The software
Grux is a Swift package released under the MIT License. That license ships with the source and it, not this page, governs what you may do with the code. In short: use it, change it, ship it commercially, keep the copyright notice, and take it as is with no warranty of any kind.
Read the limits before you rely on it
This is a security library, so its documented limits are part of these terms rather than a footnote. They are known and deliberate, not open bugs:
- URLGuard judges one URL string. It does not follow redirects, so a URL that passes is free to answer with a redirect to somewhere that would not have. Every hop is the caller's to re-check.
- URLGuard does not resolve DNS, so it cannot see DNS rebinding. A hostname is judged on the string handed to it, not on where it actually points.
- SecretRedactor is a matcher, not a parser. A credential in a format no pattern covers passes through by construction. Single case hex strings are exempt on purpose, which keeps commit hashes and checksums intact and lets a lowercase hex secret through untouched.
- Six tags published before 0.5.0 leak, from 0.1.0 through 0.4.0. They are left resolvable on purpose so existing checkouts do not break, and they are listed on the home page. Do not ship them.
Using Grux does not make an application secure, and it is not a substitute for your own review. It reduces a known class of leak. It does not remove the class.
This website
The site describes the project. Content may be wrong or out of date, and nothing on it is a warranty, a support commitment, or a service level promise.
The redaction demo on the home page is an illustrative approximation that runs entirely in your browser. It is not the library and it is not compiled from the library, and where the two disagree the Swift one is correct. Do not use the demo to decide whether a real secret is safe.
Roadmap items are plans. Anything described as not shipped has not shipped, and a date on this site is an intention rather than a commitment.
The download
Grux OS is free and MIT licensed, and the licence text that ships inside the app bundle is the one that governs your use of the software. It is offered as it is, with no warranty and no undertaking that it will suit your purpose or keep working. The download is served by GitHub rather than by this site, on GitHub's terms.
The waiting list that used to be described here was removed on August 22, 2026, when 1.0 shipped and there was nothing left to wait for. The privacy page says what became of the addresses collected while it existed, and how to have one removed.
Using the site
Read it, quote it, link to it. Do not try to break it, overload it, or gain access to anything on it that is not published, and do not use it to attack anyone else.
If you find a vulnerability in this site or in the library, the contact is security@gruxai.com. The project asks for a failing test case rather than a description: the exact input that survived SecretRedactor, or the exact URL that URLGuard allowed. There is no bounty.
No warranty, and the limit on liability
THE SOFTWARE AND THIS SITE ARE PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHOR OR COPYRIGHT HOLDER BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE, THIS SITE, OR THE USE OR OTHER DEALINGS IN EITHER.
Nothing here limits liability that the law where you live does not allow to be limited.
The name
Grux and gruxai.com identify this project. The MIT License covers the code; it does not grant a right to use the name or the domain in a way that implies this project endorses a fork, a repackaging, or a separate product.
Governing law
These terms are governed by the laws of the State of Michigan, United States, without regard to its conflict of law rules.
Changes
If these terms change, the date at the top of this page changes with them. Using the site after that is acceptance of the change.
Who operates this
Grux is built and maintained by DotcomJack, in Detroit, Michigan.
9011 Linwood St #1101, Detroit, MI 48206, United States.
General contact: jack@dotcomjack.com. Security reports: security@gruxai.com.
The privacy page is next door.