Skip to content
Gelhaus Solutions
Apps Services Security Contact
EN DE

Archived version

GAnalytics terms

Measuring public behaviour from public records, and the sharp edge of publishing a metric about an organisation that is really about a handful of people.

Version 2026-09-06 Published 6 September 2026

This is the current version. It is kept here under a fixed address so it can be cited and compared. The live document is the same text.

On this page

  1. What this covers
  2. Licence
  3. What it measures, and what that means
  4. Published figures and methodology
  5. Fair use of the API
  6. Availability
  7. No warranty, no service level, and limited liability

What this covers

GAnalytics measures how a software ecosystem behaves. Its first module analyses the CVE Program: it walks public sources through connectors, transforms what it finds, and publishes metrics, dashboards and written analysis.

These sit alongside the general terms of service.

Licence

GAnalytics is licensed under the Elastic License 2.0, plus one additional restriction from us: commercial use requires a business licence.

That addition is stated separately because ELv2 does not contain it. ELv2's own limitations are three — you may not provide the software to others as a hosted or managed service, may not circumvent the licence-key functionality, and may not remove or alter the licensing, copyright or other notices — and it otherwise permits a company to run the software commercially for its own internal purposes. Our additional term removes that permission.

Non-commercial use on your own infrastructure is free of charge. Commercial use of any kind, including internal use inside a business, needs a business licence from us.

It is being folded into GPlatform. Where you use the hosted service, the data processing agreement and its annex apply.

What it measures, and what that means

The sources are public records about vulnerabilities and the organisations that publish them. Aggregated across a programme, those records say things about how particular organisations behave — how quickly they publish, how complete their records are, how often they revise.

That is the point of the tool and it is also its sharp edge. A metric about an organisation is frequently, in practice, a metric about the few people who do that work. Publishing "this CNA is slow" is a statement about a team.

We publish analysis on that basis: measuring public behaviour from public records, describing what the records show, and not inferring anything about individuals from an organisation's aggregate.

Published figures and methodology

Published datasets, metric definitions and methodology documents carry their own terms where those are stated alongside them.

A figure is only as good as the source walk behind it. Every pipeline run records its stages, cursors and connector state, so a number can be traced to the walk that produced it and a transform is identified by the hash of its code. Where a figure changes because a source changed, that is visible rather than silent.

Fair use of the API

API keys are issued per instance and carry scopes. Do not use them to re-host the underlying public data as a competing service, which is separately a breach of the ELv2 limitation.

Availability

No service level is promised unless a separate signed agreement states one. Upstream sources are outside our control, and a source that changes shape stops a walk rather than producing a wrong number.

No warranty, no service level, and limited liability

This product is provided as it is and as it happens to be available, without warranty of any kind, and is used at your own risk. No uptime, response time or restoration time is owed unless a separate signed agreement states one. Where it is provided free of charge, liability is limited to intent and gross negligence (Section 521 BGB).

To the fullest extent the law permits, we are not liable for damage arising from its use, its unavailability, or any loss of data — and keeping your own backups is your responsibility. The limits that mandatory law requires, the exclusions that apply within them, and the additional cap that applies to business customers are set out in full in the general terms of service, which govern this product and are not restated here.

Version identifier

ganalytics-terms-2026-09-06

Content hash, SHA-256

bd2091a2904b83aeb6e882d184564c2e1e7529dabcb243e2d031e23173e4ce52

All documents →

Gelhaus Solutions

Self-hosted applications, and the platform that hosts them for the people who would rather not.

Site

  • Apps
  • Security
  • Writing
  • Contact
  • Sitemap

GHub

  • GAnalytics
  • contribution-checker
  • GAdvisory
  • GeGroups
  • GControl

Legal

  • Impressum
  • Privacy
  • Terms
  • Data processing
  • Withdrawal
  • Report content

Elsewhere

  • egelhaus@ennogelhaus.de
  • @egelhaus
  • @egelhaus
© 2026 Enno Gelhaus Built and shipped in Germany