ReadyStack Agreement

Last updated: October 7, 2026

What this covers

This agreement describes what ReadyStack does for people who use our free Docker Hub images and for customers who buy an archive. It sits alongside our Terms of Service; where they differ, the Terms of Service govern.

What we publish for every release

  • A grade with its date and reasons. We grade each release with Docker Scout's policy evaluation on the published image, show the date and the reason for every policy it fails, re-check it daily, and update the grade when it changes. The grade at release stays in the release history with its own date.
  • Signing status. Whether the release is signed with our published key (cosign.pub), measured from the registry.
  • Rebuild results. Whether we rebuilt the image from its archive with the network off and got the same digest, and when.
  • Defects. The defects we find in the upstream software or in our own package, with their status, matched to existing CVEs, advisories or upstream issues where one exists. Defects are public.

These facts are measured, not promised. When a measurement changes, the page changes. Grade reasons, signing status and rebuild results are being added to every release page during October 2026.

Support

Email [email protected]. We answer on a best-effort basis; there is no guaranteed response time.

We help with rebuilding and verifying an archive, errors in our handbooks and documentation, and defects in our image or archive. We do not support the upstream software itself, custom deployments, or software we did not package. Upstream defects you report to us are recorded and matched to the upstream project's records.

Corrections to an archive you bought

If we find, or you report, a defect in our own package for the release you bought (for example the archive does not rebuild the published image, a verification script fails because of our error, or the archive contains something it should not), we fix it, publish the defect, and make the corrected archive of that same release available to you at no charge.

Updates

An archive is a snapshot of one release. It does not include future releases; a new release of a product is a separate archive. Vulnerabilities disclosed after a release are shown in that release's current grade.

Free images

The Docker Hub images are free. They are provided as is under the upstream software's licenses, with the published facts above. There is no support obligation for free images, but we welcome reports.

Changes to this agreement

We may update this agreement. Each version carries its date; the version in force when you bought an archive applies to that purchase's corrections and support.

Contact

[email protected]