Audit engagement terms

Draft — not yet in force. These terms haven’t been reviewed by a lawyer and don’t currently govern any engagement. We publish them for transparency about how we intend to work. Questions to myles@oconnor.industries.

What the audit is

An audit is a point-in-time review of the materials you provide — a codebase at a specific commit, or the processes described in interviews on specific dates. Findings describe what we observed in those materials at that time.

What the audit is not

It isn’t a penetration test, a certification, a compliance attestation, or a guarantee that your systems are secure. No review finds every defect. Don’t read a report as a warranty that the reviewed material is free of vulnerabilities, errors, or risk. Passing an audit doesn’t make a system safe.

You decide what to do with it

Reports are advisory. Decisions about what to change, what to ship, and what risk to accept remain yours. We aren’t acting as your employee, officer, or agent, and we don’t assume operational responsibility for your systems or your business.

What you promise us

That you own the materials you share, or are otherwise authorized to share them with us and to have them reviewed. If you hand us a third party’s code or data without the right to do so, that’s on you, and you agree to cover any claim that arises from it.

Confidentiality

We treat your materials as confidential and won’t disclose them. We’ll sign your NDA or provide ours. Code is handled as described on the audit page: read-only access, sandboxed analysis with no outbound network, a single model provider under no-training and zero-retention terms, and deletion once the re-check window closes.

Fees

The price stated on the audit page is the full fee for the scope stated there. Work begins when payment clears. If we conclude before starting that the engagement isn’t a fit, or afterwards that there was nothing worth reporting, we refund in full as described on that page.

Limit of liability

To the fullest extent permitted by law, our total liability arising out of or relating to an audit is limited to the fee you paid for that audit. We aren’t liable for indirect, incidental, consequential, special, or punitive damages, or for lost profits, lost data, or business interruption, even if you told us such damages were possible.

Governing law

We’ll specify this before these terms take effect. Until then, nothing on this page is binding on either of us.