TillDevTillDev
Sign inStart free →
LEGAL
Privacy policyWhat we collect, and whyTerms of serviceThe contractSecurityControls + disclosureCookiesThe five we setData processingProcessor termsAcceptable useThe hard linesAttributionsCatalogues we ship
The fine print, plainly

Every document here is written to be read. Questions: legal@tilldev.dev

LEGAL · ATTRIBUTIONS

Attributions

Updated October 2026

TillShield maps its detection rules and checks onto public security catalogues so coverage means the same thing to you as it does to everyone else. These are the catalogues we ship, the exact version, and the notice each one asks for.

§ 01#

Catalogues we ship

CatalogueVersionWhat shipsLicence
MITRE ATT&CK® (Enterprise and Mobile)19.2, released 2026-08-05Tactic, technique and data-component IDs and names, platforms, retirement status, and which data components each technique is detected from. No descriptions.ATT&CK Terms of Use
OWASP Top 102025Category IDs and names.CC BY 3.0
OWASP Application Security Verification Standard5.0.0Chapter, section and requirement IDs and titles. Requirement text is not reproduced.CC BY-SA 4.0
OWASP Mobile Application Security Verification Standard2.1.0Group and control IDs and group titles. Control text is not reproduced.CC BY-SA 4.0
SLSA1.2Track and level names.Community Specification License 1.0

Each catalogue is pinned to the version above. A newer release reaches TillShield only after we check its licence again and every rule's tags still resolve against it.

§ 02#

Notices

MITRE ATT&CK® (Enterprise and Mobile). © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

OWASP Top 10. OWASP Top 10:2025 © OWASP Foundation, CC BY 3.0. Category names are reproduced; the text is not.

OWASP Application Security Verification Standard. OWASP Application Security Verification Standard 5.0.0 © OWASP Foundation, CC BY-SA 4.0. Chapter, section and requirement IDs and titles are reproduced; requirement text is not.

OWASP Mobile Application Security Verification Standard. OWASP MASVS 2.1.0 © OWASP Foundation, CC BY-SA 4.0. Group and control IDs and group titles are reproduced; control text is not.

SLSA. SLSA specification v1.2 © The Linux Foundation, Community Specification License 1.0. Level names are reproduced.

MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. TillShield is not affiliated with or endorsed by MITRE or the OWASP Foundation.

§ 03#

What we do not ship

CIS Benchmarks. Their licence does not allow commercial redistribution, so no CIS text or control list ships with TillShield. You can still tag your own rules with CIS references; we keep the tag as your reference and do not check it.

Sigma. TillTell rules borrow Sigma's YAML shape so they read familiarly. No Sigma rule content ships; every rule in the library was written for Till's own records.

§ 04#

Where you see them

The TillTell coverage map scores your rules against ATT&CK and prints the notice beneath the map. Coverage answers from the API carry the catalogue version and the notice in every response.

‹ PreviousAcceptable useNext ›Privacy policy
TillDevTillDev

Seven pieces of the same idea: host the code, ship the thing, see what happened, sign people in, keep the data fast and safe, seal your secrets, and keep a way back.

System status →
PRODUCTS
  • TillPulse
  • TillAuth
  • TillShield
  • TillGate
  • TillCache
  • TillSecrets
  • TillArk
  • TillForge
  • TillNotary
  • TillStudio ↗
DEVELOPERS
  • Documentation
  • TillPulse docs
  • TillAuth docs
  • API reference
  • Changelog
COMPANY
  • About
  • Support
  • Status
  • hello@tilldev.dev
LEGAL
  • Privacy
  • Terms
  • Security
  • Cookies
  • Data processing
  • Acceptable use
  • Attributions
© 2026 TillDev. Built honestly.tilldev.dev · tilldev.app