Terms of Service: Diagnostic Audit
Last updated: 4 August 2026
This Agreement is made between Gateforth Systems Limited, a company incorporated in England and Wales (company number 17149164) whose registered office is at The Old Bakery, 90 Camden Road, Tunbridge Wells, TN1 2QP (“Gateforth Systems”, “we”, or “us”), and the purchasing entity (“the Client” or “you”).
The Client confirms they are purchasing the Diagnostic Audit in the course of a business and not as a consumer. By purchasing the Diagnostic Audit, the Client agrees to be bound by the terms of this Agreement.
1. The Services
This Agreement governs the provision of the Diagnostic Audit only. Any subsequent remediation work agreed between the parties will be subject to a separate, signed contract.
- Scope of Audit: The Diagnostic Audit is a strictly observational and reporting exercise conducted exclusively via static code analysis. Gateforth Systems will not execute, build, or run the software.
- Exclusions: The audit does not include code alterations, bug fixes, server configuration changes, dynamic vulnerability assessments, penetration testing, or technical support.
- System Constraints: To qualify for the fixed-fee audit, the target codebase must be a monolithic application written in PHP and contain no more than 250,000 Lines of Code (LOC). For clarity, LOC is defined as physical lines of text excluding blank lines, comments, and third-party vendor libraries.
- Asynchronous Delivery: All services are delivered remotely and asynchronously. This agreement strictly excludes synchronous meetings or video calls.
2. Client Obligations and Dependencies
Gateforth Systems shall only commence work, and delivery timelines shall only begin, once the Client has fulfilled the following dependencies in full:
- Read-only access to the application’s primary source code repository.
- (Optional) A database schema export, strictly excluding all production data and personal identifiable information. If omitted, database health checks will be excluded from the final report.
- (Optional) Existing system architecture documentation.
3. Fees and Payment
- Fixed Fee: The fee for the Diagnostic Audit is £2,950.00, exclusive of Value Added Tax (VAT).
- Payment Terms: 100% of the fixed fee, plus applicable VAT, is due and payable upfront at the time of purchase. Work shall not commence until cleared funds are received.
- Non-Refundable: Due to the digital and upfront nature of the Diagnostic Audit, once the Client has provided all required dependencies and Gateforth Systems has commenced the audit process, the fixed fee is strictly non-refundable.
4. Delivery and Acceptance
- Timeline: The primary deliverable, a comprehensive PDF Diagnostic Audit Report, will be delivered electronically within 10 business days of Gateforth Systems receiving both cleared funds and full access to all technical dependencies.
- Clarification Period: The Client has 10 business days from delivery to submit a single written request for clarifications regarding the report findings. Gateforth Systems will provide a final written response within 5 business days.
- Closure: If no written request is received within 10 business days of delivery, the report is deemed accepted in full.
5. Confidentiality
Both parties agree to maintain the strict confidentiality of all information shared during this engagement.
- Client Confidential Information: Includes application source code, configuration files, database structures, legacy codebase repositories, and operational metrics.
- Gateforth Systems Confidential Information: Includes the structure, methodology, and contents of the Diagnostic Audit Report, alongside any commercial pricing, internal scoring metrics, or fixed-outcome remediation proposals contained therein.
- Obligations: The receiving party shall use confidential information exclusively for the purposes of this engagement and shall not disclose it to unauthorised third parties. Disclosures to reputable Data Storage Providers or cloud infrastructure platforms required to fulfil the services are permitted.
- Duration: Confidentiality obligations remain in force for 3 years following the date of disclosure.
6. Data Protection
Both parties shall comply with all applicable requirements set out in the UK Data Protection Legislation.
- Roles: The Client acts as the Data Controller, and Gateforth Systems acts as the Data Processor.
- Scope of Processing: Processing is purely incidental and limited strictly to data inadvertently exposed within code repositories, database schemas, or operational logs provided by the Client.
- Data Deletion: Upon completion of the services, Gateforth Systems shall securely delete or destroy all project technical assets within 30 calendar days. Data may be retained within electronic backup systems for a maximum of 30 days following project completion before permanent deletion. Gateforth Systems may retain administrative and account data for standard business administration and tax compliance.
7. Intellectual Property
- Client Intellectual Property: The Client retains all intellectual property rights to their source code, database structures, and internal documentation. Nothing in this Agreement transfers ownership of the Client's systems to Gateforth Systems.
- Gateforth Systems Intellectual Property: Gateforth Systems retains all intellectual property rights to its internal diagnostic tools, scripts, methodologies, and the format, structure, and proprietary scoring models contained within the Diagnostic Audit Report.
- License to Report: Upon full payment of the fixed fee, Gateforth Systems grants the Client a perpetual, non-exclusive, non-transferable licence to use the Diagnostic Audit Report strictly for internal business purposes. The Client may not commercially republish the report format, share the remediation pricing frameworks with competing service providers, or use the structural methodology to create derivative works.
8. Limitation of Liability
- Neither party shall be liable to the other for indirect, special, or consequential loss, or for loss of profits, revenue, or data (except as expressly provided regarding data protection).
- Each party's total aggregate liability under this Agreement is limited to 100% of the total fees paid for the Diagnostic Audit.
- Liability for any direct losses arising from a material breach of Data Protection Legislation is limited to £50,000 (or five times the total fees paid for the Diagnostic Audit, whichever is lower).
9. Termination
- Either party may terminate this Agreement with immediate effect by giving written notice if the other party commits a material breach and fails to remedy it within 14 days of receiving notice.
- Gateforth Systems reserves the right to terminate the audit and issue a full refund within 10 business days if the target codebase is deemed to fall significantly outside the stipulated technical constraints.
10. General Provisions
- Independent Contractor: Gateforth Systems operates as an independent contractor. Nothing in this Agreement renders Gateforth Systems an employee, agent, or partner of the Client.
- Governing Law: This Agreement shall be governed by and construed in accordance with the laws of England and Wales. The parties submit to the exclusive jurisdiction of the courts of England and Wales.