← FactFile

Terms of Service — Pilot Engagement

Last updated: 2026-08-20

Draft —This is a starting draft, not legal advice. It has not been reviewed by a lawyer. Have it checked for your jurisdiction before relying on it commercially.

1. Who this applies to

These terms apply to the one-time "Pilot" engagement purchased via the Stripe payment link on this site (€1,400, one-time). They do not apply to the subscription waitlist, which is not yet a paid product.

This service is sold to businesses only (B2B). Purchasing requires a registered company name and a valid VAT ID at checkout. We do not sell the pilot to private individuals, and purchases made without a valid business VAT ID may be refused or refunded.

The pilot's scope is fixed: one released software product, one named version, up to two repositories, across the ecosystems this kit supports (Composer/PHP, npm/Node, Gradle/Maven, PyPI/Python). A larger scope — a monorepo of multiple independently-deployed services, or a product that spans a mobile client, a backend, and infrastructure as effectively separate products — is out of scope at this price and requires a separate, agreed engagement before work begins.

2. What is delivered

For the pilot fee, we hand-build a Cyber Resilience Act evidence package for one product, built from the customer's actual repository and build artifacts. The package includes:

License enrichment is best-effort. Components whose license metadata cannot be resolved are explicitly marked as unresolved; they are not silently treated as permissively licensed.

These documents are evidence and drafting assistance. They do not constitute a certification, a legal opinion, or a guarantee of regulatory compliance. The compliance decision for the product remains the customer's, as manufacturer, under the CRA.

Explicitly not included, at this price, regardless of what the assessment finds: a penetration test or dynamic security testing; confirmation or certification of CRA compliance; a legal opinion on whether the CRA applies to the customer's product; conformity assessment by a notified body or CE marking; fixing any issue the assessment identifies; filing any notification with ENISA or a national CSIRT on the customer's behalf; or an ongoing vulnerability-remediation service.

3. Turnaround & refund

Delivery target is 7 business days from kickoff. Kickoff is defined precisely: it starts once we have received full repository access and complete answers to the evidence questionnaire — not at the moment of payment.

If the package is not delivered within 7 business days of kickoff as defined above, the customer is entitled to a full refund of the pilot fee, on request.

The clock does not run, and the refund guarantee does not apply, while any of the following is unresolved: repository access is incomplete or the provided export does not build; lockfiles or a resolved-dependency output needed to generate the SBOM are missing; the customer has not responded to the questionnaire or a reasonable follow-up question; or the product turns out to be multi-component and outside the scope defined in section 1, with no agreed scope change in place.

4. Customer responsibilities

The customer is responsible for granting timely, sufficient access to the repository and build systems needed to produce the package, and for the accuracy of any information supplied outside of what can be read directly from the repository.

5. Confidentiality

We treat the customer's source code, architecture, and any other non-public information shared during the engagement as confidential. We will not disclose it, reuse it, or reference it — including as a future public sample, case study, or marketing material — without the customer's prior written consent.

Repository access is read-only, for the duration of the engagement only. Our local copy of the repository and any artifacts derived from it are deleted within 30 days of delivery, unless we agree in writing to retain something for a specific, stated reason. A mutual NDA can be signed before repository access is granted, on request, at no extra cost.

One exception, stated explicitly: to check components against publicly known vulnerabilities, we send the list of package names and versions from the SBOM to OSV.dev, the public vulnerability database operated by Google and the OpenSSF. No source code, no configuration and no identifying information about you or your product is sent — only package coordinates. If you would rather we skipped this step, say so and we will, and the vulnerability-match report is then omitted from the package.

6. Ownership of deliverables

On full payment, the customer owns the delivered technical file, SBOM, risk assessment, and draft declaration of conformity. We keep no license to the customer's proprietary code or architecture beyond what is needed to deliver the engagement. We retain only the general methodology and tooling used to produce the package, which are not specific to the customer's product.

7. Limitation of liability

To the maximum extent permitted by law, our liability arising from this engagement is limited to the amount paid for the pilot (€1,400). We are not liable for indirect, incidental, or consequential damages, including regulatory penalties, arising from reliance on the delivered documents. The documents are an input to the customer's own compliance process, not a substitute for it.

8. Governing law

These terms are governed by the laws of Poland. Disputes are subject to the competent courts of Warsaw, Poland.

9. Contact

Veranika Aucharova, NIP PL5253094181 / REGON 545027310, ul. Nalewki 2, 00-158 Warszawa, Poland. Contact: [email protected].