The terms you accept when you send code to an AI vendor decide what that vendor may do with it. A free program can carry a broader grant than a paid enterprise contract, so read the license before the code leaves your hands, not after.
This guide is for security and engineering leaders deciding whether to send source code or data to an LLM vendor, through a scanning program, an API or a chat product. It uses one current example, Anthropic's OSS Scanner, to show how to read these terms. By the end you will know what a contributor license agreement grants, what this one says and does not say, and which questions to put to any vendor before you sign. Anthropic describes OSS Scanner as an opt-in vulnerability scanner for open-source projects, informed by its experience using Claude to find vulnerabilities, with reports generated by its strongest Claude models, including Claude Mythos.
What Anthropic launched
On October 8, 2026, Anthropic announced OSS Scanner, an opt-in service that scans open-source projects for vulnerabilities with its models at no cost. Reports are fully model-generated and reach maintainers by email with a reproducer and, where available, a proposed patch. Core maintainers of eligible projects enroll by opening a pull request against the anthropics/oss-scanner repository. The pull request adds a project.yaml naming the repository to scan, a Dockerfile, and optionally a threat model.
Three documents govern taking part:
- The Individual Contributor License Agreement v2.2. The repository's CONTRIBUTING file says it must be signed before a contributor's pull request is merged.
- The OSS Scanner Agreement. The program's FAQ says signing up means agreeing to it.
- Anthropic's Consumer Terms of Service, which the OSS Scanner Agreement incorporates "as they apply to the Service."
The concern being raised
In a widely shared LinkedIn post, one security practitioner argued that signing on "automatically grants them a full non-revocable license to do whatever they want with all of your code, including sublicense," and that the arrangement could feed model training. Their conclusion is the part worth keeping: "a safer and more secure internet cannot have as a prerequisite that we should give up control of the entire digital space to a single company."
We credit them for raising it, and we agree the terms deserve a close reading. Some of the post's points are supported by the documents. Others are inferences that the documents neither confirm nor rule out.
What a contributor license agreement is
A contributor license agreement, or CLA, is a contract in which the person submitting work to a project grants the project's owner rights over that work. It lets the owner redistribute and relicense contributions without tracing every author later. CLAs are common in open source. This one closely follows the Apache Software Foundation's Individual Contributor License Agreement v2.2, with Anthropic, PBC in place of the Foundation.
What this CLA grants
Section 2, the copyright grant, reads in full:
"Subject to the terms and conditions of this Agreement, You hereby grant to the Company and to recipients of software distributed by the Company a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Your Contributions and such derivative works."
Section 3 adds a patent license "to make, have made, use, offer to sell, sell, import, and otherwise transfer the Work." It is limited to patent claims "necessarily infringed by Your Contribution(s) alone or by combination of Your Contribution(s) with the Work to which such Contribution(s) was submitted," and it ends for anyone who files a patent suit claiming the contribution, or the work it was submitted to, infringes.
The preamble sets two limits that belong next to the grant. The Company "shall not use Your Contributions in a way that is contrary to the public benefit or inconsistent with its bylaws in effect at the time of the Contribution." And "Except for the license granted herein to the Company and recipients of software distributed by the Company, You reserve all right, title, and interest in and to Your Contributions."
Everything turns on one defined word. Section 1 defines a "Contribution" as "any original work of authorship, including any modifications or additions to an existing work, that is intentionally submitted by You to the Company for inclusion in, or documentation of, any of the products owned or managed by the Company."
What the documents say, and what they leave open
| The post says | What the documents say |
|---|---|
| A full, non-revocable license that includes sublicensing | Supported for "Contributions." Section 2 is perpetual and irrevocable, and it covers derivative works and sublicensing. |
| The license reaches all of your code | Not stated. Read plainly, the CLA covers what you intentionally submit for inclusion in Anthropic's products, which for enrollment is the pull request: the config, the Dockerfile and the threat model. The OSS Scanner Agreement separately says the participant "will provide Anthropic with the source code from a submitted open-source project." Neither document says whether that source code is a Contribution. |
| The code will be used to train models | Not stated in the CLA or the OSS Scanner Agreement. The Consumer Terms, which the Agreement incorporates, say Anthropic "may use Materials to provide, maintain, and improve the Services and to develop other products and services, including training our models, unless you opt out of training through your account settings." Feedback and content flagged for safety review are used for training even after an opt-out. The documents do not explain how that clause, or the opt-out, applies to a service joined by pull request. |
| Anthropic may claim IP in what you send | Not supported. The CLA says you reserve all right, title and interest, and the Consumer Terms say you retain your rights in your Inputs. The license is broad, but it is a license, not a transfer of ownership. |
Two more details matter. Sections 4 and 5 of the CLA ask you to represent that each Contribution is your original creation and that your employer has cleared it. A maintainer cannot give that assurance for years of code written by other people, which suggests the CLA is aimed at what you submit to Anthropic's repository rather than the whole project. That is our reading, not a statement from Anthropic, and it is the question we would put to Anthropic in writing.
The FAQ also invites maintainers to reply to reports with feedback. The Consumer Terms say Anthropic may use Feedback "however we choose," and that Feedback is used for training even if you opt out. Until Anthropic says otherwise, treat a reply to a report as feedback under those terms.
Why this matters even when the code is open source
"It is already public" is the usual answer, and it is partly right. A project under Apache 2.0 or MIT already lets anyone copy, modify and sublicense it. For those projects a CLA grant over the same code adds little on copyright.
It matters more in four cases.
Copyleft. A project under the GPL or AGPL requires derivative works to stay under the same terms. A direct license under a CLA carries no such condition, so for code it covers, the recipient could distribute derivative works under terms of its choosing.
Patents. The CLA adds an express patent license that a project's own license, MIT for example, may not give.
Revocation. You can leave OSS Scanner at any time by deleting your project directory. The CLA license is irrevocable, so it survives your exit.
Training and retention. A code license says what a recipient may distribute. The data terms say what a vendor may do with what it receives. You need to read both, because neither answers the other's question.
None of this is unusual for a CLA. It is a reason to know exactly which of your work a CLA covers before you sign one.
The fair case for the program
Free, frequent scanning by strong models helps maintainers who have no security budget. The announcement quotes maintainers from curl, wolfSSL, PostgreSQL and OpenSSL describing valid findings with usable patches. Anthropic states that scans run in sandboxes with no Internet access, that reports are held in an isolated project open to the security staff who run the program, that it covers the full cost, and that projects can pause or withdraw at any time.
The program is opt-in. For many projects it will be a reasonable choice once the questions above have written answers.
Ten questions to ask any AI vendor before you send code or data
Use these for LLM APIs, scanning services, coding assistants and chat products alike. Ask for the answer in the contract, not on a marketing page.
- License grants. What license do we grant over what we send? Is it limited to providing the service, or does it extend to redistribution, derivative works or sublicensing?
- Training use. Will our code, prompts or outputs train any model, yours or anyone else's? Is training off by default, or off once we opt out?
- Retention. How long do you keep inputs, outputs and logs, and what is deleted when we leave?
- Sublicensing and sharing. Can you pass our data, or the rights you hold over it, to affiliates, partners or downstream recipients?
- Revocation. If we stop using the service, which rights end and which survive?
- Subprocessors. Which other companies, including other model providers, touch our data, and where is that list published?
- Region. Where is our data processed and stored, and can we pin it to a region?
- Zero retention. Is there a zero-data-retention option, and which features stop working if we use it?
- Enterprise terms versus consumer terms. Which terms actually govern this product? Free programs and individual sign-ups often fall under consumer terms, with different data rules from a negotiated commercial agreement.
- Opt-out. How exactly do we opt out of training or sharing, does the opt-out cover feedback and safety review, and how do we confirm it took effect?
If a vendor cannot answer all ten in writing, treat that as an answer.
Where Safeguard stands
We hold ourselves to the same list. Here is what Safeguard's published terms and pages say today.
- License. Our Terms of Service say "You retain all rights to data you upload to the Services," and grant Safeguard "a limited license to process Your Data solely to provide the Services."
- Training. Our data processing page says customer source code "is processed transiently during a scan and is not added to model training corpora." Safeguard does not train models on customer code.
- Retention. You can export your data at any time. Data is deleted within 30 days of an account ending, unless the law requires us to keep it.
- Code that stays on your machines. Our privacy policy says the local runner "does not upload your source tree in order to run a dependency scan. The analysis happens on your machine and the findings are what leave it."
- Deployment. Safeguard can run on-premises or fully air-gapped, with its models included.
Some of our own terms belong in the same light. Our Terms take a perpetual, irrevocable license to feedback you choose to give us about the Services, and they let us use anonymized, aggregated data to improve the service. When you connect a third-party AI assistant to Safeguard, the data returned to that assistant is handled under the assistant provider's terms, not ours, as our privacy policy says.
Ask us the ten questions above. We will answer in writing.
The implication
Free scanning can make open source safer, and Anthropic's program may well do that. The terms still decide who holds rights over the code afterwards, and for how long. Read them, get the gaps answered in writing, and send code to any vendor once you know what you are granting.
This post describes published documents as of October 10, 2026. It is not legal advice.
Sources
- Anthropic, Launching an opt-in vulnerability-finding service for open-source software, October 8, 2026.
- Anthropic, OSS Scanner Individual Contributor License Agreement v2.2, committed October 8, 2026.
- Anthropic, OSS Scanner Agreement and OSS Scanner overview and FAQ.
- Anthropic, Consumer Terms of Service, effective October 8, 2025.
- Apache Software Foundation, Individual Contributor License Agreement v2.2.
- A LinkedIn post by a security practitioner discussing the program, October 2026, which prompted this guide.