Back to CoreCheck

General Terms and Conditions

Syntheticaire – CoreCheck

1. Object of the Service, Limitation and Exclusion of Liability

1.1.

The Service is an automated diagnostic code examination (CoreCheck), which analyzes the source code transmitted by the Client based on specific technical criteria, including vulnerabilities, library dependencies, reliability, maintainability, test coverage, duplication rates, leaked API keys, and sensitive data.

1.2. Total Exclusion of Liability

The Service Provider solely undertakes the execution and analysis of the codebase, and the compilation and delivery of the resulting report (hereinafter referred to as the "Report").

1.2.1.

The Service Provider provides no warranty or guarantee whatsoever that the CoreCheck system will detect one hundred percent of all existing bugs, errors, vulnerabilities, or security risks.

1.2.2.

The Service is a static diagnostic tool reflecting a snapshot of the code at a specific time and does not substitute continuous and comprehensive cyber-security analysis or live engineering software development quality assurance.

1.2.3.

To the fullest extent permitted by applicable law, the Service Provider completely excludes any and all liability for any direct or indirect damages, loss of profits, data loss, business interruption, or material damages caused to a third party, including but not limited to cyber-attacks, unauthorized access, data leaks, or system outages, arising in connection with the content of the delivered Report, hidden defects remaining in the Report, or the deployment or launch of the code by the Client or any third party.

1.3. Responsibility for Rectification and Implementation

The evaluation of the findings, recommendations, and warnings described in the Report, as well as the actual rectification of errors or the decision to ignore them, shall fall exclusively and entirely within the Client's scope of responsibility.

2. Ordering Process, Fees, and Delivery Deadline

2.1. Pricing

The fixed fee for a single CoreCheck analysis is EUR 49 per analysis.

The Client acknowledges and agrees that any subsequent analysis of a modified codebase state (for example, a repaired v1 state following the initial v0 state) shall constitute a new order and is subject to an additional fee of EUR 49 per analysis.

2.2. Conditions of Performance

The Service Provider shall only be obligated to commence the code analysis if both of the following conditions are fulfilled:

  • The service fee (EUR 49) has been received in full in the Service Provider's bank account.
  • The Client has transmitted the source code to be analyzed in a complete and accessible manner.

2.3. Method of Code Transmission

The Client may transmit the source code in the form of:

  • a ZIP archive,
  • a cloud storage share (for example Google Drive), or
  • private repository access through a version-control platform such as GitHub or GitLab.

2.4. Guaranteed Three-Day Deadline

The Service Provider undertakes to compile and deliver the completed Report electronically by e-mail within a maximum of 3 calendar days (72 hours) from the collective fulfillment of the conditions specified in Section 2.2.

3. Data Protection, Business Confidentiality, and Data Erasure Guarantee

3.1.

The Service Provider acknowledges that the source code transmitted by the Client constitutes the Client's exclusive property and strict trade secret.

The Service Provider undertakes not to make the transmitted code accessible to any third party and to use it solely for conducting the CoreCheck analysis.

3.2. Client Responsibility for the Submitted Code

The Client warrants that the transmitted codebase does not contain malware, viruses, Trojan horses, ransomware, illegal content, or any elements capable of compromising the Service Provider's infrastructure.

Should the Client breach this obligation and the transmitted source code cause infection, data loss, downtime, or any other damage to the Service Provider's systems, databases, or IT infrastructure, the Client shall fully indemnify the Service Provider for all resulting direct and indirect damages, including technical restoration costs and lost business profits.

3.3. Exclusion of Personal Data (GDPR)

The Client undertakes to permanently remove or anonymize all actual personal data, such as customer information or production database fragments, before transmitting the source code.

The Client bears sole legal responsibility for any personal data inadvertently remaining within the submitted code.

3.4. Data Erasure Guarantee

Following completion of the analysis and delivery of the Report, the Service Provider shall retain the source code for an additional 7 calendar days for security purposes and to answer potential follow-up questions.

On the seventh calendar day after delivery of the Report, the Client's source code and every copy thereof shall be permanently and irreversibly deleted from the Service Provider's systems.

4. Intellectual Property Rights and Warranty of Title

4.1.

All copyrights and ownership rights relating to the submitted source code shall remain entirely with the Client.

4.2.

The CoreCheck analysis software, the underlying algorithms, the scanning methodology, and all website elements constitute the exclusive intellectual property of the Service Provider.

Ownership of the completed Report transfers to the Client upon full payment of the service fee.

4.3. Warranty of Title

The Client warrants that they possess full authority over the submitted source code or are otherwise legally authorized to provide it for analysis.

The Client shall fully indemnify and hold the Service Provider harmless against any third-party claims relating to intellectual property infringement or confidentiality breaches concerning the submitted software.

The Client shall furthermore bear full financial responsibility for any damage caused to the Service Provider's infrastructure by infected or malicious code submitted for analysis.

5. Right of Withdrawal, Force Majeure, Governing Law, and Jurisdiction

5.1. Right of Withdrawal

If the Client qualifies as a business entity (B2B), no statutory right of withdrawal shall apply after placing the order due to the nature of the service.

If the Client is a consumer, payment of the invoice and submission of the source code shall constitute an explicit request for immediate commencement of the service.

The Client acknowledges that, once performance has begun, the statutory fourteen-day withdrawal period is forfeited and no refund of the paid amount shall be available.

5.2. Force Majeure

The Service Provider shall not be liable for failure to meet the three-day delivery deadline where delays arise from unforeseeable and unavoidable external circumstances, including:

  • global internet outages;
  • large-scale outages affecting cloud infrastructure providers such as AWS or Google Cloud;
  • targeted cyber-attacks against the Service Provider's infrastructure.

In such circumstances, the Service Provider shall perform the service without undue delay once the issue has been resolved.

5.3. Governing Law and Jurisdiction

These Terms and Conditions, the legal relationship between the Parties, and all obligations or disputes arising therefrom shall be governed exclusively by the laws of the Republic of Estonia together with the directly applicable legislation of the European Union.

The United Nations Convention on Contracts for the International Sale of Goods (CISG) is expressly excluded.

5.4. Dispute Resolution

The Parties shall first attempt to resolve any dispute through amicable negotiations.

If the dispute cannot be resolved within thirty days of the initial contact, exclusive jurisdiction shall lie with the competent court having jurisdiction over the Service Provider's registered office in Estonia.