Legal
Terms of Service
Plain English where possible, lawyer English where necessary. Last updated April 10, 2026.
1. What these terms cover
Guardra is not a software service. There is no subscription, no account, no platform and nothing to log into. These terms cover a single engagement: a manual network segmentation assessment performed by one person from artefacts you supply. Any future software product will have its own terms, published before it is offered.
2. Scope and fee
Each engagement covers one enforcement boundary — a single firewall or HA pair — for one agreed evidence window. The fee is fixed and quoted before work begins. No amount is invoiced until you have sent a sample and accepted that the data supports the deliverable; if it does not, the engagement stops there at no cost to you.
3. What is delivered
A written report within ten working days of sample acceptance, containing findings where your stated intent and your records disagree, the limits of each finding, and a coverage statement describing what the data could not show. No minimum number of findings is promised. A clean boundary is a valid outcome and the coverage statement is then the deliverable.
4. What is not promised
No uptime commitment, no service level, and no availability guarantee — there is no running service to which any of those could apply. The report is not a compliance certification and does not by itself demonstrate compliance with HIPAA or any other regime. It is evidence you may choose to use, interpreted by your own compliance function.
5. Your artefacts
You retain ownership of everything you send. Artefacts are used solely for your engagement, held encrypted or inside your own environment, never shared, and deleted within 30 days of delivery or immediately on written request, with written confirmation. Findings are yours; nothing is published or reused without your written permission.
6. Protected health information
The engagement is scoped to network metadata and structured so that PHI is not required. Note that under HHS de-identification guidance, IP addresses and device identifiers are among the listed identifiers, so whether a given export contains PHI depends on its content and context rather than on the absence of packet payload. If PHI may be in scope, a business associate agreement must be executed before any artefact is transferred.
7. Limitations of the analysis
Observing traffic between two points establishes that a path carried traffic. Observing none establishes nothing — a path may be unused in the window, or collection may not sit where expected. Asymmetric routing, sampled flow records and incomplete exports all reduce coverage. These limits are stated in the report rather than resolved by it.
8. Liability
Liability is limited to the fee paid for the engagement. Guardra is a sole trader and does not currently hold cyber liability insurance; this is stated plainly so it can be weighed before you engage rather than discovered afterwards. Remediation decisions, change approval and any action taken on a finding remain yours.
9. Governing law
These terms are governed by the laws of England and Wales. Questions to legal@guardra.ai. For engagements requiring your own contract paper, send it — this is a starting point, not a condition.