1 What this agreement is
This puts in writing what we discussed by email through July and August, and what is set out in the revised proposal dated August 3, 2026. It mirrors that proposal. If anything here reads differently from what you understood, tell us before you sign and we will fix the wording — we would rather spend five minutes now than have a surprise later.
This is not a website redesign, rebuild, or new build. It is a compliance audit of catalyst.com across three areas of risk, followed by the fixes for what that audit finds, at one fixed price with a defined ceiling.
One price, one engagement, one ceiling. There is no second invoice in this engagement and nothing here is billed by the hour.
2 What the audit covers
Three separate areas of risk, each reviewed manually against a published standard — not a scan report with a logo on it. Every finding is documented with the specific criterion it relates to, where it occurs, and what it would take to resolve.
- Image alternative text across all templates
- Skip-navigation link for keyboard users
- Colour contrast on text, buttons and brand elements
- Descriptive link text (replacing generic “read more”)
- Logical heading structure and nesting
- Visible keyboard focus indicators
- ARIA landmarks and semantic page structure
- Form labels and error messaging
- Social and icon-only link accessible names
- Screen-reader navigation walkthrough
- Keyboard-only traversal of every interactive element
- Accessibility statement (presence and adequacy)
- Privacy policy — presence, accuracy, scope
- Complete third-party tracker inventory
- What fires before consent, and what it transmits
- Consent management platform assessment
- Cookie inventory with classification and duration
- Terms of use review
- Data access and deletion request pathway
- Form and newsletter data handling
- Embedded third-party content review
- Disclosure alignment with actual site behaviour
- SSL certificates — apex and www
- HTTPS enforcement (HSTS)
- Content Security Policy
- Clickjacking protection (X-Frame-Options)
- MIME-type sniffing protection
- Referrer and Permissions policies
- WordPress core and plugin currency
- Known-vulnerability check against installed versions
- Sitemap and crawl integrity
- Mixed-content and insecure-resource scan
3 What you receive
| Deliverable | Description |
|---|---|
| Written audit report | Every finding documented criterion-by-criterion, with location, severity, and evidence. Written to be read by your counsel, not just your web team. |
| Tracker & cookie inventory | A complete register of what loads on your site, what it transmits, when it fires, and to whom. |
| Prioritised remediation plan | Every finding ranked by exposure, with the specific fix and effort for each. |
| The fixes themselves | Every finding listed in the report that sits within the ceiling in section 4 — resolved, re-tested, and confirmed in writing, not just documented for someone else to action later. |
| Findings-only register | Items we reviewed that are working correctly, or that are matters for your counsel rather than for us. Documented so you know they were checked. |
| Walkthrough call | A working session with Victor to go through the findings and answer questions. |
| 30 days of monitoring | Included from the date the fixes are confirmed complete. |
The audit report is delivered to you in full before any fix work begins, and it is written to be handed to your counsel or to another firm without translation. That is deliberate: it means the findings are an honest assessment rather than a sales document. If something in it is better handled by someone other than us, the report says so plainly.
4 The ceiling — what caps this engagement
The audit report defines the fix work. We audit first, we write the findings down, and that written list — in full — is what we resolve for $1,500. Nothing outside it, nothing added later.
You see the complete list before a single fix is made. It is not billed by the hour, it does not grow mid-engagement, and there is no discovery clause that lets it expand.
Included — fixes to your shared page templates
Your 445 pages run on a small number of shared templates. Fixing a heading structure or a contrast failure in a template fixes it on every page that uses it — that is the overwhelming majority of the site, resolved once, however many findings that turns out to be.
Not included — five things, named up front
- Writing your privacy policy text. That text is a legal document describing your firm's actual data practices, and it should not come from your web agency. You have elected to generate it through Termly (section 6). We tell you exactly what it needs to cover, and we publish and maintain the page once you have it.
- Bespoke work on individually hand-coded pages that don't run on a shared template.
- Rebuilding third-party embeds that can't be made accessible in place.
- Redesign, new pages, or new functionality of any kind.
- Third-party subscription costs — see section 6.
If we hit any of it, we stop. We tell you what it is, what it would take, and what it would cost — and we don't touch it until you say so. Declining costs you nothing; the item is simply documented in the report as outstanding.
You will never receive an invoice you did not approve in advance.
5 Timeline
Two weeks to the report, thirty days to done — from the day we have access, and excluding any wait on your privacy policy text, which is the one item whose timing isn't ours. If anything urgent surfaces mid-audit, we tell you immediately rather than holding it for the report.
6 Termly — the third-party subscription
You have chosen Termly for both the cookie consent banner and for generating your privacy policy. That is a sound choice and it is what most of our clients use.
- The subscription is yours, not ours. Termly bills you directly, at their published rate for the plan you select. We do not mark it up and we take no commission on it.
- We install, configure and connect it as part of the $1,500 — the consent banner wired so nothing fires before consent, and your generated policy published to a proper page on the site.
- The policy content is yours. Termly's generator produces the text from the answers you give it about how your firm actually handles data. Those answers, and the accuracy of them, are Catalyst's. We will tell you exactly what the page needs to disclose based on what the audit finds on your site, and we will publish and maintain it — but we do not author the legal text and we are not certifying it.
- Your counsel is welcome to review it before it goes live. That is simple to accommodate and we would rather you did.
7 What we need from you
- WordPress administrator access to catalyst.com, for the platform and plugin currency checks and for the remediation work.
- Your Termly account — set up on the plan you choose, with us able to configure it, or the credentials to do so on your behalf.
- Your privacy policy text once Termly has generated it and anyone at Catalyst who needs to has reviewed it. We cannot publish the page until that exists.
- A point of contact for approvals — the walkthrough call, and sign-off on the fix list before remediation starts.
Delays on any of these move the completion date, and we will tell you when that is happening rather than let it drift quietly.
8 The “www” issue is ours, and it is not on this invoice
We host and maintain this site, so a record that stopped pointing to the right place is our responsibility, not something to put on a proposal. The certificate warning is already resolved; the remaining routing change is ours to finish, at no charge, regardless of what you decide here. We're also adding a monitor so a lapse like it surfaces immediately rather than sitting unnoticed for months.
9 Scope and limitations
This is not legal advice
Thomas Digital assesses websites; we do not practise law. This audit documents what your website does and how it measures against published technical standards. What that means for Catalyst's legal exposure is a question for your counsel, and our report is written specifically so they can use it. It is the same reason your privacy policy text needs to describe how your firm actually handles data, stated by the people who can stand behind it — we can tell you precisely what the page must disclose, but we are not the ones certifying that you are compliant.
An audit is a snapshot, not a permanent state
Compliance drifts the moment a page is added or a new tool is installed. We'll say so plainly in the report and recommend how to keep it current — but the audit itself certifies a point in time.
We will not install an accessibility overlay widget
These are marketed as one-click compliance and they do not work. The FTC fined a leading vendor in 2025 over compliance claims, and a substantial share of US accessibility lawsuits in 2025 targeted sites that already had one installed. Real remediation means fixing the underlying code, which is what we quote for.
Standard referenced
WCAG 2.1 Level AA. WCAG 2.2 exists and adds criteria, but 2.1 AA remains the operative benchmark in US practice. We'll note any 2.2 items we encounter without representing them as the governing standard.
10 Deliverables, goals & guarantees
We agree to deliver the services above. We guarantee the work, and we will keep working on it until it is right. What we don't do is guarantee a business outcome or a legal outcome we don't control — we are not attorneys, we are not a certifying body, and no agency can promise you immunity from a claim. Anyone who tells you otherwise is guessing. We don't offer a money-back guarantee on services already rendered.
11 Ownership & rights
Everything we create for you under this agreement belongs entirely to you once it is paid for — the audit report, the inventories, the code changes. We retain no rights to it and won't reuse it on another project. We do reserve the right to reference the engagement in our portfolio and case studies without disclosing findings.
We work as an independent contractor, not as your employee, and we're responsible for our own taxes, insurance and equipment. Your domain name stays registered in your name and under your control throughout — we never take ownership of it.
The audit report and its findings are confidential to Catalyst. We will not disclose them to anyone outside Thomas Digital without your written say-so.
12 Copyright & trademark
For any text, graphics, photographs, logos or trademarks you send us to include or publish, you confirm that you either own them or have permission to use them, and you agree to hold us harmless from any claim arising from materials you provided. This includes the privacy policy text you supply under section 6.
13 What we're not responsible for
We deliver this work in good order and we stand behind it. We are not responsible for infrastructure we don't manage — your email service, your domain registrar, Termly's own platform, or third-party systems you connect later. If something outside this scope breaks, we'll help you sort it out, but it isn't covered by this agreement.
14 Payment
| Line item | Amount |
|---|---|
| Three-domain audit — accessibility, privacy & tracking, technical security | included |
| Written report, tracker & cookie inventory, prioritised remediation plan | included |
| Walkthrough call with Victor | included |
| The fixes — every finding within the ceiling, re-tested and confirmed | included |
| Consent platform installed and configured; policy page published | included |
| 30 days of monitoring after completion | included |
| 50% deposit — due on signing, work begins on receipt | $750 |
| 50% balance — due on completion, at written confirmation of the re-test | $750 |
| Total, fixed | $1,500 |
| Termly subscription — billed to you directly by the vendor, not marked up | vendor rate |
Invoices are payable on receipt. The deposit starts the work; the balance is due once we deliver the re-test confirmation that the findings within the ceiling are resolved. There is no third invoice, and nothing in this engagement is billed by the hour.
One clarification on “completion,” so neither of us is guessing later: the balance becomes due when we confirm in writing that everything within the ceiling and within our control is resolved and re-tested. Publishing your privacy policy page depends on you supplying the Termly-generated text (section 6), and that one item is the only part of this whose timing isn't ours — so an outstanding policy text does not hold up the balance. We publish the page as soon as the text reaches us, at no further charge.
Signing below starts the project. Victor will send your invoice and payment link by email separately — nothing is charged through this page.
15 Optional — Compliance Care, after the fixes
Entirely optional, and nothing below changes the $1,500 you agreed. Compliance drifts — a new page, a new marketing tool, a plugin update; any of it can reintroduce what we just resolved.