1. Scope of Services
CGT will perform a technical verification review — not a formal compliance audit, certification, attestation, or penetration test — of the Client's specified software product(s), including: verification of privacy/legal disclosures against actual code behavior; testing of user-facing forms and payment flows; review of authentication and data-access configuration; identification of exposed secrets or misconfigured infrastructure. CGT will deliver a written, severity-ranked report of findings within the agreed timeframe (3–5 business days from confirmed repo access). The review is limited to the software products, repositories, configurations, and materials expressly identified for the Engagement and made available to CGT during the agreed review period.
2. Client Access Grant & Representations
Client will provide CGT with read-only access to specified repositories, scoped to only what's needed for the Engagement. Client may revoke access at any time. Client represents that: (a) it owns or is authorized to grant access to the repositories and materials provided; (b) it has authority to enter this Agreement and authorize the review; and (c) the access granted to CGT does not violate any third party's rights.
3. Client Responsibilities
Client is responsible for: identifying the in-scope repositories and distinguishing production from test/staging environments; identifying any systems explicitly excluded from review; maintaining its own backups; and revoking CGT's access promptly upon completion of the Engagement.
4. What This Engagement Does NOT Include
CGT does not remediate, patch, or modify Client's code as part of this Engagement (a separate remediation engagement may be scoped afterward, by mutual agreement). CGT does not perform penetration testing, load testing, or exploit development. This is a review and reporting engagement, not an implementation engagement. Client is solely responsible for evaluating findings, determining appropriate remediation, implementing remediation, and validating its effectiveness.
5. No Guarantee; Not an Assurance Opinion
CGT's review represents a good-faith, time-boxed assessment and does not guarantee the identification of every possible security or compliance issue. This Engagement does not constitute legal advice. The Report is an assessment of observations identified during the Engagement and is not an assurance opinion, certification, attestation, representation of compliance, or guarantee of security.
6. Report Use & Third-Party Reliance
The Report is prepared solely for Client's internal use in connection with the Engagement and may not be relied upon by any third party (including investors, customers, or auditors) without CGT's prior written consent.
7. Fees & Payment
Fee is due in full at engagement start via the agreed payment method. The applicable 3–5 business day review period begins when both payment and the required repository access have been received and confirmed by CGT.
8. Limitation of Liability
To the maximum extent permitted by applicable law, CGT's aggregate liability arising out of or relating to this Agreement or the Engagement — whether in contract, tort, negligence, or otherwise — shall not exceed the total fees actually paid to CGT for the Engagement. This cap applies to all claims and theories of liability. CGT is not liable for indirect, incidental, or consequential damages, including damages arising from vulnerabilities not identified during the review, or from Client's action or inaction following delivery of the report. Nothing in this Agreement limits liability to the extent such limitation is prohibited by applicable law, and this limitation does not apply to fraud, willful misconduct, or intentional misconduct.
9. Intellectual Property
Client retains ownership of its source code, trademarks, business data, and other proprietary materials ("Client Materials"). CGT retains ownership of its pre-existing methodologies, checklists, templates, scripts, and know-how. Upon full payment, Client receives a perpetual, non-exclusive license to use the final Report for its internal business purposes.
10. Indemnification
Client will defend, indemnify, and hold harmless CGT from third-party claims arising from Client's lack of authorization to provide the materials or access given to CGT, or from Client's unlawful instructions or materials.
11. Confidentiality
Governed by the separately executed Mutual NDA between the parties.
12. Term & Termination
Either party may terminate this Engagement with written notice before work begins, for a full refund. Once work has commenced, fees are non-refundable except as expressly provided in this Agreement or at CGT's discretion. Work is deemed to have commenced when CGT begins reviewing Client Materials or conducting testing.
13. Independent Contractor
CGT is an independent contractor. Nothing in this Agreement creates an employment, agency, partnership, or joint-venture relationship between the parties.
14. Governing Law & Venue
This Agreement is governed by the laws of the State of New Jersey, United States. Exclusive jurisdiction and venue for any dispute shall lie in the state or federal courts located in New Jersey.
15. Attorneys' Fees
The prevailing party in an action to enforce this Agreement shall be entitled to recover reasonable attorneys' fees and costs, to the extent permitted by law.
16. Entire Agreement
This Agreement (together with the Mutual NDA) is the entire agreement between the parties regarding the Engagement and supersedes all prior discussions, marketing materials, emails, or representations, whether written or oral.
17. Amendments, Severability & Waiver
This Agreement may only be amended in writing signed by both parties. If any provision is found unenforceable, the remaining provisions remain in full effect. Failure to enforce any provision on one occasion does not waive the right to enforce it later.
18. Notices
Notices under this Agreement shall be provided by email to the addresses designated by the parties, and shall be deemed received upon confirmation of delivery or the next business day after transmission, unless the sender receives a delivery failure notice.