sunturai

Content and licensing

Most of the detection content in this catalogue was written by other people. This page says where it comes from, who owns it, when crediting an author is an obligation rather than a courtesy, what you grant by contributing, and how to tell us we got something wrong.

Last updated
25 August 2026
Applies to
The Detections service at detections.app

1. Where this content comes from

Detections gathers detection content from public repositories maintained by other projects. Each source it draws from is configured with the licence that project publishes its material under, and that licence is carried through and stated on every rule obtained from it.

Two things follow that are easy to assume wrongly. A repository being publicly readable does not by itself grant anyone the right to redistribute what is in it — accessibility and permission are different questions. And not every project Detections draws from publishes under an open-source licence: at least one uses a source-available licence, which permits some uses and restricts others, including uses a commercial service might want. The licence stated on a rule is the one that governs it, and it is not safe to generalise from one rule to another.

2. What Detections claims, and what it does not

Detections does not claim authorship of a rule because the rule appears in this catalogue. Gathering, normalising, indexing, analysing and displaying somebody else's work does not transfer their ownership of it, and nothing on this site should be read as saying otherwise. Whatever rights existed in the original material still sit where they sat.

3. A rule can carry two licences

A rule can carry two licences that are not the same: the one the upstream artefact was obtained under, and the one the version published here is offered under. For a rule ingested unchanged the two are identical. For a rule somebody derived from another, they can differ.

Detections states both and asserts nothing about which one governs — that is a licensing question rather than a field in a database, and it is not ours to answer for you. Both appear on the rule itself, with a link to the licence text, alongside the source it came from and a link to the original. If you take a rule from here and use it, satisfying the terms that apply to it is your responsibility.

4. Attribution

Where a licence calls for attribution, Detections publishes the name the document was signed with, beside the rule. Not every licence asks for it: some place work in the public domain and require nothing, and Detections offers one such licence to contributors. So attribution here follows the licence covering that particular material rather than a blanket rule of ours, and you should not infer from a credited rule that every rule is credited, nor the reverse.

Attribution is published as a name, never as an email address. A rule whose document carries no signature appears without an author rather than credited to whoever hosts the repository. Detections does not guess an author, does not infer an employer, and does not merge two people because their names match.

If an attribution naming you is wrong, write to us. What can change is how the name appears and whether the page collecting your work exists; an attribution that the applicable licence requires may need to stay, and which of those applies is a question about that licence rather than a policy we apply to everything.

5. What Detections adds

A rule from another project remains that project's. What Detections builds around it is a separate question from what the rule is: the normalisation, the technique mapping, the analysis, the relationships between rules, the interface and the documentation are its own work, and publishing a third-party rule does not place any of that under the rule's licence either. The two travel together and are not the same thing.

6. Contributing your own content

When you contribute a rule to the public catalogue, Detections asks for three things and records all of them: the licence you are publishing it under, chosen from the licences the catalogue supports; the attribution you want carried with it; and a confirmation that you are authorised to contribute the content. That confirmation is stored with the contribution.

Contributing does not transfer ownership to Detections. You keep whatever rights you hold in what you wrote, and what you grant is what publishing requires — that Detections may host, display, format, distribute and operate the contribution as part of the catalogue, under the licence you selected. That licence is what governs what anyone else may then do with it.

One consequence is worth being explicit about, because people discover it at the wrong moment. Deleting your account does not automatically withdraw a contribution you already published: it was published under a licence, other people may already be relying on it, and the account and the licence are separate things. What happens to a published contribution depends on that licence rather than on the account that submitted it.

Content in a private workspace is not part of any of this. It stays private until you take the explicit action of contributing or sharing it — see the privacy notice.

7. Names, marks and endorsement

Third-party names, projects and trademarks appear on this site to identify where material came from and what a rule is compatible with. They are used descriptively and imply no sponsorship, affiliation or endorsement in either direction: naming a vendor does not mean the vendor endorses Detections, and it does not mean Detections speaks for the vendor. Each mark belongs to its owner.

8. Reporting a content or rights issue

Write to contacto@detections.app for any of these: an attribution that is wrong, a licence recorded incorrectly, a copyright concern, content contributed by somebody who was not entitled to contribute it, material that should not have been made public, a trademark concern, or a personal-data question about a name that appears here.

Including the link to the page, what specifically is wrong, and what you would like corrected is usually enough to act on. Tell us who you are and what your relationship to the material is, because a correction to an attribution depends on it. Nothing more elaborate is required to be taken seriously.

What happens next is that a person reads it. A report is acknowledged, reviewed against the provenance recorded for the material, and acted on — which may mean correcting a licence or an attribution, restricting the content while it is reviewed, withdrawing it, or explaining why we think it is right as it stands. This page does not promise a deadline or an automatic removal, because promising either would be a claim about capacity rather than a description of what happens.