CodeSpring codebase audit
Code Confidentiality Agreement
This agreement is between Volkis Ltd, trading as CodeSpring, company number 13309940, registered in England and Wales (“we”, “us”), and you, the purchaser of a CodeSpring codebase audit (“you”).
When this agreement takes effect
This agreement applies automatically the moment you purchase an audit. You do not need to sign anything. It binds us from that moment. If you would like a countersigned copy for your records, email support@codespring.app after purchase and we will send one.
What it covers
Everything we can see through the access you grant us: your source code, your database schema, your configuration, your documentation, and the ideas, plans and business information they reveal (“your confidential information”).
What we promise
- We will not disclose your confidential information to anyone outside the team working on your audit.
- We will not use it for any purpose other than producing your audit and walking you through it.
- We will not reuse your code, copy your product, or build anything from what we see. Your idea stays yours.
- We will not use your code or your data to train any AI model.
- We will treat it with at least the care we give our own confidential information, and never less than reasonable care.
How access works
You grant us read-only access as a GitHub collaborator. Read-only means we can look and cannot change anything. You can revoke that access yourself, in your own GitHub settings, at any time, including the moment your walkthrough call ends. We recommend you do.
Deletion
We work from your repository through the access you grant, not from a permanent copy. Any copy or excerpt we hold for the audit, including notes that quote your code, is deleted within 30 days of your walkthrough call. Your audit report is yours and is not deleted; it belongs to you.
What is not covered
- Information that is already public through no fault of ours.
- Information we already lawfully knew before you granted access.
- Information we are required to disclose by law or by a court, in which case we will tell you first unless the law prevents it.
- General knowledge, techniques and experience that do not identify you or your product.
Finding the same category of vulnerability in another customer’s code does not breach this agreement.
Your ownership
You keep all rights in your code, your product and your idea. Nothing in the audit transfers any intellectual property to us. This matches clause 4.1 of our Terms of Service.
How long this lasts
Our obligations continue for as long as your confidential information remains confidential. They do not expire on a schedule.
If we break it
You may pursue any remedy available to you, including damages and injunctive relief. This agreement is enforceable against us in the courts of England and Wales, and is governed by the law of England and Wales.
Contact
support@codespring.app. Volkis Ltd, company number 13309940.
Last updated: 14 August 2026.
This agreement covers the CodeSpring codebase audit. See what the audit is.