Thirteen product photographs are served by this site with no documented reuse permission. A read-only audit of every vendor's official press and media-kit terms was carried out on 2026-09-02; the findings and the replacement plan are below.
Media-kit availability is not treated as permission anywhere in this issue. Six vendors publish downloadable product images while stating no terms at all, and "no terms stated" is not "permitted".
Their use is unresolved, not authorised. They are excluded from the project's content licence (LICENSE-CONTENT.md), which is a separate matter: exclusion says what the licence does not grant, and says nothing about the basis on which the images appear here.
Highest priority — 2 files
SatoshiLabs / Trezor is the only vendor whose published terms squarely address this, and they refuse it.
From https://satoshilabs.com/terms-of-use:
"The trademarks may not be used by you without prior, written, consent by Trezor Company s.r.o."
"You are not allowed to change, alter, copy, reproduce, distribute, republish, download, display, post, send, transmit or otherwise use…the Content or any portion of the Website…without prior written permission."
The only carve-out is "a limited, revocable, non-exclusive right … for your personal, non-commercial use only", which does not reach a published site. Their press kit at https://satoshilabs.com/presskit states no terms of its own.
| File |
Location |
Plan |
docs/assets/img/devices/trezor-safe-7-shortlist.png |
build/content.mjs — productCard on devices.html |
Remove. Use the existing icon fallback |
docs/assets/img/devices/trezor-safe-7-detail.png |
build/content.mjs — detail block #trezor on devices.html |
Redesign the area without a photograph |
Everything else on this list is "no usable terms found". These two are "terms found, and they say no", which is why they go first.
Remaining 11 files
No usable terms located for any of them.
| File |
Vendor |
Location |
Plan |
devices/bitkey.png |
Block |
shortlist card + detail block, devices.html |
Remove from card; redesign detail |
devices/bitbox02.webp |
Shift Crypto / BitBox |
shortlist card + detail block, devices.html |
Remove from card; redesign detail |
devices/blockstream-jade-plus.png |
Blockstream |
shortlist card + detail block, devices.html |
Remove from card; redesign detail |
devices/coldcard-q-mk5.png |
Coinkite |
shortlist card + detail blocks on devices.html and coinkite.html |
Remove from card; redesign both details |
devices/prime_light.webp |
Foundation |
shortlist card + detail block, devices.html |
Remove from card; redesign detail |
devices/seedsigner.webp |
SeedSigner |
shortlist card + detail block, devices.html |
Remove from card; redesign detail |
devices/krux-yahboom.png |
Krux / Yahboom |
shortlist card + detail block, devices.html |
Remove from card; redesign detail |
devices/ledger-stax-face.webp |
Ledger |
shortlist card + detail block, devices.html |
Remove from card; redesign detail |
devices/satscard.png |
Coinkite |
detail block, coinkite.html |
Redesign the area |
devices/tapsigner.svg |
Coinkite |
detail block, coinkite.html |
Redesign the area — note this is an Illustrator vector drawing, not a photograph |
coldcard-q-mk5-devices.jpg |
Coinkite (manufacturer-provided) |
build/guides.mjs — figure() in guides/coldcard-setup.html |
Replace with a project-owned photograph, keeping the filename |
Vendor findings
Approved replacement plan
Shortlist cards — 9 files → remove
productCard in build/content.mjs already has a fallback: omit image and it renders <div class="sc-icon"><i class="bi …"></i></div>. The container is height: 220px; display: grid; place-items: center with its own gradient, so card geometry does not change.
That branch is currently unexercised (0 of 9 calls), so it needs a visual check. The default icon is bi-usb-drive for every card, so each should get its own; the current subset already carries bi-cpu, bi-credit-card-2-front, bi-phone, bi-shield-lock, bi-stack, bi-window, bi-wallet2, bi-usb-drive.
Detail blocks — 12 → redesign
The media sits in col-lg-5 beside col-lg-7, so deleting it alone leaves an empty half. Preferred: replace the media column with a project-owned key-facts panel — secure element, connectivity, firmware, form factor — as HTML rather than an image. That keeps the two-column rhythm across twelve blocks and adds comparison information a photograph never carried.
Alternative, simpler and worse: widen the text to col-lg-12, which turns twelve consecutive blocks into a wall of prose.
Guide figure — 1 → replace
coldcard-q-mk5-devices.jpg is the only one carrying explanatory weight the prose depends on. Its caption reads "Same codebase, two keyboards. The Q's full QWERTY on the left, the Mk5's numeric keypad on the right." Removing it takes the point with it, so an original photograph of the same pairing should replace it. This is the only file where the filename should be preserved, because the slot and its meaning survive.
Consequences
- Alt text. The nine
imageAlt properties become unused; the icon branch is decorative and correctly has none. The twelve detail <img> elements go entirely. Only the guide figure needs new alt, describing the new composition.
- Build. Regenerates
docs/devices.html, docs/coinkite.html, docs/guides/coldcard-setup.html. The Workshop artifact digest is unaffected — none of these is inlined. Choosing any icon outside the current 43 requires npm run icons:subset, which regenerates the icon font and stylesheet.
- No stylesheet touches these. Verified: no CSS
url() references any of the thirteen. Matches for "bitkey", "satscard", "seedsigner" and "tapsigner" in site-refresh.css are class names and data-finder-value attributes, not image references.
- Per-file, not per-group. If terms are later located for a vendor, that image can be exempted without disturbing the rest.
Exit condition
Each of the thirteen ends in one of three states: documented terms recorded in LICENSING-AUDIT.md; replaced by project-owned imagery; or removed. Until then their use stays recorded as unresolved.
Thirteen product photographs are served by this site with no documented reuse permission. A read-only audit of every vendor's official press and media-kit terms was carried out on 2026-09-02; the findings and the replacement plan are below.
Media-kit availability is not treated as permission anywhere in this issue. Six vendors publish downloadable product images while stating no terms at all, and "no terms stated" is not "permitted".
Their use is unresolved, not authorised. They are excluded from the project's content licence (
LICENSE-CONTENT.md), which is a separate matter: exclusion says what the licence does not grant, and says nothing about the basis on which the images appear here.Highest priority — 2 files
SatoshiLabs / Trezor is the only vendor whose published terms squarely address this, and they refuse it.
From https://satoshilabs.com/terms-of-use:
The only carve-out is "a limited, revocable, non-exclusive right … for your personal, non-commercial use only", which does not reach a published site. Their press kit at https://satoshilabs.com/presskit states no terms of its own.
docs/assets/img/devices/trezor-safe-7-shortlist.pngbuild/content.mjs—productCardondevices.htmldocs/assets/img/devices/trezor-safe-7-detail.pngbuild/content.mjs— detail block#trezorondevices.htmlEverything else on this list is "no usable terms found". These two are "terms found, and they say no", which is why they go first.
Remaining 11 files
No usable terms located for any of them.
devices/bitkey.pngdevices.htmldevices/bitbox02.webpdevices.htmldevices/blockstream-jade-plus.pngdevices.htmldevices/coldcard-q-mk5.pngdevices.htmlandcoinkite.htmldevices/prime_light.webpdevices.htmldevices/seedsigner.webpdevices.htmldevices/krux-yahboom.pngdevices.htmldevices/ledger-stax-face.webpdevices.htmldevices/satscard.pngcoinkite.htmldevices/tapsigner.svgcoinkite.htmlcoldcard-q-mk5-devices.jpgbuild/guides.mjs—figure()inguides/coldcard-setup.htmlVendor findings
/pressreturns HTTP 403; no press or media kit locatedApproved replacement plan
Shortlist cards — 9 files → remove
productCardinbuild/content.mjsalready has a fallback: omitimageand it renders<div class="sc-icon"><i class="bi …"></i></div>. The container isheight: 220px; display: grid; place-items: centerwith its own gradient, so card geometry does not change.That branch is currently unexercised (0 of 9 calls), so it needs a visual check. The default icon is
bi-usb-drivefor every card, so each should get its own; the current subset already carriesbi-cpu,bi-credit-card-2-front,bi-phone,bi-shield-lock,bi-stack,bi-window,bi-wallet2,bi-usb-drive.Detail blocks — 12 → redesign
The media sits in
col-lg-5besidecol-lg-7, so deleting it alone leaves an empty half. Preferred: replace the media column with a project-owned key-facts panel — secure element, connectivity, firmware, form factor — as HTML rather than an image. That keeps the two-column rhythm across twelve blocks and adds comparison information a photograph never carried.Alternative, simpler and worse: widen the text to
col-lg-12, which turns twelve consecutive blocks into a wall of prose.Guide figure — 1 → replace
coldcard-q-mk5-devices.jpgis the only one carrying explanatory weight the prose depends on. Its caption reads "Same codebase, two keyboards. The Q's full QWERTY on the left, the Mk5's numeric keypad on the right." Removing it takes the point with it, so an original photograph of the same pairing should replace it. This is the only file where the filename should be preserved, because the slot and its meaning survive.Consequences
imageAltproperties become unused; the icon branch is decorative and correctly has none. The twelve detail<img>elements go entirely. Only the guide figure needs new alt, describing the new composition.docs/devices.html,docs/coinkite.html,docs/guides/coldcard-setup.html. The Workshop artifact digest is unaffected — none of these is inlined. Choosing any icon outside the current 43 requiresnpm run icons:subset, which regenerates the icon font and stylesheet.url()references any of the thirteen. Matches for "bitkey", "satscard", "seedsigner" and "tapsigner" insite-refresh.cssare class names anddata-finder-valueattributes, not image references.Exit condition
Each of the thirteen ends in one of three states: documented terms recorded in
LICENSING-AUDIT.md; replaced by project-owned imagery; or removed. Until then their use stays recorded as unresolved.