retained where legally required.
08

Security

PingTraceSSH uses read-only AWS access, temporary STS credentials, External ID confused-deputy protection, server-side handling of secrets, authenticated customer-scoped records, and signature verification for HCP Terraform and Stripe webhooks.

Review the Security Architecture
09

Children's Privacy

PingTraceSSH is intended for professional and business users and is not directed to children. PingTraceSSH does not ask users to provide their age as part of ordinary account use.

10

Privacy Rights

Depending on location, users may have rights to request access, correction, deletion, or information regarding personal data PingTraceSSH maintains. Direct requests to hello@pingtracessh.com .

11

Changes to This Privacy Policy

This policy may be updated as the service evolves. When it changes, the “Last updated” date at the top of this page will be revised.

policy 02

Terms of Service

01

Service

PingTraceSSH Cloud provides network change assurance and related infrastructure tooling, including:

  • AWS network discovery
  • Network snapshots
  • Change detection
  • Critical Path validation
  • Terraform pre-change assurance
  • HCP Terraform Run Task integration
  • Alerts
  • Network topology visualization
  • Browser-based networking tools

Features may change as the service evolves.

02

Authorized Use

Users may connect, scan, analyze, or test only AWS accounts, networks, infrastructure, and systems they own or are authorized to access.

Users may not use PingTraceSSH for unauthorized scanning, intrusion, exploitation, credential theft, malicious disruption, illegal activity, or attempts to bypass service security. Free browser-based networking tools must also be used only on systems the user is authorized to test.

03

Customer Responsibilities

Customers are responsible for:

  • Maintaining AWS account security
  • Controlling access to their PingTraceSSH account
  • Reviewing infrastructure changes before deployment
  • Choosing appropriate HCP Run Task enforcement settings
  • Validating changes for their own environment
  • Ensuring they are authorized to connect AWS environments

PingTraceSSH assists with network-change analysis but does not replace customer change management, testing, or operational review.

04

Terraform Assurance

PingTraceSSH may classify proposed Terraform network changes as:

SAFE
No configured Critical Path becomes newly unreachable based on the modeled change.
REGRESSION
At least one currently healthy Critical Path would fail after the modeled change.
INCONCLUSIVE
PingTraceSSH cannot safely prove the proposed network result.
FAILED
The analysis or required processing did not complete successfully.

Results are based on the infrastructure data and product capabilities available at analysis time. Mandatory HCP Terraform enforcement may block a Terraform run when PingTraceSSH returns a failing result. PingTraceSSH does not guarantee detection of every possible outage or configuration issue.

05

Subscription and Billing

Current paid plan
PingTraceSSH Cloud — Founding Pilot
Price
$299 USD per month

Billing is handled by Stripe. Subscriptions renew monthly unless canceled. Customers may cancel through the Stripe Customer Portal, and cancellation typically remains effective through the paid billing period. Plan access may stop after the subscription becomes inactive. Historical service data may be preserved as described in the Privacy Policy.

The Founding Pilot includes:

  • 1 AWS account
  • 1 HCP Terraform workspace or integration
  • Up to 10 active Critical Paths
  • 15-minute scheduled AWS scans

Pricing and plan limits may change for future customers. Founding Pilot customers retain the $299/month price for 12 months from the date their subscription begins.

06

Free Tools

PingTraceSSH may provide browser-based networking and diagnostic tools at no charge. These tools are provided for convenience and informational purposes.

Users remain responsible for validating generated configurations, calculations, commands, or diagnostic results before production use.

07

Availability and Changes

PingTraceSSH may modify, improve, suspend, or discontinue features as the service evolves. PingTraceSSH does not promise uninterrupted availability or provide a formal service-level agreement through these Terms.

08

No Warranty

The service and free tools are provided on an “as available” basis. Network and cloud environments are complex, and PingTraceSSH cannot guarantee uninterrupted service, complete detection of every configuration issue, prevention of every outage, correctness of every third-party system, or that every Terraform or AWS configuration can be modeled conclusively.

09

Limitation of Liability

To the extent permitted by applicable law, PingTraceSSH is not responsible for indirect, incidental, special, consequential, or punitive losses, or for lost profits, revenue, data, goodwill, or business interruption arising from use of the service or free tools.

To the extent permitted by applicable law, PingTraceSSH’s total liability for claims relating to the paid service will not exceed the amount the customer paid PingTraceSSH for that service during the 12 months before the event giving rise to the claim. These limitations do not apply where applicable law does not permit them.

10

Acceptable Use and Abuse

Users may not perform unauthorized network scanning; attack PingTraceSSH; bypass account, security, or service limits; scrape or automate abusive traffic; resell access without permission; or use the service to violate applicable law.

PingTraceSSH may suspend accounts involved in abuse or security threats.

11

Account Termination

Customers may cancel billing through Stripe. PingTraceSSH may suspend or terminate access for nonpayment, abuse, security threats, or violations of these Terms. Account and data handling after termination follows the Privacy Policy.

12

Third-Party Services

Integrations such as AWS, HCP Terraform, Stripe, and Slack operate under their own terms and availability. PingTraceSSH is not responsible for outages or failures originating solely from those third-party services.

13

Intellectual Property

PingTraceSSH software, branding, site content, and proprietary platform components remain the property of PingTraceSSH and its licensors.

Customers retain ownership of their AWS configuration, Terraform configuration, infrastructure data, and other customer-provided content. Customers grant PingTraceSSH only the rights needed to process that content to provide, secure, support, and maintain the service.

14

Contact

For legal, privacy, security, or service questions, contact hello@pingtracessh.com .