// Legal
Care Plan Service Description
Version 1.3 · Anomalist Enterprise LLC, an Indiana limited liability company
Jump to a section
Version 1.3 · Effective 2026-08-04 Anomalist Enterprise LLC · Incorporated by reference into each Sites SOW
This document defines what a Sites care plan covers. It is referenced by, and forms part of, each Statement of Work that includes a Plan. Provider may revise it on thirty (30) days' written notice; the version in effect on a client's order date governs until that client's next renewal.
1. WHAT "ONE UPDATE" MEANS
ONE UPDATE is one request, submitted through the client dashboard, that changes existing content on existing pages, and that we complete in a single working session of up to THIRTY (30) MINUTES.
Unit of work, not unit of change. "Swap these four photos and fix the phone number in the footer," sent as one request, is ONE update. The same four items sent as four separate messages over four days are FOUR updates. Batching your requests is always to your advantage.
IN SCOPE as a content update
- Text edits on existing pages
- Image swaps (you supply the image)
- Hours, prices, contact details, addresses
- Publishing a blog post or podcast episode from content you provide
- Adding or removing a navigation or menu item
- Link updates and corrections
NOT AN UPDATE — quoted separately at our published rates
- New pages ($95)
- Layout or design changes
- New sections, features, forms, or integrations
- Copywriting or content creation
- Sourcing or licensing stock imagery
- Photo or asset refresh sessions ($75)
- Anything exceeding 30 minutes of work. We tell you before we start and quote it; we never run over and bill you afterward.
CONTENT IS CLIENT-PROVIDED AND FINAL
Copy should be written and images should be at usable resolution. One typo-correction pass after we publish is included. A second substantive revision starts a new update.
NO ROLLOVER
Unused updates do not carry into the next month (MSA §11.2). Requests beyond your allowance are, at your election, quoted as a one-time add-on or deferred to the next cycle.
HOW TO SUBMIT
Updates must be submitted as a ticket in the client dashboard. This is how the count stays accurate and auditable for both of us. Requests sent by text message, phone call, or direct email are not tracked and may be missed; we will ask you to re-submit them through the dashboard.
2. ALWAYS INCLUDED — NEVER COUNTS AGAINST YOUR UPDATES
- Dependency and security patching
- Uptime monitoring
- SSL certificate and security-header maintenance
- Your monthly (or weekly) report
- Restoring a deployment that we broke
- Correcting a defect in our own work
3. WHAT EACH PLAN INCLUDES
ESSENTIALS PUBLISHER GUARDIAN
$29/mo $79/mo from $199/mo
$290/yr $790/yr $1,990/yr
Content updates $25 each, Up to 8 Up to 12
as needed per month per month
Uptime monitoring Yes 24/7 + alerts 24/7 + performance
Dependency & security Monitored, Scan on every Advanced scans +
patching patched deploy form testing
SSL / headers Maintained Maintained Maintained
Reporting Monthly Monthly + SEO Weekly + quarterly
and traffic strategy call
Client dashboard Yes Yes Yes
Response time 5 business days 1 business day Same day
Incident response Not included Not included Up to 4 hrs/mo(see Section 5)
Response time is the time within which we acknowledge and schedule your request, not the time within which the work is delivered. Delivery timing is agreed per request.
4. MONITORING, PATCHING, AND WHAT WE ACTUALLY DO
Your site is watched continuously by Provider's own automated systems. Every day we check that the site is reachable, that its certificate is valid and not near expiry, that its security headers are intact, and that its dependencies have no newly published vulnerabilities. Code changes are screened before they ship.
Security and dependency updates are reviewed by a person before they are applied to a client site. We do not auto-merge changes into client repositories. This is deliberate: an unreviewed automatic update is how sites break.
Our monitoring reduces risk. It does not eliminate it, and we do not warrant that no incident will occur (MSA §6.3, §7.3).
5. INCIDENT RESPONSE (GUARDIAN ONLY)
If the site is down, defaced, or compromised, Guardian includes up to four (4) hours per calendar month of response work during business hours (9am–5pm Central, Monday–Friday), consisting of: triage, restoring the site from version control to a known-good state, rotating any credentials we hold, and a written summary of what happened.
Incident response does NOT include: forensic investigation; legal advice; regulatory or individual breach notification; credit monitoring or remediation for affected persons; recovery of data not held in the site repository; or work on systems Provider does not maintain. Those are outside this Plan and outside Provider's scope. Hours beyond the monthly allowance are quoted before work proceeds.
6. REPORTING
Your report covers uptime, traffic, SSL and security-header status, dependency and vulnerability status, and any work performed during the period. It is delivered to your dashboard and by email. Where a data source is unavailable for a period, the report says so; we do not estimate or fill gaps.
7. DOMAIN AND HOSTING
You purchase and own your domain, with your own payment method. Provider does not purchase, hold, renew, or advance the cost of any domain, and is not responsible for a lapsed registration. We will remind you ahead of a renewal we can see, and we will advise on registrar and TLD choice.
Hosting on Cloudflare Pages is free at the volumes a site of this kind produces. If your traffic ever exceeds the free tier, we will tell you before anything changes.
Your domain and your Cloudflare account are in your own name. Your code repository is the one exception, and it works like this.
7A. YOUR CODE, AND WHERE IT LIVES
Your code is yours from the moment it is written — not when the last invoice clears (MSA §4.1). Nothing about where it is stored changes that.
We keep the repository in a private repository inside Provider's GitHub organization while we maintain it. We do that because the protections we sell only work from inside our organization: enforced review rules, blocking a credential before it can be committed, continuous scanning, and automated patching. We hold it as custodian for you (MSA §6.5), and we pay GitHub for it — you do not.
You have read access from day one. You can browse, clone, and download the complete project, full history included, whenever you like, without asking us (MSA §6.6(a)).
You can have a full copy any time. Ask, and we deliver the complete repository — every branch, every commit, plus the deployment runbook and the list of what it depends on — within five business days, at no charge. There are no conditions attached: not payment status, not a dispute, not signing anything (MSA §6.6). We never hold your code back for any reason, and we have no lien or right of retention over it (MSA §6.5.2).
Asking for it costs you nothing. Taking a copy does not change your plan, your price, or what you get. If you also want the repository moved out of our organization, we will do that free too — and within ten business days we must tell you in writing exactly which protections we can no longer run and why. Then it is your choice: keep the plan at the same price, keep it at a proportionately lower price, or cancel immediately with a refund for the unused part of the month (MSA §6.7).
There is never only one copy. We keep an independent backup outside GitHub, refreshed daily and test-restored quarterly, and where you have your own Cloudflare account we put a copy there too. If Provider ever stopped operating, your code reaches you automatically (MSA §6.8).
8. SUSPENSION, CANCELLATION, AND WHAT YOU KEEP
If a subscription charge fails, Provider may suspend Plan services, including monitoring, until payment is current (MSA §2.4). Suspension is not termination.
You may cancel at any time (MSA §11.1). Services continue through the end of the billing period you have paid for and stop at that date — there is no notice period to serve, no partial-period refund, and no cancellation fee.
On cancellation you end up with everything, and you do not have to ask for any of it.
The domain, the Cloudflare account, and the deployed site are already yours and already in your name — nothing has to move. The site keeps running the moment we stop; it is static and hosted in your own account.
The repository is the one thing we hold, so we send it to you. Within five (5) business days of the end date we deliver the complete repository — every branch, full history — together with the deployment runbook, the list of services it depends on, and the names and locations of the credentials it needs, and we confirm delivery with a checksum. You do not have to request it, and there is no fee for it. This happens even if the plan ended because of unpaid invoices (MSA §6.4).
We keep our own copy for ninety (90) days afterwards purely as a safety net in case the handover misses something — we will re-send it free during that window — and then we delete it. You can tell us to delete it sooner.
Provider removes its own access within fifteen (15) days of confirming delivery (MSA §6.4). What stops is the monitoring, the patching, the reporting, and the updates.
9. PRECEDENCE
This Service Description supplements the MSA and the applicable SOW. If it conflicts with the MSA, the MSA controls. If it conflicts with the SOW, the SOW controls.
Anomalist Enterprise LLC · support@anomalistenterprise.com
Read to the end of the description to continue.
I have read and agree — go backQuestions before you agree to anything? Email hello@anomalistenterprise.com. We would genuinely rather answer them now than argue about them later.